09/03/2026
The Kentucky Administrative Office of the Courts has confirmed that the filing system used by the Kentucky Supreme Court and the Court of Appeals was part of a cyber security incident affecting twelve jurisdictions. The unauthorized access took place in March and was discovered on June 30, according to court officials.
That system, called C-Track, is operated by an outside vendor, Thomson Reuters Court Management Solutions. The information potentially exposed includes names, Social Security numbers, driver's license numbers, dates of birth, and medical and health insurance information. Trial court records were not affected, because Kentucky courts at that level use separate internal e-filing systems. Anyone whose information was involved is being offered one year of credit monitoring and identity theft protection.
The vendor is the detail that matters most for every other organization reading this. A court, a city hall, or a small business can run its own systems carefully and still be exposed through a contractor that holds its records. Ask every vendor who touches your data what they store, where they store it, and how quickly they would tell you if something went wrong.
Read more in the comments.
Commonwealth Sentinel, 502-234-5554.