HomeSecurityCyberattack on Arizona's judicial system: 1.3 million victims

Cyberattack on Arizona's judicial system: 1.3 million victims

A recent cyberattack on the Arizona court system is one of the most serious data breaches to hit a public institution in the United States in recent years. According to SecurityWeek, the attack began when a court employee clicked on a malicious link, resulting in the theft of personal information from more than 1.3 million people. The incident highlights once again how vulnerable public infrastructure remains to targeted phishing and data exfiltration attacks.

cyberattack on Arizona court system data breach 1.3 million

The Arizona Supreme Court announced that the attack was detected on September 24, 2026, and that the court’s technology department was able to intercept it on a backup server about two hours after it was detected. The attackers did not use ransomware — instead, they copied data without encrypting it or demanding a ransom, which makes the attack even more difficult to detect. Court spokesman Alberto Rodriguezsaid there is no indication, so far, that the data has been used or shared.

See also: Perplexity: Personal Computer AI is coming to Windows

The investigation into the incident is being conducted jointly by the court and the FBI. No specific threat actor has been publicly identified, nor has the attack been attributed to any known hacking group. Importantly, no records were altered or deleted, and no information about jurors, witnesses, or court employees was stolen. However, the scope of the data copied is extremely concerning.

What data was exposed in the cyberattack on the Arizona judicial system?

The stolen data came from three different databases. First, the Fines/Fees and Restitution Enforcement Program (FARE) includes information on 1.3 million people who had unpaid fines, fees, or restitution from traffic or criminal cases — with records dating back up to 30 years. Second, records of nearly 30,000 active and inactive protective orders, which involve highly sensitive information about victims, protected persons, and defendants. Third, approximately 150,000 Foster Care Review Board reports dating back to 2010 and relate to cases where parents were found to be unfit or unfit to care for their children.

Exposing this data is not just a financial risk. Protection order and child welfare records can put the safety of the individuals involved at immediate risk. A malicious actor who knows someone has a protection order against them can use this information for intimidation. Similarly, disclosing information from child welfare cases can have serious consequences for the families involved.

See also: Google Personal Intelligence: Available to all Gemini users in the US

Cyberattack on Arizona's judicial system: 1.3 million victims

Recommendations for protection after cyberattack on the judicial system

To prevent such incidents, cybersecurity experts recommend a number of technical and organizational measures. First of all, implementing phishing-resistant multi-factor authentication (MFA) — preferably with FIDO2 security keys or passkeys — for administrators and users with access to sensitive repositories is absolutely essential. Backup systems should also be treated as critical infrastructure: they need separate credentials, network segmentation, immutable copies, encryption, and notifications for abnormal bulk reads or exports.

Data minimization is also a critical measure: keeping 30 years of personally identifiable information in accessible systems poses a huge risk. Organizations should periodically review whether historical records should remain online, whether sensitive fields can be tokenized, and whether social security numbers can be removed from operational copies. Finally, user education through phishing simulations is necessary, but not sufficient on its own — it must be combined with technical measures such as URL filtering , browser isolation , and endpoint detection and response (EDR) .

See also: Perplexity Personal Computer: A cloud-based AI agent for Mac mini

Cyberattack on Arizona's judicial system: 1.3 million victims

In summary, the cyberattack on the Arizona court system is a stark reminder that no public institution is immune. The combined exposure of financial data, protective orders, and child welfare records poses risks that go far beyond simple financial fraud. Authorities are urging affected individuals to monitor their credit reports and take immediate protective measures, while the FBI and court investigation continues.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS