Cyber & AI intelligence
Wasteland.
Briefs indexed2949
Issues30
Published Mondays07:30 CT
▣ Breach ARIZONA-COURTS-DAT 2026-10-01

Arizona Courts: Phishing Attack Exposes Protective Order, Foster Care and Court Debt Records

"Arizona's state court system has confirmed that attackers copied personal data from its backup servers. The Arizona Supreme Court says it is now notifying about 1.3 million people. That figure, reported by KVOA, covers…"

Arizona's state court system has confirmed that attackers copied personal data from its backup servers. The Arizona Supreme Court says it is now notifying about 1.3 million people. That figure, reported by KVOA, covers only the third dataset the court has disclosed so far: records from the statewide FARE Collection Program, which may include Social Security numbers. The two datasets disclosed earlier hold protective order records, including the addresses of domestic violence victims, and more than 150,000 confidential Foster Care Review Board reports on children. Chief Justice Ann Scott Timmer has confirmed the breach publicly. A court spokesperson told The Record that the incident did not involve ransomware and that no ransom demand had been made as of Monday, September 28. No group has claimed responsibility, and the FBI is investigating.

What Happened

Timmer says the attack was detected on the afternoon of Thursday, September 24, when a large volume of data started leaving the court's systems. Accounts differ on who spotted it. FOX 10, AZFamily and KTAR say court IT staff found the activity. In remarks reported by KVOA, Timmer said the alert came from a third-party security vendor that flagged "a lot of documentation being downloaded from one of your servers." Both versions agree that the system was shut down quickly. Timmer told AZFamily it was contained within about two hours.

The Supreme Court announced the incident late on Friday, September 25. Its Administrative Office of the Courts began emailing affected people and contacting domestic violence shelters and advocacy groups. Timmer said she spoke personally with the top FBI official in Arizona. She declined to share technical details, citing the ongoing investigation.

Disclosure has come out in stages:

Estimates of scale have grown sharply as each dataset surfaced. Early reports from FOX 10 and AZFamily described "thousands" to "tens of thousands" of affected people. AZFamily later reported that more than 270,000 court records were stolen. The 1.3 million figure for the FARE dataset is the largest so far. The court has not published one consolidated total, and it is not clear whether the datasets overlap or how far the full count goes beyond 1.3 million.

What Was Taken

Officials say the data was copied from backup servers and was stored in a highly compressed format. Timmer told KTAR that "whoever got this data might not be able to read it," but that a sophisticated attacker could convert it into readable text. Defenders should assume the data can be read.

Three datasets have been identified:

  1. Protective order records. These include names and addresses tied to current and expired orders, including addresses the court held as confidential (BreachNews, FOX 10, AZFamily). Timmer told KTAR this is probably "the biggest cohort" by type of court matter. The court has not given a count for this group.
  2. Foster Care Review Board reports. The court told KJZZ and AZFamily that more than 150,000 reports on current and past cases going back to 2010 were taken. They contain names of children and parents, statements, board findings, and court and Department of Child Safety (DCS) recommendations. The court says they do not contain addresses or phone numbers. It also says the information had already been shared with case participants. Even so, these are confidential child welfare records.
  3. FARE Collection Program data. This covers about 1.3 million people with court-ordered fees, fines or victim restitution going back as far as 30 years, according to KVOA. The data may include names, case numbers and Social Security numbers.

The FARE dataset carries the highest identity fraud risk because it contains SSNs. The protective order data carries the most direct physical safety risk.

Why It Matters

This breach shows the range of harm court data can cause. The risks include identity theft (SSNs from the FARE data), exposure of children's welfare cases, and physical danger to domestic violence survivors whose confidential addresses may now be in criminal hands. Timmer called it "outrageous and distressing" that victims could be re-victimized.

It also follows a pattern. The Record notes that courts remain a frequent target in state-level attacks. A 2023 ransomware attack shut down most of Kansas' court systems for months. Courts in California, Nebraska, South Carolina, Florida, Wisconsin, Louisiana, Ohio, Missouri and Illinois have faced ransomware, DDoS attacks or data breaches in the past four years.

Three lessons for defenders:

The Attack Technique

The court and its spokesperson, Alberto Rodriguez, say the attackers got in through phishing. Rodriguez told KJZZ the attackers "accessed our system via a phishing attack email and copied information from our backup servers." Timmer's own descriptions vary:

Timmer told AZFamily the activity looked automated and was "just hitting particular files," and that there was no sign of whether it was random or targeted. The court has said the forensic investigation is still ongoing and that the exact attack path is not yet confirmed. Until it publishes findings, the most defensible summary is: initial access through a user clicking a malicious link (the delivery method is disputed), then automated bulk copying from backup servers, with no ransomware and no ransom demand reported.

What Organizations Should Do

  1. Segment and lock down backup infrastructure. Backup servers should not be reachable from standard user endpoints. Restrict access to dedicated service accounts, and encrypt backups at rest with keys stored separately from the backups themselves.
  2. Alert on large outbound transfers. Volume-based detection is what triggered the shutdown here. Set baselines for normal transfer rates from file and backup servers, and alert or block automatically when they are exceeded.
  3. Defend against both email phishing and malicious search results. Combine email filtering with DNS and web filtering that blocks newly registered and lookalike domains. Teach staff that sponsored or top-ranked search results can be malicious.
  4. Enforce retention limits. Purge or archive offline any records that are not legally required, such as decades-old debt data and expired protective orders. Remove SSNs wherever a case number would do.
  5. Classify safety-critical data separately. Confidential victim addresses and child welfare records need stronger controls than general case data: separate storage, field-level encryption and tighter access auditing.
  6. Plan notification for vulnerable groups in advance. Have communication paths to victim advocacy groups and shelters ready before an incident. Arizona did this, but foster families report they were not notified directly.

Sources: Arizona court cyber attack potentially exposes 1.3M people's data... | Arizona Supreme Court says hackers stole residents’ personal data... | Arizona court data breach: Cyberattack targets judicial network, pr... | Arizona court data breach exposed foster care records | Domestic violence victims’ data may be exposed in Arizona court bre... | Hackers access sensitive Arizona court records - KTAR.com | Arizona Supreme Court data breach exposed reports on children in fo... | Arizona Courts Cyberattack Exposes Personal Data