Breaking
Cyber CrimeDeveloping Story

Arizona Courts Breach Hits 1.3 Million

A phishing email led to the theft of personal data for 1.3 million people from Arizona's court system, officials say.

··2 hours ago·5 min read
white concrete building under sky
Photo by Katie Moum on Unsplash

A single clicked link in an email opened the door to one of the largest data thefts ever reported by a state court system. Arizona's courts say personal information belonging to more than a million people was copied by attackers who reached a backup server, and the disclosure now covers records spanning three decades.

The Arizona Supreme Court said the information was taken for 1.3 million people with unpaid court fees, fines and restitution payments tied to traffic and criminal violations dating back as far as 30 years, according to the Associated Press.

How the intrusion began

The attack is believed to have started when a court employee clicked a malicious link in an email, according to the account provided by the court system.

Court technology staff detected the activity on a backup server and shut it down about two hours after spotting it on Sept. 24. Since then, the court has notified people affected by the breach.

The incident remains under investigation. The court has not said who was behind the attack or what motivated it.

The disclosure traces the theft to a backup environment rather than the court system's primary production servers, a detail that underscores how far into an organization's infrastructure an intrusion can travel after an initial phishing click.

Orders of protection and foster care records

Beyond the financial and case-related records, the attackers also took other categories of data held by the court system.

  • Records of nearly 30,000 active and inactive orders of protection.
  • 150,000 reports dating back to 2010 from a foster care board that makes recommendations in cases where parents are alleged to be unfit or unable to care for a child.

Those figures, combined with the 1.3 million people whose fee and fine records were copied, define the scope of the breach as described by the court.

What the court says was not taken

Several categories of information were left untouched, according to the court's account. No records were altered or deleted, and the attackers did not steal information about jurors, witnesses or court employees.

The attack also has not affected or delayed any court cases, state Supreme Court spokesperson Alberto Rodriguez said.

On the question of whether the stolen data has surfaced elsewhere, Rodriguez said there is no indication so far that it has been used or shared.

“We don’t have any evidence it has been used or shared”

— Alberto Rodriguez, state Supreme Court spokesperson

The two-hour detection window

Court technology staff moved to shut down the attack on a backup server about two hours after first detecting it, according to the court's timeline. The detection and response window is a specific data point in the disclosure, arriving after the copied data had already been taken.

The court has not described the technical steps the attackers took to reach the backup server from the initial phishing click, nor has it detailed the specific personal identifiers contained in the stolen records.

What is known is that the intrusion began with a malicious link in an email and ended with data copied from a backup environment — a sequence the court has confirmed in broad strokes while the investigation continues.

Notification and what happens next

The court said it has notified those affected by the breach. That notification effort followed the detection and shutdown of the attack on Sept. 24.

The investigation into the incident is ongoing. The court has not named any suspects or indicated whether a ransom demand was made.

For now, the public account rests on the court's own statements and the figures it has released: 1.3 million people whose fee, fine and restitution records were copied, nearly 30,000 orders of protection, and 150,000 foster care board reports dating back to 2010.

A distinct scale for court records

Court systems hold records that span financial obligations, family matters and protective orders, and the Arizona disclosure covers categories that go well beyond routine case filings.

The theft of orders of protection and foster care board reports means the data involved concerns not just the individuals named in court proceedings but also the family circumstances described in those filings.

The court has said no records were altered or deleted and that jurors, witnesses and employees were not affected. Those assurances sit alongside the confirmed theft of records for 1.3 million people and the additional categories of protection orders and foster care reports.

What the disclosure leaves open

Several questions remain unanswered in the court's public statements. The court has not itemized which personal identifiers were included in the stolen records, named the attackers, described their motives, or said whether any ransom demand was made.

No group has publicly claimed responsibility based on the information released so far.

The investigation is ongoing, and the court's account of what was taken and how the attack unfolded could change as that work proceeds.

Why it matters

The Arizona breach shows how a single phishing click can lead to the copying of records held across multiple court functions, including fee and fine data, protection orders and foster care board reports. For the 1.3 million people whose information was taken, the practical concern is that records tied to court fees, fines and restitution could be used in ways that outlast the news cycle — though the court says it has no evidence of misuse so far.

For organizations that hold similar records — court systems, social services agencies, protection-order registries — the disclosure raises questions about how backup environments are monitored and segmented, since that is where this attack ultimately landed. The two-hour window between detection and shutdown limited how long the attackers had access, but the data had already been copied by the time the attack was stopped.

Anyone who receives a notification related to this breach should treat it as a signal to monitor for unexpected contact referencing court fees, fines or case records. The absence of evidence of misuse today does not rule out future attempts, and the court has said its investigation continues.

#arizona courts#data breach#phishing#court records#cyberattack

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories