Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Ransomware Attack on DLA Piper Puts Law Firms, Clients on Red Alert

By Roy Strom
July 02, 2017

 

By now, every managing partner has heard the warning: Law firms and their clients' sensitive information are a treasure trove for hackers.

But the ransomware attack on June 27 on DLA Piper sounded a different type of alarm for Big Law. The world's biggest firms are just as prone to ransomware attacks as any other company, and the potential ramifications of a network-crippling malware infection are wide-ranging for a service industry that holds the legal fate of corporations in its palm.

Consider litigators unable to access motions on a deadline. Trial lawyers preparing for arguments without key documents. Transactional lawyers unable to communicate with clients attempting to close multibillion-dollar deals.

And of course, anxious and possibly angry clients.

“The domino effect of doing something like this to a law firm permeates so many different parts of business,” says John Sweeney, president of LogicForce, a startup cybersecurity consulting firm. “Suffice it to say, it's going to touch hundreds if not thousands of different points of business, and not only in the U.S. It's a nightmare, there's no doubt about it.”

Phone lines at DLA Piper were down on the day of the attack across Europe and the U.S. According to media reports and a photo tweeted by Politico reporter Eric Geller in Washington, DC, employees were instructed not to turn on their computers and to unplug their laptops from the network.

“All network services are down,” a whiteboard read in what appeared to be the firm's Washington lobby.

A DLA Piper spokesman confirmed the firm had been the target of a possible malware attack that had affected a large number of organizations across the globe, including pharmaceutical giant Merck & Co. Inc.

“The firm, like many other reported companies, has experienced issues with some of its systems due to suspected malware,” said DLA Piper's statement. “We are taking steps to remedy the issue as quickly as possible.”

Much like the WannaCry ransomware attack that spread throughout the globe in mid-May, the new round of attacks reportedly requests a payment of $300 in Bitcoin in order to obtain a “decryption code” that may unlock an organization's files.

While security experts were still scrambling to determine the extent of the encryption or any other damage levied by the newest batch of ransomware, at least 27 organizations appeared to have paid the ransom as of early June 27, according to a blockchain transaction record.

A study by LogicForce released on the same day as the DLA Piper attack shows the ubiquitous risk of hacking for law firms. The company surveyed more than 200 firms and found that all had been subjected to hacking attempts, while 40% of those attempts were successful. What's more, the 40% of firms who had been hacked were unaware of it, according to the report. Sweeney said DLA Piper was not included in his company's survey.

In response to being hit by ransomware, Sweeney says firms should perform a detailed investigation of their systems involving forensics professionals to determine how the ransomware attack entered their network. Part of that investigation should include attempting to mitigate any more damage that could occur.

The best-case scenario in some ransomware attacks would be having an incident response plan in place that involves an off-site server back-up that could potentially restore the systems' computers, says Robert Rosenzweig, another cybersecurity expert and national leader of the cyber practice at insurance brokerage Risk Strategies Co.

LogicForce's Sweeney commended DLA Piper for issuing a public statement about the ransomware attack, something few law firms have done or been forced to do.

“Can they circumvent whatever's been done to their systems and get back online? I don't know. That would be the best option,” Sweeney says.

One bit of fallout from the attack may be a renewed interest from law firms in purchasing cybersecurity insurance. The LogicForce survey states that 23% of firms polled had cybersecurity insurance policies. Those policies will pay for direct expenses associated with a hack, such as the cost of the ransom; hiring forensic investigators; and bringing on a legal team to advise the firm of its potential risk.

For damage done to clients as a result of a firm losing its ability to service them or their confidential data getting into the wrong hands, it is possible a firm would have coverage under a more traditional legal malpractice insurance policy, Rosenzweig says. He says a “business interruption” component in a cybersecurity policy may also provide some relief, but added that a loss of a law firm's ability to service its clients due to a cyber breach could have long-tailed repercussions.

“The risk and the potential for a complex and expensive loss is a lot more significant,” Rosenzweig says.

The increased risk of ransomware attacks may also cause more law firm clients to perform cybersecurity audits as part of their hiring process, says LogicForce's Sweeney. His firm's report states that 34% of firms reported undergoing a cyber audit from a client, and LogicForce expects that number to grow to 65% by 2018.

“More and more clients are demanding these audits,” Sweeney says. “And quite frankly we're seeing some law firms losing business because they can't comply with the audit.”

*****
Roy Strom
, based in Chicago, covers the business of law for ALM, with a focus on how the Big Law business model is changing. He can be reached at [email protected]. On Twitter: @RoyWStrom.

 

 

By now, every managing partner has heard the warning: Law firms and their clients' sensitive information are a treasure trove for hackers.

But the ransomware attack on June 27 on DLA Piper sounded a different type of alarm for Big Law. The world's biggest firms are just as prone to ransomware attacks as any other company, and the potential ramifications of a network-crippling malware infection are wide-ranging for a service industry that holds the legal fate of corporations in its palm.

Consider litigators unable to access motions on a deadline. Trial lawyers preparing for arguments without key documents. Transactional lawyers unable to communicate with clients attempting to close multibillion-dollar deals.

And of course, anxious and possibly angry clients.

“The domino effect of doing something like this to a law firm permeates so many different parts of business,” says John Sweeney, president of LogicForce, a startup cybersecurity consulting firm. “Suffice it to say, it's going to touch hundreds if not thousands of different points of business, and not only in the U.S. It's a nightmare, there's no doubt about it.”

