Tens of thousands of people may have had their personal information compromised in a cyberattack on Arizona’s judicial network, after hackers gained access through a phishing email, court officials said.
The attack began on Thursday, 24 September, and was detected when court IT staff saw an unusually large volume of data being downloaded. The system was shut down less than two hours after the intrusion was identified, according to the Arizona Supreme Court.
Chief Justice Ann Scott Timmer said criminal hackers or automated “bots” copied backup court files containing personally identifiable information. The material included records linked to active and inactive protective orders, some of which contained sensitive details such as names and addresses. ([azcourts.gov](https://www.azcourts.gov/cybersecurityalert))
Evidence so far suggests the breach began when a court employee clicked on a malicious link in an email. Timmer said the incident demonstrated how a single mistake could allow an automated system to enter and move through a wider network.
“It only takes one time for an employee to click on the email they shouldn’t click on,” she said. “And in comes some kind of bot or automated system or something that can worm its way into your system and that’s what happened.”
Protective-order records among files copied
The court has begun contacting people whose information may have been taken, including individuals with current or expired protective orders. Officials have stressed that the attack was directed at court records generally and was not aimed at a particular person.
There is currently no evidence that the copied information has been shared, and investigators have not established a motive. Court officials also said the format of much of the material meant it was unclear whether the data could be easily read. ([azcourts.gov](https://www.azcourts.gov/cybersecurityalert))
The court said no information relating to jurors, witnesses or court employees was included in the files copied, based on what investigators and IT specialists know so far. No court records were deleted, altered or erased, and the breach is not expected to affect pending cases, court orders or scheduled hearings. ([azcourts.gov](https://www.azcourts.gov/cybersecurityalert))
The FBI and state law enforcement agencies have been notified. Timmer said she had spoken directly to Rebecca Day, the FBI special agent in charge in Arizona, and pledged the court’s full co-operation with the investigation. ([azcourts.gov](https://www.azcourts.gov/cybersecurityalert))
The Arizona Judicial Branch said it had 24-hour cyber-security monitoring, regular security scans and mandatory annual training for employees before the incident. Court leaders are to carry out a full review and introduce any changes needed to protect court data.
Timmer apologised to people with protective orders who were worried that confidential information might have been exposed. She said anyone who believed they were in immediate danger should contact local police, while the court’s public information service continued to answer questions from those affected.
