Arizona courts backup-data incident

Arizona’s courts disclosed a cyberattack in which backup files were copied.

Last modified

Summary

  • Environment: Court backup servers
  • Operational impact: Court reported no delays to proceedings
  • Financial impact: No incident cost established in the reviewed evidence
  • Record status: Developing record. Reviewed October 7, 2026; updated as evidence emerges.

What happened

Arizona’s courts disclosed a cyberattack in which backup files were copied. [1]

Impact

The FARE debt-collection dataset involved approximately 1.3 million individuals. [1]

Copied material also included protective-order records and foster-care reports. [1]

Timeline

  1. Attack detected and stopped

    Court staff contained the attack.

    [1]
  2. Public disclosure

    The court issued its news release.

    [2]
  3. Briefing updated

    This briefing was last reviewed and updated on October 7, 2026.

Threat Group & Attack Vector

The court said evidence suggested an employee clicked a phishing link. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Court staff stopped the attack and began notifying affected people. [2]

The court reported no record alteration or delays to proceedings. [1]