Arizona court system breach exposes residents' data

Arizona court system breach exposes residents' data

Hackers broke into Arizona's state court system and copied personal information belonging to "many Arizonans," the Arizona Supreme Court said on Friday.

The announcement came from Chief Justice Ann Scott Timmer. She said the courts were targeted by criminal hackers "or their bots." The court has not said how many people are affected, what kind of data was taken, or how the attackers got in.

"Court leaders believe the criminal hackers copied personally identifiable information about many Arizonans," Timmer said in a statement. "The Supreme Court's Administrative Office of the Courts is in the process of alerting as many people as possible whose information it believes the criminal hackers copied."

The Administrative Office of the Courts is the administrative arm of the Arizona Supreme Court and supports the day-to-day running of the state's judicial branch. It is now handling notifications to affected residents.

No ransomware, no ransom demand

A court system spokesperson told Recorded Future News that ransomware was not involved in the incident. As of Monday, the attackers had not demanded payment for the stolen data.

No hacking group has claimed responsibility so far.

Timmer said the court will not share more details for now, because doing so could affect the investigation. She added that she had spoken directly with the FBI.

"I personally spoke with the topranking FBI leader in the state, and I pledged our full commitment to supporting their investigation and minimizing the likelihood that the information will be used to further jeopardize Arizonans," she said. "We're in touch with those affected and will share more information as soon as we're able."

That leaves several open questions. It is not known when the intrusion started, which systems were accessed, or whether the attackers still have access. It is also unclear whether residents should expect targeted phishing or fraud attempts using the stolen records.

Courts remain a popular target

Arizona is far from the first state judiciary to be hit. Court systems store large amounts of sensitive personal information along with law enforcement data, and that makes their servers attractive to attackers.

In 2023, a ransomware attack took down nearly all of Kansas' court systems. Recovery took months.

Over the past four years, state and municipal courts in California, Nebraska, South Carolina, Florida, Wisconsin, Louisiana, Ohio, Missouri and Illinois have dealt with ransomware attacks, distributed denial-of-service (DDoS) incidents and data breaches.

More recent cases show how disruptive these attacks can be:

  • In November, ransomware attackers breached the Pennsylvania Office of the Attorney General. The state's court system was disrupted for nearly a month, and courts had to grant time extensions in some criminal and civil cases.
  • Also in November, ransomware hit the organization that manages real estate and civil court filings in Georgia.

Unlike those incidents, the Arizona breach has so far been described as a data theft, not a system lockdown. The court has not reported any disruption to hearings or filings.

Why It Matters

For readers outside the US, the Arizona case is a useful reminder that public sector breaches do not always look like classic ransomware. There was no encryption and no ransom note, at least not so far. What is left is a copy of residents' personal data in unknown hands. This fits a wider pattern where the stolen data is the main asset, as seen in recent incidents such as the Pentagon DMDC breach.

The mention of "bots" is vague, but it suggests some level of automation in the attack. The court has not explained what it means, so it should not be read as more than that.

It is worth watching whether a group claims the attack or tries to extort the courts later, as data theft crews have done in other cases. Affected Arizonans should treat unexpected messages that reference court matters with caution. The breach notifications should also show how much data was taken and what types of records were involved.