Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Data
Arizona Courts Cyberattack (TL-2026-2768), also tracked as Arizona Courts Cyber Attack, is a high-severity data breach, first published 2026-09-29. It has no confirmed attribution, affects Arizona Judicial Branch Arizona state court system backup court files, maps to 5 MITRE ATT&CK techniques (T1005, T1020, T1119), and is covered by 9 detection rules and 6 indicators of compromise.
Key facts for TL-2026-2768
- Threat ID
- TL-2026-2768
- Also known as
- Arizona Courts Cyber Attack, Arizona Judicial Branch data breach
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, judiciary, legal
- Target regions
- North America, united states of america, Arizona
- Detection rules
- 9
- Indicators of compromise
- 6
On 2026-09-24 attackers breached the Arizona Judicial Branch, reportedly via a phishing link clicked by a court employee, and copied backup court files containing personal data of many Arizonans, including addresses tied to active and inactive protective orders. Court IT shut the activity down in under two hours; the FBI is investigating and no group has claimed responsibility.
How Arizona Courts Cyberattack works
The Arizona Judicial Branch publicly disclosed on Friday 2026-09-25 (Chief Justice Ann Scott Timmer; 'URGENT NOTICE: Arizona Courts Experience Cyber Attack') that criminal hackers had targeted the state court system within the preceding ~36 hours and are believed to have copied personally identifiable information of 'many Arizonans'. The court's cybersecurity alert hub states the attack occurred on Thursday 2026-09-24 at around 11:30 a.m. and that court IT staff shut it down in less than two hours after identification. (One azfamily article dates the activity to 'last Thursday (September 25)'; the court's own hub says September 24, which this record uses. The Record's article carries a 2026-09-29 publish date and describes the announcement as a Friday; the court's release is dated 2026-09-25.)
Initial access: the court's hub page states the attack 'began with a common phishing attack, where a court employee received an email and clicked a malicious link'. Separately, Chief Justice Timmer told reporters that IT staff 'noticed unusual activity' involving large data transfers and that 'it appears that it's some type of automated bot that just went in and started hitting particular files'. Media reports quote officials saying there is no indication whether the access was random or targeted and that 'just large chunks of data is all we know at this point'. These accounts are not mutually exclusive (phishing-obtained access followed by automated bulk file access) but the court has published no technical detail reconciling them.
Data affected: per the court's hub, the copied files were backup court files containing a mix of public and non-public records, including active and inactive protective orders and some sensitive information ('much of the information is considered public'). Media reports (azfamily, KJZZ, Fox 10, NewsNation) emphasize names and confidential addresses of people with current or past protective orders, and domestic-violence victims are among those affected; azfamily reported tens of thousands of records. Officials said the format of the copied data makes it unclear whether most of it can easily be read, and that there is no evidence so far that the hackers have shared the data. The court states the copied files did not include information on jurors, witnesses, or court employees, and that no court records were deleted, altered or erased and pending cases and court dates are unaffected. No ransomware was involved and no ransom demand or group claim has been reported; The Record reports no operational disruption.
Response: the Administrative Office of the Courts began emailing affected individuals on Friday evening after business hours (the court stresses the notification email 'is not a scam'), reached out to domestic-violence shelters and advocacy groups, and posted updates at azcourts.gov/cybersecurityalert. Chief Justice Timmer personally spoke with the top-ranking FBI official in Arizona and pledged full support for the investigation; the court initiated a cybersecurity action plan. The court reports existing controls of a robust security policy, annual mandatory employee cybersecurity training, twice-yearly security scans, full-time cybersecurity staff and a 24/7 monitoring service.
Context: The Record lists prior US court-system attacks (Kansas 2023 ransomware that disabled nearly all court systems for months; incidents in California, Nebraska, South Carolina, Florida, Wisconsin, Louisiana, Ohio, Missouri and Illinois). NewsNation additionally references the 2026 Thomson Reuters C-Track case-management breach affecting other jurisdictions; Arizona is not among the reported affected jurisdictions and no source links the two incidents.
