Arizona court system hack leads to theft of personal data belonging to 1.3 million Americans
Someone "clicked on a link in an email"
- A successful phishing attack at the Arizona Supreme Court led to data compromise
- More than a million people are now thought to be affected
- The court's operations were not disrupted
The Arizona Supreme Court has suffered a cyberattack in which it lost sensitive data on more than a million people after an employee allegedly “clicked a malicious link in an email”, which led to the compromise of information on 1.3 million people.
Information is still scarce on the issue, as we don’t know if that malicious link resulted in the victim’s device being infected with an infostealer, or if they were asked to log into a bogus portal, allowing the threat actors to access their account directly.
It was confirmed that the threat actors copied information on 1.3 million people with unpaid court fees, fines and restitution payments for traffic and criminal violations dating back 30 years. They also nabbed almost 30,000 active and inactive orders of protection, as well as 150,000 reports dating back to 2010 from a foster care board making recommendations in cases where parents were allegedly unable or unfit to care for a child.
This kind of data is a gold mine for cybercriminals. Personal and private information can be used to tailor unique, personalized phishing lures which the victims will have a very hard time identifying. These emails can lure the recipients into downloading malware, or navigating to spoofed login portals designed to steal credentials. That malware can then spread to the victims’ employers, possibly resulting in ransomware deployments or data theft and extortion.
Responding to the attack
According to the Associated Press (AP), the court’s IT team shut down the attack on a backup server, roughly two hours after being spotted, on September 24. Since then, they have been notifying the affected individuals about the breach and theft.
So far, the data has not yet made it to the dark web, it seems: “We don’t have any evidence it has been used or shared” after the attack, Supreme Court spokesperson Alberto Rodriguez said.
This would also suggest that this was not the work of any known ransomware groups or data extortionists because by now they would have at least bragged about it on the dark web.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The investigation is still ongoing. The court’s operations have not been disrupted in any way, Rodriguez added. The records were not altered, or deleted, and the attackers apparently did not steal information about jurors, witnesses, or court employees.
Attacking courts
Courts (both in the US and elsewhere) are frequent targets, mostly due to the sensitivity of the information they work with.
In early September 2026, it was reported that Thomson Reuters, the IT company behind the Reuters news agency, suffered a similar incident in March.
The company operates a court case-management system called C-Track, used by different courts to manage things like cases, filings, hearings, and schedules. It is used by courts in several US states, the US Virgin Islands, as well as Ontario, Canada. Unnamed miscreants managed to break in, obtaining “court records and personal information” across 11 US states, the US Virgin Islands, and Ontario, Canada.
Earlier still, on November 21, 2025, the Georgia Superior Court Clerks’ Cooperative Authority (GSCCCA), which manages court and public-record services across Georgia, detected hackers trying to break into the network. The attack was claimed by threat actors called Devman, which claimed to have stolen sensitive files and demanded a ransom payment in exchange. The GSCCCA temporarily shut down its websites and online services, while the FBI warned the authority of an imminent threat.
However, GSCCCA said it stopped the attackers before they were able to extract or encrypt any data and refused to pay the ransom. Devman is not a household name in the cybercriminal underworld, and apparently, it is a financially motivated group, not a state-sponsored one.
Via AP News
➡️ Read our full guide to the best antivirus
1. Best overall:
Bitdefender Total Security
2. Best for families:
Norton 360 with LifeLock
3. Best for mobile:
McAfee Mobile Security
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.
You must confirm your public display name before commenting
Please logout and then login again, you will then be prompted to enter your display name.