|
11:24 Wed 05.08.26 |
Legal privilege is under threat: why compromising a work device is dangerous |
|
If a work computer is infected with an infostealer, it could grant unauthorized parties access to an advocate’s email, legal information systems, government services, bank accounts, cloud storage, messaging apps, and artificial intelligence services including the client information stored therein. Digital risks were discussed during the webinar «Information security for advocates: how to prevent the leakage of legal privilege», organized by the UNBA NextGen in Kyiv. The speaker was cybersecurity expert Dmytro Ashkinazi. An infostealer is malware that collects data from an infected device and transmits it to the Darknet. It can take as little as a few hours from infection to the appearance of the stolen information there. The archive of stolen data may include saved passwords, bank card and crypto wallet details, messenger settings, a list of installed programs, files from the desktop, and even the contents of the clipboard. Cookies data from an active session that keep a user logged in to a website pose a particular danger. Stealing them can allow an attacker to impersonate the user’s browser and bypass two-factor authentication. The speaker demonstrated data from an infected computer belonging to a law firm. It contained saved login credentials for more than two hundred websites, including the personal account on the UNBA website, bank accounts, and government agency sites, as well as over 4,000 files. He also highlighted the possibility of accessing artificial intelligence services, where users upload their own data and client information via a hijacked session. One method of infection is downloading a program from a fake advertisement. Another method involves a fake CAPTCHA that prompts the user to press Windows + R, followed by Ctrl + V: in this way, the user themselves executes the prepared code, which steals data from the browser. A fake message may also appear on the website stating that Windows needs to be updated. D. Ashkinazi warned that a website cannot perform an operating system update and an «I’m not a robot» verification should not require executing commands on the computer. Such instructions should not be followed. If information has already been leaked to the Darknet, it is impossible to remove it from there. In such a case, the speaker advised changing all compromised passwords as soon as possible, deactivating connected devices, and ending active sessions in accounts. If hundreds of passwords have been stolen, it is necessary to prioritize which ones to change first and determine the sequence of further actions. According to the expert, it can take anywhere from a few hours to several months between the time of a leak and the use of the information. Therefore, he described monitoring the Darknet as the last line of defense, which makes it possible to detect a breach and respond before the stolen data is used in an attack. |
|
|
© 2026 Unba.org.ua Всі права захищені |
|