Security News

Phishing Email Led to Arizona Court Breach Exposing 1.3 Million People's Data

The Record · 8 Oct 2026
Key Takeaway Train staff to spot and report suspicious email links, and keep backup files secured and limited in how long old personal data is retained, because a single phishing click can expose decades of records.

A cyberattack on Arizona's court system gave hackers access to the sensitive information of more than 1.3 million people. Court officials say federal and state investigators confirmed that the attackers accessed and copied backup court files. Investigators believe the attack began with a phishing email, where a court employee clicked a malicious link.

The attackers breached the Fines/Fees and Restitution Enforcement (FARE) Program, which helps collect outstanding debts tied to traffic and criminal violations. The stolen data dates back 30 years and includes names, social security numbers and case numbers. Victims will be contacted by text message and have been urged to place holds on their credit lines. The court says the format of the stolen files may make them difficult for the hackers to read.

The hackers also accessed more than 150,000 Foster Care Review Board reports dating back to 2010, including information on 8,000 children currently in foster care, as well as records involving protective orders. The court says the incident did not involve ransomware, and no ransom demands or claims of responsibility had been made at the time of reporting. The attack began on September 24 and continued until the court's IT team shut the system down entirely.

Summarised by CISO AI from The Record, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.