Arizona courts say hackers stole info on more than 1.3 million people
Hackers stole court records on more than 1.3 million people after phishing an Arizona courts employee.
Arizona court officials said investigators confirmed criminal hackers accessed and copied backup files from the statewide Fines/Fees and Restitution Enforcement (FARE) program, exposing names, Social Security numbers, and case numbers for more than 1.3 million people spanning about 30 years. The intrusion, announced September 25, began September 24 after an employee clicked a malicious email link and continued until IT shut the system down. Attackers also copied more than 150,000 Foster Care Review Board reports dating to 2010, including records on about 8,000 children currently in care, plus some protective-order records. Officials said the incident was not ransomware and that no group has claimed it or demanded a ransom.
- FARE breach exposed names, SSNs, and case numbers for 1.3 million people over about 30 years.
- Attack began September 24 after an employee clicked a malicious email link.
- More than 150,000 foster-care reports were copied, covering about 8,000 children currently in care.
- Officials say it was not ransomware and no ransom demand or group claim has been made.
Full article437 words · extracted from therecord.media · click to collapse
A cyberattack on Arizona’s court system gave hackers access to the sensitive information of more than 1.3 million people. In an updated FAQ published this week, Arizona court officials said federal and state investigators confirmed that criminal hackers “accessed and copied backup court files.” The court’s statement claims the format of the stolen files may make it difficult for the hackers to read the files. The investigation into the incident revealed cybercriminals were able to breach the Fines/Fees and Restitution Enforcement (FARE) Program, a statewide program that helps the court collect outstanding debts tied to traffic and criminal violations. The breached data, which dates back 30 years, includes names, social security numbers and case numbers of 1.3 million people. Text messages will be sent to victims of the FARE breach and they urged victims to put holds on their credit lines. In addition to the FARE breach, the hackers also accessed reports created by the Foster Care Review Board, which handles childcare cases and provides recommendations to juvenile court judges. The reports have troves of information on children, statements from families, investigative findings and administrative notes. The breach involved more than 150,000 reports for current and past cases dating back to 2010, including 8,000 children currently in foster care. Arizona’s court system has sent breach notifications to the Department of Child Safety, attorneys representing parents, judges and members of the Foster Care Review Board. The hackers also copied records involving active and inactive protective orders, including some sensitive information. Arizona’s Supreme Court announced the breach on September 25, telling the public that the cyberattack began on September 24 and continued until the court’s IT team shut off the system entirely. The new FAQ said investigators believe the cyberattack began with a phishing attack, where a court employee clicked a malicious link in an email. Arizona Supreme Court Chief Justice Ann Scott Timmer said she personally spoke with FBI Special Agent in Charge Rebecca Day about the incident and is coordinating with state officials on the recovery effort. No hacking group has taken credit for the attack as of Wednesday. A spokesperson for the court system previously told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.