NEWS

Arizona Court Breach Affects Over 1 Million People, Records Span 30 Years

Arizona's Supreme Court confirms over 1.3 million people had data stolen in the September cyberattack, with some records dating back 30 years.

Dylan H.

News Desk

October 6, 2026
9 min read
Arizona Court Breach Affects Over 1 Million People, Records Span 30 Years

Arizona Court Breach Affects Over 1 Million People, Records Span 30 Years

The Arizona Supreme Court confirmed on October 6, 2026, that the cyberattack on its court network — first disclosed on September 25 — exposed personal information belonging to more than 1.3 million people, with some of the stolen records dating back as far as 30 years. The figure is the first official scale estimate since the court initially described the toll only as affecting "many Arizonans," and it elevates an incident that had been framed around protective-order and foster-care records into one of the larger publicly disclosed government data breaches of the year.

The bulk of the newly quantified exposure comes from the court's Fines/Fees and Restitution Enforcement (FARE) collection program, which tracks people with unpaid court debt — fines, fees, and restitution tied to traffic and criminal violations — stretching back three decades. Court officials said names, case numbers, and Social Security numbers tied to FARE accounts were among the data copied. Separately, roughly 30,000 active and inactive protective order records and more than 150,000 foster care review board reports dating to 2010 were also confirmed as affected, building on the categories identified in the court's original disclosure.


Updated Incident Details

AttributeValue
TargetArizona court system (Administrative Office of the Courts / Arizona Supreme Court)
Attack vectorPhishing — employee clicked a malicious link believing it was legitimate
Attack dateSeptember 24, 2026
Detection-to-shutdownApproximately two hours after a security vendor flagged abnormal bulk downloads
Initial public disclosureSeptember 25, 2026
Updated scale disclosureOctober 6, 2026
Total individuals affectedOver 1.3 million
FARE (court-debt) records affectedApproximately 1.3 million, including names, case numbers, and Social Security numbers
Protective order records affectedApproximately 30,000 (active and inactive)
Foster care review board reports affectedMore than 150,000, dating to 2010
Oldest records involvedUp to 30 years old
Data conditionCopied from a backup server in a compressed, encrypted format
Evidence of data use/saleNone found as of October 6, per court spokesperson
Records altered or deletedNone
Jurors, witnesses, or court employees affectedNo
Investigating agenciesFBI; previously also cited DHS and Arizona DPS

What's New Since the September Disclosure

The First Official Scale Figure

When the Arizona Supreme Court first went public on September 25, Chief Justice Ann Scott Timmer described the victim population only as "many Arizonans," and early reporting suggested a toll in the tens of thousands tied mainly to protective-order and foster-care records. The October 6 update is the first time the court has put a hard number on the incident: more than 1.3 million people, an order of magnitude larger than what earlier coverage implied — driven almost entirely by the previously unmentioned FARE court-debt population rather than the protective-order and foster-care categories that dominated the initial story.

The FARE Program Is the Real Driver of Scale

The September disclosure centered on protective orders and foster care records. The October update reveals that the largest single category by far is the FARE collection program — Arizona's mechanism for tracking unpaid traffic and criminal fines, fees, and restitution. Because FARE records are retained for enforcement purposes going back up to 30 years, the exposed dataset includes names, case numbers, and Social Security numbers for people whose court debt may predate the modern internet. Court officials say the backup archive the attackers accessed had simply never been purged of decades-old entries.

Notification Is Underway

The Administrative Office of the Courts said notification of affected individuals was in progress as of the October disclosure. FARE program recipients are receiving text message notifications, and an alert is being added to collection notices sent by mail to reach people whose contact information on file is outdated — a practical concession to the fact that some affected records are decades old. Protective order holders identified in the September disclosure had already been contacted separately.

No Evidence of Misuse — Yet

Court spokesperson Alberto Rodriguez reiterated that the court has "no evidence" the stolen data "has been used or shared." Officials have repeatedly emphasized that the archive taken from the backup server was in a compressed and encrypted format, meaning whoever holds it would need to decipher it before the data becomes usable — a mitigating factor investigators continue to cite, though not a guarantee against eventual exposure or resale.

Scope Narrowed on Some Fronts

Officials also clarified what was not affected: no records were altered or deleted, and the intrusion did not touch information belonging to jurors, witnesses, or court employees. No court cases have been delayed or otherwise disrupted as a result of the breach. The attack itself lasted only about two hours on September 24 before IT staff shut down the affected backup server after a security vendor flagged an abnormal volume of downloads.

Impact Assessment

Impact AreaDescription
Scale of exposureConfirmed at over 1.3 million people — far larger than the "many Arizonans" framing used in the initial disclosure
FARE/court-debt populationNames, case numbers, and Social Security numbers exposed for records spanning up to 30 years, raising identity-theft risk for people who may no longer monitor old court-related mail or contact info
Protective order holdersRoughly 30,000 active and inactive records affected; address exposure remains a safety concern for people who sought orders specifically to stay hidden from an abuser
Foster care participantsOver 150,000 review board reports (2010–present) affected, involving children, parents, and other case participants
Notification logisticsDecades-old contact information complicates reaching some FARE-program individuals, requiring fallback channels like mailed collection-notice alerts
Public trustA sevenfold-plus jump in the disclosed victim count within two weeks raises questions about how quickly the court itself understood the scope of its own backup data
Data monetization riskNo evidence of use or sale yet, but SSNs and case data from a compressed/encrypted archive remain a latent risk if decrypted

Recommendations

For Affected FARE Program Participants

  • Watch for the text notification or mailed collection-notice alert described by the court, but verify legitimacy independently — do not click links in unexpected texts or letters; navigate directly to official state resources instead.
  • Place a credit freeze or fraud alert with Equifax, Experian, and TransUnion, particularly if your Social Security number may be tied to a decades-old FARE record you no longer actively track.
  • Visit identitytheft.gov and the Arizona Attorney General's data breach resource (azag.gov/consumer/data-breach) for state-specific guidance and to report suspected misuse.

For Protective Order Holders and Foster Care Participants

  • Confirm with the Administrative Office of the Courts whether your specific record was among those affected, since the September and October disclosures describe overlapping but distinct record categories.
  • Protective order holders should consider enrolling in an address-confidentiality program if available in their county, given the historical concern that exposed location data can help an abuser locate a victim.

For Court and Government IT Administrators

  • Apply data retention limits to backup archives — the FARE exposure reached 30 years back specifically because old records had never been purged, turning a backup server into a much larger liability than the live production dataset.
  • Encrypt backup data by default and verify that compression alone is not relied upon as a security control; pair encryption with strict access segmentation for backup infrastructure.
  • Build tiered notification pipelines in advance of an incident (SMS, mail, email) so that stale contact information on decades-old records doesn't delay legally required breach notification.

For Security Teams

  • Treat the jump from an initial "many Arizonans" estimate to a confirmed 1.3 million figure as a reminder to scope backup and archival systems fully during incident response, not just the record types first flagged by frontline staff.
  • Continue dark web and criminal-marketplace monitoring specifically for Arizona court-related PII, since encrypted/compressed archives can still be decrypted and monetized well after an initial "no evidence of use" statement.

Key Takeaways

  1. The confirmed victim count has grown from an unquantified "many Arizonans" on September 25 to over 1.3 million people as of October 6 — a scale increase driven almost entirely by a record category not emphasized in the initial disclosure.
  2. The largest exposed population is tied to the FARE court-debt program, with names, case numbers, and Social Security numbers affected for records dating back up to 30 years.
  3. Protective order records (~30,000) and foster care review board reports (150,000+) remain affected, consistent with the original September disclosure.
  4. The intrusion lasted only about two hours on September 24 before court IT staff shut down the compromised backup server; no records were altered, deleted, or tied to jurors, witnesses, or court staff.
  5. Officials say the stolen archive was compressed and encrypted, and as of the October update there is no evidence the data has been accessed, decrypted, or shared or sold.
  6. Notification is complicated by the age of some records — the court is supplementing standard notices with text alerts and mailed collection-notice inserts to reach people whose contact information may be outdated.

Sources