Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

2 U.S. Law Firms Among Cybercrime Victims

By Patrick Smith
June 01, 2019

The U.S. Department of Justice (DOJ) said last month that two U.S.-based law firms were among the victims of a “complex transnational organized cyber-crime network” that has been taken down, thanks to a law enforcement effort involving cooperation between U.S. and European officials.

The DOJ's statement did not specify the names of the entities, only that one was a law firm in Washington, DC, and another was a law office in Wellesley, MA.

The hackers were using the GozNym malware, which is designed to capture online banking login credentials. The hackers then gain access to bank accounts and steal money from victims by laundering those funds through U.S. and foreign beneficiary bank accounts controlled by the hackers. All in all, the group was hoping to make out with more than $100 million, the DOJ said.

This isn't the first time that law firms have been the targets of cyberattacks — and it likely won't be the last. The American Lawyer reported in January that an unnamed U.S. firm had been hacked by the Chinese government-sponsored group called APT10 between November 2017 and September 2018.

|

Six Months to Discover; Two Months to Contain

A study conducted by IBM in 2018 found that it takes about six months to discover that a breach has occurred, and then an average of 69 days to contain the breach. Law firms, because of the sensitive information they possess regarding their various clients, are a very attractive target for those looking to obtain data to sell or expose. By hacking one system, attackers can get information on potentially hundreds of companies and individuals.

According to the indictment, Alexander Konovolov, aka “NoNe” and “none_1,” of Tbilisi, Georgia, was the organizer and leader of the GozNym network that controlled about 41,000 victim computers infected with the malware.

U.S. Attorney Scott W. Brady of the Western District of Pennsylvania made the announcement of the indictments at Europol in The Hague, Netherlands.

“International law enforcement has recognized that the only way to truly disrupt and defeat transnational, anonymized networks is to do so in partnership,” Brady said. “The collaborative and simultaneous prosecution of the members of the GozNym criminal conspiracy in four countries represents a paradigm shift in how we investigate and prosecute cybercrime. Cybercrime victimizes people all over the world. This prosecution represents an international cooperative effort to bring cybercriminals to justice.”

The defendants reside in Russia, Georgia, Ukraine, Moldova and Bulgaria. Without the hope of extradition to the United States, five of the hackers who reside in Russia remain at large.

The case is being prosecuted by Assistant U.S. Attorney Charles A. “Tod” Eberle, the chief of national security and cybercrime for the Western District of Pennsylvania.

*****

Patrick Smith, based in New York, covers the business of law, including the ways law firms compete for clients and talent, cannabis law and marketing innovation for ALM. He can be reached at [email protected] or on Twitter at @nycpatrickd.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
How Secure Is the AI System Your Law Firm Is Using? Image

In a profession where confidentiality is paramount, failing to address AI security concerns could have disastrous consequences. It is vital that law firms and those in related industries ask the right questions about AI security to protect their clients and their reputation.

COVID-19 and Lease Negotiations: Early Termination Provisions Image

During the COVID-19 pandemic, some tenants were able to negotiate termination agreements with their landlords. But even though a landlord may agree to terminate a lease to regain control of a defaulting tenant's space without costly and lengthy litigation, typically a defaulting tenant that otherwise has no contractual right to terminate its lease will be in a much weaker bargaining position with respect to the conditions for termination.

Pleading Importation: ITC Decisions Highlight Need for Adequate Evidentiary Support Image

The International Trade Commission is empowered to block the importation into the United States of products that infringe U.S. intellectual property rights, In the past, the ITC generally instituted investigations without questioning the importation allegations in the complaint, however in several recent cases, the ITC declined to institute an investigation as to certain proposed respondents due to inadequate pleading of importation.

The Power of Your Inner Circle: Turning Friends and Social Contacts Into Business Allies Image

Practical strategies to explore doing business with friends and social contacts in a way that respects relationships and maximizes opportunities.

Authentic Communications Today Increase Success for Value-Driven Clients Image

As the relationship between in-house and outside counsel continues to evolve, lawyers must continue to foster a client-first mindset, offer business-focused solutions, and embrace technology that helps deliver work faster and more efficiently.