Arizona Supreme Court phishing attack exposes data of 1.3 million people
Arizona Supreme Court phishing attack exposes data of 1.3 million people, TechRadar reports.
TechRadar reported that it is still unclear whether the malicious link infected the employee's device with an infostealer or sent the employee to a bogus login portal, giving attackers direct access to the account. Investigators have been notifying affected individuals since the breach.
The attackers copied information on 1.3 million people with unpaid court fees, fines and restitution payments for traffic and criminal violations dating back 30 years. They also took nearly 30,000 active and inactive orders of protection and 150,000 reports from a foster care board dating back to 2010. Those reports contained recommendations in cases where parents were allegedly unable or unfit to care for a child.
TechRadar reported that such records can help criminals build tailored phishing messages that are difficult for victims to identify. The messages can lead recipients to download malware or enter credentials on spoofed login pages, and the malware can spread to victims' employers, potentially leading to ransomware, data theft, or extortion.
Supreme Court spokesperson Alberto Rodriguez said there is no evidence that the data has been used or shared, and it does not appear to have reached the dark web. Rodriguez added that the court's operations have not been disrupted, the records were not altered or deleted, and the attackers did not steal information about jurors, witnesses, or court employees. The investigation is ongoing.
Courts in the United States and elsewhere are frequent targets because of the sensitive information they handle. In early September 2026, it was reported that Thomson Reuters, the IT company behind the Reuters news agency, suffered a similar incident in March. The company operates C-Track, a court case-management system used by courts in several US states, the US Virgin Islands, and Ontario, Canada. Unnamed attackers obtained court records and personal information across 11 US states, the US Virgin Islands, and Ontario.
Earlier, on November 21, 2025, the Georgia Superior Court Clerks' Cooperative Authority detected hackers trying to break into its network. A group called Devman claimed responsibility, said it stole sensitive files, and demanded a ransom. The authority temporarily shut down its websites and online services, while the FBI warned it of an imminent threat. The GSCCCA said it stopped the attackers before they could extract or encrypt data and refused to pay the ransom. Devman is financially motivated and not state-sponsored, according to the report.