September 2026 government data breach news centers on a third-party C-Track court-records breach affecting multiple jurisdictions. New security advisories also warn government users to patch actively exploited SonicWall flaws and vulnerable Citrix NetScaler appliances. The evidence does not establish that court networks were breached. Many important details—including the number of affected people, the exact files exposed, and the extent of identity-theft risk—remain under investigation.
Table of Contents
- What happened in the C-Track breach?
- Which courts and people may be affected?
- What should potentially affected people do?
- Which security advisories require attention?
- Key takeaways for readers and agencies
What happened in the C-Track breach?
C-Track is a court case-management platform operated by West Publishing. A third party obtained files from multiple government court systems in March 2026, according to the company. C-Track discovered unauthorized activity on June 30 and issued its public notice on September 2. The affected files may contain names, Social Security numbers, driver's-license numbers, birth dates, medical information, insurance information, and other personal data.
Some courts' files may include confidential, redacted, or sealed material, according to the C-Track and West Publishing notice. This is a vendor incident, not a confirmed compromise of court networks. C-Track says court systems and payment-processing systems did not cause the breach and were not affected. It has found no evidence of fraud or misuse so far, but that finding does not reveal whose information was accessed.
Which courts and people may be affected?
Oregon said the incident involved its appellate-court data and affected at least 11 other states. Oregon's circuit courts, Tax Court, and court operations were not affected, while the exact information involved remained unknown, according to the Oregon Judicial Department release. Ohio reported that its C-Track production platform hosts filings for 10 of the state's 12 appellate courts. The state had not determined which people were affected or what personal information was exposed. Wyoming said names, addresses, and birth dates may have been compromised in historical Supreme Court and district-court data.
The potential exposure primarily concerns people who interacted with those courts from 2015 through 2025. Wyoming had not determined the total number affected. Ontario's three chief justices also confirmed that someone accessed court information stored in Thomson Reuters' cloud environment. They said the content, affected people, and identity-theft implications remained uncertain. Court operations continued.
What should potentially affected people do?
People should not assume that every court filing or every person involved in a listed jurisdiction was exposed. The available notices describe affected data differently, and several courts still do not know whose records were involved.
C-Track is offering eligible people in the United States 12 months of Experian IdentityWorks monitoring. Enrollment closes December 31, 2026. Potentially affected readers should:.
- Follow enrollment instructions in the official C-Track notice.
- Review credit reports for accounts or activity they do not recognize.
- Check financial account statements for unauthorized transactions.
- Treat unexpected messages about court records or exposed personal data cautiously.
- Continue monitoring even if no misuse appears immediately.
Which security advisories require attention?
The Canadian Centre for Cyber Security reported active exploitation of SonicWall CVE-2026-83548 and CVE-2026-83549. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, making prompt patching important for government organizations using affected SMA1000 appliances, according to the Canadian Cyber Centre advisory. A separate September 4 alert concerns affected Citrix NetScaler ADC and Gateway appliances.
The Canadian Cyber Centre urged emergency patching and log review because an authentication-bypass flaw can allow an unauthenticated remote attacker to circumvent controls in specified gateway configurations, as detailed in its Citrix NetScaler alert. Government IT teams should first determine whether they operate the affected SonicWall or Citrix products. Where they do, patching and log review are immediate operational tasks, while the C-Track matter requires separate assessment of vendor-held court data.
Key takeaways for readers and agencies
The C-Track notices show why a government-data incident may originate outside government infrastructure. Court systems can continue operating while information previously supplied to a vendor remains exposed or under investigation. For individuals, the practical priority is determining whether an official notice applies and monitoring for unauthorized activity.
For agencies, the September advisories point to two distinct risks: investigating data held by a court technology vendor and urgently addressing vulnerable internet-facing security appliances. The largest unresolved issue is scope. Oregon and Ohio did not yet know the exact personal data involved, Wyoming did not know the number of affected people, and Ontario had not established the affected content or identity-theft impact.
You Might Also Like
- What Is New With Healthcare Data Breach News in August 2026? Latest breach notices and security advisories and Key Takeaways
- What Is New With Financial Sector Data Breach News in August 2026? Latest breach notices and security advisories and Key Takeaways
- What Is New With Ransomware Attacks in August 2026? Latest breach notices and security advisories and Key Takeaways