Arizona court hack exposes 150,000 foster care reports

Published

Hackers who got into Arizona's court system copied backup files holding records on protective orders and foster care cases, including more than 150,000 reports written about children in the state's care. The Arizona Supreme Court disclosed the attack and later expanded on what was taken, as Malwarebytes Labs reported on September 30, 2026.

The court says the intrusion began with a phishing email: a court employee clicked a malicious link. From there, the attackers copied sensitive backup files. The court says it has no evidence so far that information about jurors, witnesses or court employees was among them, and it has not identified the attackers or a motive. The case is under investigation with the FBI, and no ransomware group has publicly claimed responsibility.

Reports on children dating back to 2010

The largest known set is more than 150,000 recommendation reports created by Arizona's Foster Care Review Board, covering current and past cases back to 2010. According to the court, those reports can include information about children, the names of people involved, case materials the board considered, and its findings and recommendations for courts, parents and the Arizona Department of Child Safety. The court says they do not include contact details such as addresses or telephone numbers. Arizona has about 8,000 children in foster care today, the court says.

The protective order records carry a different kind of risk. These orders exist to shield people from abuse, harassment or threats, and Malwarebytes points out that even where parts of a record are public, combining names, case details and locations can endanger someone who is trying to stay out of an abuser's reach.

The backups built for recovery were the target

There is an uncomfortable irony in what was taken. The copied files were highly compressed backups that the court kept so it could recover from ransomware and other destructive incidents. The data meant to be the court's safety net became the thing the attackers walked away with.

Watch for impersonators and check the court's notice

The court says it is contacting people it believes were affected and has no evidence yet that the data has been shared, though that can change as investigators work out exactly what was taken and watch for publication, sale or misuse. Anyone notified should follow the specific advice on the court's dedicated breach page and treat unexpected calls, texts or emails claiming to come from the court or another agency with suspicion, verifying them through a separate, trusted channel before acting.

IntelFusions tracks attacks like this one on its United States country profile. The lesson here is a plain one: a single clicked link was enough, and the most sensitive records sat in the files built to save the day.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions