
On September 24, 2026, a malicious email link opened a backdoor that allowed attackers to copy the personal data of 1.3 million people linked to Arizona’s court system. The stolen records cover unpaid court fees and restitution for traffic and criminal violations dating back 30 years, and include 30,000 active and inactive orders of protection, plus 150,000 foster‑care reports from 2010.
Court technology staff detected the intrusion and shut down the compromised server within two hours, restoring operations from a backup. Since then, the court has notified those affected, and a spokesperson—Alberto Rodriguez—asserted that no evidence of data misuse has surfaced.
“It’s a wake‑up call for our entire state’s judicial infrastructure,” Rodriguez said. He added that no records were altered or deleted and that the breach did not impact ongoing cases.
For one Phoenix resident, the breach revealed a decade‑old unpaid fine for a minor traffic violation that had kept a family from moving into a new apartment. The victim, whose identity remains confidential, said the revelation forced him to confront a long‑standing debt he thought was forgotten.
The Arizona Supreme Court will release a follow‑up security report next month, while federal investigators probe the breach’s source. Residents can expect a detailed assessment of how the court’s cybersecurity protocols failed and what steps will be taken to prevent a repeat incident.