Arizona Supreme Court Data Breach Compromises Records of 1.3 Million People
A phishing link allowed attackers to extract 30 years of court records, protective orders, and foster care evaluations.

The Arizona Supreme Court suffered a data breach after an employee clicked a malicious email link, leading to the unauthorized exfiltration of personal records belonging to 1.3 million people, according to reporting by TechRadar Pro .
The incident originated when an employee interacted with an email link. Investigators have not publicly confirmed whether the link deployed info-stealing malware or directed the user to a credential-harvesting phishing page. However, the resulting access allowed threat actors to copy records from a backup server.
The compromised data includes records of 1.3 million individuals with unpaid court fees, fines, and restitution payments spanning 30 years of traffic and criminal violations. Threat actors also extracted nearly 30,000 active and inactive orders of protection, as well as 150,000 foster care review board reports dating back to 2010.
IT personnel detected the intrusion on September 24 and isolated the affected backup server roughly two hours later, according to Associated Press reporting cited by TechRadar Pro. The court system has since begun issuing breach notifications to affected individuals.
Arizona Supreme Court spokesperson Alberto Rodriguez stated that judicial operations were not interrupted, and no court files were altered or deleted. Rodriguez confirmed that data on jurors, witnesses, and court staff was not compromised, and officials have found no evidence that the stolen data has been published or traded on dark web forums.
The breach follows a series of recent incidents targeting judicial IT infrastructure. In early September 2026, reports revealed a March breach at Thomson Reuters affecting its C-Track court case-management software across 11 U.S. states, the U.S. Virgin Islands, and Ontario. In November 2025, the Georgia Superior Court Clerks' Cooperative Authority blocked an attempted intrusion and extortion attempt by the threat group Devman without suffering data exfiltration.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



