|
11:26 Thu 10.09.26 |
What should an advocate do after discovering a «bugging device»? |
|
From a professional standpoint, the discovery of a device that may be covertly collecting information raises a number of practical questions: how to document the find, whom to notify of the incident and how to prevent further disclosure of attorney-client privilege. Specialized and household devices The actions of advocates and the specifics of technical inspections of premises were discussed during the roundtable «Attorney-client privilege under threat: covert information gathering and technical protection». The event took place on September 8 at the initiative of the UNBA Committee on cybersecurity and virtual assets. It was moderated by the Committee chairman Andriy Galych and his deputy Roman Ostrovsky. As A. Galych explained, devices for obtaining information can be installed in premises and vehicles, either with or without physical access. Some devices transmit data in real time, while others store it and send it to a server only periodically. The Committee chairman cited an example where, during an inspection at a Kyiv law firm, specialists discovered approximately nine such devices. Cameras equipped with microphones were disguised as fire detectors and placed in offices. Committee expert Andriy Suprunenko noted that not only specially manufactured devices but also ordinary household or communications equipment can be used to covertly obtain information. Devices can be embedded in interior fixtures, electronics, power supplies or cables, while cameras can be concealed in small openings or parts of household items. How to document it During the discussion, participants noted that a suspicious device cannot always be immediately classified as a special technical device for covert information gathering. Committee expert Roman Molchenko explained that SSU experts can determine whether a device falls into this category. According to him, current regulations do not provide detailed answers to all questions that arise when such devices are discovered in private life or business. Deputy chairman of the Committee on the protection of advocates’ rights and guarantees of legal practice at the UNBA Oleksandr Levadny suggested first and foremost documenting the very fact of possible illegal access to information. To this end, he advised using permissible methods, such as photography, video recording and screenshots, as well as involving individuals who can later confirm the circumstances surrounding the discovery of the device or the data leak. The next step, according to O. Levadny, should be to notify law enforcement agencies and the regional bar association. He also suggested involving a representative of the bar association in procedural actions related to the seizure of equipment and ensuring their participation during the subsequent examination of devices that may contain attorney-client privilege. The advocate drew attention to the procedural formalities for seizing a mobile phone or computer equipment. According to him, the seizure must take place within the framework of the relevant procedural action and be recorded in a protocol. If the equipment was seized without proper documentation, the advocate should challenge such actions, notify the bar association, and raise questions regarding the admissibility of the evidence obtained. At the same time, O. Levadny advises advocates not to provide law enforcement with passwords to devices containing client information. Instead, he suggested participating in a properly documented examination of the equipment as physical evidence. Voluntarily granting access to attorney-client privilege may violate the duty to maintain it and could result in disciplinary consequences. During the discussion, participants did not reach a consensus on the form of the initial documentation of the discovery. A proposal was made to draw up an inspection report with the involvement of a technical specialist. It was also suggested to prepare an official record, since the requirements for a procedural report and the circle of persons authorized to draw it up are defined by the Code of Criminal Procedure. At the same time, participants agreed that the circumstances of the discovery must be documented using available means, with the persons present noted. Searching for a radio signal is not enough R. Molchenko pointed out that a professional inspection of the premises is not limited to searching for active radio transmitters. Devices can store information and transmit it on a schedule or upon receiving a specific command, so they may not be emitting a signal during the inspection. To locate them, specialists combine radio monitoring, analysis of power consumption and heat signature, optical inspection, examination of cable networks, and a physical inspection of potential installation sites. If the technical inspection fails to detect a device, a specialist’s inspection of the premises or vehicle may yield results. Inspecting an office measuring 25–30 square meters can take about two hours, while inspecting a single vehicle can take four to six hours. This duration is due to the need to systematically apply various methods rather than relying on a single measurement. For regular monitoring prior to confidential meetings, simple tools can be used to alert you to the presence of a new radio transmitter in the room. However, such an alert merely indicates a potential threat and does not replace a professional inspection. R. Molchenko also advised against informing a wide circle of employees about planned search operations. According to him, in cases investigated by specialists, the installation of a device often occurred with the involvement of a person who had access to the company or could provide information about the premises and equipment. Therefore, keeping the inspection under wraps allows for the device to be removed before the search team arrives. When selecting contractors for the inspection, the expert suggested finding out what methods they use and what equipment they employ. If you lack technical expertise, you can submit the relevant list to relevant specialists or the professional community for evaluation. Spyware Means of covertly obtaining information do not necessarily take the form of a separate physical device. Committee expert Vladislav Plekhanov explained that malicious software can run on a computer, smartphone, TV, in-car system, or other connected devices. It can access files, passwords, the camera, microphone, screen and keystrokes. A malicious link or file can also come from someone you know if their account has been compromised. Other sources of infection include emails, messages in instant messengers, documents, advertisements or fake apps. To mitigate these risks, V. Plekhanov advised verifying the sources of applications, website addresses, digital signatures, and suspicious files, and using an isolated environment (a so-called “sandbox”) or a separate device when working with them. He also recommended keeping personal and professional activities separate and not using a single device for all tasks. During the event, participants were shown radio monitoring equipment, as well as thermal imaging and optical inspection tools. A separate demonstration illustrated how to detect a hidden camera by observing the reflection of light from its lens. At the end of the roundtable, the organizers announced that the Committee is working on guidelines for responding to hidden devices and cyber threats. Representatives from the State Special Communications Service and the Security Service of Ukraine are planned to be invited for further discussion on the procedure for action after a device is detected. |
|
|
© 2026 Unba.org.ua Всі права захищені |
|