Bởi ITCuli

Cảnh báo Thomson Reuters Court Software: rủi ro cần kiểm tra ngay

Cảnh báo Thomson Reuters Court Software: rủi ro cần kiểm tra ngay

Bản viết lại dựa trên nguồn: https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data –> #1 Trusted Cybersecurity News Platform Followed by 5.70+ million      Get the Latest News Home Newsletter Webinars Home Threat Intelligence Vulnerabilities Cyber Attacks Webinars Expert Insights Awards    Resources Webinars Awards Free eBooks About Site About THN Jobs Advertise with us Contact/Tip Us  Reach out to get featured—contact us to send your exclusive story idea, research, hacks, or ask us a question or leave a comment/feedback! Follow Us On Social Media       RSS Feeds  Email Alerts Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data Swati KhandelwalSep 03, 2026Data Breach / Privacy Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names, Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information, the company said. The firm is offering potentially affected individuals 12 months of Experian IdentityWorks credit monitoring, with enrollment open until December 31, 2026, using a multi-use code published in the notice, and a hotline at 1-833-918-5294 that requires the engagement number B171847. In Canada, Thomson Reuters Canada Limited is offering 12 months of TransUnion myTrueIdentity monitoring with a call center scheduled to open on September 4. "Certain confidential, redacted or sealed information may have been impacted for certain affected courts," West Publishing said in its September 2 notice, adding that there is no evidence to date of fraud or misuse of the information. The West Publishing notice and the Canadian notice from Thomson Reuters Canada Limited name the following court systems – Alabama - Alabama Appellate Courts Kentucky - Kentucky Appellate Courts Montana - Montana Supreme Court Nevada - Nevada Appellate Courts New Hampshire - The New Hampshire Supreme Court North Dakota - North Dakota Supreme Court Ohio - First, Second, Third, Fourth, Fifth, Sixth, Seventh, Ninth, Eleventh, and Twelfth District Courts of Appeals Pennsylvania - Commonwealth of Pennsylvania Environmental Hearing Board (former client), Court of Common Pleas of Washington County, Fifth Judicial District of Pennsylvania, and the Court of Common Pleas of Monroe County, which the notice lists by county name only South Carolina - Supreme Court of South Carolina and the South Carolina Court of Appeals Tennessee - Tennessee Appellate Court Clerk's Office Wyoming - Wyoming Judicial Branch U.S. Virgin Islands - Supreme and Superior Courts Ontario - Court of Appeal for Ontario, Ontario Superior Court of Justice, and Ontario Court of Justice The Hacker News reviewed the West Publishing notice on September 3, 2026; it lists 24 court bodies in 11 states and the U.S. Virgin Islands, with Minnesota absent from the list. The Minnesota Judicial Branch said on September 2 that data from its appellate courts was exposed in the incident, that it has terminated Thomson Reuters' access to the courts' electronic environments, and that users of the appellate case management system must change their passwords. Minnesota Supreme Court Chief Justice Natalie Hudson said she is "deeply troubled that our court users' data has been compromised." In Montana Supreme Court's release, the court said the material taken was backup data stored on Thomson Reuters servers, drawn from database copies that had been "supplied to TR for the purpose of troubleshooting the applications." Those databases may hold case numbers, party names and addresses, phone numbers, the charge and docket entry descriptions, and, for some individuals charged with a crime, driver's license numbers and dates of birth, the release said. Unauthorized access to that storage location ran from March 1 through June 29, 2026, per the court's account of the vendor's notice. The Alabama Appellate Courts said West Publishing later told them that a copy of some Alabama appellate court data was kept in a backup file within the company's cloud environment, a backup the courts said they had neither requested nor known about. "This incident occurred within our vendor's systems, not our own," Alabama Chief Justice Sarah Stewart said. The Supreme Court of Ohio, however, said in its own statement that Thomson Reuters Court Management Solutions (TRCMS) informed it on August 31 that "the unauthorized access took place on the Court's production platform." That platform hosts the filing system data of the 10 Ohio appellate districts that use C-Track, with the Eighth and Tenth districts unaffected. The Hacker News has reached out to Thomson Reuters for clarification on which environment was accessed and whether Minnesota courts are affected, and will update this story