NEWS

Arizona Supreme Court Says Hackers Stole Residents' Personal Data

Hackers used a phishing email to steal protective-order and foster care records from Arizona's court system, affecting many residents.

Dylan H.

News Desk

September 29, 2026
7 min read
Arizona Supreme Court Says Hackers Stole Residents' Personal Data

Arizona Supreme Court Says Hackers Stole Residents' Personal Data

The Arizona Supreme Court disclosed on Friday, September 25, 2026, that hackers breached the state's court network and copied personal information belonging to "many Arizonans," including people with current or former protective orders and children named in foster care review board records. Chief Justice Ann Scott Timmer said the intrusion did not involve ransomware and that, as of Monday, September 28, the attackers had not issued a ransom demand for the stolen data.

According to officials, the breach traces back to a phishing email — a county court employee clicked a malicious link despite prior security-awareness training, which allowed an automated tool to gain a foothold in the network. Court IT staff detected a surge in unauthorized data downloads and shut down the affected systems, but not before a substantial volume of records — described by officials as compressed archives pulled largely from backup files — had already been copied.


Incident Details

AttributeValue
TargetArizona court system (Administrative Office of the Courts / Arizona Supreme Court)
Attack vectorPhishing email — county employee clicked a malicious link
Malware deployedNone reported — attackers copied/downloaded data rather than installing malware
Intrusion windowDetected within roughly 36 hours of the September 25 disclosure
Public disclosureSeptember 25, 2026
Data exposedNames, addresses, protective-order records, foster care review board records (including children's names)
Individuals affectedNot officially quantified; described as "many Arizonans," with some reporting suggesting tens of thousands
Ransomware involvedNo
Ransom demandNone as of September 28, 2026
AttributionUnknown — no group has claimed responsibility
Investigating agenciesFBI, U.S. Department of Homeland Security, Arizona Department of Public Safety

How It Happened

Initial Access via Phishing

Chief Justice Timmer described the entry point in blunt terms: a single county employee clicked a link in a phishing email despite having been trained not to. "It only takes one time for an employee to click on the email they shouldn't click on," she said, explaining that the click let "some kind of bot or automated system" work its way into the court's network. No malware was installed as part of the intrusion; instead, the attackers used the access to locate and exfiltrate data, largely from backup archives rather than live production systems.

Detection and Containment

Court IT staff noticed a spike in outbound data transfers consistent with mass unauthorized downloads and moved to shut down the affected systems, cutting off the attackers before they could copy additional records. Officials said the compromised data had been compressed into archive files, meaning the stolen material would require further processing before it could be read or used by whoever holds it — a detail investigators are treating as a small mitigating factor while the scope of the theft is assessed.

What Was Taken

Two record categories have been specifically identified as affected. The largest appears to be protective order data — including injunctions against harassment — which typically contains petitioners' and respondents' names, addresses, and other identifying and location details. Advocates have raised concern that exposure of this category could let abusers locate people who obtained protective orders specifically to stay hidden from them. The second category is foster care review board records, confidential recommendations to the court that are ordinarily shared only with parents and other case participants; Timmer said these records generally don't include addresses but do contain children's names, which she called "still very concerning."

Investigation Status

No hacking group has claimed responsibility, and authorities have not identified a suspect or attributed the intrusion to any known threat actor. Timmer said she personally briefed the top-ranking FBI official in Arizona shortly after learning of the attack, and the court is now working with the FBI, DHS, and the Arizona Department of Public Safety. A retired FBI special agent quoted in coverage of the incident said financially motivated data resale remains the most likely driver behind this type of theft, noting that stolen PII "can be worth a lot" on criminal marketplaces. As of the most recent update, the Arizona Supreme Court's communications office said there was no new information to share and that the Administrative Office of the Courts was still working through notifications to affected individuals.

Impact Assessment

Impact AreaDescription
Protective order holdersPotential exposure of addresses and location details could help abusers locate victims who sought court protection specifically to stay hidden
Foster care participantsChildren's names appear in exposed review board records tied to active family court cases
Public trust in judicial ITA state supreme court network compromise raises scrutiny of cybersecurity practices across court systems handling highly sensitive case data
Data monetization riskNo ransom demand has surfaced, but stolen PII from backups is commonly resold on criminal marketplaces regardless of ransomware involvement
Investigation integrityOfficials have limited public detail specifically to avoid compromising the ongoing FBI-led investigation

Recommendations

For Court and Government IT Administrators

  • Enforce phishing-resistant multi-factor authentication (FIDO2/hardware keys) for all staff with access to case-management and backup systems, not just email.
  • Encrypt backup archives at rest and segment backup infrastructure from general network access — this incident specifically targeted backup files rather than live production data.
  • Deploy endpoint detection and response (EDR) tooling capable of flagging anomalous bulk data-egress patterns before large archives leave the network, as happened here.
  • Run recurring, unannounced phishing simulations for court and county staff, with escalating remediation training for repeat clicks rather than one-time onboarding sessions.

For Security Teams

  • Audit who can access backup exports and case-management databases containing protective-order and family-court records, and apply least-privilege controls.
  • Establish dark web and criminal-marketplace monitoring for court-record data specifically, since resale — not ransomware — appears to be the likely motive here.
  • Coordinate breach notification language carefully with legal counsel for protective-order holders, given the elevated physical-safety risk if address data is misused.

For Affected Residents

  • Individuals with current or former Arizona protective orders should watch for official notification from the Administrative Office of the Courts and consider address-confidentiality program enrollment if available in their county.
  • Enroll in credit monitoring if offered, and treat unsolicited calls, texts, or emails referencing court case numbers or protective-order details with suspicion — they may be follow-on phishing or extortion attempts.
  • Parents or guardians involved in foster care cases should confirm with their caseworker whether their child's record was among those affected and ask what additional protections are being applied.

Key Takeaways

  1. A single phishing click by a county employee gave attackers a foothold in Arizona's court network, underscoring how one lapse in user training can lead to a large-scale data-theft incident.
  2. The stolen data centers on two sensitive categories — protective order records and foster care review board files — both of which carry outsized real-world safety risk if misused.
  3. No ransomware was deployed and no ransom demand has been made, distinguishing this from the typical extortion playbook seen in most publicized government breaches.
  4. Attackers reportedly pulled data mostly from compressed backup archives, highlighting backup infrastructure as a soft target that often receives less security scrutiny than production systems.
  5. The FBI, DHS, and Arizona DPS are jointly investigating, but no attribution or suspect has been identified as of the September 29 reporting date.
  6. The exact number of affected residents remains undisclosed; officials have characterized it only as "many Arizonans," with some reporting suggesting a toll in the tens of thousands.

Sources