Technology·News & analysis
Arizona court hack exposed data on 1.3 million people after one phishing click
A phishing link opened by a court employee let attackers copy backups with Social Security numbers, protective order records and foster care reports.

Tide
Ripple
Sci-fi
1/10
Reality
Shipping
One email link, two hours, and decades of court backups copied.How we rate
Arizona's court system says attackers copied personal data on about 1.3 million people after an employee clicked a phishing link on September 24.
The stolen backups include Social Security numbers from a court debt program, records tied to nearly 30,000 protective orders and over 150,000 foster care reports. The data goes back as far as 30 years. The FBI is investigating, and the court is urging affected people to freeze their credit.
What to know
- Attackers copied names, case numbers and Social Security numbers for about 1.3 million people referred to Arizona's court debt collection program, going back 30 years.
- They also took records tied to nearly 30,000 protective orders and more than 150,000 Foster Care Review Board reports dating back to 2010.
- The court says it started when an employee clicked a malicious link in a phishing email on September 24, and IT staff stopped it within about two hours.
- The data came from compressed backups, and the court says it has no evidence it has been read or shared. The FBI is investigating.
Arizona's court system says attackers copied personal data on about 1.3 million people after a single court employee clicked a bad link in an email. The Arizona Supreme Court has been notifying people since late September, and the Associated Press reported the full scope on Tuesday.
So how does one click turn into Social Security numbers, protective order records and foster care reports walking out the door? Here's what we know.
What actually happened?
On Thursday, September 24, someone got into the Arizona courts' network and started copying data from a backup server. The court's technology staff spotted it and shut it down about two hours later, the AP reports.
Chief Justice Ann Scott Timmer announced the attack the next day. In her statement, she said the court system was targeted by criminal hackers "or their bots," and that they copied personal information about "many Arizonans."
Over the following week, the court released more detail in stages:
- September 25: first announcement; the FBI is notified.
- September 28: the court discloses that foster care review reports were taken.
- September 30: it adds that names and Social Security numbers of about 1.3 million people were copied.
- October 6: the court tells the AP the attack hasn't affected or delayed any court cases.
What data did they take?
There are three main groups of records, according to the court and the outlets that covered it.
- Court debt data: names, case numbers and Social Security numbers for about 1.3 million people referred to the FARE program, going back 30 years.
- Protective orders: records tied to nearly 30,000 active and inactive orders of protection, the AP reports. ABC15 says court officials put the number of people with protective orders who may be affected at about 170,000.
- Foster care reports: more than 150,000 Foster Care Review Board reports for current and past cases dating back to 2010.
FARE stands for Fines/Fees and Restitution Enforcement. It's the statewide program that collects unpaid court-ordered debt from civil traffic, criminal traffic and criminal cases. The court notes that people who were never sent to collections aren't in this data set.
What was not taken: the court says no records were deleted or altered. It also says there's no evidence that information about jurors, witnesses or court employees was in the copied files.
Why are the foster care files so sensitive?
The Foster Care Review Board is a set of citizen panels inside the Supreme Court's Administrative Office of the Courts. They review children's cases and make recommendations to juvenile court judges.
According to the court, the copied reports can include information about children, names of the people involved, statements, the board's findings and its recommendations for courts, parents and the Arizona Department of Child Safety. They don't include addresses or phone numbers.
Arizona has about 8,000 children in foster care right now, KJZZ reports, citing the court. The court says the reports hold case information that was already shared with participants, including parents, through the board's normal process.
A foster care report or a protective order file is not like a leaked password: you can't reset it. That's why people connected to these records have reacted so strongly.
How did one click cause all this?
It started with phishing: a fake email designed to look real, so the person reading it clicks a link or types in a password.
Spokesperson Alberto Rodriguez told the Arizona Republic that this was not a targeted attack. A court employee opened a phishing email, and the attackers used that foothold to copy files. In Rodriguez's words to KJZZ, they "accessed our system via a phishing attack email and copied information from our backup servers."
Think of it like a building where someone props open the side door for a moment. The front desk can be excellent, but the storage room in the basement is still down the hall.
The catch: the files they grabbed were backups, kept for recovery after ransomware and other destructive attacks, according to Malwarebytes' summary of the court's update. Backups are supposed to be the safety net. Here, they were the target.
Can the hackers actually read the data?
That's still unclear. The court says the backups were stored in a highly compressed format, and the Arizona Republic reports the data was encrypted.
"The court has no evidence that any data has been accessed, is readable, or has been shared," the court said in a statement quoted by KJZZ. Rodriguez repeated on Tuesday that "we don't have any evidence it has been used or shared."
A court spokesperson told Recorded Future News that this was not a ransomware attack and that no ransom had been demanded. No hacking group has publicly taken credit.
What's next: the FBI is investigating, and Timmer said she spoke directly with the special agent in charge. She told ABC15 that the courts have also alerted the state police.
Who's affected, and how are they hearing about it?
The court says it's contacting people it believes were affected. People in the FARE program are being notified by text message, FOX 10 reports, and KJZZ says the court will also include breach information in mailed collections notices.
