Skip to content
Security & Trust

Arizona courts breach exposes data on more than 1.3 million people

Investigators say hackers copied backup court files. Separately, exposed FARE records on 1.3 million people go back 30 years.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Arizona courts breach exposes data on more than 1.3 million people
In brief
  • Arizona court officials say investigators confirmed hackers copied backup court files. Separately, exposed FARE data on more than 1.3 million people dates back 30 years. Investigators believe phishing started the attack.
  • The court has not said whether the FARE records were in the backups. WebPulse's view is that the case still shows why backup retention is a security decision.
  • Leaders should ask what their backups hold, how long they keep it, who can reach it, and whether stored data is protected on its own.

Most breach stories ask how the attackers got in. A better question is what they found. In Arizona, court officials say hackers copied backup court files. Separately, the exposed FARE data on more than 1.3 million people reaches back 30 years.

The court has not said whether the FARE records were in the backups. This piece treats these as two confirmed facts, then asks what the case suggests about backups in general.

What happened

The Arizona Supreme Court announced the incident on September 25. The intrusion began on September 24 and continued until court IT staff shut the system off entirely.

An updated FAQ adds detail. The Record reports that officials said federal and state investigators confirmed the criminal hackers "accessed and copied backup court files."

Investigators found the intruders also breached FARE, a statewide program the courts use to collect unpaid debts tied to traffic and criminal violations.

1.3 million+
People in the FARE data
Source: Arizona courts FAQ, as reported by The Record (October 7, 2026)
30 years
Age of the FARE records (not stated to come from backups)
Source: Arizona courts FAQ, as reported by The Record (October 7, 2026)

The exposed FARE records include names, Social Security numbers and case numbers. The court will text affected people and urges them to place holds on their credit.

Foster care reports were also accessed

The hackers also accessed reports from the Foster Care Review Board. The board handles childcare cases and makes recommendations to juvenile court judges.

The reports hold details about children, statements from families, investigative findings and administrative notes. More than 150,000 reports from current and past cases were involved, going back to 2010. They include 8,000 children currently in foster care.

150,000+
Foster Care Review Board reports involved
Source: Arizona courts FAQ, as reported by The Record (October 7, 2026)

The hackers also copied records of active and inactive protective orders, including some sensitive information. The court has sent notices to the Department of Child Safety, attorneys for parents, judges and board members.

How it worked

Investigators believe the attack began with phishing. A deceptive email led a court employee to open a harmful link. Phishing endures because it targets a person rather than a system.

Public reporting does not describe how the attackers got from that email to the backups, or how those backups were stored and protected. Those gaps matter for any organisation judging its own exposure.

The court also offered a hopeful note: the way the stolen files are formatted could slow the hackers down. It gave no detail on that format or on encryption. Treat the point as unconfirmed.

WebPulse's view: backups hold history, and history has a long reach

This section is WebPulse's interpretation. A live system holds today's work. A backup is a copy of everything, kept so an organisation can recover from a bad day. That makes it a very complete record of the past.

If a backup is breached, the exposure can reach back further than the live system. Arizona does not prove this. It is the question the case should prompt in every organisation.

The FARE program collects debts tied to traffic and criminal violations, so the people in it are linked to court cases. People in the FARE data cannot take it back; the court's advice is to place credit holds. The foster care reports concern children and families in juvenile cases.

Open questions remain. No group had claimed the attack as of Wednesday. A court spokesperson told Recorded Future News the incident did not involve ransomware. No ransom demand had been issued as of Monday. Without a demand, it is unclear what the hackers plan to do with the files.

Questions for your team

Ask what your backups contain and how far back they go. Ask whether every year of data is still needed, and who decided that.

Ask who can reach backups and whether one stolen employee login could do it. Ask whether stored data is protected separately, so a copied file is hard to read.

Ask how many staff would follow a convincing link today, and what limits the damage when one does. Ask how fast you could identify and notify the people in an old archive.

A backup protects you from losing your history. It can also put that history within one intruder's reach.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.

Share this insight