with any response. "There has been no operational disruption to C-Track as a result of this incident," a Thomson Reuters spokesperson told Reuters, adding that the company considers the platform safe to keep using. The Supreme Court of Ohio said it has yet to receive comprehensive details of the enhanced security measures TRCMS told it have been deployed. Ontario's Court of Appeal, Superior Court of Justice, and Court of Justice said in the three chief justices' statement that Thomson Reuters detected the activity within one of its cloud environments. The chief justices said "it is still unclear what information may have been compromised," and that anyone involved in court proceedings or mentioned in court documents could have had personal information involved. In Wyoming, the material taken was historical data from the Wyoming Supreme Court and district courts, primarily involving people who dealt with those courts between 2015 and 2025, the state's Judicial Branch said in its release. The preliminary review indicates that "limited personal information, including names, addresses and dates of birth, was compromised," the branch added. Wyoming gives the hotline's hours as 7 a.m. to 7 p.m. Mountain Time. The Virgin Islands courts said they received notice on July 27 and can so far confirm only that the accessed data "related to its 2018 system implementation project." Trial court e-filing in Kentucky is untouched because the state does not use third-party vendors for it, Kentucky's court administrators said, adding that there is "no indication at this point that the unauthorized third party distributed the Kentucky data." Montana and Minnesota each said that court documents were not part of the accessed data, although the vendor's notice states that sealed material may have been affected for certain courts. The vendor notified the courts and Ontario's Ministry of the Attorney General between July 23 and July 27. Public disclosure followed on September 2, a date Montana said was chosen so that the vendor and the other states involved could issue simultaneous announcements. As of September 3, no party had published a count of affected individuals, the method by which the files were obtained, or the identity of whoever was responsible. North Dakota's statement said the incident involved only North Dakota Supreme Court data, with the state's district courts and its Odyssey system unaffected. It added that there is no evidence nCourt, the system used to process financial transactions, was impacted. "There is an active criminal investigation into this incident," the North Dakota Court System said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share  Share on Facebook Share on Twitter Share on Linkedin Share on Reddit Share on Hacker News Share on Email Share on WhatsApp Share on Facebook Messenger Share on Telegram SHARE  Cloud security, data breach, Supply Chain ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control Cybersecurity Webinars Here's How to Fight Back How to Identify Which CVEs Are Truly Exploitable Within Hours See how to test new CVEs against your environment, confirm what attackers can actually exploit, and fix the exposures that pose the greatest risk. Register Know Your Real Exposure Learn How to Know What to Fix First Before AI Speeds Up the Attack Learn how to identify exploitable risk faster, prioritize what matters most, and reduce exposure before AI-powered attacks accelerate the threat. Register ⚡ Latest News Cybersecurity Resources 11 Real Stories: How Identity Exposure Unlocks Active Attack PathsMap cross-domain privilege escalation to sever breach routes at key choke points. SANS 2026 Security Awareness & Culture Report Shows What's Next11 years of practitioner data on what it takes to keep pace with a field that keeps shifting. Prevention Already Failed. What Does Your Monitoring Actually Catch?A 6-day SANS course rebuilds hybrid detection across cloud, endpoint, and network. GMON, Sept 21. ​ Expert Insights Articles Videos Blind Spots and Backdoors: Practical Advice for Identity Risk Reduction September 7, 2026 Read ➝ The Economics of Dwell Time and Why AI Native SIEM Changes the Equation September 7, 2026 Read ➝ Shadow AI Is Now Hiding Inside Sanctioned AI Tools August 31, 2026 Read ➝ The EU CRA Will Make You Report What It Hasn't Yet Made You Fix August 31, 2026 Read ➝ Get the Latest News in Your Inbox Get the latest news, expert insights, exclusive resources, and strategies from industry leaders, all for free. Email Connect with us! 2,300,000 Followers 730,000 Followers 26,000 Subscribers 180,000 Followers 1,800,000 Followers 65,000 Followers Company About THN Advertise with us Contact Pages Webinars Awards Privacy Policy  RSS Feeds  Contact Us © 2026 The Hacker News. All Rights Reserved.