Phone lines at DLA Piper were down on the day of the attack across Europe and the U.S. According to media reports and a photo tweeted by Politico reporter Eric Geller in Washington, DC, employees were instructed not to turn on their computers and to unplug their laptops from the network.

“All network services are down,” a whiteboard read in what appeared to be the firm's Washington lobby.

A DLA Piper spokesman confirmed the firm had been the target of a possible malware attack that had affected a large number of organizations across the globe, including pharmaceutical giant Merck & Co. Inc.

“The firm, like many other reported companies, has experienced issues with some of its systems due to suspected malware,” said DLA Piper's statement. “We are taking steps to remedy the issue as quickly as possible.”

Much like the WannaCry ransomware attack that spread throughout the globe in mid-May, the new round of attacks reportedly requests a payment of $300 in Bitcoin in order to obtain a “decryption code” that may unlock an organization's files.

While security experts were still scrambling to determine the extent of the encryption or any other damage levied by the newest batch of ransomware, at least 27 organizations appeared to have paid the ransom as of early June 27, according to a blockchain transaction record.

A study by LogicForce released on the same day as the DLA Piper attack shows the ubiquitous risk of hacking for law firms. The company surveyed more than 200 firms and found that all had been subjected to hacking attempts, while 40% of those attempts were successful. What's more, the 40% of firms who had been hacked were unaware of it, according to the report. Sweeney said DLA Piper was not included in his company's survey.

In response to being hit by ransomware, Sweeney says firms should perform a detailed investigation of their systems involving forensics professionals to determine how the ransomware attack entered their network. Part of that investigation should include attempting to mitigate any more damage that could occur.

The best-case scenario in some ransomware attacks would be having an incident response plan in place that involves an off-site server back-up that could potentially restore the systems' computers, says Robert Rosenzweig, another cybersecurity expert and national leader of the cyber practice at insurance brokerage Risk Strategies Co.

LogicForce's Sweeney commended DLA Piper for issuing a public statement about the ransomware attack, something few law firms have done or been forced to do.

“Can they circumvent whatever's been done to their systems and get back online? I don't know. That would be the best option,” Sweeney says.

One bit of fallout from the attack may be a renewed interest from law firms in purchasing cybersecurity insurance. The LogicForce survey states that 23% of firms polled had cybersecurity insurance policies. Those policies will pay for direct expenses associated with a hack, such as the cost of the ransom; hiring forensic investigators; and bringing on a legal team to advise the firm of its potential risk.

For damage done to clients as a result of a firm losing its ability to service them or their confidential data getting into the wrong hands, it is possible a firm would have coverage under a more traditional legal malpractice insurance policy, Rosenzweig says. He says a “business interruption” component in a cybersecurity policy may also provide some relief, but added that a loss of a law firm's ability to service its clients due to a cyber breach could have long-tailed repercussions.

“The risk and the potential for a complex and expensive loss is a lot more significant,” Rosenzweig says.

The increased risk of ransomware attacks may also cause more law firm clients to perform cybersecurity audits as part of their hiring process, says LogicForce's Sweeney. His firm's report states that 34% of firms reported undergoing a cyber audit from a client, and LogicForce expects that number to grow to 65% by 2018.

“More and more clients are demanding these audits,” Sweeney says. “And quite frankly we're seeing some law firms losing business because they can't comply with the audit.”

*****
Roy Strom
, based in Chicago, covers the business of law for ALM, with a focus on how the Big Law business model is changing. He can be reached at [email protected]. On Twitter: @RoyWStrom.

 

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
Overview of Regulatory Guidance Governing the Use of AI Systems In the Workplace Image

Businesses have long embraced the use of computer technology in the workplace as a means of improving efficiency and productivity of their operations. In recent years, businesses have incorporated artificial intelligence and other automated and algorithmic technologies into their computer systems. This article provides an overview of the federal regulatory guidance and the state and local rules in place so far and suggests ways in which employers may wish to address these developments with policies and practices to reduce legal risk.

Is Google Search Dead? How AI Is Reshaping Search and SEO Image

This two-part article dives into the massive shifts AI is bringing to Google Search and SEO and why traditional searches are no longer part of the solution for marketers. It’s not theoretical, it’s happening, and firms that adapt will come out ahead.

While Federal Legislation Flounders, State Privacy Laws for Children and Teens Gain Momentum Image

For decades, the Children’s Online Privacy Protection Act has been the only law to expressly address privacy for minors’ information other than student data. In the absence of more robust federal requirements, states are stepping in to regulate not only the processing of all minors’ data, but also online platforms used by teens and children.

Revolutionizing Workplace Design: A Perspective from Gray Reed Image

In an era where the workplace is constantly evolving, law firms face unique challenges and opportunities in facilities management, real estate, and design. Across the industry, firms are reevaluating their office spaces to adapt to hybrid work models, prioritize collaboration, and enhance employee experience. Trends such as flexible seating, technology-driven planning, and the creation of multifunctional spaces are shaping the future of law firm offices.

From DeepSeek to Distillation: Protecting IP In An AI World Image

Protection against unauthorized model distillation is an emerging issue within the longstanding theme of safeguarding intellectual property. This article examines the legal protections available under the current legal framework and explore why patents may serve as a crucial safeguard against unauthorized distillation.