Skip to content

Security1 publisher2 min readPublished

One phishing click let attackers copy over 150,000 foster-care reports from Arizona court backups

Arizona's Supreme Court says attackers copied over 150,000 foster-care review reports dating to 2010 from backups after an employee clicked a phishing link. The court kept those copies to recover from ransomware, so the store meant to survive an attack is the one that leaked.

The Watch · Security desk

Photograph accompanying One phishing click let attackers copy over 150,000 foster-care reports from Arizona court backups
Photo: malwarebytes.com

What happened

  • The stolen reports can include children's information, names of involved parties, case materials, board findings, and recommendations to courts, parents and the Department of Child Safety.
  • According to the court, the foster-care reports do not contain addresses or telephone numbers.
  • The court says it has no evidence so far that data on jurors, witnesses or court employees was in the copied files.
  • The court has not identified the attackers or a motive and is investigating the case with the FBI.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Protective-order records put abuse victims most directly at risk, since Malwarebytes says combining names, case details and locations can expose people trying to keep away from an abusive or threatening person.
  • decision Agencies holding ransomware-recovery copies of sensitive records have to decide whether those stores get production-level access controls and exfiltration monitoring, because in Arizona the backup copy is what the attackers took.
  • exposure People notified of the breach become targets for follow-on phishing from impersonators posing as the Arizona Supreme Court or another agency, Malwarebytes warns.

The attack began when a court employee clicked a malicious link in a phishing email [2]. It ended with the attackers copying backup files that held protective-order and foster-care records [3]. The court's account does not say how they got from one inbox to the backup store, or what protected the files once they were there.

The copied files were stored in a highly compressed format and kept for recovery after ransomware and other destructive incidents [10]. Backups kept for that purpose hold the same records as the systems they protect. Guarding a backup against deletion is one control. Guarding it against being read is a different one.

More than 150,000 Foster Care Review Board recommendation reports were copied [7]. According to the court, about 8,000 children are in Arizona foster care today [12]. That works out to roughly 19 reports for every child now in care [1]. The reports cover past cases as well as current ones, going back to 2010 [7]. The exposed set includes families whose cases have closed.

The court's announcement said "Arizona's court system was targeted by a cyber attack from criminal hackers or their bots." [1] No ransomware group has publicly claimed responsibility [6]. For now, everything public about the intrusion comes from the court's own statements. The court says it has no evidence the data has been shared [11]. Malwarebytes, which reported the breach, wrote that this can change as investigators work out exactly what was taken and watch for publication, sale or misuse [15].

What to watch

  • Whether the court discloses how the attackers moved from the phished employee's machine to the backup store, and whether the backup files were encrypted.
  • Any leak-site post, sale listing or extortion demand involving the foster-care or protective-order data.
  • A count and description of the protective-order records in the copied backups.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories