On June 23, 2011, the hacktivist group LulzSec released about 700 confidential files from Arizona Department of Public Safety servers, including intelligence bulletins, phone numbers, and home addresses of officers. A follow-on release on June 29, published under the AntiSec banner by a LulzSec offshoot, added passwords, Social Security numbers, online dating accounts, voicemails, and chat logs for about a dozen officers. The attackers framed the breach as retaliation for Arizona SB 1070.
What happened
On June 23, 2011, the hacktivist group LulzSec posted an archive titled "Chinga La Migra" containing about 700 files from Arizona Department of Public Safety servers. It included intelligence bulletins, training manuals, officer emails and passwords, and the home addresses and phone numbers of named highway patrol officers.
Six days later, a follow-on release under the AntiSec banner went further. Published by a LulzSec offshoot, it exposed passwords, Social Security numbers, online dating account credentials, voicemails, and personal chat logs for about a dozen officers. Arizona DPS confirmed the breach was authentic. WIRED, NBC News, and The Guardian covered it that week.
The archive was hosted on file-sharing networks and stayed available for years.
Why LulzSec targeted Arizona DPS
LulzSec framed the breach as retaliation for Arizona SB 1070, the state's 2010 immigration enforcement law. The group ran a roughly 50-day campaign in mid-2011 that also hit Sony, the U.S. Senate website, and the CIA's public site.
The breach came through the email accounts of at least seven DPS employees who had remote access, not through the agency's servers. Arizona DPS said there was no evidence the attack reached its servers, its computer systems, or the larger state network. What went public was the material sitting in those officer email accounts.
Several people tied to LulzSec were later identified, arrested, and prosecuted for the group's hacking campaign.
Why this case matters
The Arizona DPS breach was an early, large-scale doxxing of U.S. law enforcement. Other hacktivist dumps in the years after took a similar shape: break into an agency, publish what turns up, and attach a political motive.
The comparison worth drawing is with today. In 2011, exposing officer home addresses at this scale meant breaking into a state agency's servers. That is a federal crime, and people went to prison for the LulzSec campaign.
By 2026, a similar home address is often for sale on a commercial people-search page. A data broker can legally compile it from voter rolls, property records, and other public sources, then sell access to anyone who pays. The federal computer-fraud law that applied to LulzSec does not reach a broker doing this legally.
The exposure is wider now, and reaching it costs a buyer very little.
What this means for your exposure
If you work in any sworn role, your home address may sit on broker pages right now, with no crime committed to put it there. That address points to where you and your family live. It is the modern version of the file LulzSec had to steal.
Two laws treat that exposure as removable. New Jersey's Daniel's Law lets covered public servants, including police officers, require data brokers to stop posting their home address and unpublished phone number. The federal Daniel Anderl Judicial Security and Privacy Act, known as the Lieu Act, gives federal judges a similar right against data brokers. Neither law removes a record automatically. Both work through removal requests and, when those are ignored, enforcement.
Frontline Privacy finds these broker listings, files removal requests, and keeps checking for the records to come back.
For the broader pattern and a 2026 parallel at federal scale, see /doxxing and the ICE List leak.
What reduces this risk
In 2011, exposing Arizona officers' home addresses at this scale required breaking into a state agency's servers, a federal crime that sent people to prison. By 2026, a similar home address is often available on a commercial people-search page, compiled legally from voter rolls and property records. The break-in is no longer required, and the exposure reaches more people. Removing those broker listings and re-checking when they reappear addresses the modern version of the same exposure.
Public sources
- Lulz Security Hacks Arizona Police — WIRED, 2011-06-24
- Hacker group LulzSec releases data from Arizona police — NBC News, 2011-06-24
- LulzSec releases Arizona law enforcement data — The Guardian, 2011-06-24
- Hackers Breach the Web Site of Stratfor Global Intelligence — The New York Times, 2011-06-23