
Arizona’s court system says hackers copied backup files containing sensitive information on about 1.3 million people in its debt collection program, along with protective order records and more than 150,000 foster care reports.
The attack appears to have started around 11:30 a.m. on September 24, 2026. Court IT staff stopped it less than two hours after identifying it, with preliminary evidence pointing to a phishing email containing a malicious link that a court employee clicked.
Chief Justice Ann Scott Timmer first publicly disclosed the incident on September 25, but the court published a detailed FAQ page explaining the full scope of the incident earlier this month.
The affected systems held records supporting several judicial functions, including the statewide Fines/Fees and Restitution Enforcement (FARE) program. FARE helps courts collect outstanding court-ordered debts associated with civil traffic, criminal traffic, and criminal violations.
Sensitive records copied
According to the court’s announcement, the FARE dataset contained names, case numbers, and Social Security numbers for about 1.3 million individuals, with debts dating back 30 years.
The attackers copied this information from a backup server storing highly compressed data. Court officials say they have no evidence that the FARE information has been read or shared, and its readability remains uncertain.
Separately, the stolen files included more than 150,000 Foster Care Review Board recommendation reports covering current and historical cases dating back to 2010. Citizen panels prepare these reports by reviewing dependency cases and recommending actions to juvenile court judges.
Their contents include information about children and their cases, names and statements of interested parties, board findings, and recommendations for courts, the Department of Child Safety, and parents. The court says these reports contain no addresses or telephone numbers.
The records also included both active and inactive protective orders and contained some sensitive information.
Based on the investigation so far, the copied data did not include information on jurors, witnesses, or court employees. Officials also found no evidence that records were deleted or altered, and say the incident will not affect pending proceedings, court dates, or the validity of court orders.
Notifications and assistance
Timmer has spoken with the FBI and pledged the court’s cooperation. State and federal law enforcement have been contacted, while court leaders plan to review the incident and make necessary security changes.
Notifications have already gone to the Department of Child Safety, attorneys representing parents and children, juvenile presiding judges, and Foster Care Review Board members.
FARE participants will receive text notifications, and mailed collection notices now carry a breach alert. Official communications will come from no-reply@courts.az.gov or the text short code 83958.
People referred to FARE can check their status through the verification tool linked from the court’s cybersecurity information hub. The court encourages potentially affected individuals to freeze their credit files with Equifax, Experian, and TransUnion, and consult IdentityTheft.gov for assistance.







Leave a Reply