
Arizona Court Network Intrusion Exposes Records of Over One Million People
A phishing incident granted intruders entry to archives spanning three decades, scooping up payment tallies, protective orders, and sensitive foster care files.
7 Oct 2026
A single deceptive email opened the door to decades of sensitive legal history in Arizona. State judicial officials confirmed that an intruder gained access to court records after an employee clicked an untrusted link, leading to the unauthorized copying of personal details tied to more than one million residents.
The breach struck a backup server on September 24. Technical personnel detected the unauthorized activity and severed access within roughly two hours, yet the digital trespassers had already duplicated extensive amounts of stored material before the machine was taken offline.
The bulk of the exposed data belongs to roughly 1.3 million individuals who owed court costs, fines, or restitution stemming from traffic citations and criminal charges. In many instances, the financial and case files reached back thirty years into state archives.
Beyond monetary disputes, the intrusion reached far more delicate proceedings. The copied files included roughly 30,000 protection orders, covering both active restrictions and lapsed injunctions designed to shield individuals from harm.

Another layer of confidential material fell into the attackers' reach: approximately 150,000 reports authored by a state foster care advisory panel. Those evaluations, dating back to 2010, evaluate household conditions and provide formal recommendations when biological parents face allegations of neglect or incapacity.
Judicial administrators stressed that key parts of the system remained untouched. According to court representatives, the culprits did not view or take files pertaining to jurors, witnesses, or administrative personnel, nor did they manipulate or erase existing database entries.
Daily operations across Arizona courtrooms have continued without pause, and the ongoing investigation has yielded no indications that the stolen information was published online or used for fraud, said state Supreme Court representative Alberto Rodriguez.
Authorities have begun alerting the individuals whose identities were caught in the exfiltrated backups, while internal teams and outside investigators work to trace the full footprint of the breach.