Arizona's state court system was breached in a cyberattack the courts disclosed on the evening of 26 September 2026, and the intrusion may have copied personal data belonging to people who have had contact with the courts, including confidential addresses tied to protective orders [2]. A woman identified only as Ashley, who has held a protective order for years, said learning that her file may have been copied left her feeling "very vulnerable" [1].
Background
A protective order lets a person who fears a named individual ask a court to keep their home address confidential in the case file, specifically so that person cannot learn where they live. A court file supporting such an order can also contain a full legal name, date of birth and case history, information a retired FBI agent quoted by AZFamily described as "a lot of sensitive information that's shared with the judge" to justify the order in the first place [1].
That distinction is what separates this incident from a typical data breach at a retailer or an app. A breach of a shopping account usually exposes an email address and a password, both of which can be changed. A protective-order file can expose a piece of information a court specifically agreed to withhold from one named person, precisely because that person might use it to cause harm, and an address cannot be reset the way a password can.
Findings
Arizona Supreme Court Chief Justice Ann Scott Timmer announced the attack on the evening of 26 September; court IT staff detected and stopped it, and Timmer called it an "outrageous criminal attack" on the courts [2]. According to KJZZ, the intrusion copied personal information belonging to "many Arizonans" who have had contact with the court system, not a specific, named list of targeted people [3]. AZFamily reports the exposed data included confidential addresses tied to current and past protective orders [1]. Court administrators began contacting affected people after hours, and the FBI is investigating; officials say they have no evidence so far that the copied data has been shared or posted anywhere [2].
The whole reason I had a protective order and had my information on file with the court was because I need that information protected.
Ashley, protective-order holder, quoted by AZFamily
Implications for those affected
Anyone who has been a party in an Arizona court case, filed for or been named in a protective order, served as a juror, or otherwise had contact with the Arizona court system may have information among what was copied [2] [3]. The courts say they are notifying people directly, so a letter or call referencing this specific incident is how someone would learn they were affected, not an unsolicited email asking them to "verify" their details. Someone with no history with Arizona's courts has no exposure from this incident specifically, though the general advice on phishing below applies regardless.
Recommendations
- If a protective order is in place and there is a concern about immediate danger, contact local law enforcement now rather than waiting for a letter from the court.
- If a notification arrives from the Arizona courts, read it carefully, but go to the court’s own site (azcourts.gov) rather than a link in an unexpected email or text.
- Expect phishing that references this breach: messages posing as "Arizona Courts" or "case services" asking for a login, a fee, or an address to be confirmed. Courts do not request payment or passwords by text or email.
- Anyone whose address was tied to a protective order should talk to a local victim-services advocate or the court about what further protections are available.
- Watch accounts and credit for anything unfamiliar in the coming months; a name, birth date and address are enough for an identity-theft attempt.
Relevance to FireAI
FireAI cannot undo a breach of a government system, and has no way to know what was inside a specific court file. What it can do is reduce the damage that phishing following a breach like this can cause on a Mac.
- FireAI’s threat lists are an opt-in feature that check a Mac’s connections against free public phishing-domain lists once a day, so a link to a fake "Arizona Courts" site already reported elsewhere can be blocked before the Mac connects to it.
- When an unfamiliar app tries to connect for the first time, FireAI asks and shows where the connection is headed on the world map.
- Investigate a connection allows checking a suspicious connection before deciding whether to allow it.
- The kill switch cuts all internet access at once, for locking everything down while sorting out a suspicious message or device.
FireAI does not scan files, does not detect identity theft, and cannot protect a protective order’s confidentiality once a government system has been breached. That part is on the courts and the FBI. FireAI is made by HisnLabs.
Limitations
None of the three sources gives a total number of people or records affected, and KJZZ's phrase "many Arizonans" is the most specific figure reported [3]. It is not established which attacker or group carried out the intrusion, how it gained access, or how long it went undetected before court IT staff stopped it. Officials say they have no evidence the copied data has been shared or posted, but that is a statement about what has been observed so far, not a guarantee about what happens next [2]. None of the sources says whether the notifications going out to affected people specify exactly which pieces of their information were involved, or whether every notified person had a protective order on file rather than some other kind of case contact.
Try FireAI, by HisnLabs free for 17 days.