Breach Watch: Arizona Courts Breach Exposes 1.3M

Breach Watch: Arizona Courts Breach Exposes 1.3M
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · October 6, 2026

TL;DR for CISOs: A single phishing click let attackers copy data on about 1.3 million people from Arizona's court system, the FBI says a contractor's missed patch opened the door to ShinyHunters, and Atlassian has patched a CVSS 9.3 file-access flaw across eight self-hosted products.

BOTTOM LINE FOR CISOS
  1. Backups are a target. In Arizona the reported loss came from copied backup files, which often hold decades of records that no live system would still keep. Know what your backups contain and who can reach them.
  2. Outsourced patching is still your risk. The FBI publicly blamed a contractor for not applying an available fix. Ask each managed-platform vendor for patch evidence, not assurances.
  3. Patch before exploitation starts. Atlassian reports no exploitation yet, but the flaw is unauthenticated and rated 9.3. The window between advisory and attack is the cheapest time to act.

Lead story: Phishing click exposes data on 1.3 million people in Arizona's court system

CRITICAL · CONFIRMED BREACH
Key facts
Affected organization: Arizona Supreme Court and the state court system
Scale: About 1.3 million people with unpaid court fees and fines going back as far as 30 years, per SecurityWeek. Fox10 Phoenix reports the same 1.3 million figure for a debt-collection program, while its headline says "over 1 million"
Data involved: Names, case numbers and Social Security numbers for people in the debt program (Fox10 Phoenix). SecurityWeek also reports nearly 30,000 protection orders and more than 150,000 Foster Care Review Board reports dating to 2010. Malwarebytes says the foster care reports do not contain addresses or phone numbers
Method: An employee clicked a malicious link in a phishing email; the attackers then copied backup files (per Malwarebytes)
Timeline: Detected September 24 and shut down in about two hours (SecurityWeek, Fox10 Phoenix). Publicly announced around September 29 (The Record). Further detail published October 6
Response: FBI notified; the court began notifying affected people and, per Fox10 Phoenix, sent text alerts and urged credit freezes
Attribution: None. No ransomware group has claimed it and no ransom demand has been reported. The court says it has no evidence the data has been used or shared

What happened

The Arizona Supreme Court disclosed that attackers copied personal information after a court employee followed a link in a phishing email. Court IT staff cut off the access within roughly two hours of detection. Records were not altered or deleted, and court operations continued, according to SecurityWeek.

The sensitivity of the data is what raises this above a routine breach. Beyond fee and fine records, the reporting describes protection-order files and child welfare reports. Malwarebytes notes that names and case details in protection orders could put people at risk if combined with other information. Reporting also differs on detail: Fox10 Phoenix cites an advocate saying parents of some children in foster care had not been told, which the court has not been quoted answering in the sources reviewed.

Evidence

Verified against independently fetched sources:
1. SecurityWeek, Personal information for over 1 million people stolen in a cyberattack on Arizona's court system
2. Fox10 Phoenix, Arizona court system cyberattack potentially exposes over 1 million in debt program
3. Malwarebytes, Hackers steal protective order and foster care records from Arizona courts
4. The Record, Arizona Supreme Court says hackers stole data

What this means for your team

One click led to copied backups, and backups tend to be the largest, oldest and least-watched copy of your data. Thirty years of records in a single reachable location is a retention decision as much as a security one. If the data was not needed to run the court today, it was a liability waiting for a phishing email.

Public-sector and regulated organizations should also read the notification detail closely. When the exposed group includes vulnerable people, such as the subjects of protection orders, the notice itself needs a safe delivery channel and a plan for people who cannot be reached.

Action checklist
  1. Inventory where backups and archives of regulated or sensitive records live, and confirm that access requires separate credentials and multi-factor authentication from day-to-day accounts.
  2. Apply a retention limit to archived records and remove data that no process needs, starting with anything containing Social Security numbers or case details.
  3. Run a phishing exercise aimed at staff who can reach archives, and measure how long it takes for a reported click to reach your incident team.
  4. Draft a notification plan for vulnerable data subjects, including channels that do not reveal sensitive context to a third party.

