Federal Public Defender for the District of Arizona
Incident posture
Linked entities
- Victim
- Federal Public Defender for the District of Arizona
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A ransomware attack on the Arizona Federal Public Defender’s Office resulted in significant operational disruption, delaying the mental competency proceedings for a death row inmate. The incident caused a loss of access to critical case files, including a nearly complete 25-page draft reply brief that had to be rebuilt from scratch. In response, the office shut down its systems and restricted employees from using personal laptops due to security concerns, while the IT team assessed the extent of the damage and potential data recovery. To mitigate the impact, the State offered to provide discovery files and exhibits from its own records to assist the defense. A district judge granted an extension for filing the brief and rescheduled the related court arguments to a later date, allowing additional time for the defense to recover and prepare its materials.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
A ransomware attack targeted the Arizona Federal Public Defender's Office, disrupting operations and causing the loss of digital case files. The incident had immediate consequences for active legal proceedings, most notably delaying progress in the death penalty case of Ralph Menzies, who has been on Utah's death row for nearly four decades following his 1986 conviction for the kidnapping and murder of Maurine Hunsaker, a mother and phone company employee. The cyberattack effectively halted the defense team's ability to access critical case materials and continue their work on a pending reply brief addressing Menzies' mental competency for execution.
In response to the breach, the office was forced to shut down its systems entirely and prohibited employees from using personal laptops to continue working, citing security concerns. This containment measure, while necessary to prevent further compromise, significantly hampered the defense team's capacity to prepare legal filings. The office reported losing a nearly complete 25-page draft of the reply brief they had been preparing to file on Menzies' behalf, representing substantial lost work product. Defense attorneys filed a motion asking the court for additional time to rebuild the document and complete their response to the State's arguments regarding Menzies' fitness for execution, which centers on whether he understands what is happening to him and why. The IT team continued assessing the damage, and at the time of reporting, it remained unclear whether any of the lost data could be recovered or how long it would take to regain system access.
The impact of the attack extended beyond the immediate loss of files and system access, affecting the broader judicial timeline in the Menzies case. The court granted the defense team's request for an extension, allowing them to file the brief by April 18. District Judge Matthew Bates approved this extension on Tuesday, and the State did not object to the delay. To assist the defense team in reconstructing their work, the State offered to provide discovery files and exhibits from its own records, demonstrating interagency cooperation despite the opposing parties' positions in the case. The cyberattack forced the rescheduling of arguments that had originally been set for April 18; these were moved to May 7 at 2 p.m. and will be held in person, ensuring the case could proceed once the defense had adequate time to recover and rebuild their legal arguments in light of the disruption caused by the ransomware incident.
Sources
Sources available to members: 1 source.