Arizona court breach may expose data of over 1.3 million people

Arizona court breach may expose data of over 1.3 million people
Arizona's court breach may have put child-welfare and protective-order records at risk for over 1.3 million people. Officials say the intrusion combined a phishing foothold with access to aging legacy back-end systems holding archived family-safety files since 2010. Important: 1.3 million is a population estimate, not a confirmed tally of stolen records. No file is confirmed leaked, and FBI coordination is ongoing. The open question: did attackers copy those files before containment?

Chief Justice Ann Scott Timmer reported on Sept. 25, 2026 that a cyberattack on Arizona's state court systems may have exposed personal and location data of a large number of people. State officials have put the population at risk at over 1.3 million, with roughly 150,000 foster-care reports dating to 2010 among the material. The FBI's Arizona office is coordinating with the Administrative Office of the Courts, which detected the unauthorized access and says it notified affected individuals.

What the attackers got into

The breach hit databases run by the Administrative Office of the Courts, which handles the state's judicial case-management systems, in cooperation with the Arizona Department of Child Safety. What's confirmed is narrower than what was swept up: names, addresses, dates, and case numbers tied to vulnerable children, court debtors, and domestic-violence protective orders are the material at risk.

A phishing entry and a legacy backdoor

Investigators' working account is that the intrusion combined two failures. Attackers used phishing to get a foothold in court IT systems, then leveraged that access against older backend systems still holding legacy child-welfare documents. Reports also point to a backup server compromise tied to the breach. The two-step path matters: the front-door compromise by itself would not have reached the archived family-safety files, which sat in systems outside the day-to-day case workflow. That means the exposure risk isn't merely that some records were touched—it's that the sensitive material relied on an aging archive that apparently lacked the isolation or access controls of the main case systems.

What remains unknown is exactly how the trust boundary between the phished account and the legacy database was crossed, and which files the attackers succeeded in copying before containment.

What the numbers do and don't say

The 1.3 million figure is a population estimate of people whose records sit in the affected datasets, not a confirmed count of stolen records. Officials have not put a number on how many files were actually exfiltrated, and no specific breach timeline has been disclosed as of late September. The scale is serious either way: orders of protection and foster-care reports are exactly the material that can expose vulnerable people's locations and family situations if leaked.

The hardest unknown

The most consequential open question is whether the attackers pulled child-welfare and protective-order files before the intrusion was contained. Officials say the investigation remains active and that no evidence of misuse has been reported yet. Until forensic analysis establishes which records left the systems, this is a breach of unknown scope—not yet a confirmed leak of any individual file. That distinction is the difference between a contained incident with an access window and a data release with victims who cannot be re-secured.