One phishing click was enough to put three of the Arizona judiciary's most sensitive data sets in criminal hands. The Arizona Supreme Court says hackers copied backup court files containing the names, case numbers and Social Security numbers of roughly 1.3 million people referred to its FARE debt-collection programme, records on active and inactive protective orders, and more than 150,000 Foster Care Review Board recommendation reports going back to 2010. Court IT staff shut the intrusion down within two hours of spotting it on September 24, but the data had already been copied. Anyone who has owed the Arizona courts a fine, fee or restitution in the past 30 years should treat their SSN as exposed and freeze their credit now.
What happened: a phishing email, then the backup servers
Chief Justice Ann Scott Timmer announced the attack on the evening of September 25, 2026, saying the state court system "was the target of a cyberattack by criminal hackers or their bots" and that court leaders believed the attackers had copied personally identifiable information about many Arizonans. According to the court's resource hub, the attack appears to have begun around 11:30 a.m. on Thursday, September 24, and court IT staff shut it down less than two hours after it was identified.
On the root cause, the court is direct: "Evidence so far suggests the cyberattack began with a common phishing attack, where a court employee received an email and clicked a malicious link." What it has not disclosed is the path from that click to the data. The court has not said whether the link delivered malware or harvested credentials, whether multi-factor authentication was in place on the account involved, how the attackers reached the backup servers, or how long they had access before the activity was detected.
The target, however, is clear. The court says criminal hackers "accessed and copied backup court files" and that the FARE data "was copied from a back-up server where highly compressed information is maintained." It adds that, given the format of the copied files, "it's unclear whether most of the data can be easily read." That is a statement about compression, not encryption. The court has not said whether the backup archives were encrypted, and defenders should not read compression as protection: compressed archives are built to be restored.
What the court says was not affected
- No court records were deleted, altered or erased, and the attack will not affect pending cases, court orders or court dates.
- None of the copied data included information on jurors, witnesses or court employees.
- The court says it has no evidence that any of the information has been shared.
The court has not named a threat actor, and it has not said whether there has been a ransom or extortion demand.
Timeline of the Arizona courts cyberattack
| Date (2026) | Event |
|---|---|
| Thu 24 Sep, ~11:30 a.m. | Attack appears to have started, per the court's FAQ. Evidence points to a phishing email link clicked by a court employee. |
| 24 Sep (within two hours of identification) | Court IT staff shut the attack down. Backup court files had already been copied. |
| Fri 25 Sep (evening) | Chief Justice Ann Scott Timmer announces the attack and alerts Arizonans through official court email accounts. She says she spoke personally with the state's top FBI official. |
| From 25 Sep | The Administrative Office of the Courts begins notifying affected people. Official email comes only from no-reply@courts.az.gov. |
| Ongoing | FARE individuals notified by text message, with an alert added to collections notices sent by U.S. Postal Service. A FARE "verify" lookup is listed as "coming soon." |
Chief Justice Timmer spoke with FBI Special Agent in Charge Rebecca Day and pledged the court's full cooperation with the investigation. The court says state and federal law enforcement have been contacted.
Data affected: three judicial data sets
| Data set | Contents (per the court) | Scale | Notification channel |
|---|---|---|---|
| FARE (Fines/Fees and Restitution Enforcement) programme | Case numbers, names and Social Security numbers of people referred for collection of court-ordered debt (civil traffic, criminal traffic and criminal violations) | Approximately 1.3 million individuals, with court debts dating back 30 years | Text message, plus an alert on mailed collections notices |
| Protective orders | Records involving active and inactive protective orders, "including some sensitive information" | Not disclosed | Email from no-reply@courts.az.gov |
| Foster Care Review Board (FCRB) recommendation reports | Case information, child information, names and statements of interested parties, FCRB findings, recommendations to the court, DCS and parents. The court says the reports contain no addresses or phone numbers | More than 150,000 reports for current and past cases, dating back to 2010 | Arizona Department of Child Safety, attorneys including public defenders, juvenile presiding judges and FCRB members |
For identity fraud, the FARE set matters most: about 1.3 million names paired with Social Security numbers and court case numbers. For personal safety, the protective-order and foster-care records matter most. Protective orders typically involve people trying to keep an abuser away, and FCRB reports describe children in the dependency system. The court says about 8,000 children are currently in foster care. It says much of the copied information is considered public, but it acknowledges that each set includes sensitive material.
