Minnesota Judicial Branch
Incident posture
Linked entities
- Victim
- Minnesota Judicial Branch
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The Minnesota Judicial Branch disclosed that a breach of its third‑party case‑management vendor exposed personal information of court users, including names paired with Social Security numbers, driver’s license numbers, medical details, dates of birth and health insurance data, while case filings themselves remained unaffected. The vendor, C‑Track provided by Thomson Reuters, detected unauthorized file access that also affected appellate courts in several other states, prompting the branch to cut the vendor’s access, audit accounts, involve internal cybersecurity experts and law enforcement, and notify affected users to reset passwords; the vendor has since added security measures and is offering complimentary credit monitoring and identity‑theft protection to those impacted.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In March 2026 an unauthorized party obtained certain files from the C‑Track system used by Thomson Reuters to manage court case filings for the Minnesota Judicial Branch and several other state court systems. On June 30 2026 C‑Track detected unauthorized activity involving those files and launched an investigation that confirmed the earlier intrusion. The investigation revealed that the intruder had accessed files belonging to appellate courts in Alabama, Kentucky, Montana, Nevada, North Dakota, South Carolina, Tennessee, New Hampshire, Wyoming and the U.S. Virgin Islands, as well as multiple Ohio appellate courts and several Pennsylvania courts including the Environmental Hearing Board, the Court of Common Pleas of Monroe County, the Court of Common Pleas of Washington County and the Fifth Judicial District. Minnesota officials stated that case documents such as orders and briefs were not part of the compromised data, but that the breach could have exposed private information including users’ names combined with Social Security numbers, driver’s license numbers, medical information, dates of birth and health insurance details, with certain confidential, redacted or sealed information possibly affected. The Minnesota Judicial Branch noted that while most court case information is public, some case data contains private details that were therefore at risk.
Upon learning of the incident the Minnesota Judicial Branch terminated Thomson Reuters’ access to the courts’ electronic environments, conducted an audit of affected accounts and engaged internal cybersecurity experts alongside state authorities to investigate the breach. The breach was reported to law enforcement as required. Users of the appellate courts’ case management system were notified that they must change their passwords, with any attempt to log in using a previous password resulting in a lockout. C‑Track implemented additional security measures to help prevent a recurrence and began offering complimentary credit monitoring and identity theft protection services to individuals whose data may have been exposed. Affected individuals can direct questions to the Minnesota Judicial Branch via [email protected] or contact C‑Track at 1‑833‑918‑5294, providing engagement number B171847. Minnesota Supreme Court Chief Justice Natalie Hudson expressed that the branch is working with Thomson Reuters and internal experts to understand the root cause and scope of the breach and to safeguard users’ information. C‑Track stated that there is no evidence that systems processing financial transactions were impacted and no evidence of fraud or misuse of the compromised data to date.
Sources
Sources available to members: 1 source.