LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
breach

Thomson Reuters reveals breach that exposed U.S. and Canadian court records

Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published the disclosure publicly on Wednesday, along with separate notification pages for affected individuals in the United Sta

zeroday.news ·

Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, which exposed court records and sensitive personal information across numerous jurisdictions in the United States and Canada. The company publicly announced the incident on Wednesday, September 2, 2026, alongside dedicated notification pages for individuals in both countries.

The breach was discovered on June 30, 2026, when Thomson Reuters identified unauthorized activity related to certain C-Track information. An investigation, conducted with external cybersecurity experts and law enforcement, determined that an unauthorized third party had accessed and obtained C-Track files in March 2026.

In Canada, the affected court systems include the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. The chief justices of these courts noted that the precise scope of compromised information and the number of affected individuals remain under assessment. They indicated that personal information of individuals involved in or mentioned in court proceedings could have been exposed.

In the U.S., the breach impacted appellate courts in Alabama, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, and New Hampshire. Also affected were the entire state court system of Wyoming, the U.S. Virgin Islands Supreme and Superior Courts, and multiple District Courts of Appeals in Ohio (First, Second, Third, Fourth, Fifth, Sixth, Seventh, Ninth, Eleventh, and Twelfth). County-level courts in Pennsylvania (Washington County and the Fifth Judicial District) and Ohio (Monroe County) were also affected. The Oregon Judicial Department confirmed its appellate courts were impacted, and the Commonwealth of Pennsylvania Environmental Hearing Board, a former client, was also involved.

Thomson Reuters stated that the incident occurred within its own cloud environment and was not a result of vulnerabilities in the networks, systems, or data security of the affected courts. The C-Track platform remains fully operational, and the company has implemented additional security measures, reviewed and approved by outside experts.

The exposed data varied by location but may have included individuals' names along with one or more of the following: Social Security numbers, driver's license numbers, medical information, dates of birth, and health insurance information. In some U.S. courts, confidential, redacted, or sealed court information may also have been compromised.

As of the disclosure, Thomson Reuters has found no evidence that the exposed information has been used for fraud or other misuse, nor that systems handling financial transactions were affected. The company is offering 12 months of free credit monitoring and identity theft protection to all affected individuals.

Key details regarding the identity of the attacker, the full extent of data taken, and the method of initial access remain publicly undisclosed by Thomson Reuters. The company's investigation with cybersecurity experts and law enforcement is ongoing.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

FBI Probes Possible Breach of 153 Million Driver’s Licenses

The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

phishing

Outsider Phishing Kit Survives Takedown With 700 New Pages

Outsider phishing kit generated 700 new pages after a Google-led disruption

security

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]

nation-state

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms

Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Institute of Science and Technology (KAIST), working with the National University of Singapore and Singapore Management University