FBI blames an Accenture contractor's missed patch for the ShinyHunters breach

HIGH · THIRD-PARTY RISK
Key facts
Affected system: The FBI's jobs website, running Oracle PeopleSoft and managed by a third-party contractor
What the FBI said: Cyber division head Brett Leatherman said the incident resulted from a failure on a platform managed by a third party after a contractor did not apply an available security patch. The FBI removed the contractor (SecurityWeek, The Hacker News)
Data involved: Personal information of thousands of FBI employees (SecurityWeek)
Attacker claim: ShinyHunters said in September it used a new PeopleSoft zero-day and took 2 to 3 TB of employee and applicant data (BleepingComputer). The FBI account of a missed patch conflicts with the zero-day claim, and neither source reconciles the two
Single-source details: The Hacker News names CVE-2026-35273 in the PeopleSoft Environment Management Hub endpoint, describes URL-encoding to bypass a web application firewall, and reports two ShinyHunters members have been arrested. These points are not confirmed elsewhere in the sources reviewed

What happened

ShinyHunters announced the FBI jobs-site intrusion on September 22 and, per BleepingComputer, said it was retaliation for a May 2026 FBI report on the group, demanding a correction within a week. On October 6 the FBI gave its own explanation: the platform belonged to a contractor, and the contractor had not installed a patch that was already available.

Treat the two accounts as separate claims. The group says zero-day; the FBI says known fix, not applied. Both can be partly true if a patch existed by the time the contractor was breached, and no source reviewed settles the sequence.

Evidence

Verified against independently fetched sources:
1. SecurityWeek, FBI blames contractor's missed patch for ShinyHunters breach
2. The Hacker News, FBI removes Accenture contractor after ShinyHunters breach
3. BleepingComputer, ShinyHunters claims FBI hack and data theft in PeopleSoft zero-day breach

What this means for your team

The FBI decided to say publicly that the failure sat with a contractor. That is unusual, and it points at where accountability will increasingly land: the organization whose data it is. Regulators and boards will not accept a vendor's missed patch as a full answer.

The practical gap is evidence. Most contracts promise timely patching, but few ask the vendor to prove it for the specific systems that hold your data. If your HR, recruiting or payroll platform is run by a managed provider, ask when the last critical patch landed and how you would know.

Action checklist
  1. List every platform that holds employee or applicant data and is managed by a third party, including PeopleSoft and similar HR systems, and record who patches each one.
  2. Request patch-level evidence from each provider for critical fixes in the last 90 days, and add an agreed time limit to the contract.
  3. Confirm that web application firewall rules are not your only protection on internet-facing HR portals, since encoding tricks can bypass them.
  4. Decide in advance what you will publicly say about a vendor failure, and who approves it.

Atlassian patches a critical file-access flaw across eight self-hosted products

HIGH · PATCH NOW
Key facts
Vulnerability: CVE-2026-21589, CVSS 9.3, unauthenticated access to specific files in the web application root directory (BleepingComputer, SecurityWeek)
Affected products: Self-hosted Data Center editions of Bitbucket, Bamboo, Crowd, Crucible, Confluence, Fisheye, Jira Service Management and Jira, per SecurityWeek. Atlassian cloud services are already patched
Limits on exploitation: An attacker must already know the exact file path; directory listing is not possible. The risk rises if sensitive files such as SSO configuration sit in predictable locations (SecurityWeek)
Exploitation status: No active exploitation reported by Atlassian as of publication (BleepingComputer, SecurityWeek)
Fix: Patched versions are listed in Atlassian's advisory; check it for your product line. Where patching is delayed, the reporting points to WAF or URL-rewrite mitigations or removing internet exposure

What happened

Atlassian published fixes for a flaw that lets an unauthenticated user read files inside the web root of its self-hosted collaboration and development tools. The company said it knows of no exploitation. Researchers at watchTowr, quoted by SecurityWeek, note that this class of bug has been used by ransomware groups and state-backed actors in the past.

Evidence

Verified against independently fetched sources:
1. BleepingComputer, Atlassian warns of critical file-access flaw in Jira, Confluence
2. SecurityWeek, Atlassian patches critical vulnerability affecting 8 products
3. The Hacker News, Critical Atlassian flaw lets attackers access files

What this means for your team

The path-knowledge requirement lowers the immediate urgency but not the end result. Atlassian tools often hold credentials, tokens and build secrets, and attackers who guess common file locations tend to find them. Once a patch is public, researchers can reverse it into a working exploit within days, so the unexploited period is short.

Action checklist
  1. Identify every self-hosted Atlassian instance, including forgotten Bamboo, Crowd and Fisheye servers, and record its version and whether it faces the internet.
  2. Apply the vendor patch to internet-facing instances first; if you cannot, add the vendor-suggested WAF or rewrite rule and restrict access to your network.
  3. Review web server logs for requests to unusual static file paths in the last 30 days and rotate any secrets stored in the web root.
  4. Move SSO and integration secrets out of predictable file locations.

ASOS app notifications hijacked; attackers claim a Snowflake compromise

NOTABLE · CLAIMS UNCONFIRMED
Key facts
What happened: On October 6, unauthorized push notifications were sent through the ASOS mobile app, pointing users to a Telegram channel run by a group calling itself Xuanye Group (BleepingComputer, Hackread)
ASOS confirmed: Unauthorized activity involving third-party communication platforms, and that basic personal information such as names and contact details may have been accessed. ASOS said payment card details and account passwords were not affected
Attacker claims, unverified: The group says it fully compromised ASOS's Snowflake environment and holds customer data. It published no evidence, and ASOS has not confirmed the Snowflake claim or a customer count (BleepingComputer)
Other reported detail: Hackread reports Snowflake found no evidence its own platform was breached, the UK NCSC is assisting, and ASOS shares fell about 10%. These points come from one source

What happened

Customers received push notifications that ASOS did not send. The messages claimed a data theft and invited readers to a Telegram channel. ASOS warned customers in the app to ignore the alerts and said the access involved third-party communication tooling rather than payment data.

Evidence

Verified against independently fetched sources:
1. BleepingComputer, ASOS confirms data breach after hacked in-app notifications
2. Hackread, ASOS hackers hijack app notifications, claim Snowflake data breach

What this means for your team

Marketing and engagement platforms sit outside many security programs, yet they can speak directly to your customers with your brand. An attacker with that access does not need to steal much to cause damage; the message itself is the incident. Separate what was confirmed from what was claimed in your own communications, as ASOS did.

Action checklist
  1. Inventory third-party tools that can send push, email or SMS under your brand, and enforce multi-factor authentication and API key rotation on each.
  2. Add approval or rate limits to bulk customer messaging, and alert on sends outside the normal schedule.
  3. Prepare a holding statement for an unauthorized customer message that states what is confirmed and what is a claim.
  4. If you use Snowflake, check that every account enforces multi-factor authentication and review recent access from unfamiliar locations.

Also notable

  • Ninja Forms and WPC Product Bundles: attackers are exploiting stored cross-site scripting flaws (CVE-2026-94504 in Ninja Forms 3.15.3 and earlier, CVE-2026-93836 in WPC Product Bundles) to create hidden administrator accounts on WordPress sites. Fixes are Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7. Patching does not remove existing infections. Single source: BleepingComputer.
  • MALFEX npm campaign: SecurityWeek reports eight malicious packages published since August 2023 that have accumulated about 40,000 downloads. Single source: SecurityWeek.
  • Microsoft Exchange: CVE-2026-96940 (CVSS 8.8) lets an authenticated attacker read other users' mailboxes, per The Hacker News headline summary. Details were not reviewed in full. Single source: The Hacker News.
  • Yesterday's edition: the Danish population register breach, Korean bank intrusions and the Rejetto HFS exploit are covered in the October 5 briefing.

Frequently asked questions

How many people were affected by the Arizona court system breach?
About 1.3 million people with unpaid court fees and fines, according to SecurityWeek and Fox10 Phoenix. Separately, nearly 30,000 protection orders and more than 150,000 foster care review reports were reported as copied.

How did the attackers get into the Arizona courts?
Reporting says a court employee clicked a malicious link in a phishing email. Malwarebytes reports the attackers then copied backup files. No group has claimed responsibility.

Who did the FBI blame for the ShinyHunters breach?
The FBI said a contractor managing the platform failed to apply an available security patch, and it removed the contractor. ShinyHunters had claimed a PeopleSoft zero-day, so the two accounts differ.

Is the Atlassian flaw being exploited?
Atlassian and the reporting reviewed say no active exploitation has been observed. The flaw, CVE-2026-21589, is rated CVSS 9.3 and affects self-hosted Data Center products; cloud services are already patched.

Did ASOS confirm a Snowflake breach?
No. ASOS confirmed unauthorized activity involving third-party communication platforms and possible exposure of names and contact details. The Snowflake claim comes from the attackers and is unverified.

What should a CISO do first this week?
Locate self-hosted Atlassian instances and patch them, ask managed-platform vendors for patch evidence, and review who can reach your backups and archives.

CISO Platform Breach Intelligence Team
Curated by Pritha Aash, Community Head, CISO Platform

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

★
★
★
★
★
Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion