Arizona Court Breach Affects Over 1 Million People, Records Span 30 Years
The Arizona Supreme Court confirmed on October 6, 2026, that the cyberattack on its court network — first disclosed on September 25 — exposed personal information belonging to more than 1.3 million people, with some of the stolen records dating back as far as 30 years. The figure is the first official scale estimate since the court initially described the toll only as affecting "many Arizonans," and it elevates an incident that had been framed around protective-order and foster-care records into one of the larger publicly disclosed government data breaches of the year.
The bulk of the newly quantified exposure comes from the court's Fines/Fees and Restitution Enforcement (FARE) collection program, which tracks people with unpaid court debt — fines, fees, and restitution tied to traffic and criminal violations — stretching back three decades. Court officials said names, case numbers, and Social Security numbers tied to FARE accounts were among the data copied. Separately, roughly 30,000 active and inactive protective order records and more than 150,000 foster care review board reports dating to 2010 were also confirmed as affected, building on the categories identified in the court's original disclosure.
Updated Incident Details
| Attribute | Value |
|---|---|
| Target | Arizona court system (Administrative Office of the Courts / Arizona Supreme Court) |
| Attack vector | Phishing — employee clicked a malicious link believing it was legitimate |
| Attack date | September 24, 2026 |
| Detection-to-shutdown | Approximately two hours after a security vendor flagged abnormal bulk downloads |
| Initial public disclosure | September 25, 2026 |
| Updated scale disclosure | October 6, 2026 |
| Total individuals affected | Over 1.3 million |
| FARE (court-debt) records affected | Approximately 1.3 million, including names, case numbers, and Social Security numbers |
| Protective order records affected | Approximately 30,000 (active and inactive) |
| Foster care review board reports affected | More than 150,000, dating to 2010 |
| Oldest records involved | Up to 30 years old |
| Data condition | Copied from a backup server in a compressed, encrypted format |
| Evidence of data use/sale | None found as of October 6, per court spokesperson |
| Records altered or deleted | None |
| Jurors, witnesses, or court employees affected | No |
| Investigating agencies | FBI; previously also cited DHS and Arizona DPS |
What's New Since the September Disclosure
The First Official Scale Figure
When the Arizona Supreme Court first went public on September 25, Chief Justice Ann Scott Timmer described the victim population only as "many Arizonans," and early reporting suggested a toll in the tens of thousands tied mainly to protective-order and foster-care records. The October 6 update is the first time the court has put a hard number on the incident: more than 1.3 million people, an order of magnitude larger than what earlier coverage implied — driven almost entirely by the previously unmentioned FARE court-debt population rather than the protective-order and foster-care categories that dominated the initial story.
The FARE Program Is the Real Driver of Scale
The September disclosure centered on protective orders and foster care records. The October update reveals that the largest single category by far is the FARE collection program — Arizona's mechanism for tracking unpaid traffic and criminal fines, fees, and restitution. Because FARE records are retained for enforcement purposes going back up to 30 years, the exposed dataset includes names, case numbers, and Social Security numbers for people whose court debt may predate the modern internet. Court officials say the backup archive the attackers accessed had simply never been purged of decades-old entries.
Notification Is Underway
The Administrative Office of the Courts said notification of affected individuals was in progress as of the October disclosure. FARE program recipients are receiving text message notifications, and an alert is being added to collection notices sent by mail to reach people whose contact information on file is outdated — a practical concession to the fact that some affected records are decades old. Protective order holders identified in the September disclosure had already been contacted separately.
No Evidence of Misuse — Yet
Court spokesperson Alberto Rodriguez reiterated that the court has "no evidence" the stolen data "has been used or shared." Officials have repeatedly emphasized that the archive taken from the backup server was in a compressed and encrypted format, meaning whoever holds it would need to decipher it before the data becomes usable — a mitigating factor investigators continue to cite, though not a guarantee against eventual exposure or resale.
Scope Narrowed on Some Fronts
Officials also clarified what was not affected: no records were altered or deleted, and the intrusion did not touch information belonging to jurors, witnesses, or court employees. No court cases have been delayed or otherwise disrupted as a result of the breach. The attack itself lasted only about two hours on September 24 before IT staff shut down the affected backup server after a security vendor flagged an abnormal volume of downloads.
