CSIDB logo
Incident

C-Track

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-09 20:42

Linked entities

Victim
C-Track
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

C-Track, a Thomson Reuters subsidiary that provides state court records systems, was hit by a cyberattack that affected courts in 11 states. A subset of court records was involved, including records that may contain personal identification information, and some confidential, redacted, and sealed records may also have been accessed. The company said the incident was not caused by issues with state court systems or their security measures, and it had no evidence that financial transaction systems were impacted.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

C-Track, a Thomson Reuters Corp. subsidiary that provides state court records systems, was affected by a cyberattack that occurred in March 2026. The incident impacted courts in 11 states. The available source material identifies C-Track as the Thomson Reuters company subsidiary targeted in the attack. It states that a subset of court records was involved. Some of those records may have contained personal identification information. The source also states that some confidential, redacted, and sealed records may have been accessed. The articles do not identify the specific states affected, the number of records involved, the type of cyberattack used, or the identity of the attacker.

The incident was discovered on June 30, 2026. According to the news release described in the articles, the incident did not occur because of issues with state court systems or with any of their security measures. The release also stated that C-Track had no evidence that systems for financial transactions were impacted. The articles do not describe additional confirmed details about containment, remediation, law enforcement involvement, customer notification, or restoration activities. The public information provided is limited to the occurrence of the March cyberattack, its discovery on June 30, the involvement of court records in 11 states, the possible exposure of personal identification information, the possible access to confidential, redacted, and sealed records, and the statement that financial transaction systems were not known to be affected.

Sources

Sources available to members: 2 sources.

CSIDB