The American Bar Association observed unusual activity on its network on 17 March 2023. By 23 March its investigation had identified that an unauthorised third party acquired usernames and hashed, salted passwords used on the ABA’s old website prior to 2018 and on its Career Center since 2018.
Reporting places the affected population at 1,466,000 members and the initial access at a decommissioned server around 6 March 2023. It was not a ransomware incident, and no other personal data was reported taken.
The Server Was Retired And Still Reachable
A decommissioned system is one nobody is responsible for. It receives no patches because it is not in the estate, generates no alerts because nobody monitors it, and is discovered by an attacker for the same reason it was forgotten — it is still answering.
The corpus files the same shape at 26-0613 for a legacy patient archive and 26-0616 for a brand outliving the company that manages its data. Decommissioning is an intention; switching something off is an action, and the two are frequently not the same event.
Hashing Is Not The End Of The Question
The credentials were hashed and salted, which is the correct handling and materially reduces the harm. The residual risk the ABA itself identified is reuse: a member who used the same password on the current membership portal is exposed through the old one.
That is the mechanism the corpus records at 23-1204, where credential stuffing at 23andMe used passwords recovered from unrelated breaches. Password reuse converts every historical breach into a live one.
The Population Is Lawyers
The corpus notes at 25-0519 that legal document estates are a distinct target class because the material is time-limited, precise and tradeable. This file is not that — no documents were taken — but the population overlaps exactly.
A credential belonging to a practising lawyer is worth more than the average credential for reasons that have nothing to do with the ABA.
Built on contemporaneous reporting of the ABA’s notification to members. The 17 March detection, the 23 March identification, the affected systems, the hashed-and-salted handling and the 1,466,000 figure are as reported from the association’s own notice. The approximate 6 March initial access via a decommissioned server is from that reporting. One outlet reported the figure as 1.5 million; this file carries the more precisely stated number and notes the discrepancy. No actor attribution is made. Graded high. Corrections: corrections@forensicpost.com.
- American Bar Association data breach hits 1.4 million membersBleepingComputer
- American Bar Association Breach Hits 1.5 Million MembersInfosecurity Magazine