AI Security AI安全 7h ago Updated 2h ago 更新于 2小时前 41

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data 汤森路透法院软件漏洞可能泄露社保号和密封数据

Thomson Reuters disclosed that an unauthorized party accessed C-Track court case management platform files between March 1 and June 29, 2026, affecting courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada A subset of exposed court records may contain highly sensitive personal data including Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information Thomson Reuters is offering 12 months of credit monitoring throug Thomson Reuters旗下C-Track法院案件管理平台于2026年3月至6月遭未经授权访问,影响美国11个州、美属维尔京群岛及加拿大安大略省共24个法院机构 泄露数据包含姓名、社会安全号码、驾照号码、出生日期、医疗及健康保险信息等敏感个人数据,部分涉及密封或删减的机密案件信息 各州法院对事件性质存在分歧:部分称数据来自第三方备份环境,俄亥俄州则确认攻击发生在法院生产平台 Thomson Reuters提供12个月Experian/TransUnion身份监控服务,截至2026年9月尚未发现数据被滥用或欺诈证据 明尼苏达州已终止Thomson Reuters访问权限并要求用户更改密码,

62
Hot 热度
60
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • Thomson Reuters disclosed that an unauthorized party accessed C-Track court case management platform files between March 1 and June 29, 2026, affecting courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada
  • A subset of exposed court records may contain highly sensitive personal data including Social Security numbers, driver's license numbers, dates of birth, medical information, and health insurance information
  • Thomson Reuters is offering 12 months of credit monitoring through Experian (U.S.) and TransUnion (Canada) for affected individuals, with enrollment open until December 31, 2026
  • Minnesota Judicial Branch confirmed its appellate court data was exposed despite not being listed in the original notice, and has terminated Thomson Reuters' access to its electronic environments
  • There is currently no evidence of fraud or misuse of the compromised information, and Thomson Reuters maintains that C-Track operations remain uninterrupted and safe to use

Why It Matters

This breach highlights the critical supply-chain risks inherent in government agencies relying on third-party vendors for sensitive court case management systems, where a single vendor compromise can cascade across multiple jurisdictions. The exposure of sealed, redacted, and confidential judicial data—including SSNs and medical information—underscores the severe privacy and security implications for individuals whose most sensitive personal records were entrusted to a commercial platform. For AI and technology practitioners, this incident serves as a stark reminder that cloud-based legal tech infrastructure requires rigorous vendor security audits, transparent data retention policies, and clear contractual boundaries around backup data storage.

Technical Details

  • The breach occurred on Thomson Reuters' C-Track platform, a court case management system operated by its West Publishing Corporation unit, with unauthorized access spanning from March 1 through June 29, 2026, and discovered on June 30, 2026
  • The scope of compromised data varied by jurisdiction: some courts reported exposure of backup data stored on Thomson Reuters servers (Montana, Alabama), while Ohio reported unauthorized access directly on the production platform hosting filing system data for 10 appellate districts
  • Affected data types include names, Social Security numbers, driver's license numbers, dates of birth, addresses, phone numbers, case numbers, charge and docket entry descriptions, medical information, and health insurance information; certain confidential, redacted, or sealed court information was also potentially impacted
  • The incident affected 24 court bodies across Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, the U.S. Virgin Islands, and Ontario, Canada, with Minnesota confirming exposure despite not being in the original notice
  • Thomson Reuters stated there has been no operational disruption to C-Track and considers the platform safe to continue using, though Ohio's Supreme Court noted it has not yet received comprehensive details of enhanced security measures deployed by TRCMS

Industry Insight

  • Government agencies and court systems must conduct thorough vendor risk assessments that go beyond production environments to include backup data, cloud storage locations, and troubleshooting database copies—since some courts discovered unauthorized data retention they never requested or authorized
  • Legal technology vendors should implement transparent data governance frameworks that clearly define what data is stored, where backups reside, and who has access, as the lack of clarity across jurisdictions has eroded trust and created confusion about the true scope of the breach
  • The incident reinforces the importance of contractual clauses requiring vendors to notify clients promptly of security incidents and provide detailed breach disclosures, as conflicting narratives between Thomson Reuters and individual courts about whether access occurred on production or backup systems have complicated response efforts and damaged institutional confidence

TL;DR

  • Thomson Reuters旗下C-Track法院案件管理平台于2026年3月至6月遭未经授权访问,影响美国11个州、美属维尔京群岛及加拿大安大略省共24个法院机构
  • 泄露数据包含姓名、社会安全号码、驾照号码、出生日期、医疗及健康保险信息等敏感个人数据,部分涉及密封或删减的机密案件信息
  • 各州法院对事件性质存在分歧:部分称数据来自第三方备份环境,俄亥俄州则确认攻击发生在法院生产平台
  • Thomson Reuters提供12个月Experian/TransUnion身份监控服务,截至2026年9月尚未发现数据被滥用或欺诈证据
  • 明尼苏达州已终止Thomson Reuters访问权限并要求用户更改密码,Alabama首席大法官强调事件发生在供应商系统而非法院自身系统

为什么值得看

本文揭示了法律科技基础设施供应链安全的典型风险案例——法院系统高度依赖第三方平台管理敏感案件数据,一旦供应商遭攻击将引发跨司法管辖区的连锁泄露。对AI从业者而言,该事件凸显了云端案件管理系统在数据备份策略、生产/测试环境隔离及供应商安全审计方面的关键漏洞,为司法AI系统的合规部署提供了反面教材。

技术解析

  • C-Track平台架构:Thomson Reuters West Publishing部门运营的云端法院案件管理系统,托管11个州上诉法院的立案系统数据,采用云环境存储生产数据及备份副本,部分法院(如Alabama)存在未经请求的自动备份文件
  • 数据泄露范围:未经授权访问持续3个月(2026年3月1日至6月29日),涉及备份服务器及生产平台两类环境,泄露数据类型包括案件编号、当事人姓名地址、电话号码、指控描述、驾照号码及出生日期等
  • 各州响应差异:Montana法院确认泄露数据为用于故障排除的数据库副本;Ohio最高法院指出攻击发生在法院生产平台;Ontario法院表示受影响数据与2018年系统实施项目相关;Wyoming法院限定为2015-2025年历史数据
  • 身份监控方案:美国地区提供Experian IdentityWorks 12个月监控(注册截止2026年12月31日),加拿大地区提供TransUnion myTrueIdentity服务,设立专属热线(B171847)处理咨询

行业启示

  • 供应链安全审计必要性:法院等关键基础设施高度依赖第三方SaaS平台,需建立供应商安全分级评估机制,明确数据备份策略、环境隔离标准及访问权限边界,避免"影子IT"成为攻击入口
  • 司法数据分级保护标准:案件数据包含大量PII及密封信息,应实施动态脱敏、加密存储及访问日志审计,对历史数据归档与生产数据实行物理或逻辑隔离,降低单点泄露影响范围
  • 应急响应透明度建设:各州法院对事件性质表述存在矛盾,建议建立统一的网络安全事件通报框架,明确供应商披露时限、数据影响范围评估方法及跨辖区协同响应流程,提升公众信任度

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Legal AI 法律AI