Hackers steal protective order and foster care records from Arizona courts
Attackers phished an Arizona court employee and copied over 150,000 foster-care and protective-order records.
The Arizona Supreme Court said criminal hackers breached the state court system after an employee clicked a malicious link in a phishing email. The attackers copied highly compressed backup files containing protective-order records and more than 150,000 Foster Care Review Board recommendation reports dating to 2010. Those reports can include information about children, involved parties, case materials, findings, and recommendations, but the court says they do not contain addresses or telephone numbers. The FBI is investigating; no ransomware group has claimed responsibility, and the court says it has no evidence the stolen information has been shared. Arizona currently has about 8,000 children in foster care.
- A court employee clicked a malicious link in a phishing email.
- Attackers copied compressed backups covering protective orders and foster care.
- More than 150,000 Foster Care Review Board reports dating to 2010 were taken.
- Reports may include children's case details but not addresses or phone numbers.
- No ransomware claim; the FBI is investigating and no public leak is known.
Full article551 words · extracted from malwarebytes.com · click to collapse
“Arizona’s court system was targeted by a cyber attack from criminal hackers or their bots.”
This is how the Arizona Supreme Court announced that hackers had attacked the state’s court system and stolen the personal information of “many Arizonans.”
The court says the attack began with a phishing email containing a malicious link that a court employee clicked. The attackers copied sensitive backup files containing records related to protective orders and foster care cases.
The court says it has no evidence, so far, that information about jurors, witnesses, or court employees was included in the copied files. It has not identified the attackers or a motive. It says the case is under investigation with the FBI, and no ransomware group has publicly claimed responsibility.
In an update, the court revealed that the attackers copied more than 150,000 recommendation reports created by Arizona’s Foster Care Review Board. The reports cover current and past cases involving children’s care and protection, dating back to 2010.
Those documents can include information about children, names of involved parties, case materials considered by the board, findings, and recommendations for courts, parents, and the Arizona Department of Child Safety. The court says the reports do not contain contact information such as addresses or telephone numbers.
The copied files were backups stored in a highly compressed format, kept for recovery after ransomware and other destructive incidents.
Information associated with protective orders can raise particularly serious safety and privacy concerns. These orders can protect people from abuse, harassment, or threats. Even where some records are public, combining names, case details, locations, and other sensitive context could create risks for people who are trying to limit their exposure to an abusive or threatening individual.
Breaches happen every day. Don’t be the last to know.
The court currently says it has no evidence that the information has been shared. As with many breach investigations, however, this can change as investigators determine exactly what was taken and monitor for publication, sale, or misuse of the data.
Arizona has about 8,000 children currently in foster care, according to the court. It is contacting people believed to have been affected.
What to do if you’re affected
- Check the court’s advice. Every breach is different, so check its dedicated webpage for updates and follow any specific advice it offers.
- Watch out for impersonators. Cybercriminals may contact you posing as the Arizona Supreme Court, another government agency, or someone you know. Verify anyone who contacts you through a separate, trusted channel.
- Take your time. Phishing attacks often impersonate people or brands you know and pressure you to act urgently, using themes such as missed deliveries, account suspensions, and security alerts.
- Get an early warning if your information appears on the dark web. If you’ve been notified that your information was copied in the Arizona court breach, identity monitoring can help you watch for signs of exposure and get support if you become a victim of identity theft.
Let’s face it, an incognito window can only do so much. Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
About the author
Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.