Over One Million Law Firm Passwords Appear on the Dark Web

Over One Million Law Firm Passwords Appear on the Dark Web

New research has found that over one million passwords linked to UK law firms have been found circulating on the dark web.

Researchers from Atlas Cloud, a company that provides IT services to the recruitment and legal sector, has published research showing that nearly three-quarters of UK law firms have employee username and password combinations in lists in the darkest places on the internet.

They found that of the 5140 firms audited, 72.2% had at least one instance present on these lists. A total of 1,001,313 passwords relating to UK firms were found in the study.

Atlas Cloud have warned that cybercriminals who use this side of the internet could use the information to access a firm’s IT systems, and therefore access to valuable data or transactions.

The UK-based based company compiled these findings while auditing firms for breached passwords, protection against phishing and email hijack protection. They also assessed firms’ alignment with the UK Government’s Cyber Essentials programme.

The study identified further cyber threats, finding that DMARC – a security measure in preventing domain hijacking – has been implemented by less than half of UK firms. Atlas Cloud have warned that if a domain is hacked, it allows hackers to send emails that appear to be from the domain, therefore creating an opportunity for exploitation.

CEO of Atlas Cloud, Pete Watson stated:

“The sheer volume of password combinations available to criminals is a stark reminder of the threat that cyber poses to a firm.

“You can minimise this risk by applying multi-factor authentication on your systems, which adds an additional one-time authentication token, but criminals have been known to find ways around this too.”

You might also like

man working from home office
read more
The Challenges of Hybrid Working: Maintaining Data Security More

COVID-19 created unprecedented operational and security challenges for businesses globally across multiple sectors...

Data Privacy Week: Dealing with Data Breaches and SARs
read more
Data Privacy Week: Dealing with Data Breaches and SARs More

With Data Privacy Week spanning from 24th – 28th January, Briefed want to join the international effort to create awareness about data privacy and the pitfalls affecting the legal industry...

What Is a Compliance Framework? Blog
read more
What Is a Compliance Framework? More

A compliance framework is a system of requirements and procedures that an organisation needs...