Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Oct 05, 2026 · 8 min read

Arizona Courts Phishing Breach: 1.3 Million SSNs Copied

On September 24, 2026, a court employee clicked a malicious link in an email. Within hours, criminals had copied backup files holding court debt records with Social Security numbers for about 1.3 million people, more than 150,000 foster care reports and protective order data. The court is now warning victims by email and text, the same channels scammers will use next.

If you have paid an Arizona traffic ticket, a criminal fine or court ordered restitution at any point in the last three decades, your name and Social Security number may have been on a backup server the Arizona judicial branch no longer controls. The court's own cybersecurity alert page puts the count at "Approximately 1.3 million individuals who have court debts dating back 30 years."

The way in was ordinary. "Evidence so far suggests the cyberattack began with a common phishing attack, where a court employee received an email and clicked a malicious link," the court wrote. One email, one click.

Key Takeaways

  • The Arizona Supreme Court says the attack started on Thursday, September 24, 2026 around 11:30 a.m., and court IT staff shut it down less than two hours after it was identified.
  • FARE, the state's court debt collection program, lost a data set with case numbers, names and Social Security numbers for approximately 1.3 million people with court debts going back 30 years.
  • More than 150,000 Foster Care Review Board reports dating back to 2010 and records on active and inactive protective orders were also copied.
  • Chief Justice Ann Timmer said the court assumes the attackers "will be able to read the names and match it to a Social Security number," even though the files were stored in a highly compressed format.
  • The court is telling FARE participants to freeze their credit with Equifax, Experian and TransUnion, and according to a Yahoo News report it is not currently offering to pay for credit monitoring.
An open laptop showing an email inbox on a wooden bench in an empty marble courthouse hallway lit by late afternoon light

What Happened in the Arizona Courts Breach?

Hackers got in through a phishing email and copied backup court files before IT staff cut them off. Per the court's FAQ, the attack "appears to have started on Thursday, September 24 around 11:30 a.m." and staff "shut it down less than two hours after it was identified."

Disclosure came in stages:

  • September 25: Chief Justice Ann Scott Timmer issued an urgent notice saying "Court leaders believe the criminal hackers copied personally identifiable information about many Arizonans." That day, at least one protective order petitioner got an email warning that information related to a past protective order may have been compromised, FOX 10 Phoenix reported.
  • September 29: KJZZ reported that the hackers had accessed reports about children in foster care.
  • September 30: The court disclosed the FARE data set, the 1.3 million figure, as KJZZ reported that day.

The court says Timmer personally spoke with FBI Special Agent in Charge Rebecca Day, and the FBI is investigating. None of the sources we reviewed name a threat actor. Nothing was locked either: "In this case, the information was taken," security consultant Ian Marlow told Yahoo News.

What Data Did the Hackers Copy?

The attackers copied three categories of backup data, and the FARE debt records are the largest. FARE stands for the Fines/Fees and Restitution Enforcement Program, which per the court "helps the courts collect outstanding court-ordered debt associated with civil traffic, criminal traffic, and criminal violations."

  • FARE program data: "case numbers, names, and social security numbers" for about 1.3 million people.
  • Foster Care Review Board reports: more than 150,000 reports for current and past cases dating back to 2010. They include child information and board findings, but "No contact information such as addresses and phone numbers."
  • Protective orders: records on active and inactive orders, "including some sensitive information." The court has not published a count.

The court says no juror, witness or employee data was copied, and that "no court records were deleted, altered, or erased."

To put the FARE figure in scale: 1.3 million is about 17% of Arizona's 7,623,818 residents in the Census Bureau's July 2025 estimate, roughly one person in six. Thirty years of debtors includes many who have since left the state.

Does "Highly Compressed" Mean the Data Is Safe?

No. Compression is not encryption, and the court's own chief justice is planning as if the data can be read. The FAQ says the FARE data "was copied from a back-up server where highly compressed information is maintained" and that the court "has no evidence that any data has been accessed, is readable, or has been shared."

Timmer was blunter in remarks reported by Yahoo News. "Our assumption is that they will be able to read the names and match it to a Social Security number," she said, while noting that for now the data is not readable without considerable format changes. On whether it could end up on the dark web: "Is it possible to read this, put it on the dark web? Yes, it is possible."

