The news
Hackers copied backup files holding records on active and inactive protective orders and more than 150,000 foster care case reports in an Arizona courts cyberattack that appears to have started on September 24, according to the Arizona Supreme Court.
Chief Justice Ann Scott Timmer announced the attack on the evening of Friday, September 25, saying court leaders believe criminal hackers copied personally identifiable information about many Arizonans. The court's cybersecurity alert page says the attack appears to have begun around 11:30 a.m. on Thursday, September 24, and that court IT staff shut it down less than two hours after it was identified. Evidence so far suggests it began with a phishing email, in which a court employee clicked a malicious link, the court said.
According to the court, the copied files included records involving active and inactive protective orders, including some sensitive information. They also included more than 150,000 reports from the Foster Care Review Board, a court program that reviews the cases of children in foster care, covering current and past cases back to 2010. The court said about 8,000 children are currently in foster care. It also said that, based on the format of the copied files, it is unclear whether most of the data can be easily read, and that none of the copied data involved jurors, witnesses or court employees.
Fox 10 Phoenix reported on September 28 that tens of thousands of people may have had personal information compromised, including names and addresses tied to current and expired protective orders. Timmer told the station that "an inordinate amount of data was going out" of the court's systems, and that it was shut down immediately.
The FBI is investigating, and Timmer said she spoke personally with the top-ranking FBI official in the state. The court's Administrative Office of the Courts is notifying affected people by email and has stressed that those emails are genuine, not a scam. The court said no records were deleted, altered or erased and that no pending cases or court dates are affected.
The Record, from Recorded Future News, reported that the incident did not involve ransomware and that the hackers had not issued a ransom demand as of Monday, September 28. No group had publicly claimed the attack, the outlet reported, leaving open how the copied data might be used.
The numbers
- Foster Care Review Board reports copied (court)
- More than 150,000, dating back to 2010
- Children currently in Arizona foster care (court)
- About 8,000
- Time to shut down the attack after it was identified
- Less than two hours
- People who may be affected (Fox 10 Phoenix)
- Tens of thousands
Why CEOs should care
For CISOs, the sequence the court describes is familiar: a phishing click by one employee, followed by the copying of backup files. Backups concentrate years of records in one place and are often less watched than live systems. Ask whether your backups are encrypted, kept on segmented networks and covered by alerts for unusual outbound transfers. In Arizona's case, Timmer described a large volume of data leaving the system as the trigger for the shutdown.
For general counsel and risk officers, this breach shows that the harm from some data can be physical, not just financial. Fox 10 Phoenix reported that names and addresses tied to protective orders may have been copied and that local law enforcement has been alerted. Any organization that holds similar data, such as HR investigation files, benefits records or legal-services case files, should map where it sits, who can reach it and how quickly affected people could be warned.
For boards and communications leads, note the notification problem. The court had to tell recipients that its breach emails are genuine, and fraudsters often copy real notices to run follow-up scams. Plan breach notices that give people a way to verify them without clicking a link. With no ransom demand and no claimed group, the attackers' purpose is unknown, so the court's caution that the files may be hard to read should not be treated as proof the data is safe.
The bigger picture
Courts hold identity data that criminals value and that people cannot change, from home addresses to family case histories. The Record noted a string of earlier attacks on judicial systems in other states, including a 2023 ransomware attack in Kansas that shut down nearly all of its court systems. Arizona's case differs in one respect: so far, the attackers have taken data quietly and asked for nothing.
What’s next
Watch for the court's final count of affected people, any claim of responsibility or data-leak posting, and findings from the FBI investigation. Arizona's courts said AZCourts.gov will be the most accurate source for updates.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







