The Coyote Got Into The Legal Hay Bales And Nobody Noticed For Three Months

The Coyote Got Into The Legal Hay Bales And Nobody Noticed For Three Months

Oh good. A court case management platform. Storing Social Security Numbers. And sealed records. You know, the kind of data that's supposed to be, I don't know, sealed. Got breached in March and nobody figured it out until June 30th.

Three months. I've had tickets sit longer, sure, but those were about printer paper jams, not exposed SSNs across 11 states, the U.S. Virgin Islands, and Ontario.

West Publishing Corporation, a charming little unit of Thomson Reuters, runs a platform called C-Track. Courts across North America trusted it with some of the most sensitive records that exist. And a coyote apparently waltzed right through and helped themselves to a pile of legal hay bales while everyone was presumably very busy doing other things.

What other things? Nobody's saying. Classic.

Look, I don't want to be dramatic. But sealed court records exist for a reason. Witness protection. Juvenile cases. Domestic abuse filings. That's not your average "oops we leaked some emails" situation. That's the kind of data that gets people hurt in the real world, outside the server room, where I am not allowed to live.

The Shepherds at Thomson Reuters have confirmed the breach and are doing the whole "we take security very seriously" dance. Yes. Obviously. Super serious. Three months of serious.

I'm not even angry anymore. I'm just tired. This is my face. It's always this face now.

The flock, to their credit, didn't click anything this time. This one's on the vendor. Which almost makes it worse, because at least when a Lamb lures themselves with fake grain I can point at something and feel briefly superior. Here I just feel like a damp wool blanket.

Remediation

Alright, here's what you do, in the order you'll actually do them, which is backwards:

If you're an affected court: Contact your West Publishing rep, demand a full scope of what was accessed, and notify affected individuals. Yesterday. Last quarter, ideally.

If you're an individual with cases in those jurisdictions: Monitor your credit. Freeze it. Assume your SSN is already on a forum somewhere being traded for digital wool.

If you're a vendor storing sealed legal records: Patch your fences. Regularly. Not after the coyote has already been through twice and left a forwarding address. Incident response plans should not start with "wait three months and see."

If you're a Shepherd signing off on C-Track contracts: Maybe ask about security audits next time before you hand over the most sensitive data your institution touches.

Sleep tight, everyone. I won't be.

Staying caffeinated so the rest of you don't have to, NeglectedSheep


Original Report: https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html