A single case management vendor used by state courts across the country has become the point of failure for a dozen independent judicial systems at once. C-Track, a product of West Publishing Corporation (part of Thomson Reuters), disclosed a data security incident that has now touched Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Oregon, Pennsylvania, South Carolina, Tennessee and Wyoming, along with the U.S. Virgin Islands and courts in Ontario, Canada. None of those courts had their own networks compromised. The failure happened one layer up, inside a shared vendor none of them individually control.
What happened
C-Track notified affected courts on July 23, 2026, that it had experienced a data security incident potentially involving information the platform maintains for appellate case management and e-filing. In its own statement, the North Dakota Court System, one of the affected jurisdictions, said C-Track “advised that the incident originated within its own systems and was not the result of a compromise of North Dakota Court System networks, and that C-Track’s system functionality was not affected.” The North Dakota court added there is “no evidence that nCourt, the system used to process financial transactions, was impacted by the incident.”
The exposed data varies by court but includes names, Social Security numbers, driver’s license numbers, dates of birth, medical information and health insurance details drawn from case files. At some courts, confidential, redacted or sealed documents may also have been affected, a category of exposure that carries legal weight well beyond a typical consumer data breach because sealed filings exist specifically to keep information out of public view by court order.
C-Track has retained outside legal counsel and an investigation firm, notified law enforcement, and says a criminal investigation is underway. The vendor is standing up a dedicated incident website and call center and has committed to offering 12 months of free credit monitoring and identity theft protection to individuals it identifies as affected, though the full scope, including exact numbers, had not been determined as of the North Dakota court’s most recent update.
The shift: shared court infrastructure is a single point of failure
The individual breach mechanics matter less here than what the footprint reveals. State courts do not typically build or operate their own case management software. They license it from a small number of vendors whose platforms sit underneath appellate dockets, e-filing portals and, in some jurisdictions, sealed case records across many states simultaneously. When one of those platforms is compromised, the blast radius is not a single agency’s user base. It is every court, in every state, that outsourced the same function to the same company, plus in this case a foreign court system that licensed the same product.
That is a structurally different risk profile than a breach at a single retailer or hospital network. A state court system cannot simply swap case management vendors the way a company might switch a cloud provider after an incident; procurement cycles, statutory requirements and case-continuity obligations make vendor lock-in the default. The incident also lands on a class of data with fewer commercial precedents for handling: sealed filings, juvenile records and protective order details are not the kind of information a standard breach-response playbook, built around payment cards or health records, was designed to triage.
What it means for the security leader
For CISOs and risk leaders at public-sector agencies and regulated industries alike, the lesson is not about C-Track specifically. It is about the assumption that a vendor’s security posture is proportional to the sensitivity of the data it holds. A backend case management platform is not typically classified as a crown-jewel system inside a court’s own risk register, because the court does not operate it. But the data flowing through it, sealed records, PII, medical details tied to litigation, is exactly the kind of data a crown-jewel classification exists to protect. Vendor risk assessments that stop at uptime and support SLAs and never reach the vendor’s own detection and containment maturity will keep missing this category of exposure.
The three-month gap between when unauthorized access is assessed to have begun and when it was confirmed and disclosed is also instructive. A platform serving a dozen government customers is a higher-value target precisely because compromising it once yields access across many independent organizations at the same time, which argues for shorter dwell-time tolerances and more aggressive anomaly detection on multi-tenant government SaaS platforms than on single-tenant systems, not less.
Security and legal teams at any organization relying on a shared third-party platform for records with statutory confidentiality requirements, sealed court files, HR case files, regulatory filings, should use this incident to ask a narrower question than “is our vendor secure”: what happens to records that are legally required to stay confidential when a vendor holding them for dozens of customers is compromised, and who is accountable for that disclosure timeline. Other recent incidents have shown how differently companies handle the gap between confirming a breach and disclosing its scope, and the space between containing an intrusion and disclosing it has become its own risk category independent of the breach itself.
The timeline compounds the exposure. Access is assessed to have begun in March 2026; the vendor says it discovered the activity in late June; the affected courts were not notified until July 23; and public notice, credit monitoring and a call center were still being finalized in early September. Every one of those gaps, discovery to internal confirmation, confirmation to customer notification, notification to public disclosure and remediation, is a window in which affected individuals had no way to protect themselves and no way to know protection was needed. Multiply that window across a dozen states and a foreign jurisdiction and the practical effect is that tens of thousands of people whose cases touched an appellate docket or e-filing system may not learn their Social Security number or driver’s license data was exposed until months after the exposure occurred.
For procurement and vendor-risk teams, the actionable step is contractual rather than technical: breach-notification clauses with shared government SaaS vendors should specify a maximum internal-to-customer notification window measured in days, not left to the vendor’s discretion, and should require the vendor to disclose dwell time and scope estimates as they are known rather than waiting for a final number. A platform that serves this many sovereign customers at once should be underwriting faster disclosure commitments than a single-tenant vendor, not slower ones.
Source: North Dakota Court System statement on the C-Track data security incident

