A cyberattack targeting a widely used court software vendor compromised the Montana Supreme Court’s case management system for nearly four months earlier this year, Chief Justice Cory Swanson announced Wednesday in a news release, as first reported by the Billings Gazette. The breach was part of a multistate hacking campaign directed at Thomson Reuters, which operates the C-Track software used by Montana and more than a dozen other courts nationwide to store case information.

What Was Compromised

The unauthorized access to C-Track occurred between March 1 and June 30. Thomson Reuters notified Montana Court Administrator Dave McAlpin on July 23 that hackers had gained entry to the system, and the company made a broader public announcement two days later.

C-Track serves as the Montana Supreme Court’s primary case management platform and also backs up the court’s electronic filing system. While the bulk of data accessed appears to consist of publicly available court information, the court’s IT team found that some files did contain personally identifiable information — including driver’s license numbers and dates of birth.

Court documents, which are generally treated as public records, are not stored on C-Track and were not part of the breach. Investigators also found no evidence that financial processing systems were accessed or compromised.

Scope of the Multistate Campaign

Montana was one of at least twelve states and territories affected by the attack. Courts in Alabama, Pennsylvania, Kentucky, Nevada, North Dakota, South Carolina, Tennessee, New Hampshire, Ohio, Wyoming, and the U.S. Virgin Islands were also impacted. The breach was attributed to Thomson Reuters’ systems, not to any security failure on the part of the courts themselves.

Thomson Reuters has faced scrutiny in recent years over its handling of private information. The company provides case management and backup services to courts in several states, making a vulnerability in its platform a significant exposure point for court systems that rely on centralized vendors.

Court Response and Ongoing Review

Court staff and Thomson Reuters employees are continuing to review the files swept up in the hack and are searching for additional vulnerabilities. The scale of the breach — including the number of individuals whose information may have been exposed — was not included in Wednesday’s announcement.

Chief Justice Swanson said the court has worked to determine whether any Montanan suffered harm from the intrusion. “We appreciate the rapid support of other state Supreme Courts and the National Center for State Courts,” he said, as reported by the Billings Gazette. He added that the court intends to keep working with Thomson Reuters to ensure court operations can continue “without fear of compromise of personal privacy.”

What Comes Next

The review of affected files is ongoing, and the court has not yet released a full accounting of how many individuals may have had personal information accessed. Anyone who has interacted with the Montana Supreme Court system and is concerned about their information may want to monitor for notifications as the review continues.

The incident highlights the growing cybersecurity risk facing state court systems that depend on third-party vendors for core infrastructure. For a court system that handles sensitive matters — from natural resource disputes to regulatory appeals — maintaining the integrity of case data is a foundational concern. Montana’s courts, like those across the country, increasingly rely on centralized digital platforms that, while efficient, can become systemic vulnerabilities when a single vendor is compromised.

The court has not yet indicated whether it will pursue alternative vendors or seek additional safeguards for data stored in third-party systems going forward.