Arizona · verified official-source register

Arizona Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

Arizona case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Uber Technologies, Inc.

Date
not stated in the official release
Amount
$148 million to the states; Arizona’s share: $2,738,794.47
Legal basis
Arizona data-breach and consumer-protection law

Why the action was brought

In November 2016, hackers gained access to personal information Uber maintained about its drivers, including driver’s license information pertaining to approximately 600,000 drivers nationwide. Arizona law required Uber to notify affected Arizona residents, but Uber failed to report the breach in a timely manner and waited until November 2017.

View Official Multistate Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Anthem, Inc.

Date
not stated in the official release
Amount
$39.5 million; over $280,000 to Arizona
Legal basis
HB2154; Arizona's data breach consumer protection laws

Why the action was brought

Cyber attackers infiltrated Anthem’s systems using malware installed through a phishing email and accessed its data warehouse. Anthem failed to prevent unauthorized access to names, birth dates, Social Security numbers, healthcare identification numbers, addresses, email addresses, phone numbers, and employment information affecting 78.8 million Americans, including over 400,000 Arizona residents.

View Official Multistate Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Blackbaud

Date
not stated in the official release
Amount
$49.5 million payment to states; Arizona will receive more than $1.8 million
Legal basis
state consumer protection laws, data breach notification laws, and HIPAA

Why the action was brought

Blackbaud allegedly failed to implement reasonable data security and remediate known security gaps, allowing unauthorized persons to access its network and exposing personal information of millions of consumers during a 2020 ransomware event. It allegedly delayed or failed to notify affected consumers and provided customers with incomplete or inaccurate breach information.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.