Root cause and the backup-server problem
The court's FAQ lists the controls it already had: statewide cybersecurity policies, required cybersecurity scans and remediation twice a year, mandatory annual training for all employees, full-time cybersecurity staff, and a "top-tier 24x7 cyber security monitoring service." Those controls did help: the activity was detected and contained within hours. They did not stop one click from reaching backup servers that held 30 years of SSNs.
Two lessons follow from what the court has disclosed:
- Backups are a data store, not just a recovery asset. Attackers increasingly go after backup repositories because they hold full, consolidated copies of production data in one place. If a user-facing foothold can reach the backup tier, the backup tier is part of the attack surface.
- Retention multiplies the blast radius. The FARE set covers court debts dating back 30 years and the FCRB set goes back to 2010. Every year of retained identifiers adds people to a breach.
The court says its leaders "will conduct a full review of this incident and adopt changes necessary to protect court data."
Notification obligations: why Arizona's breach statute treats courts differently
Arizona's data breach law, A.R.S. § 18-552, generally requires a "person" that owns or licenses computerized personal information to notify affected individuals within 45 days of determining that a breach occurred. Where more than 1,000 individuals must be notified, the statute also requires notice to the three largest nationwide consumer reporting agencies, and written notice to the Attorney General and the director of the Arizona Department of Homeland Security. However, A.R.S. § 18-551 explicitly excludes "a court" from the definition of "person," along with the Department of Public Safety, sheriff's and police departments and prosecution agencies.
Courts are instead covered by § 18-552(O), which requires them to "create and maintain an information security policy that includes notification procedures for a security system breach." In practice, the Arizona judiciary's notification duties come from its own policy rather than the 45-day statutory clock that applies to businesses and most state agencies. The court has not published that policy. Its outreach so far includes email, text messages, alerts on mailed collections notices and media coverage. It has also directed people to the FTC's identitytheft.gov and to the Arizona Attorney General's data-breach page.
Defensive playbook for public-sector and enterprise defenders
If you may be affected
- Place a credit freeze or fraud alert with Equifax, Experian and TransUnion, as the court recommends for FARE individuals.
- Treat only email from
no-reply@courts.az.govas official. Expect follow-on phishing and smishing that impersonates the court or debt collectors. - Report identity misuse at identitytheft.gov. If you are a protected party under a protective order, review your safety plan with your advocate or attorney.
For security teams running similar environments
- Make phishing-resistant MFA the default. Use FIDO2/WebAuthn security keys or platform passkeys for every account that can reach file shares, backup consoles or hypervisors. Push or SMS one-time codes can be relayed by adversary-in-the-middle phishing kits.
- Separate backup infrastructure from user identity. Run backup servers and consoles in a dedicated management zone with a separate administrative identity domain. Allow no interactive logons from user workstations and no SMB/RDP from user VLANs.
- Encrypt backups at rest with keys held outside the production domain (HSM or KMS with separate administrative control), so copied archives cannot simply be restored by whoever steals them.
- Watch for egress from the backup tier. Backup servers should rarely start large outbound transfers to the internet. Alert on any outbound session from backup subnets that is not going to your sanctioned replication target.
- Minimise retained data. Set retention schedules for collections and case data, and tokenise or truncate SSNs in backup sets wherever the full value is not needed for business purposes.
- Pre-register an official notification sender and publish it, as the court did with no-reply@courts.az.gov, so affected people can tell real notices from scams.
- Rehearse breach notification against your actual legal regime. For Arizona courts, that means the information security policy required under § 18-552(O), not the 45-day clock that applies to other entities.



