Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publicly on Wednesday, along with separate notification pages for affected individuals in the United Sta

Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, which exposed court records and sensitive personal information across numerous jurisdictions in the United States and Canada. The company publicly announced the incident on Wednesday, September 2, 2026, alongside dedicated notification pages for individuals in both countries.
The breach was discovered on June 30, 2026, when Thomson Reuters identified unauthorized activity related to certain C-Track information. An investigation, conducted with external cybersecurity experts and law enforcement, determined that an unauthorized third party had accessed and obtained C-Track files in March 2026.
In Canada, the affected court systems include the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. The chief justices of these courts noted that the precise scope of compromised information and the number of affected individuals remain under assessment. They indicated that personal information of individuals involved in or mentioned in court proceedings could have been exposed.
In the U.S., the breach impacted appellate courts in Alabama, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, and New Hampshire. Also affected were the entire state court system of Wyoming, the U.S. Virgin Islands Supreme and Superior Courts, and multiple District Courts of Appeals in Ohio (First, Second, Third, Fourth, Fifth, Sixth, Seventh, Ninth, Eleventh, and Twelfth). County-level courts in Pennsylvania (Washington County and the Fifth Judicial District) and Ohio (Monroe County) were also affected. The Oregon Judicial Department confirmed its appellate courts were impacted, and the Commonwealth of Pennsylvania Environmental Hearing Board, a former client, was also involved.
Thomson Reuters stated that the incident occurred within its own cloud environment and was not a result of vulnerabilities in the networks, systems, or data security of the affected courts. The C-Track platform remains fully operational, and the company has implemented additional security measures, reviewed and approved by outside experts.
The exposed data varied by location but may have included individuals' names along with one or more of the following: Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance information. In some U.S. courts, confidential, redacted, or sealed court information may also have been compromised.
As of the disclosure, Thomson Reuters has found no evidence that the exposed information has been used for fraud or other misuse, nor that systems handling financial transactions were affected. The company is offering 12 months of free credit monitoring and identity theft protection to all affected individuals.
Key details regarding the identity of the attacker, the full extent of data taken, and the method of initial access remain publicly undisclosed by Thomson Reuters. The company's investigation with cybersecurity experts and law enforcement is ongoing.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]