For foster care cases, the court says it notified the Department of Child Safety, attorneys for parents and children, juvenile court presiding judges and review board members.
Not everyone says they've heard anything. FOX 10 spoke with Lori Ford, an advocate with the Arizona Department of Child Safety Oversight Group, who said parents whose children's information may be involved have not been notified. A Mesa foster parent told AZFamily that court officials did not contact her either.
People with protective orders are feeling it too. One woman told ABC15 her records included her children's names and family addresses. She's now using a P.O. box, added security cameras and bought identity theft protection.
In real life If you get a text or email saying you're part of this breach, don't click any links in it. Go to azcourts.gov yourself, or call the court using a number you looked up on your own, to confirm it's real.
How big is this compared with other court hacks?
Courts hold exactly the kind of data attackers want. Recorded Future News notes that a ransomware attack shut down nearly all of Kansas' court systems in 2023 and took months to fully resolve.
State and local courts in California, Nebraska, South Carolina, Florida, Wisconsin, Louisiana, Ohio, Missouri and Illinois have faced ransomware, denial-of-service attacks or data breaches over the last four years, according to the same report.
We covered another huge government data leak just this week, when Denmark's national ID register was breached. Different country, different method, same lesson: the biggest risk often comes through a door that was supposed to be legitimate.
What it means for you
- If you've ever owed Arizona court fines or fees: you may be in the FARE data. Consider a credit freeze with Equifax, Experian and TransUnion, as the court recommends.
- If you have a protective order in Arizona: the court says your order is still valid and you don't need to refile. The AZPoint website was not compromised and is safe to use.
- Watch for fake follow-ups: scammers love a fresh breach. Anyone contacting you "about the Arizona court breach" should be verified through a channel you found yourself.
- Anywhere else: this all began with one phishing click. If an email link at work feels even slightly off, check with your IT team before you open it.
The bottom line
A single phishing click gave attackers about two hours inside Arizona's court network, and that was enough to copy backups covering 1.3 million people and some of the state's most sensitive family records. The court says there's no sign the data has been read or shared yet, and the FBI is on it. If you might be in the data, a credit freeze is the simplest step you can take today.
Key facts
- People in the debt program data
- About 1.3 million, going back 30 years
- Other records copied
- Nearly 30,000 protective orders and 150,000+ foster care reports
- How it started
- A court employee clicked a malicious link in a phishing email
- When
- September 24, 2026; stopped in about two hours
- Who's investigating
- The FBI, with state police alerted
Got questions?
Quick answers, plain wordsWhat happened to Arizona's court system?
Attackers got into the Arizona courts' network on September 24, 2026 and copied data from a backup server before IT staff shut them out about two hours later, according to the Arizona Supreme Court.
How many people are affected?
About 1.3 million people referred to the state's FARE court debt collection program, plus people connected to nearly 30,000 protective orders and more than 150,000 foster care review reports. ABC15 reports court officials put the number of people tied to protective orders at about 170,000.
What is the FARE program?
FARE stands for Fines/Fees and Restitution Enforcement. It's the Arizona Judicial Branch's statewide program for collecting unpaid court-ordered debt from civil traffic, criminal traffic and criminal cases.
What information was taken?
For the FARE data: names, case numbers and Social Security numbers. The foster care reports include information about children, names of people involved, statements, findings and recommendations, but no addresses or phone numbers, the court says.
How did the hackers get in?
A court employee clicked a malicious link in a phishing email, the court says. Spokesperson Alberto Rodriguez said it was not a targeted attack.
Was it ransomware?
No, a court spokesperson told Recorded Future News. There had been no ransom demand, and no hacking group has publicly taken credit.
Has the stolen data been leaked?
The court says it has no evidence the data has been read, used or shared. It was stored in a highly compressed, encrypted format, so it's unclear how easily it can be read.
Are court cases or protective orders affected?
No. The court says no records were deleted or altered and no cases were delayed. Existing protective orders stay valid, and the AZPoint website for requesting them was not compromised.
Were jurors, witnesses or court employees affected?
The court says there's no evidence their information was in the copied files.
What should I do if I'm affected?
The court recommends placing a hold or freeze on your credit with Equifax, Experian and TransUnion, and visiting identitytheft.gov and the Arizona Attorney General's data breach page.
SourcesArizona Judicial Branch
Topics and tagsCybersecurity, data breach, cybersecurity, phishing
Related stories

Denmark's national ID register breached, exposing 8.8 million people's CPR numbers
Unknown attackers abused a private company's legal access to Denmark's Central Person Register to pull names, addresses and CPR numbers for about 8.8 million people.

ASOS app users get an 'ASOS HACKED' alert as attackers claim a Snowflake breach
A push notification from the ASOS app told the retailer's data protection and IT teams that hackers had 'fully compromised' its Snowflake data and would leak it. ASOS shares fell about 10%.

FBI drops an Accenture contractor after a missed patch exposed staff data
A senior FBI official says a contractor failed to apply a security patch to a system it managed. Sources say it was Oracle's PeopleSoft and the contractor was Accenture, tying it to last month's ShinyHunters breach.
More in brief
- Rapidus signs up 17 design firms to find customers for its 2nm chipsOct 7
- Man who streamed AI songs with bots for $8 million gets 18 months in prisonOct 7
- Claude plans give about 5x the AI usage of ChatGPT's, SemiAnalysis findsOct 7
- Jaguar reveals the Type 01, its 1,000-hp electric grand tourerOct 7
- OpenAI publishes 722 math papers written by an unreleased AI modelOct 6
- Hackers hijacked three country domains to get fake Google certificatesOct 6