A single clicked email link cost the Arizona Supreme Court the personal records of 1.3 million people.
An employee opened a phishing email and clicked a malicious link, giving attackers a way into court systems on or before September 24. The court's IT team spotted the intrusion and shut it down on a backup server within roughly two hours. The attackers copied 30 years of records on unpaid court fines, fees, and restitution tied to traffic and criminal cases, along with almost 30,000 active and inactive protective orders and 150,000 foster-care board reports dating back to 2010. Court operations were not disrupted, and officials say data on jurors, witnesses, and employees was untouched, with no records altered or deleted.
Court records are a uniquely useful haul for criminals because they double as a blueprint for believable scams. Knowing someone's case number, fine amount, or custody history lets an attacker write a phishing email that looks like it came from the court itself. So far, the data has not surfaced on the dark web, which argues against a ransomware or extortion motive, but a quiet sale or slow-burn fraud campaign would look exactly the same in these early days.
This is at least the third US court-system breach to surface in under a year. Thomson Reuters disclosed in September that its C-Track case-management software had been breached across 11 states, the US Virgin Islands, and Ontario; the Georgia Superior Court Clerks' Cooperative Authority fought off a ransom demand from a group called Devman in November 2025. Courts keep getting hit for the same reason banks do - they hold decades of sensitive data - without anything like a bank's security budget.