Most coverage leads with the reassurance, but the admission matters more. Compressed backups exist to be restored, and unless they are also encrypted, reading one is a format problem, not a lock. Arizona's own breach notification statute, A.R.S. 18-552, is written around "unencrypted and unredacted computerized personal information," and nothing the court has published says these backups were encrypted.

How Did One Phishing Email Get Past a Trained Workforce?

The court has not explained what the link did, only that an employee clicked it. That gap matters, because a credential phishing page and a malware download both start with a click but call for different fixes.

The court lists "required annual cybersecurity training for all court employees" and "a top-tier 24x7 cyber security monitoring service" among its defenses. Neither stopped the click. Staff did shut the intrusion down within two hours of spotting it, but that was enough to copy 30 years of debt records.

Arizona is not unusual. Phishing was the initial access vector for 16% of breaches in the Verizon 2026 Data Breach Investigations Report, according to SC Media's summary of the DBIR, which also found email "remained the most common social-engineering vector at 98%." It is the same entry point we saw in the Xsolis breach that exposed 1.4 million patients.

Why Email Users Should Care: The Next Wave Is Fake Court Notices

The stolen data is a ready made phishing script. Every record pairs a real person with a real court case number and a real court debt. A scammer holding that could send a text or email claiming your FARE balance is past due, and quote your actual case number to prove it. That beats the generic lures in the fake traffic violation texts that already hit eight states earlier this year.

The court's notification plan raises the stakes. It is contacting FARE participants "via text messages," adding alerts to mailed collection notices, and using "its email system to contact as many affected people as possible." Its alert page even says "This is not a scam." Victims are being taught to trust an unexpected court message about this breach at the exact moment criminals have the data to fake one. Verizon's DBIR adds a warning, per SC Media: users were "40% more likely to fall for mobile-based phishing lures than email lures in phishing simulations."

We checked the sending domain. The court's official address is no-reply@courts.az.gov, and the courts.az.gov DMARC record publishes p=quarantine, not p=reject (a nonsense subdomain control returned NXDOMAIN). Under RFC 7489, quarantine asks receivers to treat failing mail "as suspicious," which can mean "place into spam folder." Forged mail from the exact court domain can still land in a spam folder instead of being refused, and DMARC does nothing about lookalike domains.

What Does Arizona Law Require After a Breach Like This?

Arizona's statute sets a 45 day clock. Under A.R.S. 18-552, a covered entity must notify affected individuals "within forty-five days after the determination" of a breach. Above 1,000 people, it must also notify "The three largest nationwide consumer reporting agencies" plus the attorney general and the director of the Arizona Department of Homeland Security. Civil penalties are capped at $500,000 for a breach or series of related breaches.

Courts get their own line. Subsection O says the Department of Public Safety, sheriff's departments, police, prosecution agencies "and a court shall create and maintain an information security policy that includes notification procedures for a security system breach."

This is also the second blow to US court data in about a month. In early September, a breach at Thomson Reuters' C-Track platform hit appellate courts in 12 states, and Arizona was not on that list. As with the Pentagon DMDC breach that exposed 3 million SSNs, the real question is why so many SSNs sat where one intruder could copy them. A 30 year archive of debtors' SSNs on a backup server is a liability no phishing training can cover.

What Should Affected Arizonans Do Right Now?

Freeze your credit first, then lock down your tax identity and treat every court message as suspect until you verify it yourself.

  1. Freeze your credit at all three bureaus. The FTC says "There's no cost to place or lift a credit freeze," and a freeze "lasts until you lift it."
  2. Get an IRS Identity Protection PIN. The IRS IP PIN is "a six-digit number that prevents someone else from filing a tax return using your Social Security number."
  3. Never pay a court debt from a link. If a text or email says you owe FARE money, type azcourts.gov into your browser yourself. The court's own "VERIFY HERE" lookup for FARE participants was still marked "Coming Soon" when we checked.
  4. Check the sender address in full. The court says official breach email comes from no-reply@courts.az.gov. Anything from a lookalike domain is not the court.
  5. Report misuse. Use IdentityTheft.gov for a recovery plan, and the Arizona Attorney General's data breach page, which the court also recommends.
  6. Protective order petitioners should plan for the worst case. The court has not said which protective order fields were copied. If your safety depends on your address staying private, talk to your advocate or attorney now.

For security teams, the lesson is shorter. Encrypt backups that hold SSNs and purge records you no longer need. Then assume the click will happen anyway.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.