Montana Court Data Exposed in Thomson Reuters Vendor Breach
Chief Justice Cory Swanson reports unauthorized access to C-Track backup files affecting multiple state courts.
The Montana state court system has fallen victim to a data breach that exposed sensitive judicial records and personal information. The incident, which occurred over several months, highlights the systemic vulnerabilities inherent in relying on third-party vendors for critical government infrastructure.
According to Montana Supreme Court Chief Justice Cory Swanson, unauthorized access took place between March 1, 2026, and June 29, 2026. The breach specifically targeted backup files within the C-Track case management and E-Filing systems. Crucially, the compromised systems were not owned or operated by the state of Montana, but were instead managed by West Publishing Co., a subsidiary of Thomson Reuters. The exposure was not isolated to one region, as the breach affected multiple state courts across the U.S.
The Vendor Vulnerability
This incident underscores a growing trend of "supply chain" attacks where government entities are compromised not through their own networks, but through the software providers they employ. By utilizing centralized platforms like C-Track for case management and electronic filing, state judiciaries gain efficiency but inherit the security risks of the vendor. In this instance, the vulnerability lay in the backup architecture of Thomson Reuters, meaning the state's data was exposed despite the internal security measures of the Montana court system itself.
Implications for Judicial Privacy
Breaches within the judicial branch are uniquely damaging because they can compromise the privacy of litigants and potentially expose sealed documents. When personally identifiable information (PII)—such as driver's license numbers and dates of birth—is leaked, it creates long-term identity theft risks for citizens interacting with the law. Beyond the individual harm, such lapses undermine public trust in the integrity of the legal process, as the court is expected to be the ultimate guarantor of confidentiality and the rule of law.
Next Steps and Oversight
As the investigation continues, the focus shifts to the exact volume of data exfiltrated and the specific identities of those affected. Legal experts and policymakers are likely to scrutinize the contracts between state governments and vendors like Thomson Reuters, specifically regarding liability and the frequency of security audits for backup systems. For now, the Montana judiciary remains in a position of damage control, waiting for full disclosure from the vendor on how the entry occurred and what measures have been implemented to prevent a recurrence.