Arizona Courts Confirm Cyberattack Exposed Personal Data

Arizona’s court system confirmed hackers copied personal information belonging to many residents, including confidential address data associated with some protective orders.
Arizona Supreme Court seal centered on a dark blue cybersecurity background with subtle blue and red diagonal accents.

Arizona’s state court system has confirmed a cyberattack in which criminal hackers are believed to have copied personally identifiable information belonging to many Arizonans, including confidential address information associated with some protective orders.

The Arizona Supreme Court announced the incident late Sept. 25 after court IT personnel detected the attack and moved to contain it. The Administrative Office of the Courts has begun notifying people whose information it believes was copied.

The FBI is involved in the investigation, according to Arizona Supreme Court Chief Justice Ann Scott Timmer, who said she personally spoke with the agency’s top-ranking official in the state following discovery of the attack.

The court has not disclosed how the attackers gained access, the total number of people affected or who is responsible.

Protective order addresses among potentially exposed data

Notifications sent to some affected Arizonans provide additional detail about the information potentially compromised.

People with current or past protective orders were among those contacted by the court system. The notices warn that information connected to those protective orders, including confidential addresses held by the court, may have been copied during the attack.

The court said the attack occurred within approximately 36 hours of the notifications being sent and targeted a broad collection of court records rather than a specific individual.

Officials believe the attackers copied personally identifiable information about many Arizonans. The court has not yet published a comprehensive list of compromised data types or disclosed how many records were accessed.

The court also told affected people that, based on the format of the copied information, it remains unclear whether much of the data can be easily read.

There is currently no evidence that the attackers have distributed the information they obtained, according to the court.

Arizona Courts working with FBI

Court IT personnel discovered the cyberattack and took steps to stop the activity as quickly as possible. Arizona Courts has since activated its cybersecurity response plan while investigators work to determine the scope of the incident and identify those responsible.

Chief Justice Timmer said the court is working with the FBI and contacting people whose information may have been compromised.

The court has not publicly attributed the attack to a known threat actor or ransomware operation, and no ransom demand has been disclosed.

Officials are withholding some technical and investigative details to avoid interfering with the investigation or creating additional risks for affected individuals.

Confidential location data raises additional risks

The potential exposure of addresses associated with protective orders makes the incident particularly sensitive.

Protective orders can involve people seeking legal protection from stalking, harassment, domestic violence or other threats. Disclosure of an address that was intended to remain confidential could therefore create risks beyond conventional identity theft or phishing.

The court advised people who believe they may be in immediate danger to contact local law enforcement.

For other affected Arizonans, the broader theft of personally identifiable information could create risks including targeted phishing, impersonation and identity fraud, depending on the specific information copied.

Scope of breach still under investigation

The Arizona Supreme Court has created a dedicated cybersecurity information hub for updates as the investigation continues.

Several major questions remain unanswered, including the initial access vector, how long the attackers had access before detection, the exact types and volume of information copied, and whether the attack affected individual court systems differently.

The court has also not disclosed whether malware was deployed or whether the attackers attempted to encrypt systems.

The Administrative Office of the Courts said it is working to alert as many affected people as possible. Additional information is expected as investigators determine the scope of the breach.

Arizona Courts said its cybersecurity information hub will serve as the primary source for further public updates.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site →