Arizona Court Cyberattack Exposes Data of 1.3 Million People A cyberattack on Arizona's court system copied personal information for 1.3 million people after an employee clicked a malicious email link, the Arizona Supreme Court said. A cyberattack on Arizona's court system copied personal information for 1.3 million people, and investigators believe it began when a court employee clicked a malicious link in an email. Arizona Supreme Court Discloses Massive BreachThe Arizona Supreme Court disclosed the breach and said the copied data involved people with unpaid court fees, fines and restitution payments for traffic and criminal violations. Some of those records date back as far as 30 years. The attackers also took records of nearly 30,000 active and inactive orders of protection.In addition, they copied 150,000 reports dating back to 2010 from a foster care board. That board makes recommendations in cases where parents are alleged to be unfit or unable to care for a child. The court's technology staff shut down the attack on a backup server about two hours after spotting it on Sept. 24. Since then, the court has notified those affected by the breach.The attack remains under investigation. State Supreme Court spokesperson Alberto Rodriguez said Tuesday that there is no sign the stolen information has been misused. We don't have any evidence it has been used or shared after the attack, Rodriguez said. He also said the attack has not affected or delayed any court cases.No records were altered or deleted during the breach, according to the court. The attackers also did not steal information about jurors, witnesses or court employees. Those groups were not included in the data that was copied. The breach is tied to a single malicious email link that a court employee clicked, which is believed to have started the incident.Stolen Data Includes Unpaid Fees and OrdersThe affected population includes 1.3 million people with unpaid court fees, fines and restitution payments for traffic and criminal violations. The stolen material spans roughly three decades of records. The order of protection records number nearly 30,000 and include both active and inactive orders. The foster care board reports number 150,000 and date back to 2010.The court said its technology staff responded quickly once the attack was detected on a backup server. The shutdown came about two hours after the spotting on Sept. 24. Notification to those affected has followed. Rodriguez said the investigation is ongoing and that no court cases have been affected or delayed.The court also said no records were altered or deleted. Information about jurors, witnesses and court employees was not stolen. The breach did not involve those categories of data. The Arizona Supreme Court said the information was copied for 1.3 million people with unpaid court fees, fines and restitution payments.Those payments relate to traffic and criminal violations dating back as far as 30 years. The attackers also took the orders of protection records and the foster care board reports. The foster care board reports cover cases where parents are alleged to be unfit or unable to care for a child. The board makes recommendations in those cases.The reports date back to 2010 and total 150,000. The court's technology staff shut down the attack on a backup server about two hours after spotting it on Sept. 24. Since then, the court has notified those affected. The attack is under investigation.Investigation Shows No Evidence of MisuseRodriguez said there is no evidence the data has been used or shared after the attack. He said the breach has not affected or delayed any court cases. No records were altered or deleted, and jurors, witnesses and court employees were not affected. The incident began when a court employee clicked a malicious link in an email, according to the court.The copied data covered 1.3 million people. It included unpaid court fees, fines and restitution payments for traffic and criminal violations going back as far as 30 years. The attackers also copied nearly 30,000 active and inactive orders of protection. They took 150,000 reports dating back to 2010 from a foster care board.That board recommends in cases where parents are alleged to be unfit or unable to care for a child. Court technology staff shut down the attack on a backup server about two hours after spotting it on Sept. 24. The court has notified those affected. The investigation continues.Rodriguez said Tuesday that there is no evidence of use or sharing after the attack. He said no court cases have been affected or delayed. No records were altered or deleted, and jurors, witnesses and court employees were not compromised.