Arizona Supreme Court Reports 1.3 Million Records Breached in Cyberattack
The scale of the breach, which includes active protection orders, raises questions about federal court cybersecurity standards and congressional appropriations for state judicial infrastructure.
A cyberattack on Arizona's state court system resulted in the copying of personal information belonging to 1.3 million individuals, the Arizona Supreme Court confirmed in a public statement reported by the New York Post on October 6, 2026.
The court said the compromised records belong to individuals who had unpaid court fees, fines, or restitution obligations for traffic and criminal violations, with some records dating back 30 years. In addition to the financial obligation data, attackers accessed records for nearly 30,000 active and inactive orders of protection.
The Arizona Supreme Court indicated investigators believe the attack began when a court employee clicked a malicious link in a phishing email. The specific method by which attackers then moved through court systems, and whether they accessed any networked federal systems, has not been confirmed in the court's public statement.
Orders of protection are civil court documents issued to restrict contact between individuals in cases involving domestic violence, stalking, or harassment. Exposure of those records can identify both the protected party and the respondent, including home addresses and the nature of allegations filed. The court has not yet confirmed in its public statement whether addresses or case-specific details were included in the extracted data.
The breach falls under state jurisdiction, but it intersects with federal policy on at least two tracks. First, the federal State Justice Institute, authorized under 42 U.S.C. 10701, provides grants to state court systems for modernization and security improvements. Second, the Cybersecurity and Infrastructure Security Agency, operating under the Department of Homeland Security, designates courts and judicial systems as critical infrastructure under the Government Facilities Sector.
Congress has appropriated funds for CISA's state and local cybersecurity grant program under the Infrastructure Investment and Jobs Act, signed into law in 2021 (Public Law 117-58), which authorized $1 billion over four years for state and local cyber improvements. Whether Arizona's court system drew on those funds, and whether the grant conditions required specific security controls such as phishing-resistant email authentication, is not addressed in the Arizona Supreme Court's statement.
The Senate Judiciary Committee and the House Committee on the Judiciary both have jurisdiction over federal judicial security matters, though state court systems operate independently unless federal funds or federal data systems are involved. Neither committee had issued a public statement on the Arizona breach as of the publication of this article.
At the federal level, the Judiciary Information Technology Office manages cybersecurity for Article III courts under the Administrative Office of the U.S. Courts. That office publishes an annual report to Congress on technology investments. Whether any data shared between Arizona state courts and federal case management systems was accessible through the breach is not yet known.
Protection order records carry particular sensitivity under the Violence Against Women Act reauthorization (Public Law 117-103, signed 2022), which includes provisions requiring states to maintain confidentiality of certain domestic violence records as a condition of federal STOP grant funding administered by the Department of Justice Office on Violence Against Women. Whether Arizona's breach triggers any federal compliance review under that statute has not been stated publicly by the Department of Justice.
The total number of Arizona residents notified as of October 6, 2026, the timeline for notification, and the identity of the threat actor or actors remain unknown based on available public statements. A full accounting of what specific data fields were extracted would appear in any incident report filed with the Arizona Attorney General's Office under Arizona Revised Statutes Section 18-552, which governs breach notification. That filing, if submitted, would be a public record.
What remains unknown includes whether the breach extended to any federally networked system, whether Arizona has applied for or received CISA state and local cybersecurity grants, and whether the Department of Justice has opened a review of the state's VAWA grant compliance in connection with the exposure of protection order records. Those answers would be contained in CISA grant award records on USASpending.gov, DOJ Office on Violence Against Women grant documentation, and any Arizona Attorney General breach notification filing.