Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Peer-to-Peer May Share Some Nightmares

By Tresa Baldas
November 25, 2008

Unknown to corporate America, the popular peer-to-peer file-sharing networks that allow music and movies to be shared could be sharing something else with the public: company secrets and personal data.

Management-side lawyers are sounding alarms to their corporate clients, warning that peer-to-peer (“P2P”) networks are increasingly becoming a gateway for trade secrets, confidential financial information and personal data.

Many of these security risks, they note, have already materialized.

In Washington, the Walter Reed Army Medical Center is investigating the possible disclosure of the personal information of roughly 1,000 military health beneficiaries, whose data may have been leaked through unauthorized sharing on a P2P network.

In 2007, Citigroup Inc.'s ABN Amro Mortgage Group reported that the personal information, including Social Security numbers, of more than 5,000 customers was leaked when a business analyst signed up to use a P2P file-sharing service on a home computer containing the personal information.

Also in 2007, Pfizer Inc. was hit with a P2P problem, whereby the names and Social Security numbers of 17,000 current and past employees were leaked after the partner of an employee downloaded file-sharing software onto a company laptop.

P2P file-sharing technology, which emerged in 1999 with the online music file-sharing service Napster, is used by millions to share electronic files with one another. Computer users, known as “peers,” can share communications and data files that contain a number of things, such as vacation photos, literary works, music or movies. Among the risks, however, is inadvertent file sharing, which happens when computer users mistakenly share more files than they intended.

Opening a Window

“It's like opening a window in downtown Manhattan and watching all of the documents fly out,” Jackson Lewis partner Joseph Lazzarotti says of inadvertent P2P disclosure. “And it's not just personal information. Company secrets get out, minutes of board meetings and proprietary information ' that's all just running around on these networks that are created by P2P software. That's what's going on.”

Unfortunately, says Lazzarotti, many companies are still unaware of the risks “because people don't really realize how many times this has happened.”

David Bateman, a partner in the Seattle office of K&L Gates, agrees that P2P file sharing is a growing problem for companies. He says he has dozens of clients who are “actually concerned about it and taking proactive steps to limit the risk.”

Bateman says a nightmare situation would be employees taking work home with them on a laptop or copying sensitive company data onto their home computer. Then they or their teenager goes onto the laptop or home computer and sets up a P2P account and “shares all that data with the world.”

Corporations Respond

But corporate America is aware of the threat, Bateman believes, and starting to respond to it: “I am seeing more and more companies coming to learn of the risk and then consult with me.”

Maybe so, but corporate counsel are being very tight-lipped about P2P concerns. More than a dozen corporate counsel at major companies were contacted for this story, but none would comment. Private attorneys also asked clients if their general counsel would speak, but none would do so.

The Association of Corporate Counsel had no comment on the subject.

Rodney Satterwhite, a partner at Richmond, VA-based McGuireWoods, says P2P file sharing is part of a bigger problem for employers: trying to keep up with technological advancements. New technologies are continually cropping up, he says, and workplace policies can't keep up.

“There's always a new frontier of technology that employees get first,” Satterwhite says, noting that P2P file sharing is the latest headache for employers.

Joan Canny, a management-side attorney in the Miami office of Morgan, Lewis & Bockius, agrees, saying P2P technology is just one more technological headache for employers: “If people embrace a new tool before we've had time to allow our security systems to catch up, we're going to have some of these problems.”


Tresa Baldas writes for the National Law Journal, an Incisive Media affiliate of Internet Law & Strategy.

Unknown to corporate America, the popular peer-to-peer file-sharing networks that allow music and movies to be shared could be sharing something else with the public: company secrets and personal data.

Management-side lawyers are sounding alarms to their corporate clients, warning that peer-to-peer (“P2P”) networks are increasingly becoming a gateway for trade secrets, confidential financial information and personal data.

Many of these security risks, they note, have already materialized.

In Washington, the Walter Reed Army Medical Center is investigating the possible disclosure of the personal information of roughly 1,000 military health beneficiaries, whose data may have been leaked through unauthorized sharing on a P2P network.

In 2007, Citigroup Inc.'s ABN Amro Mortgage Group reported that the personal information, including Social Security numbers, of more than 5,000 customers was leaked when a business analyst signed up to use a P2P file-sharing service on a home computer containing the personal information.

Also in 2007, Pfizer Inc. was hit with a P2P problem, whereby the names and Social Security numbers of 17,000 current and past employees were leaked after the partner of an employee downloaded file-sharing software onto a company laptop.

P2P file-sharing technology, which emerged in 1999 with the online music file-sharing service Napster, is used by millions to share electronic files with one another. Computer users, known as “peers,” can share communications and data files that contain a number of things, such as vacation photos, literary works, music or movies. Among the risks, however, is inadvertent file sharing, which happens when computer users mistakenly share more files than they intended.

Opening a Window

“It's like opening a window in downtown Manhattan and watching all of the documents fly out,” Jackson Lewis partner Joseph Lazzarotti says of inadvertent P2P disclosure. “And it's not just personal information. Company secrets get out, minutes of board meetings and proprietary information ' that's all just running around on these networks that are created by P2P software. That's what's going on.”

Unfortunately, says Lazzarotti, many companies are still unaware of the risks “because people don't really realize how many times this has happened.”

David Bateman, a partner in the Seattle office of K&L Gates, agrees that P2P file sharing is a growing problem for companies. He says he has dozens of clients who are “actually concerned about it and taking proactive steps to limit the risk.”

Bateman says a nightmare situation would be employees taking work home with them on a laptop or copying sensitive company data onto their home computer. Then they or their teenager goes onto the laptop or home computer and sets up a P2P account and “shares all that data with the world.”

Corporations Respond

But corporate America is aware of the threat, Bateman believes, and starting to respond to it: “I am seeing more and more companies coming to learn of the risk and then consult with me.”

Maybe so, but corporate counsel are being very tight-lipped about P2P concerns. More than a dozen corporate counsel at major companies were contacted for this story, but none would comment. Private attorneys also asked clients if their general counsel would speak, but none would do so.

The Association of Corporate Counsel had no comment on the subject.

Rodney Satterwhite, a partner at Richmond, VA-based McGuireWoods, says P2P file sharing is part of a bigger problem for employers: trying to keep up with technological advancements. New technologies are continually cropping up, he says, and workplace policies can't keep up.

“There's always a new frontier of technology that employees get first,” Satterwhite says, noting that P2P file sharing is the latest headache for employers.

Joan Canny, a management-side attorney in the Miami office of Morgan, Lewis & Bockius, agrees, saying P2P technology is just one more technological headache for employers: “If people embrace a new tool before we've had time to allow our security systems to catch up, we're going to have some of these problems.”


Tresa Baldas writes for the National Law Journal, an Incisive Media affiliate of Internet Law & Strategy.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
COVID-19 and Lease Negotiations: Early Termination Provisions Image

During the COVID-19 pandemic, some tenants were able to negotiate termination agreements with their landlords. But even though a landlord may agree to terminate a lease to regain control of a defaulting tenant's space without costly and lengthy litigation, typically a defaulting tenant that otherwise has no contractual right to terminate its lease will be in a much weaker bargaining position with respect to the conditions for termination.

How Secure Is the AI System Your Law Firm Is Using? Image

What Law Firms Need to Know Before Trusting AI Systems with Confidential Information In a profession where confidentiality is paramount, failing to address AI security concerns could have disastrous consequences. It is vital that law firms and those in related industries ask the right questions about AI security to protect their clients and their reputation.

Authentic Communications Today Increase Success for Value-Driven Clients Image

As the relationship between in-house and outside counsel continues to evolve, lawyers must continue to foster a client-first mindset, offer business-focused solutions, and embrace technology that helps deliver work faster and more efficiently.

Pleading Importation: ITC Decisions Highlight Need for Adequate Evidentiary Support Image

The International Trade Commission is empowered to block the importation into the United States of products that infringe U.S. intellectual property rights, In the past, the ITC generally instituted investigations without questioning the importation allegations in the complaint, however in several recent cases, the ITC declined to institute an investigation as to certain proposed respondents due to inadequate pleading of importation.

The Power of Your Inner Circle: Turning Friends and Social Contacts Into Business Allies Image

Practical strategies to explore doing business with friends and social contacts in a way that respects relationships and maximizes opportunities.