Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Data

Arizona Courts Cyberattack (TL-2026-2768), also tracked as Arizona Courts Cyber Attack, is a high-severity data breach, first published 2026-09-29. It has no confirmed attribution, affects Arizona Judicial Branch Arizona state court system backup court files, maps to 5 MITRE ATT&CK techniques (T1005, T1020, T1119), and is covered by 9 detection rules and 6 indicators of compromise.

Key facts for TL-2026-2768

Threat ID
TL-2026-2768
Also known as
Arizona Courts Cyber Attack, Arizona Judicial Branch data breach
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, judiciary, legal
Target regions
North America, united states of america, Arizona
Detection rules
9
Indicators of compromise
6

On 2026-09-24 attackers breached the Arizona Judicial Branch, reportedly via a phishing link clicked by a court employee, and copied backup court files containing personal data of many Arizonans, including addresses tied to active and inactive protective orders. Court IT shut the activity down in under two hours; the FBI is investigating and no group has claimed responsibility.

How Arizona Courts Cyberattack works

The Arizona Judicial Branch publicly disclosed on Friday 2026-09-25 (Chief Justice Ann Scott Timmer; 'URGENT NOTICE: Arizona Courts Experience Cyber Attack') that criminal hackers had targeted the state court system within the preceding ~36 hours and are believed to have copied personally identifiable information of 'many Arizonans'. The court's cybersecurity alert hub states the attack occurred on Thursday 2026-09-24 at around 11:30 a.m. and that court IT staff shut it down in less than two hours after identification. (One azfamily article dates the activity to 'last Thursday (September 25)'; the court's own hub says September 24, which this record uses. The Record's article carries a 2026-09-29 publish date and describes the announcement as a Friday; the court's release is dated 2026-09-25.)

Initial access: the court's hub page states the attack 'began with a common phishing attack, where a court employee received an email and clicked a malicious link'. Separately, Chief Justice Timmer told reporters that IT staff 'noticed unusual activity' involving large data transfers and that 'it appears that it's some type of automated bot that just went in and started hitting particular files'. Media reports quote officials saying there is no indication whether the access was random or targeted and that 'just large chunks of data is all we know at this point'. These accounts are not mutually exclusive (phishing-obtained access followed by automated bulk file access) but the court has published no technical detail reconciling them.

Data affected: per the court's hub, the copied files were backup court files containing a mix of public and non-public records, including active and inactive protective orders and some sensitive information ('much of the information is considered public'). Media reports (azfamily, KJZZ, Fox 10, NewsNation) emphasize names and confidential addresses of people with current or past protective orders, and domestic-violence victims are among those affected; azfamily reported tens of thousands of records. Officials said the format of the copied data makes it unclear whether most of it can easily be read, and that there is no evidence so far that the hackers have shared the data. The court states the copied files did not include information on jurors, witnesses, or court employees, and that no court records were deleted, altered or erased and pending cases and court dates are unaffected. No ransomware was involved and no ransom demand or group claim has been reported; The Record reports no operational disruption.

Response: the Administrative Office of the Courts began emailing affected individuals on Friday evening after business hours (the court stresses the notification email 'is not a scam'), reached out to domestic-violence shelters and advocacy groups, and posted updates at azcourts.gov/cybersecurityalert. Chief Justice Timmer personally spoke with the top-ranking FBI official in Arizona and pledged full support for the investigation; the court initiated a cybersecurity action plan. The court reports existing controls of a robust security policy, annual mandatory employee cybersecurity training, twice-yearly security scans, full-time cybersecurity staff and a 24/7 monitoring service.

Context: The Record lists prior US court-system attacks (Kansas 2023 ransomware that disabled nearly all court systems for months; incidents in California, Nebraska, South Carolina, Florida, Wisconsin, Louisiana, Ohio, Missouri and Illinois). NewsNation additionally references the 2026 Thomson Reuters C-Track case-management breach affecting other jurisdictions; Arizona is not among the reported affected jurisdictions and no source links the two incidents.

Gaps: the actor, the specific system holding the backup files, the number of affected individuals, the exact fields exposed and any network indicators (IPs, domains, hashes, phishing infrastructure) have not been published. Court details were withheld to protect the investigation and victims. This record documents only sourced facts and will need an update when attribution or technical details emerge.

MITRE ATT&CK techniques used in TL-2026-2768

Collection

T1005 Data from Local System; T1119 Automated Collection

Exfiltration

T1020 Automated Exfiltration

Execution

T1204.001 Malicious Link

Initial Access

T1566.002 Spearphishing Link

Affected products and versions in Arizona Courts Cyberattack

  • Arizona Judicial Branch — Arizona state court system backup court files (protective orders and other court records)

Remediation for Arizona Courts Cyberattack

Immediate actions

  • Individuals with current or past protective orders who fear for their safety should contact local law enforcement; the Arizona 24-hour domestic abuse hotline cited by the court is 602-269-2980
  • Treat court notification emails as legitimate only when they match the notice at azcourts.gov/cybersecurityalert; the court states its notification emails are not a scam
  • Court and government staff: report and quarantine emails with unexpected links, and reset credentials for any user who clicked a suspicious link
  • Review egress and access logs for bulk reads of backup file stores and unusually large outbound transfers around 2026-09-24

Longer-term hardening

  • Restrict and monitor access to backup repositories containing non-public court records; apply least privilege and separate backup credentials
  • Deploy phishing-resistant MFA and link-protection/detonation on judicial-branch email
  • Encrypt backups at rest so copied files are unreadable without separately held keys
  • Alert on automated, high-volume file access and large data transfers from records systems

Timeline of Arizona Courts Cyberattack

  • Backup court files containing a mix of public and non-public records, including active and inactive protective orders, were copied; no records were deleted, altered or erased.
  • Court IT staff noticed unusual activity and large data transfers ('some type of automated bot... hitting particular files') and shut the attack down in less than two hours.
  • Per the court's alert hub, the attack began with a phishing email in which a court employee clicked a malicious link; the attack occurred around 11:30 a.m.
  • The Administrative Office of the Courts began emailing affected individuals after business hours on Friday and pointed the public to azcourts.gov updates.
  • Timmer spoke personally with the top-ranking FBI official in Arizona and pledged full support for the FBI investigation.
  • Chief Justice Ann Scott Timmer announced that criminal hackers likely copied personal identifying information of 'many Arizonans'; the Judicial Branch issued an urgent notice.
  • The court's cybersecurity alert information hub at azcourts.gov/cybersecurityalert was posted with the phishing attack description, data scope and the exclusion of juror, witness and employee data.
  • Local media reported that confidential addresses of people with current or past protective orders may have been copied; officials said no evidence the data was shared and it is unclear whether most copied data is readable.
  • azfamily reported an affected protective-order holder describing feeling vulnerable after being told her information and location may have been copied.
  • azfamily reported tens of thousands of records affected including domestic-violence victims, with outreach to shelters and advocacy groups; The Record reported no ransomware, no ransom demand and no group claim.

Sources cited for Arizona Courts Cyberattack

More in data breach

Detection coverage for TL-2026-2768

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2768 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats