A cyberattack detected on 24 September 2026 affected Arizona’s court system. On 6 October, the state Supreme Court said information relating to about 1.3 million people had been copied, along with sensitive records tied to protection orders and foster care. Courts believe an employee likely clicked a malicious link in an email.
The datasets that were copied
The largest group concerns people with unpaid court fees, fines, or restitution for traffic and criminal violations, in some cases dating back 30 years. The court also reported nearly 30,000 active and inactive protection orders and about 150,000 reports from the Foster Care Review Board, with records dating to 2010.
These categories should not be confused with access to every court file in the state. Authorities say cases were not delayed and information about jurors, witnesses, and employees was not stolen. No records were reported altered or deleted.
Phishing is the likely entry point
Information provided to the Associated Press says the attack likely began when an employee opened a malicious link in an email. Technology staff spotted activity on a backup server and stopped it about two hours later. Available sources do not yet describe every technical step or identify the people responsible.
A click can expose a session or device, but that detail alone does not establish how attackers reached the backup data. Wait for investigation findings rather than assigning an unconfirmed technique or scope to the incident.
A sensitive impact, with no evidence of use so far
Protection-order records can concern people facing risks of violence; foster-care reports concern families and children. Treating these records as just another large number would understate their sensitivity. Institutions should explain what was copied and how affected people can get help without requiring them to repeat sensitive details through an unverified channel.
A court spokesperson said there was no evidence the information had been used or shared after the attack. That statement describes what investigators had observed when it was published; it cannot rule out future use.
What affected people can do
Watch for official updates from Arizona’s courts and verify any notice using contact details published on their website, rather than a link in an unexpected email. Someone connected to a protection order or family case can ask the relevant court what specific steps apply to their case.
Avoid sharing case numbers, family information, or documents with an unsolicited caller or sender. If a message claims that urgent payment or verification is required, call the court using a number found independently.
The Soclyde connection
Soclyde does not protect Arizona’s court systems and cannot secure copied records. Its local-first vault helps users manage passwords and access on their devices. Within an organisation, phishing prevention, backup access controls, and notification procedures remain the responsibility of the relevant teams and services.
The takeaway
Arizona’s Supreme Court reports that records for about 1.3 million people were copied, along with protection orders and foster-care reports. Phishing is the likely entry point, and authorities say they had found no evidence the data was used or shared as of 6 October. Verify messages through official channels and protect sensitive information. Read our NIS2 cybersecurity guide for practical team security measures.