Gaps: the actor, the specific system holding the backup files, the number of affected individuals, the exact fields exposed and any network indicators (IPs, domains, hashes, phishing infrastructure) have not been published. Court details were withheld to protect the investigation and victims. This record documents only sourced facts and will need an update when attribution or technical details emerge.
MITRE ATT&CK techniques used in TL-2026-2768
Collection
T1005 Data from Local System; T1119 Automated Collection
Exfiltration
Execution
Initial Access
Affected products and versions in Arizona Courts Cyberattack
- Arizona Judicial Branch — Arizona state court system backup court files (protective orders and other court records)
Remediation for Arizona Courts Cyberattack
Immediate actions
- Individuals with current or past protective orders who fear for their safety should contact local law enforcement; the Arizona 24-hour domestic abuse hotline cited by the court is 602-269-2980
- Treat court notification emails as legitimate only when they match the notice at azcourts.gov/cybersecurityalert; the court states its notification emails are not a scam
- Court and government staff: report and quarantine emails with unexpected links, and reset credentials for any user who clicked a suspicious link
- Review egress and access logs for bulk reads of backup file stores and unusually large outbound transfers around 2026-09-24
Longer-term hardening
- Restrict and monitor access to backup repositories containing non-public court records; apply least privilege and separate backup credentials
- Deploy phishing-resistant MFA and link-protection/detonation on judicial-branch email
- Encrypt backups at rest so copied files are unreadable without separately held keys
- Alert on automated, high-volume file access and large data transfers from records systems
Timeline of Arizona Courts Cyberattack
- Backup court files containing a mix of public and non-public records, including active and inactive protective orders, were copied; no records were deleted, altered or erased.
- Court IT staff noticed unusual activity and large data transfers ('some type of automated bot... hitting particular files') and shut the attack down in less than two hours.
- Per the court's alert hub, the attack began with a phishing email in which a court employee clicked a malicious link; the attack occurred around 11:30 a.m.
- The Administrative Office of the Courts began emailing affected individuals after business hours on Friday and pointed the public to azcourts.gov updates.
- Timmer spoke personally with the top-ranking FBI official in Arizona and pledged full support for the FBI investigation.
- Chief Justice Ann Scott Timmer announced that criminal hackers likely copied personal identifying information of 'many Arizonans'; the Judicial Branch issued an urgent notice.
- The court's cybersecurity alert information hub at azcourts.gov/cybersecurityalert was posted with the phishing attack description, data scope and the exclusion of juror, witness and employee data.
- Local media reported that confidential addresses of people with current or past protective orders may have been copied; officials said no evidence the data was shared and it is unclear whether most copied data is readable.
- azfamily reported an affected protective-order holder describing feeling vulnerable after being told her information and location may have been copied.
- azfamily reported tens of thousands of records affected including domestic-violence victims, with outreach to shelters and advocacy groups; The Record reported no ransomware, no ransom demand and no group claim.
Sources cited for Arizona Courts Cyberattack
- Sept. 25, 2026 URGENT NOTICE: Arizona Courts Experience Cyber Attack (Arizona Judicial Branch news release)
- Arizona Courts Cybersecurity Alert Information Hub
- Arizona Supreme Court says hackers stole residents' personal data (The Record, Jonathan Greig)
- Cyberattack targets Arizona courts, gaining personal information of 'many Arizonans' (KJZZ)
- Cyberattack on Arizona courts may have exposed protective order addresses (azfamily)
- Victim says Arizona court cyberattack has left her feeling 'vulnerable' (azfamily)
- Domestic violence victims' data may be exposed in Arizona court breach; FBI investigating (azfamily)
- Arizona court cyberattack under FBI investigation, potentially compromising personal data (Fox 10 Phoenix)
- Arizona courts hit by cyberattack, personal data may be exposed (NewsNation)
- Thomson Reuters court software breach (The Hacker News) - related court-sector context only; no reported link to Arizona
- Thomson Reuters cyberattack data (The Record) - related court-sector context only; no reported link to Arizona
More in data breach
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal Data
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection
- ShinyHunters Hacks Clop Ransomware Gang's Tor Leak Site via Grav CMS File Upload Flaw, Threatens 72-Hour Extortion
Detection coverage for TL-2026-2768
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2768 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.