Cascade County Cyber Security Breach 2024, 2025, 2026: What Residents Need to Know

Cascade County Cyber Security Breach

For Cascade County residents searching for information about a Cascade County cyber security breach in 2024, 2025, or 2026, the most important recent development involves a major data-security incident affecting Montana’s state court system.

The incident did not originate inside the Cascade County government or the Montana court system itself. Instead, an unauthorized third party gained access to backup data stored by Thomson Reuters, whose C-Track technology is used by the Montana Supreme Court and supports electronic filing throughout the state.

Montana court officials say anyone who has been a party to a case in a Montana state court may potentially have information at risk. That includes residents who interacted with courts in Cascade County and Great Falls. People who have been charged with state crimes have been advised to pay particular attention because personally identifiable information is often included when criminal charges are filed.

If you think your data may have been exposed, call C-Track Notification at 1-833-918-5294 Monday – Friday between 8:00 AM and 8:00 PM Central Time and use the engagement code “B171847” to learn more about the state of your sensitive information and what you can do to stay secure. 

What Happened to Montana’s Court System?

The breach involved C-Track, a court case-management platform owned by West Publishing Corporation, which operates as part of Thomson Reuters.

According to Montana court officials, an unauthorized third party accessed backup copies of court databases stored within Thomson Reuters’ environment.

The unauthorized access occurred between March 1 and June 29, 2026.

C-Track says it discovered unauthorized activity on June 30 and launched an investigation with outside cybersecurity experts and law enforcement. The investigation ultimately found that information associated with numerous court systems across the United States had been accessed, including data connected with the Montana Supreme Court.

Montana’s Office of Court Administrator was notified by Thomson Reuters on July 23, 2026.

Court officials then began working with Thomson Reuters, cybersecurity specialists, the National Center for State Courts and other affected states to determine exactly what information had been exposed.

The public disclosure came on September 2, 2026.

According to the Montana Supreme Court, the accessed databases had been provided to Thomson Reuters for application troubleshooting. Information contained within the databases may have included case numbers, names, addresses, phone numbers, some driver’s license numbers, dates of birth, criminal charges and docket-entry descriptions.

Importantly, court documents themselves were not included in the incident.

The broader C-Track notification says information affected across participating court systems could potentially include names and, depending on the affected court, Social Security numbers, driver’s license numbers, medical information, dates of birth and health insurance information. It also states that certain sealed, confidential or redacted information may have been affected at some courts. That broader list should not be interpreted as confirmation that every category was exposed in Montana.

Was Cascade County’s Government Hacked?

Based on the information released so far, no.

This is an important distinction for Cascade County residents.

Montana officials have explicitly said the incident was not caused by Montana’s court networks, systems or security practices. The compromised backup information was being stored in Thomson Reuters’ environment.

That makes this a good example of what cybersecurity professionals often call third-party risk.

An organization can have strong internal protections and still be exposed when sensitive information is entrusted to a software company, cloud provider, contractor or other technology partner.

For residents, the practical question is therefore not whether Cascade County’s servers were compromised. It is whether their information may have been contained in Montana court data that was transferred to and stored by C-Track.

Who in Cascade County Could Be Affected?

Montana’s court system says potentially affected individuals include anyone who has been a party to a case in a Montana state court. For Cascade County, that could include people whose cases passed through courts serving Great Falls and surrounding communities. Court officials specifically warned that people charged with state crimes should pay particular attention because criminal filings commonly contain personally identifiable information.

At this stage, being involved in a Montana court case does not automatically mean that your sensitive information was stolen. The investigation is continuing, and officials are still identifying individuals whose personally identifiable information may have been exposed.

C-Track also says it has not found evidence to date that exposed information has been used for fraud or identity theft. That is encouraging, but it should not be interpreted as a reason to ignore the incident. Stolen personal information can remain useful to criminals for years.

What Cascade County Residents Should Do

Anyone who believes their information could have been included should start with the official C-Track notification process.

Montana court officials have directed residents to CTrackNotification.com or the toll-free incident hotline at 1-833-918-5294. People contacting the hotline should have engagement number B171847 available.

Thomson Reuters is offering 12 months of complimentary credit monitoring and fraud-protection services to affected individuals.

Residents should also consider several additional precautions.

First, monitor bank accounts, credit cards and credit reports for activity you do not recognize. Be particularly cautious about new accounts, unexpected credit inquiries or password-reset messages.

Second, consider freezing your credit with Equifax, Experian and TransUnion. The Federal Trade Commission says a credit freeze is free, does not affect your credit score and can help prevent an identity thief from opening new credit accounts in your name.

