Security.io Intelligence DeskFriday, 4 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Third-Party Risk · Executive briefing

C-Track breach exposes the limits of court-vendor assurance

Files obtained from a hosted court-management environment may include personal, medical, confidential, redacted or sealed information, while the affected-person and court-level inventories remain unresolved.

Data ProtectionThird-Party RiskRegulatory
Why it is in today’s brief

The file acquisition dates to March and detection to June 30; public notices arrived September 2, just beyond the core 30-hour window, and September 3 reporting consolidated the multi-jurisdiction scope and unresolved record inventory. Inclusion is justified because courts and organisations named in litigation now need vendor-specific data scoping and notification governance, a different decision from platform availability or routine SaaS assurance.

Read first

C-Track disclosed that an unauthorised party obtained files associated with multiple North American court systems. Platform operations continued, but the possible inclusion of sealed and sensitive records requires court-specific data scoping, safety assessment and defensible notification decisions.

Act now

Identify every court, agency and legal workflow dependent on C-Track.

Accountable owner

CISO with court administration, general counsel, privacy leadership and safeguarding teams

Decision horizon

Dependency identification and vendor engagement today; record-level risk and notification disposition within 48 hours.

AssessmentMedium confidence
Emerging riskCourt-level file inventories, affected-person counts, evidence of misuse, direct notifications, access-vector details and law-enforcement attribution.

What happened

In March 2026, an unauthorised party obtained certain C-Track files associated with multiple court systems. On June 30, 2026, C-Track discovered unauthorised third-party activity and began an investigation with external experts and law enforcement. On July 23, 2026, C-Track notified the North Dakota Court System that information maintained by the state supreme court might have been involved. On September 2, 2026, C-Track and multiple courts publicly disclosed the incident and began coordinated notification.

A subset of affected court records could contain names, Social Security numbers, driver’s licence numbers, medical information, dates of birth or health-insurance information, and certain confidential, redacted or sealed information may have been involved. The C-Track notice named court systems in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, Oregon, South Carolina, Tennessee, New Hampshire, Ohio, Wyoming and the U.S. Virgin Islands, while Reuters separately reported 11 U.S. states, the Virgin Islands and Canada.

C-Track reported no operational disruption, no evidence that financial-transaction systems were affected and no evidence of fraud or information misuse at the time of notice. The selected sources did not publish an initial-access vector, actor identity, definitive affected-person count or court-by-court file inventory. Attribution posture: Reuters could not determine who was responsible, and no actor attribution has been established.

Why this matters now

Court data has consequences beyond ordinary identity theft. Sealed, redacted or confidential records can contain protected addresses, medical details, information about minors, witnesses, litigants and law-enforcement activity. A generic credit-monitoring response does not address personal-safety, legal-process or confidentiality risks associated with each affected case.

The incident demonstrates a third-party boundary that many institutions do not inventory well: backup and troubleshooting data supplied to a hosted platform. Court networks could remain uncompromised and operations could continue normally while sensitive information held in the provider environment was obtained. Local system health is therefore not evidence that institutional data escaped the incident.

Organisations outside the named court systems may still need action if employees, customers or protected parties appear in affected proceedings. General counsel, privacy teams and security leaders should establish whether the organisation has relevant litigation exposure and ensure suspicious messages referencing court matters receive enhanced verification.

The decision for security leaders

Demand scoped assurance rather than accepting the provider’s aggregate notice. Each affected institution needs its own file categories, case identifiers, access dates, data subjects, remediation evidence and remaining investigative limitations. Where the vendor cannot provide that inventory, record the assurance gap and adopt a conservative notification posture.

Create a separate safety review for sealed, redacted and otherwise protected material. Legal, privacy and safeguarding teams should determine whether exposed information could endanger an individual, reveal a protected address or compromise an active proceeding. Credit monitoring is not a substitute for this assessment.

Review the full data lifecycle with court-platform providers. Contracts, architecture and operating procedures should identify what backup or troubleshooting data leaves institutional systems, how long it remains, who can access it and what evidence the provider must produce after an incident.

Evidence of closure

  • A vendor inventory identifies affected files, cases, courts and data subjects.
  • Legal records document the disposition of every sealed or protected matter.
  • Notification records identify each person notified or the approved reason for non-notification.
  • Supplier assurance documents the access boundary, remediation evidence and unresolved limitations.

The Security.io assessment

Direct notices establish that files were obtained from the provider environment and that operations remained available. They do not establish an exact affected-person population, complete court inventory or downstream use. Confidence is therefore high in the incident itself but lower in the public scope description.

The jurisdiction discrepancy should remain visible until reconciled. It may reflect different customer definitions, notice timing or affected-system lists, but the selected evidence does not establish the reason. Security.io does not convert those inconsistent lists into a definitive state or court count.

The absence of known fraud does not materially reduce the confidentiality concern associated with sealed or sensitive legal records. The decision is not whether to stop using functioning court services; it is whether each institution can prove which data the provider held, what was obtained and which individuals require direct support or protection.

Questions for the morning meeting

  • Which court, agency or legal workflows rely on C-Track or associated vendor backups?
  • Can the vendor provide a court-specific file and person inventory?
  • Which sealed or protected matters require safety-focused escalation?
  • Who owns coordinated legal, privacy and individual notification decisions?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →