Key Facts
- Breach Timeline: Unauthorized access began in March 2026, detected on June 30, 2026 — approximately 120 days of undetected access
- Affected Jurisdictions: 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada
- Affected Courts: Appellate courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, Ohio, Pennsylvania, Wyoming
- Vendor: C-Track, owned by West Publishing Corporation (a subsidiary of Thomson Reuters)
- Data Potentially Exposed: Names, addresses, Social Security numbers, driver’s license numbers, medical information, sealed court filings, juvenile records, mental health proceedings, domestic violence protective orders, grand jury proceedings
- India’s e-Courts Scale: Over 1.25 crore cases e-filed; 817 courts equipped with ICT infrastructure in Odisha alone
Direct Answer
The C-Track breach represents a systemic risk that India’s rapidly digitizing judiciary cannot afford to ignore. In March 2026, an unauthorized third party gained access to Thomson Reuters’ C-Track court case management platform.
The intrusion remained undetected for 120 days — until June 30, 2026. The breach affected court systems in at least 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The files potentially contained personal information, including Social Security numbers, driver’s license numbers, medical records, and sealed court filings — including juvenile records, mental health proceedings, and domestic violence protective orders. The incident exposes a fundamental vulnerability: one vendor serving multiple courts creates concentrated supply-chain risk.
India, with its e-Courts Mission Mode Project digitizing the judicial system at scale — over 1.25 crore cases e-filed, 817 courts equipped with ICT infrastructure, and the Inter-operable Criminal Justice System (ICJS) integrating police, courts, and prisons — must learn from this breach. The Digital Personal Data Protection (DPDP) Act, 2023, provides a framework, but Section 17(1)(b) exempts courts from key provisions while preserving the obligation for “reasonable security safeguards” under Sections 8(1) and 8(5). The C-Track breach is a warning: India must ensure its digital courts are not just accessible, but resilient.
In this article:
- The C-Track Breach: What Happened
- Systemic Risk: One Vendor × Many Courts
- What Data Was Exposed
- Why the 120-Day Dwell Time Matters
- India’s Judicial Digitization at Scale
- The DPDP Act and the Court Exemption
- What India Must Learn from C-Track
- FAQ
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police forces since 1996.
The C-Track Breach: What Happened
On June 30, 2026, Thomson Reuters detected unauthorized activity within one of its cloud environments. The activity was traced to the company’s C-Track case management platform, a system used by courts to manage case files, track proceedings, and store sensitive information.
The Timeline
- March 2026: An unauthorized third party obtained certain C-Track files
- June 30, 2026: Thomson Reuters detected the unauthorized activity
- July 2026: Affected court systems were notified
- September 2026: The breach became public
The breach went undetected for approximately 120 days — from March 1 through June 29, 2026.
The Affected Jurisdictions
The breach impacted court systems in:
- 11 U.S. states: Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, South Carolina, Tennessee, Ohio, Pennsylvania, and Wyoming
- The U.S. Virgin Islands
- Ontario, Canada
Systemic Risk: One Vendor × Many Courts
The C-Track breach exposes a fundamental vulnerability in modern court systems: vendor concentration.
As one cybersecurity analyst observed: “Court-management platforms can aggregate information from many independent judicial organizations inside a single technology ecosystem. That creates concentrated supply-chain risk: One vendor compromise → multiple courts → multiple jurisdictions → potentially sensitive legal records.”
The Problem
When multiple court systems rely on a single vendor for case management, a breach at that vendor becomes a breach across all those systems. The C-Track breach affected appellate courts across 11 states, the U.S. Virgin Islands, and Ontario — all because one vendor’s systems were compromised.
The Scale
Thomson Reuters is not a small vendor. C-Track is used by 24 court organizations across North America. The breach affected court systems in multiple jurisdictions simultaneously, demonstrating the cascading nature of vendor-based risk.
The Lesson
As Brent Arnold, a partner at INQ Law in Toronto, noted: “Organizations are very dependent on their vendors, so it points to the real importance of having robust cybersecurity in those vendors, and making sure you have the protections you need for your data that you would want to put in place if you were managing it yourself.”
What Data Was Exposed
The breach potentially exposed highly sensitive information that courts are legally obligated to protect.
Types of Data Potentially Accessed
The Sealed Records Problem
C-Track is not a public records portal. It is the case management infrastructure behind state court operations. Sealed records — including juvenile case files, mental health proceedings, and domestic violence protective orders — are protected by court order. Their disclosure is, in many jurisdictions, a criminal offense.
The Personal Stake
One commentator, writing about the breach, noted: “My juvenile records are sealed. Not ‘private’ — sealed. There’s a court order saying those files do not exist in any database a background check can reach… And if that file leaks, every search of your name pulls it up. Every employer, landlord, school, agency. The expungement order is still there, but the file is in the wild, and you can’t expunge Google.”
Why the 120-Day Dwell Time Matters
The breach went undetected for 120 days. In cybersecurity terms, “dwell time” — the period between initial compromise and detection — is a critical metric.
120 Days Is Not an Intrusion. It Is Residency.
As one cybersecurity expert observed: “One hundred twenty days is not an intrusion. It’s residency.”
The Implications
- Data Exfiltration: An attacker with 120 days of access can exfiltrate vast amounts of data
- Lateral Movement: The attacker could have moved to other systems within the vendor’s environment
- Persistence: The attacker could have established backdoors for future access
- Compounding Risk: The longer the dwell time, the greater the damage
The Response
Thomson Reuters engaged external cybersecurity experts, notified law enforcement, and secured the C-Track environment. However, the damage had already been done.
India’s Judicial Digitization at Scale
India is digitizing its judicial system at a scale that dwarfs the C-Track breach’s scope.
The e-Courts Mission Mode Project
The e-Courts Mission Mode Project is being implemented in phases across the country to strengthen the use of Information and Communication Technology (ICT) in the judicial system.
Key Statistics (as of June 30, 2026)
- Over 1.25 crore cases filed through the e-Filing system
- 817 out of 845 courts equipped with ICT hardware in Odisha alone
- 42.96 lakh legacy case records digitized (24.17 crore pages) in Odisha
- 3.10 lakh FIRs and 2.29 lakh chargesheets consumed through the Inter-operable Criminal Justice System (ICJS) platform since January 2026
- 7.61 lakh virtual hearings conducted in Odisha
The ICJS Framework
The Inter-operable Criminal Justice System (ICJS) is based on the principle of ‘one data one entry’. It connects the five pillars of the criminal justice system: police, courts, prisons, forensics, and prosecution.
The Attack Surface
As India’s courts digitize rapidly — embracing video conferencing, e-filing, live-streaming, and digital case records — the attack surface has expanded. The Delhi High Court experienced a cybersecurity incident in April 2026 when obscene content disrupted a virtual hearing before the Chief Justice’s Bench. This incident triggered a police cybercrime probe and renewed concerns over courtroom security.
The DPDP Act and the Court Exemption
The Digital Personal Data Protection (DPDP) Act, 2023, provides the legal framework for data protection in India.
Section 17(1)(b) Exemption
Section 17(1)(b) of the DPDP Act exempts the processing of personal data by any court or tribunal or any other body in India entrusted with judicial or quasi-judicial functions.
The Rationale
The exemption is intended to preserve the independence of the judiciary and ensure that courts can function without regulatory interference.
The Obligation That Survives
However, the fundamental obligation to provide reasonable safeguards to prevent breaches of personal data still applies under Section 8(1) and Section 8(5) of the DPDP Act. Courts are not exempt from the obligation to protect personal data — they are exempt from certain procedural requirements.
The Gap
The DPDP Act’s Section 17 exemptions effectively remove enforcement mechanisms for court-processed personal data. This creates a governance gap: courts have the obligation to protect data but may lack the regulatory oversight needed to ensure compliance.
What India Must Learn from C-Track
The C-Track breach is not a distant problem. It is a warning for India’s judicial digitization efforts.
1. Vendor Risk Management Is Critical
India’s e-Courts project relies on multiple technology vendors. The C-Track breach demonstrates that vendor concentration creates systemic risk. The ICJS framework, which integrates data across police, courts, and prisons, must ensure that every vendor in the chain meets robust security standards.
2. Real-Time Monitoring Is Essential
A 120-day undetected breach is unacceptable. India’s digital court systems must implement real-time monitoring, intrusion detection, and rapid incident response capabilities.
3. Sealed Records Must Be Protected
Indian courts handle sealed records — juvenile cases, matrimonial disputes, witness protection files, and sensitive commercial matters. The C-Track breach demonstrates that sealed records are not immune to cyberattacks.
4. Zero-Trust Architecture
Courts must adopt zero-trust access controls, immutable logs, and strict identity verification for all users accessing case management systems.
5. Independent Audits
Regular, independent security audits of all court technology systems — including vendor-supplied systems — must be mandatory.
6. Judicial Cyber-Forensic Response Teams
India should establish dedicated judicial cyber-forensic response teams to investigate and respond to breaches affecting court systems.
7. DPDP Act Implementation
The government must ensure that the DPDP Act’s security safeguards are effectively implemented for court systems, despite the Section 17(1)(b) exemption.
8. The Delhi High Court Incident
The April 2026 incident, where obscene content disrupted a virtual hearing in the Delhi High Court, was a warning. The C-Track breach is a confirmation. India’s digital courts must be not just accessible, but resilient.
FREQUENTLY ASKED QUESTIONS (FAQ)
What is the C-Track breach?
