Arizona Supreme Court Data Breach: What Happened and Who's Affected

A phishing click exposed Social Security numbers, protective-order files and 150,000+ foster-care records in Arizona's court system. Here's what's known and how to protect yourself.

The Arizona Supreme Court courtroom bench with U.S. and Arizona flags, in the state's Supreme Court building in Phoenix
The Arizona Supreme Court courtroom in Phoenix, where Chief Justice Ann Scott Timmer and her colleagues hear oral arguments. Image: Arizona Supreme Court.

Arizona's court system has confirmed that criminal hackers broke into its network after an employee clicked a malicious link, copying Social Security numbers and case records tied to more than 1.3 million people enrolled in the state's court-debt-collection program, along with backup files containing protective-order and foster-care records. The Arizona Supreme Court's Administrative Office of the Courts (AOC) says IT staff shut the intrusion down within about two hours, the FBI was notified immediately, and notifications to affected individuals — including by text message — began in the final days of September 2026.

What happened

According to the AOC, the breach began with a phishing email containing a malicious link. A court employee clicked it, giving attackers a foothold inside the court system's network. Chief Justice Ann Scott Timmer has said the hackers did not deploy ransomware or other malware to lock down systems; instead, they used their access to copy, or exfiltrate, files before court IT staff detected and shut down the intrusion. "It was detected fairly quickly and shut down, but not until a lot of information was downloaded," Timmer said, according to reporting reviewed for this article.

No hacking or ransomware group has publicly claimed responsibility, and the AOC says it has not identified the attackers or a motive, according to reporting by The Record. Officials have said they have no evidence so far that the stolen data has been shared or posted publicly, though Timmer has acknowledged the risk that it could be sold. "I suppose you could use it to try to sell it to anybody interested in locating information, and that's what's most concerning," she said.

Timeline of the breach

DateEvent
Late September 2026A court employee clicks a malicious link in a phishing email, giving attackers access to Arizona court network resources.
Same dayCourt IT staff detect the intrusion and contain it within approximately two hours; the FBI is notified.
~Sept. 25–26, 2026The AOC begins notifying people believed to be affected, including text-message alerts to individuals in the FARE court-debt program.
Sept. 27, 2026Arizona court officials publicly announce the cyberattack and confirm FBI involvement.
Sept. 29–30, 2026Chief Justice Ann Scott Timmer gives additional interviews detailing the scope, including confirmation that protective-order and Foster Care Review Board records were among the copied files.

Exact dates have shifted slightly across reports as the AOC has released information in stages; this piece reflects the dates most consistently reported by outlets that reviewed court notices and official statements.

What data was exposed

The court has described the exposure in several overlapping categories rather than a single flat list. Based on statements from the AOC and Chief Justice Timmer, the copied files include:

Data categoryDetails
FARE program recordsNames, case numbers and Social Security numbers tied to people referred to Arizona's Fines/Fees and Restitution Enforcement (FARE) program, which collects court-ordered debt. More than 1.3 million people may be affected.
Protective order recordsDescribed by Timmer as "the biggest cohort" of affected records — information tied to people who have current or former injunctions against harassment or orders of protection.
Foster Care Review Board filesMore than 150,000 recommendation reports dating back to 2010, covering children's names, case details and board findings from Arizona's Foster Care Review Board.

The court has said it has no evidence so far that information belonging to jurors, witnesses or court employees was included in the copied files, and that contact information such as home addresses or phone numbers was largely not part of the exposed data — though case content itself, including sensitive details tied to protective orders and foster-care proceedings, was, according to Malwarebytes Labs' review of the incident.

Who's affected, in short:
  • More than 1.3 million people connected to Arizona's FARE court-debt program, whose names, case numbers and Social Security numbers may have been copied.
  • People with current or former protective orders (injunctions against harassment) through Arizona courts.
  • Families and children tied to more than 150,000 Foster Care Review Board case files dating to 2010.
What to do right now: place a freeze on your credit file with Equifax, Experian and TransUnion, watch for an official notice from the Arizona courts (including by text message for FARE participants), and treat unsolicited calls or texts claiming to be from the court system with suspicion.

What the FARE program is, and why it was targeted

FARE stands for Fines/Fees and Restitution Enforcement — Arizona's statewide program for collecting court-ordered debt, including unpaid fines, fees and restitution. Because the program tracks individuals by case number and Social Security number in order to process payments and collections, its backend systems hold exactly the kind of identity data that makes a breach costly for the people involved: full names paired with SSNs and case history, the building blocks of tax-refund fraud, synthetic identity theft and account takeover. The Arizona courts' own FARE program page describes the unit's role in centralizing collection of court debt across the state's counties — the same centralization that made it a single point of exposure once attackers got inside.

What court and FBI officials are saying

Chief Justice Timmer has been the court system's public face on the breach. "As soon as I learned about this outrageous criminal attack on Arizona's Courts, I immediately called our team together to formulate a response," she said in a statement. "I personally spoke with the top-ranking FBI leader in the state, and I pledged our full commitment to supporting their investigation and minimizing the likelihood that the information will be used to further jeopardize Arizonans."

The FBI is leading the criminal investigation, and the AOC has said it is deliberately withholding some technical details of the intrusion so as not to compromise that investigation or give copycat attackers a roadmap. That has left some of the people whose records were affected, including foster-care advocates, saying communication has been too slow — according to FOX 10 Phoenix reporting that cited child-welfare advocate Lori Ford, parents of children whose foster-care files were exposed had not been directly notified as of late September, even as FARE participants began receiving text alerts.

How this breach compares to other recent incidents

The Arizona courts breach is notable less for its entry method — a single clicked phishing link is still how a large share of breaches start — and more for the sensitivity of the records involved. Unlike a retailer or SaaS vendor breach that typically exposes payment data or account credentials, this incident touches core government case files: protective orders meant to shield people from harassment, and foster-care records involving minors. That combination of scale (over 1.3 million people in the FARE cohort alone) and the categories of data involved puts it in the same tier of severity as other 2026 government and institutional breaches this desk has covered, including the Pentagon's DMDC data breach. As with that incident, the people affected had no direct relationship with — and no choice about — the system that lost their data; they were court filers, debtors, protective-order holders and children in the foster-care system, not customers of a product they opted into.

Investigation status

As of early October 2026, no ransomware group or hacking crew has publicly claimed the attack, which is itself notable: most large-scale data-theft intrusions that don't involve ransomware are typically followed within days or weeks by a leak-site posting or an extortion attempt, used as leverage to pressure the victim into paying. The absence of a claim so far could mean the attackers are still assessing or trying to monetize the data quietly, that they intend to sell it through other channels, or simply that they haven't moved yet. The court says it has no evidence that the data has been shared or appeared for sale, but has been careful to frame that as "no evidence so far" rather than an assurance the data is safe.

The AOC has also declined to say publicly how the attackers moved from a single employee's compromised account to the backup files containing protective-order and foster-care data, citing the active FBI investigation, as Cybernews has reported. That's a common tension in breach disclosures involving law enforcement: victims are often advised to withhold technical indicators of compromise that could otherwise help the public and other potential targets harden their own defenses, in order to avoid tipping off the attackers or jeopardizing a prosecution. For affected Arizonans, the practical effect is that key questions — how long the attackers had access before detection, exactly which backup systems were reached, and whether any data has since left the attackers' possession — remain unanswered for now.

A separate, earlier incident involving a court vendor

This breach is distinct from an earlier, unrelated incident in which Managed.com, a hosting vendor used for the public-facing azcourts.gov website, suffered its own ransomware attack that caused a service interruption to the website itself. That vendor-side outage did not involve the court's internal case-management systems or the FARE, protective-order and foster-care data described above, and officials have said it did not affect individual county court or clerk's office operations. The two incidents are worth keeping separate: one was a website availability problem at a third-party host, while the breach detailed in this article involves direct, unauthorized access to sensitive records inside the Arizona court system's own network.

What to do if you think you're affected

If you have ever had a case referred to Arizona's FARE collections program, held a protective order through an Arizona court, or have a child whose case was reviewed by Arizona's Foster Care Review Board since 2010, you should treat yourself as potentially affected until you receive — or confirm the absence of — an official notice.

  • Watch for an official notice. The AOC says it is notifying FARE participants it believes were affected by text message; do not assume every text claiming to be from the Arizona courts is legitimate. Verify independently by contacting the court system directly rather than clicking links in an unsolicited text.
  • Freeze your credit. A credit freeze with all three major bureaus — Equifax, Experian and TransUnion — is free and blocks new accounts from being opened in your name using a stolen SSN. The FTC's IdentityTheft.gov walks through the process step by step and is the government's official recovery portal if you do become a victim of identity theft.
  • Be alert for targeted phishing. Because the stolen data includes case numbers and details tied to real court matters, any follow-on scam attempts could look unusually convincing — for example, a fake call referencing a real case number tied to a protective order or a FARE debt. Treat unsolicited contact asking you to "verify" personal details or make a payment with suspicion, and confirm independently with the court.
  • Consider a data removal service if you're repeatedly targeted. Stolen identity data tends to circulate through data broker and people-search sites over time. If you're dealing with a wave of unwanted contact after a breach like this, a service that removes your personal details from broker sites — compared in our DeleteMe vs. Incogni vs. Aura comparison — can reduce how easily that data is found and reused.
  • Watch your phone number too. Because FARE notifications are going out by text, and because SSNs plus names are a stepping stone to account takeover, it's worth reviewing the warning signs in our SIM swap scams explainer if you start noticing unusual account or carrier activity.
  • Foster-care-connected families who have not received direct notice should not assume their information was not affected; advocates have said notification to this group has lagged behind FARE notifications. Contacting Arizona's Foster Care Review Board directly is a reasonable step if you believe a case involving your family may be covered.

This is a developing story. The Arizona Administrative Office of the Courts has said it will share more information as the FBI investigation allows, and Pandromeda will update this piece if the court discloses a final, confirmed count of affected individuals or new details about the attackers.

Frequently asked questions

What is Arizona's FARE program?

FARE (Fines/Fees and Restitution Enforcement) is the Arizona court system's statewide program for collecting court-ordered debt, including fines, fees and restitution. It tracks people by name, case number and Social Security number, which is the category of data that was exposed in this breach.

How many people are affected by the Arizona courts data breach?

More than 1.3 million people connected to the FARE program may have had their names, case numbers and Social Security numbers copied, according to the Arizona Administrative Office of the Courts. That figure does not include everyone affected by the separate protective-order and foster-care record exposure.

Was my Social Security number stolen in the Arizona courts breach?

If you have ever had a case referred to Arizona's FARE collections program, your Social Security number may be among the data attackers copied. The court is notifying FARE participants it believes were affected, including by text message.

Were foster-care and protective-order records affected too?

Yes. Chief Justice Ann Scott Timmer has said protective-order records are likely the largest category of affected files, and attackers also copied more than 150,000 Foster Care Review Board recommendation reports dating back to 2010.

Has the stolen Arizona court data been leaked or sold?

As of early October 2026, no ransomware group or hacking crew has publicly claimed the attack, and the court says it has no evidence the data has been shared or appeared for sale — though officials have stressed that could change.

What should I do if I think I'm affected?

Place a free credit freeze with Equifax, Experian and TransUnion, verify any text or call claiming to be from Arizona courts before responding, and use the FTC's IdentityTheft.gov if you notice signs of identity theft.

Sources

More on Arizona Courts Data Breach →Arizona Supreme CourtData BreachFARE ProgramIdentity TheftFoster Care Records
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all