Arizona’s state court system was compromised after a court employee clicked a malicious link in a phishing email, allowing criminal hackers to copy compressed backup files containing personally identifiable information. The stolen material includes protective-order records and more than 150,000 Foster Care Review Board recommendation reports dating to 2010, potentially exposing highly sensitive information about Arizona residents.
The Arizona Supreme Court said it has no evidence that the data has been publicly released, and it has not identified the attackers, their motive, or a responsible ransomware group. The incident was not ransomware and no ransom demand had been received; the FBI is investigating while the Administrative Office of the Courts identifies and notifies affected individuals. Officials said available evidence does not indicate that juror, witness, or court-employee data was included.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Chief Justice Ann Scott Timmer disclosed that hackers copied personally identifiable information associated with many Arizonans. The court said it was notifying people believed to be affected and investigating with the FBI.
The copied backups included protective-order materials and more than 150,000 Arizona Foster Care Review Board recommendation reports, including current and historical child-care and protection cases dating back to 2010.
A court employee clicked a malicious link in a phishing email, allowing criminal hackers to compromise Arizona’s state court system and copy compressed backup files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcetherecord.media
Open sourceazcourts.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.