SecurityWeek reported on Oct. 7 that attackers copied personal data from Arizona's court system. The Arizona Supreme Court said the data covers 1.3 million people with unpaid court fees, fines or restitution, from traffic and criminal cases up to 30 years old. The attackers also took records of nearly 30,000 orders of protection, active and inactive, and 150,000 foster care board reports dating to 2010.
The court believes the attack began when an employee clicked a bad link in an email. Staff spotted it on Sept. 24 and stopped it about two hours later, on a backup server. The court has not said whether that server was the target or just where the attack ended. Spokesperson Alberto Rodriguez said on Tuesday that there is no evidence the data was used or shared. The investigation continues. No cases were delayed, no records changed, and no data on jurors, witnesses or court staff was taken.
Analyst view, not the court's: the loss may owe as much to long record retention as to the entry point. Budget signers can ask: how long do we keep records, what can one user's account reach, and how fast would we spot a bulk copy?