The Oregon Judicial Department on Sept. 2 disclosed a data breach of the case management system used by the Oregon Court of Appeals and Oregon Supreme Court and said the agency is taking action to secure all department systems and networks.
"As the Judicial Branch, our primary concern is the people who appear before our courts, and the security of their information when interacting with these systems. That's why we take all measures available to ensure that security," Chief Justice Meagan Flynn said in a statement. "For a vendor to allow a security breach of this nature to occur is unacceptable. The Oregon Judicial Department is publicly sharing what information we do have in the interest of transparency and out of an abundance of caution, and we will continue to share information as we get it from our vendor."
According to an incident website, West Publishing Corporation, doing business as Thomson Reuters, discovered unauthorized activity involving certain information in the cloud-hosted system it operates, known as C-Track, on June 30.
In a statement, C-Track said it launched an investigation into the incident as part of its cybersecurity incident response protocols and found that, in March, an unauthorized party obtained certain C-Track files associated with several court systems, including the Oregon Appellate Courts.
None of Oregon's systems, including circuit courts or the Tax Court, were involved, and the daily operations of Oregon's courts throughout the state were also not impacted, OJD said.
The incident website said the subset of court records affected could contain individuals' names and one or more of the following: Social Security numbers, driver's license numbers, medical information, dates of birth and health insurance information.
"Certain confidential, redacted or sealed information may have been impacted for certain affected courts. While these courts' data was affected, the incident was not caused by the courts' networks, systems or data security. There is no evidence that systems used to process financial transactions were impacted by the incident," C-Track said in a statement.
The Oregon Judicial Department said it had done an "extensive cyber analysis" since learning of the incident and taken steps to ensure continued security. OJD said it has also been "demanding answers and accountability," and leadership expects more details from Thomson Reuters in the coming weeks, including what data may have been involved.
OJD said that if it learns any personal or confidential information was exposed, it will work to notify each impacted individual and share information about available options, including free credit monitoring.
Questions should be directed to the Thomson Reuters hotline at 1-833-918-5294 with an engagement number B171847, OJD said.
Dianne Lugo covers the Oregon Legislature and equity issues. Reach her at [email protected] on X @DianneLugo or Bluesky @diannelugo.bsky.social
This article originally appeared on Salem Statesman Journal: Case system used by Oregon's appellate courts part of data breach