Incident
Published 2026-09-25
Verified 2026-10-07

Arizona court system: phishing click led to theft of backup files covering about 1.3 million people in the FARE court-debt program, nearly 30,000 protective-order records and 150,000 foster care review reports

The Arizona Supreme Court says criminal hackers accessed and copied backup court files in an attack that began around 11:30 a.m. on Thursday 24 September 2026 (Arizona time). Court IT staff shut it down less than two hours after spotting it, and Chief Justice Ann Timmer alerted affected people by email the next day. The court believes it started with a phishing email in which an employee clicked a malicious link. On 6 October the court told the Associated Press the copied data covers about 1.3 million people referred to its Fines/Fees and Restitution Enforcement (FARE) collection program, with court debts going back up to 30 years; court officials told FOX 10 Phoenix this includes names, case numbers and Social Security numbers. The attackers also took records on nearly 30,000 active and inactive protective orders, including confidential addresses, and more than 150,000 Foster Care Review Board reports on child dependency cases dating back to 2010. The court says no records were altered or deleted, no juror, witness or employee data was taken, it has no evidence the data has been shared, and because the files came from a compressed backup it is unclear how easily most of the data can be read. FARE notifications go out by text from short code 83958 and on mailed collection notices, and the FBI is investigating. Primary: Arizona Courts cybersecurity alert; wire: AP via SecurityWeek.

Product
Arizona Judicial Branch backup servers (FARE program, protective orders, Foster Care Review Board reports)
Versions
n/a — incident
Exploited in Australia?
unknown
Patch to
Affected Arizonans: official court messages come only from the court's email address or text short code 83958, so treat anything else as a likely scam; consider a credit freeze with Equifax, Experian and TransUnion; people with protective orders should contact police if they feel unsafe (orders stay valid). Organisations: backup servers often hold the most data with the least monitoring, so restrict access to them, encrypt backup sets, alert on bulk reads, and keep phishing-resistant MFA on staff accounts that can reach them.

Primary: Arizona Courts — Cybersecurity Alert and FAQs (attack 24 Sep 2026) · AP — Personal information for over 1 million people stolen in a cyberattack on Arizona's court system (6 Oct 2026)

breaches