What happened
In March 2026, an unauthorised party obtained certain C-Track files associated with multiple court systems. On June 30, 2026, C-Track discovered unauthorised third-party activity and began an investigation with external experts and law enforcement. On July 23, 2026, C-Track notified the North Dakota Court System that information maintained by the state supreme court might have been involved. On September 2, 2026, C-Track and multiple courts publicly disclosed the incident and began coordinated notification.
A subset of affected court records could contain names, Social Security numbers, driver’s licence numbers, medical information, dates of birth or health-insurance information, and certain confidential, redacted or sealed information may have been involved. The C-Track notice named court systems in Alabama, Pennsylvania, Kentucky, Montana, Nevada, North Dakota, Oregon, South Carolina, Tennessee, New Hampshire, Ohio, Wyoming and the U.S. Virgin Islands, while Reuters separately reported 11 U.S. states, the Virgin Islands and Canada.
C-Track reported no operational disruption, no evidence that financial-transaction systems were affected and no evidence of fraud or information misuse at the time of notice. The selected sources did not publish an initial-access vector, actor identity, definitive affected-person count or court-by-court file inventory. Attribution posture: Reuters could not determine who was responsible, and no actor attribution has been established.
Why this matters now
Court data has consequences beyond ordinary identity theft. Sealed, redacted or confidential records can contain protected addresses, medical details, information about minors, witnesses, litigants and law-enforcement activity. A generic credit-monitoring response does not address personal-safety, legal-process or confidentiality risks associated with each affected case.
The incident demonstrates a third-party boundary that many institutions do not inventory well: backup and troubleshooting data supplied to a hosted platform. Court networks could remain uncompromised and operations could continue normally while sensitive information held in the provider environment was obtained. Local system health is therefore not evidence that institutional data escaped the incident.
Organisations outside the named court systems may still need action if employees, customers or protected parties appear in affected proceedings. General counsel, privacy teams and security leaders should establish whether the organisation has relevant litigation exposure and ensure suspicious messages referencing court matters receive enhanced verification.
The decision for security leaders
Demand scoped assurance rather than accepting the provider’s aggregate notice. Each affected institution needs its own file categories, case identifiers, access dates, data subjects, remediation evidence and remaining investigative limitations. Where the vendor cannot provide that inventory, record the assurance gap and adopt a conservative notification posture.
Create a separate safety review for sealed, redacted and otherwise protected material. Legal, privacy and safeguarding teams should determine whether exposed information could endanger an individual, reveal a protected address or compromise an active proceeding. Credit monitoring is not a substitute for this assessment.
Review the full data lifecycle with court-platform providers. Contracts, architecture and operating procedures should identify what backup or troubleshooting data leaves institutional systems, how long it remains, who can access it and what evidence the provider must produce after an incident.
Evidence of closure
- A vendor inventory identifies affected files, cases, courts and data subjects.
- Legal records document the disposition of every sealed or protected matter.
- Notification records identify each person notified or the approved reason for non-notification.
- Supplier assurance documents the access boundary, remediation evidence and unresolved limitations.
The Security.io assessment
Direct notices establish that files were obtained from the provider environment and that operations remained available. They do not establish an exact affected-person population, complete court inventory or downstream use. Confidence is therefore high in the incident itself but lower in the public scope description.
The jurisdiction discrepancy should remain visible until reconciled. It may reflect different customer definitions, notice timing or affected-system lists, but the selected evidence does not establish the reason. Security.io does not convert those inconsistent lists into a definitive state or court count.
The absence of known fraud does not materially reduce the confidentiality concern associated with sealed or sensitive legal records. The decision is not whether to stop using functioning court services; it is whether each institution can prove which data the provider held, what was obtained and which individuals require direct support or protection.
Questions for the morning meeting
- Which court, agency or legal workflows rely on C-Track or associated vendor backups?
- Can the vendor provide a court-specific file and person inventory?
- Which sealed or protected matters require safety-focused escalation?
- Who owns coordinated legal, privacy and individual notification decisions?