Executive Summary
On September 24, 2026, the Arizona Supreme Court experienced a significant cyberattack that resulted in the unauthorized copying of highly sensitive, encrypted data from a backup server. The breach affected approximately 1.3 million individuals with court-ordered debts and included more than 150,000 confidential foster care reports. The compromised data spans 30 years and includes case numbers, names, and Social Security numbers. The incident was traced to a phishing email opened by a court employee, which allowed the attacker to gain access. There is currently no evidence that the encrypted data has been deciphered, accessed in a readable form, or shared. The attack was discovered within two hours, and immediate mitigation steps were taken. Impacted individuals were advised to freeze their credit files and monitor for identity theft. No specific threat actor has been identified, and no technical indicators such as malware or command-and-control infrastructure have been reported. All information in this summary is based on the official statements and evidence available as of October 5, 2026 (GovTech, 2026-10-05).
Technical Information
The cyberattack on the Arizona Supreme Court was initiated through a phishing email, a common social engineering technique where an attacker sends deceptive messages to trick recipients into revealing credentials or executing malicious actions. In this case, a court employee inadvertently opened the phishing email, granting the attacker initial access to the court’s digital environment. This method aligns with the MITRE ATT&CK technique Phishing (T1566), which is widely recognized as a primary vector for initial access in both targeted and opportunistic attacks.
Once inside the network, the attacker accessed a backup server containing highly compressed and encrypted data. The data set included records of approximately 1.3 million court debtors—comprising case numbers, names, and Social Security numbers—and over 150,000 confidential foster care reports. The foster care data included information on children, their parents, and statements from individuals involved in foster cases dating back to 2010. Notably, addresses and phone numbers were not part of the compromised data.
The attacker copied the data from the backup server. However, according to official statements, there is no evidence that the data has been decrypted, accessed in a readable format, or disseminated. The data’s encrypted state significantly reduces the immediate risk of exposure, but the potential for future decryption cannot be ruled out.
No specific malware, tools, or command-and-control infrastructure were identified in the incident. The absence of technical artifacts such as file hashes, malicious domains, or IP addresses limits the ability to conduct further forensic analysis or attribute the attack to a known threat actor. The attack was not targeted at the judicial sector specifically but was instead opportunistic, exploiting a common vulnerability in human behavior—susceptibility to phishing.
The incident was detected by court IT staff within two hours of initiation, and immediate steps were taken to halt the attack. No court records were deleted or altered during the incident. The court’s response included notifying affected parties, recommending credit freezes, and providing resources for identity theft protection.
Affected Versions & Timeline
The breach impacted the Fines/Fees and Restitution Enforcement (FARE) Program, which is responsible for collecting outstanding court-ordered debts related to civil and criminal violations. The affected data set includes individuals referred to the FARE program for collections over the past 30 years. Additionally, the Foster Care Review Board program, operating within the Arizona Supreme Court’s Administrative Office of the Courts, was affected, with confidential reports dating back to 2010 being compromised.
The timeline of the incident is as follows: The attack occurred on September 24, 2026, and lasted approximately two hours before being discovered by IT staff. Initial public disclosure was made on September 25, 2026, with further details about the foster care data breach released on September 28, 2026. A comprehensive report was published on October 5, 2026.
Threat Activity
The threat activity in this incident was characterized by the use of a phishing email to gain initial access. This technique is not unique to any specific threat actor and is commonly employed in both cybercriminal and state-sponsored campaigns. The opportunistic nature of the attack is confirmed by official statements indicating that the breach was not targeted but resulted from a court employee’s interaction with a phishing message.
After gaining access, the attacker located and copied data from a backup server. The data was encrypted and highly compressed, which has so far prevented unauthorized access to its contents. There is no evidence of lateral movement, privilege escalation, or deployment of ransomware or other destructive malware. The lack of technical indicators and the absence of data decryption or sharing suggest that the attacker’s capabilities may have been limited to data exfiltration.
Attribution remains undetermined, as there are no technical artifacts or unique tactics, techniques, and procedures (TTPs) linking the incident to a known threat actor or group. The attack’s reliance on phishing and the absence of further malicious activity are consistent with opportunistic cybercrime rather than a sophisticated, targeted campaign.
Mitigation & Workarounds
The following mitigation steps and workarounds are recommended, prioritized by severity:
Critical: All individuals potentially affected by the breach should immediately place a freeze or hold on their credit files with major credit reporting agencies, including Equifax, Experian, and TransUnion. This action helps prevent unauthorized credit activity and identity theft.
High: Impacted individuals should monitor their financial accounts and credit reports for signs of suspicious activity. They are advised to utilize resources provided by identitytheft.gov and the Arizona Attorney General’s Office at azag.gov/consumer/data-breach for guidance on responding to data breaches and identity theft.
Medium: Organizations should reinforce phishing awareness training for all employees, emphasizing the risks associated with opening unsolicited emails and attachments. Regular simulated phishing exercises can help reduce susceptibility to social engineering attacks.
Medium: IT departments should review and enhance email filtering and anti-phishing controls to detect and block malicious messages before they reach end users.
Low: Organizations should ensure that backup servers and sensitive data repositories are segmented from the main network and protected with strong access controls and encryption. Regular audits of backup server access logs can help detect unauthorized activity.
Indicators of Compromise
The following indicators are provided as a point-in-time reference and should be validated before enforcement in any security controls. These indicators are derived directly from the primary source and are not associated with malicious infrastructure but are included due to their mention in official guidance for affected individuals.
Type | Indicator | Reported (date) | Source
|
Domain | azag[.]gov | 2026-10-05 | https://www.govtech.com/security/arizona-courts-cyber-attack-exposed-30-years-of-personal-data |
Domain | identitytheft[.]gov | 2026-10-05 | https://www.govtech.com/security/arizona-courts-cyber-attack-exposed-30-years-of-personal-data |
References
GovTech, "Arizona Courts Cyber Attack Exposed 30 Years of Personal Data," October 5, 2026. Source: https://www.govtech.com/security/arizona-courts-cyber-attack-exposed-30-years-of-personal-data
About Rescana
Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organizations identify, assess, and monitor cyber risks in their extended digital ecosystem. Our platform enables continuous monitoring of vendor security posture, automated risk assessments, and actionable insights to support incident response and compliance efforts. For questions regarding this incident or to discuss how our capabilities can support your organization’s risk management strategy, please contact us at info@rescana.com.



