Information going back decades on more than a million people was part of the recent Arizona courts' digital records cyberattack, according to a government spokesperson.
The Sept. 24 cyberattack consisted of approximately 1.3 million court debtors and included more than 150,000 confidential foster care reports, according to a news release from Arizona Supreme Court spokesperson Alberto Rodriguez. Case numbers, names and Social Security numbers dating back 30 years were compromised in the data breach.
"This data set does not include information for individuals who have not been sent to collections for unpaid court-ordered fees, fines, or restitution," Rodriguez said in a Sept. 30 email update.
Rodriguez told The Arizona Republic that the attack took place Sept. 24 and lasted about two hours before being discovered.
People are also reading…
Who was affected and what can they do?
Those impacted were referred to the Fines/Fees and Restitution Enforcement (FARE) Program. The statewide FARE Program is part of the Arizona Judicial Branch and is used to collect outstanding court-ordered debt related to civil traffic, criminal traffic and criminal violations, according to the press release.
"The data was copied from a backup server where highly compressed information is maintained. The court has no evidence that any data has been accessed, is readable, or has been shared," Rodriguez said in his email. "No court records were deleted or altered."
Rodriguez told The Republic that whoever obtained the information must decipher it and share it, as it was encrypted, adding there was no evidence that had taken place. This was not a targeted attack, but instead an instance of a court employee opening a phishing email, Rodriguez said. As of Sept. 30, it was not known who the hacker or hackers were, he added.
"The court is taking measures to mitigate potential adverse effects of an unauthorized disclosure of information for individuals referred to the FARE program for collections," Rodriguez said in his email.
Rodriguez recommended that those potentially affected hold or freeze their credit files through either the Equifax, Experian or TransUnion credit reporting agencies, and to visit identitytheft.gov and azag.gov/consumer/data-breach.
Who was part of the first batch breached?
Foster care review reports as part of the cyberattack were disclosed Sept. 28 by Rodriguez after the court system announced the incident three days before. Breached data included information on children, their parents and the names and statements of people involved in foster cases going back to 2010, according to Rodriguez. The specific number of impacted individuals was not specified.
Addresses and phone numbers were not included, Rodriguez said.
The Foster Care Review Board program operates within the Arizona Supreme Court’s Administrative Office of the Courts, and its citizen panels review children’s cases and recommend actions to juvenile court judges, according to the court’s website and Arizona Department of Child Safety policy.
Officials notified DCS, attorneys representing children and parents, juvenile court presiding judges and review board members, Rodriguez said.
Active dependency cases will not be affected, Rodriguez added.
Court IT staff discovered the attack and took steps to stop it, according to a Sept. 25 press release from Chief Justice Ann Scott Timmer.

