PrivacySignal
Breach

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

The Hacker News · · International · Data Breaches

A data breach affecting Thomson Reuters court software may have exposed Social Security numbers and sealed legal records, according to reports. The full scope of the incident has not been confirmed, but the nature of the data involved points to serious risks for individuals whose information passes through the legal system.

Why this matters: Sealed records are sealed for a reason. They protect victims, juveniles, whistleblowers, people in witness protection, and anyone a court decided deserved a layer of safety. A breach that touches that data is not a typical password leak. Thomson Reuters runs software that sits inside legal infrastructure, which means a single security failure can reach people who never chose to interact with Thomson Reuters at all. SSNs on top of sealed case data is a combination that enables fraud, harassment, and worse. The company owes clear answers about what was exposed, for how long, and who is affected.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
HIPAA Journal · · US Federal

Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack

Midwest Spine and Brain Institute, along with Brookhaven ENT Allergy and Facial Surgery and Digestive Disease Center, have disclosed data breaches stemming from a ransomware attack on a shared vendor. The incidents follow a pattern of healthcare providers being exposed through third-party service relationships.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
DataBreaches.net · · International

CNIL: Health data breach: €500,000 fine imposed on the Loire Private Hospital

France's data protection authority, the CNIL, fined the Loire Private Hospital €500,000 after an attacker gained unauthorized access to its electronic patient record system during the summer of 2025, exposing data belonging to patients and some of their family members.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals

#breach#enforcement#healthcare Read original →
Breach
The Guardian — Tech · · International

Serbians targeted with spyware in country’s ‘largest documented wave of surveillance’

At least 14 members of Serbian civil society, including student protesters, were infected with advanced spyware in what digital rights group Share Foundation calls the largest documented surveillance wave in Serbia. The infections came to light in August after Apple alerted probable spyware victims across 110 countries.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#surveillance#privacy Read original →
Breach
BleepingComputer · · International

French hospital fined €500,000 after breach exposes data of 727,000

France's data protection authority, CNIL, fined a private Loire hospital €500,000 after a breach exposed personal data belonging to 727,000 patients and their relatives. The penalty reflects a failure to maintain adequate data security standards.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · AI governance · General readers · Policy

#breach#enforcement#gdpr#privacy Read original →
Breach
DataBreaches.net · · International

The New School Safety Perimeter: Where Cybersecurity Meets Physical Security

Schools and universities increasingly tie student ID numbers to both digital systems and physical access controls — the same credential that logs a student into a portal may also open their dorm room. A breach of that central database can therefore compromise physical security across an entire campus, not just personal data.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai Read original →
Breach
BleepingComputer · · International

Coder's registry infrastructure compromised to push malicious modules

Attackers breached Coder's Cloudflare infrastructure and inserted unauthorized registry servers that served up malicious Terraform modules designed to steal credentials. The compromise affected the supply chain for infrastructure code that organizations use to build and manage cloud environments.

Who should care: Cybersecurity · Privacy officers · Administrators