TrustCenter

Thomson Reuters court software breached in March, disclosed in September

September 8, 2026. From issue 5 of The Compliance Brief, 3 stories for Canadian companies answering customer security reviews.

Last reviewed 2026-09-08Written by Jacob Masse, TrazTech Inc.

Issue 5 of The Compliance Brief was published on September 8, 2026. 3 of its 5 stories bear on security reviews, vendor diligence and trust, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: The Hacker News

Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing unit, in March 2026. The company said it discovered the activity on June 30, 2026.

Our take, in short

The number that matters here is not the state count, it is the four months between intrusion and detection, followed by another two before public disclosure. Every enterprise security questionnaire you fill out asks how quickly you detect and notify, and buyers are getting better at asking whether your clock starts at intrusion or at discovery.

Read the full take on traztech.ca

McKesson tells the SEC it was hit through third-party applications

Source: Help Net Security

McKesson disclosed a cybersecurity incident in which attackers got into third-party applications and stole data, with the intrusion detected on August 25, 2026. The SEC filing says the investigation is in its early stages and the company has not determined the incident is material or likely to be material.

Our take, in short

Read that filing from the other side of the table. You are the third-party application in somebody's stack, and when a customer of yours writes their own version of this disclosure, your name goes in it.

Read the full take on traztech.ca

An ID verification vendor appears to be the source of 153 million licence scans

Source: Krebs on Security

A new dark web identity theft service is selling digital scans of more than 153 million driver's licences belonging to people in the United States and Canada. Interviews with affected individuals suggest the images were siphoned from a widely used identity verification company based in Louisiana.

Our take, in short

Anyone doing KYC has an identity verification vendor, and most founders I talk to have never asked that vendor how long it keeps the document images after the check comes back clean. Retention is the control that would have made this a much smaller story, and it costs nothing to shorten.

Read the full take on traztech.ca

Also in issue 5

Outside security reviews, vendor diligence and trust, but in the same email:

Older: issue 4 All issues on TrustCenter Newer: issue 6