The C-Track breach is a cybersecurity incident where an unauthorized third party gained access to Thomson Reuters’ C-Track court case management platform in March 2026. The intrusion remained undetected until June 30, 2026 — approximately 120 days.
How many jurisdictions were affected?
The breach affected court systems in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.
What data was potentially exposed?
The breach potentially exposed names, addresses, Social Security numbers, driver’s license numbers, medical records, and sealed court filings — including juvenile records, mental health proceedings, and domestic violence protective orders.
What is systemic risk in this context?
Systemic risk refers to the vulnerability created when multiple court systems rely on a single vendor. One vendor compromise can affect all the courts that use that vendor’s systems.
What is India’s e-Courts project?
The e-Courts Mission Mode Project is India’s initiative to digitize the judicial system, including e-filing, video conferencing, digital case records, and the Inter-operable Criminal Justice System (ICJS).
How many cases have been e-filed in India?
Over 1.25 crore cases have been filed through the e-Filing system as of June 30, 2026.
What is the DPDP Act’s Section 17(1)(b) exemption?
Section 17(1)(b) exempts courts and tribunals from certain provisions of the DPDP Act, but the obligation to provide “reasonable security safeguards” under Sections 8(1) and 8(5) still applies.
What happened in the Delhi High Court in April 2026?
Obscene content disrupted a virtual hearing before the Chief Justice’s Bench, triggering a police cybercrime probe and raising concerns about court cybersecurity.
What should India do to prevent a C-Track-style breach?
India should implement vendor risk management, real-time monitoring, zero-trust access controls, independent audits, and dedicated judicial cyber-forensic response teams.
Is the C-Track breach relevant to India?
Yes. India is digitizing its judicial system at scale, and the C-Track breach demonstrates the systemic risks of vendor concentration and inadequate cybersecurity in court systems.
KNOWLEDGE CHECK QUIZ
Q: What specific platform was compromised in the C-Track court management data breach detected in June 2026? Ans: Thomson Reuters’ C-Track cloud-based court case management platform.
Q: How long was the unauthorized intrusion undetected, representing a critical “dwell time”? Ans: Approximately 120 days, spanning from March 1 to June 29, 2026.
Q: What statutory provision under India’s DPDP Act, 2023, provides an exemption for courts and tribunals? Ans: Section 17(1)(b).
Q: Despite the court exemption under the DPDP Act, what substantive security obligations still apply to data fiduciaries managing judicial data? Ans: The obligation to implement “reasonable security safeguards” under Sections 8(1) and 8(5) of the DPDP Act.
FREQUENTLY ASKED QUESTIONS (FAQ)
Q: What makes vendor concentration a systemic risk in modern court administration?
Ans: When multiple independent judicial jurisdictions rely on a single vendor’s software ecosystem, a single vulnerability compromise cascades across all connected court systems simultaneously.
Q: What categories of highly sensitive data were potentially exposed in the C-Track breach? Ans: Personal identifiers (Social Security and driver’s license numbers), medical records, and protected sealed court filings such as juvenile records, mental health proceedings, and domestic violence protective orders.
Q: How does India’s Inter-operable Criminal Justice System (ICJS) magnify cybersecurity stakes? Ans: The ICJS connects police, courts, prisons, forensics, and prosecution under a ‘one data one entry’ framework, vastly expanding the digital attack surface if a single pillar is compromised.
Q: What practical lessons must Indian judicial IT administrators draw from the C-Track incident? Ans: Administrators must enforce rigorous vendor risk management, deploy real-time threat monitoring to eliminate extended dwell times, maintain zero-trust access controls, and mandate independent security audits.
Explore More:
Read my blog: Shoeb Hakim Blog
Book Now: Book a Consultation
Contact: Contact Adv. Shoeb Hakim
Careers: Careers at Shoeb Hakim
By Adv. Shoeb Hakim
Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police since 1996.
📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
Additional Page Metadata
Author:
Adv. Shoeb Hakim
Author Bio:
Adv. Shoeb Hakim is a Mumbai-based criminal defence, AML, digital forensics and cybercrime specialist. Former General Counsel at Credit Suisse. Has been training police forces since 1996. Provides expert commentary on cybersecurity, data protection, and judicial technology.
Article Publisher:
Adv. Shoeb Hakim
Article Section:
Cybersecurity | Data Protection | Judicial Technology | e-Courts
Article Tags:
C-Track breach, Thomson Reuters, court data breach, systemic risk, e-Courts India, ICJS, DPDP Act, judicial cybersecurity, vendor risk, data protection, Adv Shoeb Hakim
#AdvShoebHakim #CTrackBreach #Cybersecurity #DigitalCourts #DPDPAct #ICJS #WhiteCollarCrime #DigitalForensics #LegalDefense #Compliance



Leave a Reply