Thomson Reuters court software breached in March, disclosed in September
September 8, 2026. From issue 5 of The Compliance Brief, 2 stories for founders and executives who own security.
Issue 5 of The Compliance Brief was published on September 8, 2026. 2 of its 5 stories bear on breaches, incidents and security leadership, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for founders and executives who own security.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: The Hacker News
Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing unit, in March 2026. The company said it discovered the activity on June 30, 2026.
Our take, in short
The number that matters here is not the state count, it is the four months between intrusion and detection, followed by another two before public disclosure. Every enterprise security questionnaire you fill out asks how quickly you detect and notify, and buyers are getting better at asking whether your clock starts at intrusion or at discovery.
Read the full take on traztech.ca
An ID verification vendor appears to be the source of 153 million licence scans
Source: Krebs on Security
A new dark web identity theft service is selling digital scans of more than 153 million driver's licences belonging to people in the United States and Canada. Interviews with affected individuals suggest the images were siphoned from a widely used identity verification company based in Louisiana.
Our take, in short
Anyone doing KYC has an identity verification vendor, and most founders I talk to have never asked that vendor how long it keeps the document images after the check comes back clean. Retention is the control that would have made this a much smaller story, and it costs nothing to shorten.
Read the full take on traztech.ca
Related on HireACISO
- Do you need a vCISO? A six question check
- Security maturity assessment, seven domains
- Vendor risk management, done proportionately
- Bringing in a vCISO after a breach
Also in issue 5
Outside breaches, incidents and security leadership, but in the same email:
- FTC takes $4.85M from Nuvei over who it let onto its rails
- McKesson tells the SEC it was hit through third-party applications
- AI coding agents are pulling packages nobody registered
Older: issue 4 All issues on HireACISO Newer: issue 6
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.