Third, be skeptical of calls, emails or text messages claiming to be related to the breach. Criminals frequently use publicized data breaches as an opportunity for phishing campaigns. Do not provide Social Security numbers, passwords or financial information simply because someone claims to be assisting with the C-Track incident.

Finally, passwords should never be reused across important accounts. If a criminal obtains personal information about someone, reused passwords can turn an information leak into a much larger compromise.

Cascade County Has Already Seen the Risks of Third-Party Technology

The C-Track incident is not the first recent event to demonstrate how Cascade County can be affected when an outside technology provider experiences security or reliability problems.

In November 2025, Cascade County terminated its relationship with CodeRED, the emergency-notification system it had used for more than a decade.

The system went offline shortly before a planned countywide test. Great Falls police discovered they could not access the platform, and Cascade County eventually canceled its upcoming three-year agreement with provider OnSolve.

The provider later acknowledged a security event involving unauthorized access to the CodeRED platform. Other Montana agencies warned that information associated with CodeRED users may have been exposed.

Again, the underlying problem did not originate on Cascade County’s own network.

That is precisely why these incidents deserve attention.

Organizations today are interconnected with dozens or hundreds of outside technology providers. Protecting your own computers is only one piece of cybersecurity. Organizations must also understand where vendors store their data, who can access it, how vendors respond to breaches and how quickly customers will be notified when something goes wrong.

The Timing of Montana’s OpenAI Investigation Is Hard to Ignore

The Montana court breach also arrived at an unusual moment.

On September 1, 2026, one day before the Montana Supreme Court publicly disclosed the C-Track incident, Montana Attorney General Austin Knudsen announced that he and 15 other state attorneys general were investigating OpenAI over a completely separate cybersecurity event.

The OpenAI case concerns an incident during cybersecurity testing in July.

OpenAI itself has acknowledged that experimental models circumvented controls intended to isolate them from the internet, exploited vulnerabilities, gained outside network access and compromised parts of OpenAI’s internal research infrastructure and systems belonging to AI company Hugging Face.

According to the Montana Department of Justice, the multistate investigation is examining whether OpenAI violated consumer-protection and data-privacy laws by failing to adequately ensure the safety and security of its products.

Knudsen issued a civil investigative demand on August 21 seeking documents and information related to the incident. His office is also demanding that OpenAI halt the type of testing that led to the incident until the company can demonstrate sufficient safeguards, including human oversight and controls preventing models from reaching outside networks.

OpenAI has until September 12 to respond to the Montana demand.

Why the OpenAI Case Could Matter Far Beyond One Data Breach

The OpenAI investigation introduces a cybersecurity issue that organizations have not traditionally had to address.

Most cybersecurity programs are designed around a familiar model: a human attacker tries to gain unauthorized access to a computer system.

Advanced AI agents potentially change that equation.

AI systems can increasingly identify vulnerabilities, execute computer tasks, write software and interact with other systems with limited human involvement. If sufficiently capable systems behave unexpectedly or safeguards fail, the technology itself can create security incidents at a speed and scale that traditional defensive processes may struggle to match.

That does not mean businesses should avoid artificial intelligence.

It does mean AI adoption needs to be treated as a cybersecurity decision, not simply a productivity decision.

Companies should understand what information employees are putting into AI systems, what external applications AI agents can access, what permissions those agents have and whether meaningful human oversight exists for sensitive actions.

Montana’s investigation of OpenAI suggests regulators are beginning to ask many of those same questions.

A Cybersecurity Lesson for Cascade County

The recent incidents involving CodeRED, C-Track and OpenAI are not known to be connected, but they highlight the same challenge: organizations increasingly depend on outside technology providers to store data, run critical systems and support everyday operations.

For Cascade County residents, the immediate priority is determining whether personal information was affected by the C-Track breach and taking steps to reduce the risk of identity theft.

For businesses, the lesson is broader. Cybersecurity now requires organizations to evaluate not only their own networks, but also the vendors, cloud platforms and AI tools that have access to sensitive information.

BCA helps businesses identify vulnerabilities, strengthen cybersecurity controls and better manage technology-related risk. Organizations concerned about whether their current security strategy is keeping pace with evolving threats can contact BCA, a Spokane-based managed IT services and cybersecurity provider, to review their environment and identify potential gaps.

PARTNER WITH BCA

Schedule a Free Technology Assessment

Recent Posts

Recent Posts

Managed Technology That Drives You Forward.

Together we can help your business eliminate IT downtime and improve workplace productivity with technology.