C-Track, a court-management platform owned by Thomson Reuters subsidiary West Publishing Corporation, has confirmed that an unauthorized party obtained files associated with courts in the United States and Canada. C-Track discovered unauthorized activity on June 30, 2026. Its investigation found that the party had obtained certain files in March. Montana's Supreme Court says the access affecting its data continued from March through June.
The US notification names court systems in 11 states and the US Virgin Islands. Oregon disclosed its appellate courts separately, bringing the publicly known US state count to at least 12. Ontario's three courts also confirmed that they use the affected platform. The incident occurred in C-Track's environment, not because the affected courts' own networks or security controls were breached.
What C-Track has confirmed
C-Track says an unauthorized third party obtained a subset of court files. Depending on the court and record, those files could contain names and possibly Social Security numbers, driver's-license numbers, medical information, dates of birth or health insurance information. Some confidential, redacted or sealed information may also have been involved.
Those categories describe possible contents, not a finding that every listed field was taken from every jurisdiction or every person. Nevada officials cautioned that the data varies by court, and Montana said most of its affected material appeared to be public. C-Track has not published a person count, a file count or a court-by-court inventory.
The company says C-Track remained operational, financial-transaction systems show no evidence of impact, and it has no evidence of fraud or information misuse to date. It engaged external cybersecurity specialists and law enforcement, contained the activity and implemented additional security measures.
A vendor copy can become the shared point of failure
Court systems need vendors for hosting, support, backup and specialist workflows. The C-Track incident shows the concentration risk created when one provider holds copies for many institutions. An organization can secure its own network and still face exposure through a supplier environment that stores production data or support copies.
The practical question is not merely whether a vendor has the same data. It is why each copy exists, which fields it contains, who can retrieve it, how access is recorded and when the copy expires. A backup, diagnostic export or support bundle should not quietly become a second permanent case archive.
Separate the record, the authorization and the secret
Incident responders and court administrators need an audit trail: which system was affected, who approved an action, what was transferred and whether delivery completed. They do not need the password, recovery code or sensitive file embedded in the same long-lived ticket or chat transcript.
Keep authorization and evidence in the case-management or incident system. Transfer the minimum necessary file or recovery value separately after verifying the recipient. A compromised ticket account should not automatically reveal both the approval context and the plaintext material needed to act on it.
A safer workflow for sensitive court transfers
- Classify before exporting. Distinguish public filings from sealed, redacted and identity-bearing records before creating a support copy.
- Minimize the data set. Remove fields, cases and date ranges that the recipient does not need. Use synthetic or redacted examples for troubleshooting whenever possible.
- Set an owner and expiry. Every temporary export should have a business owner, a defined purpose and a deletion deadline at the court and the vendor.
- Verify the recipient independently. Do not approve a sensitive transfer solely from the email, call or chat that requested it.
- Use a separate delivery channel. Keep the audit record in the workflow system while moving the actual file or secret through an encrypted, short-lived path.
- Confirm receipt before deleting the source copy. A sender should not destroy the only recoverable copy until the recipient confirms successful decryption and validation.
- Audit supplier copies. Require evidence showing where production, backup and support data lives, who accessed it and when it was deleted.
Where Secretus fits—and where it does not
Secretus can reduce persistent exposure when an authorized court or vendor operator must deliver a small sensitive file, credential or recovery value. Standard and Maximum Security modes support encrypted file transfers up to 5 MB; one-time secret links can keep plaintext credentials out of permanent email, chat and ticket history.
Secretus is not a court-records repository, backup system, identity-proofing service or substitute for vendor access controls. It cannot make an unnecessary export necessary, clean a compromised endpoint or prevent an authorized recipient from saving a copy. Data minimization and independent recipient verification must happen before delivery.
What remains unknown
C-Track has not identified the attacker, initial-access method, total volume obtained or exact number of affected people. Public notices also do not provide a consistent jurisdiction count because Oregon disclosed its involvement separately. Further court reviews may narrow or expand the known record categories, so organizations should rely on their own court notice rather than assuming every field listed nationally applies to them.
