Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: c-track (1 article)Clear

Thomson Reuters court software breach exposed personal and sealed case records

Thomson Reuters disclosed that attackers obtained files from C-Track, a court case-management platform sold by its West Publishing unit, affecting courts across eleven US states, the US Virgin Islands, and Ontario, Canada. The intrusion happened in March and was not discovered until the end of June. Exposed records may include names, Social Security numbers, driver's license numbers, dates of birth, and medical and insurance information, and at some courts confidential, redacted, or sealed court information may also have been taken. The stolen data came from database backups that courts had supplied to the vendor for troubleshooting. How the attackers got in, and why they went unnoticed for months, remains unanswered.

Check
People in affected court cases should watch for identity theft and use the offered credit monitoring, and organizations should limit the sensitive and backup data they hand to software vendors for support.
Affected
Individuals whose details appear in affected court records, including some sealed cases; exposed names, Social Security numbers, and health data enable identity theft and fraud, with added risk from sealed-case exposure.
Fix
Affected people should monitor credit and court accounts; organizations should minimize data shared with vendors, avoid supplying sensitive backups for troubleshooting, encrypt vendor-held data, and hold third parties to strong security terms.