Minnesota Courts Cut Ties With Thomson Reuters After Multi-State Breach
The Minnesota Judicial Branch terminated vendor access following a four-month compromise of the C-Track case management platform.
The Minnesota Judicial Branch, including the state's Supreme Court and Court of Appeals, has severed its electronic ties with a major software vendor following a massive data breach. The compromise originated within a third-party case management platform, exposing the systemic vulnerability of judicial infrastructure to vendor-side attacks.
Unauthorized actors maintained access to the C-Track platform, sold by West Publishing (a unit of Thomson Reuters), from March 1 through June 29, 2026. The vendor detected the intrusion on June 30, but the incident was not publicly disclosed until September 2, 2026. In response to the discovery, the Minnesota Judicial Branch terminated Thomson Reuters' access to its electronic environments.
A Cross-Border Compromise
The breach was not isolated to Minnesota; it affected judicial systems across 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. The scale of the incident created a complex notification timeline, as officials reportedly delayed the public announcement from June to September to ensure simultaneous disclosures across all affected jurisdictions.
There remains a discrepancy regarding the nature of the accessed data. While some jurisdictions, such as Montana and Alabama, reported that the breach involved backup data used for troubleshooting, the Supreme Court of Ohio indicated that the unauthorized access occurred directly on the production platform.
Systemic Judicial Risk
This incident underscores the critical risk posed by the centralization of judicial data within third-party software ecosystems. When a single vendor like Thomson Reuters manages case data for multiple states and international provinces, a single point of failure can jeopardize the privacy of thousands of litigants and the integrity of court records across an entire continent.
The potential for unauthorized access to judicial platforms is particularly acute because these systems often handle sensitive personal identifiers and sealed documents. While the vendor's general notice suggested that sealed material may have been affected for certain courts, the Minnesota Judicial Branch has specifically claimed that court documents were not part of the accessed data in its own system.
Next Steps for Oversight
As the Minnesota Judicial Branch moves away from the compromised environment, the focus shifts to the long-term security of court case management. Legal experts and IT auditors are expected to scrutinize the four-month window in which the breach went undetected by the vendor.
It remains to be seen whether other affected states will follow Minnesota's lead in terminating their relationship with the C-Track platform or if the vendor will implement structural changes to prevent similar production-level access in the future.