Arizona’s Judicial Branch says criminal hackers accessed and copied backup court files containing information tied to about 1.3 million people. The September 24 cyberattack also affected records connected to protection orders and the state’s Foster Care Review Board.
The court has created an official lookup tool for people referred to its Fines/Fees and Restitution Enforcement program, known as FARE. Anyone checking should use only the Arizona court system’s official Emergency Data Breach Notification Lookup, because a large breach can also attract impersonation scams.
What happened in the Arizona court cyberattack
The incident began after a court employee clicked a malicious link in an email, according to Associated Press reporting. Court technology staff detected the activity and shut down the affected backup server about two hours later on September 24.
Investigators determined that the attackers accessed and copied backup files. The largest affected collection came from FARE, a statewide program used to collect unpaid court fees, fines and restitution associated with traffic and criminal violations. Those records go back as far as 30 years.
The court says roughly 1.3 million people were included in the FARE data. Reporting based on the court’s updated information says the records can contain names, Social Security numbers and case numbers. The unusual file format may make some of the copied information harder for attackers to read, but that is not the same as encryption or a guarantee that the data cannot be used.
Protection-order and foster-care records were also copied
The affected files were not limited to unpaid balances. Nearly 30,000 active and inactive protection-order records were copied, according to the court. Approximately 150,000 reports dating back to 2010 from the Arizona Foster Care Review Board were also taken.
Those categories are especially sensitive because they may relate to domestic violence, family circumstances or allegations about a parent’s ability to care for a child. The court has not publicly said that all information within every affected file was readable or that it has been misused.
A court spokesperson told the AP there was no evidence at the time of reporting that the stolen information had been used or shared. Officials also said no records were altered or deleted, and that the incident did not affect juror, witness or court-employee information. Court proceedings have continued without delays attributed to the attack.
How to check whether your information was affected
The Arizona Judicial Branch’s online checker currently focuses on people who were referred to FARE by a court. It asks for a last name and the final four digits of a Social Security number, then checks those details against the affected data.
Use the tool only through an azcourts.gov or apps.azcourts.gov address. Do not follow an unsolicited text-message link or give a full Social Security number, password, bank information or payment to someone claiming they can perform the lookup.
The main Arizona courts cybersecurity alert hub is intended to carry the latest official information. Its guidance may change as the investigation continues, so people with a relevant Arizona court history should return there for updates rather than relying on social-media posts.
What affected people should do now
A court-related data exposure does not necessarily mean identity theft has occurred. Still, names, Social Security numbers and case details can be combined with information from other breaches to make phishing messages more convincing.
- Freeze your credit. A security freeze is free and can help prevent someone from opening new credit in your name. Place freezes separately with Equifax, Experian and TransUnion, then securely store the PIN or account credentials needed to lift them.
- Review credit reports. Use AnnualCreditReport.com, the federally authorized source, and look for unfamiliar accounts, addresses or inquiries.
- Watch existing accounts. Enable transaction and login alerts for banking, email and mobile-carrier accounts. Contact the institution through its official app or the number on a statement if something looks wrong.
- Secure your email first. Use a unique password and multifactor authentication, preferably an authenticator app or security key where available. Email access can let a criminal reset other accounts.
- Treat court-themed messages carefully. A scammer may mention a real traffic case, balance or protection order to appear credible. Look up the court’s phone number independently before responding.
- Report suspected identity theft. The Federal Trade Commission’s IdentityTheft.gov can generate a recovery plan and documentation.
What remains unknown
The investigation is continuing, and several important questions remain unanswered. Officials have not provided a complete field-by-field inventory for every copied dataset, identified the attackers publicly or established whether anyone beyond the attackers obtained the files.
There is also no evidence that every Arizona resident is affected. The largest identified group consists of people referred to FARE, while the protection-order and foster-care collections concern narrower populations. Readers should use the official checker and notices instead of assuming inclusion based only on living in Arizona.
Why this breach matters beyond Arizona
The incident shows how long data can remain risky after its original purpose has passed. Court debt records spanning three decades create a large target, and backup systems can contain the same sensitive information as production databases without receiving the same day-to-day attention.
For consumers, the practical lesson is not to panic but to reduce the value of stolen information: freeze new credit, protect the email account used for recovery, verify unexpected court communications independently and keep monitoring official updates.