Impact Assessment
| Impact Area | Description |
|---|---|
| Scale of exposure | Confirmed at over 1.3 million people — far larger than the "many Arizonans" framing used in the initial disclosure |
| FARE/court-debt population | Names, case numbers, and Social Security numbers exposed for records spanning up to 30 years, raising identity-theft risk for people who may no longer monitor old court-related mail or contact info |
| Protective order holders | Roughly 30,000 active and inactive records affected; address exposure remains a safety concern for people who sought orders specifically to stay hidden from an abuser |
| Foster care participants | Over 150,000 review board reports (2010–present) affected, involving children, parents, and other case participants |
| Notification logistics | Decades-old contact information complicates reaching some FARE-program individuals, requiring fallback channels like mailed collection-notice alerts |
| Public trust | A sevenfold-plus jump in the disclosed victim count within two weeks raises questions about how quickly the court itself understood the scope of its own backup data |
| Data monetization risk | No evidence of use or sale yet, but SSNs and case data from a compressed/encrypted archive remain a latent risk if decrypted |
Recommendations
For Affected FARE Program Participants
- Watch for the text notification or mailed collection-notice alert described by the court, but verify legitimacy independently — do not click links in unexpected texts or letters; navigate directly to official state resources instead.
- Place a credit freeze or fraud alert with Equifax, Experian, and TransUnion, particularly if your Social Security number may be tied to a decades-old FARE record you no longer actively track.
- Visit identitytheft.gov and the Arizona Attorney General's data breach resource (azag.gov/consumer/data-breach) for state-specific guidance and to report suspected misuse.
For Protective Order Holders and Foster Care Participants
- Confirm with the Administrative Office of the Courts whether your specific record was among those affected, since the September and October disclosures describe overlapping but distinct record categories.
- Protective order holders should consider enrolling in an address-confidentiality program if available in their county, given the historical concern that exposed location data can help an abuser locate a victim.
For Court and Government IT Administrators
- Apply data retention limits to backup archives — the FARE exposure reached 30 years back specifically because old records had never been purged, turning a backup server into a much larger liability than the live production dataset.
- Encrypt backup data by default and verify that compression alone is not relied upon as a security control; pair encryption with strict access segmentation for backup infrastructure.
- Build tiered notification pipelines in advance of an incident (SMS, mail, email) so that stale contact information on decades-old records doesn't delay legally required breach notification.
For Security Teams
- Treat the jump from an initial "many Arizonans" estimate to a confirmed 1.3 million figure as a reminder to scope backup and archival systems fully during incident response, not just the record types first flagged by frontline staff.
- Continue dark web and criminal-marketplace monitoring specifically for Arizona court-related PII, since encrypted/compressed archives can still be decrypted and monetized well after an initial "no evidence of use" statement.
Key Takeaways
- The confirmed victim count has grown from an unquantified "many Arizonans" on September 25 to over 1.3 million people as of October 6 — a scale increase driven almost entirely by a record category not emphasized in the initial disclosure.
- The largest exposed population is tied to the FARE court-debt program, with names, case numbers, and Social Security numbers affected for records dating back up to 30 years.
- Protective order records (~30,000) and foster care review board reports (150,000+) remain affected, consistent with the original September disclosure.
- The intrusion lasted only about two hours on September 24 before court IT staff shut down the compromised backup server; no records were altered, deleted, or tied to jurors, witnesses, or court staff.
- Officials say the stolen archive was compressed and encrypted, and as of the October update there is no evidence the data has been accessed, decrypted, or shared or sold.
- Notification is complicated by the age of some records — the court is supplementing standard notices with text alerts and mailed collection-notice inserts to reach people whose contact information may be outdated.
Sources
- Personal information for over 1 million people stolen in a cyberattack on Arizona's court system — SecurityWeek
- Personal information for over 1 million people stolen in a cyberattack on Arizona's court system — The Associated Press
- Arizona Courts cyber attack potentially exposes 1.3M people's data — KVOA News 4 Tucson
- Arizona Courts Cyber Attack Exposed 30 Years of Personal Data — Government Technology