Law Firm Rustam Kurmaev and Partners were attacked by the Cyber Hacktivist group Anonymous on Saturday, with the group leaking approximately 1TB of data.

Rustam Kurmaev and Partners actively work with the Russian government, and also with high-profile banking, media, oil and industrial companies. Their clients are not exclusive to Russia, with the firm managing several American firms.

The leak could be devastating for the company, considering that it specialises in resolving real estate, construction, corporate, and commercial sector disputes, and holds a substantial amount of highly sensitive information. The law firm is partly at fault for this data leak, as it shows that the company has not effectively implemented cyber security measures in their organisation, such as Phishing Training, a service offered by TecSec.

The law firm also resolves disputes regarding the criminal defence of businesses and typically creates a systematic defence strategy for corporate managers and top management in various stages of criminal proceedings. The company’s involvement in anti-corruption law also shows that the data they hold is highly sensitive, and will have a huge impact on existing court cases being resolved by the firm.

Anonymous

Anonymous has waged a cyberwar against Russia since late February of 2022 as a result of the country invading Ukrainian territories.

This attack on RKP Law has come just two days after the hacktivist collective leaked hundreds of gigabytes of data from the servers of Russia’s largest media holdings. These servers contained data from over 100 regional radio stations and severely limited the country’s ability to spread propaganda through their national radios.Anonymous released this statement through Twitter regarding their attack on the law firm:

Once again, #Anonymous delivers Many thanks to @DepaixPorteur. Just In: #Anonymous released a terabyte of data and emails from Rustam Kurmaev and Partners (RKP Law), a Russian law firm that works with major banking, media, oil, and industrial firms and state interests, including American companies. #OpRussia

 Law Firms and Data Leaks

This news shares similarities with a data leak experienced by a UK law firm, Tuckers LLP. The difference between the two is that RKP Law was targeted by a group of highly motivated hackers, whereas Tuckers LLP were negligent with their cyber security, and as a result fell victim to one of a hundred cyber attacks launched on UK businesses every day.

As a result, on the 10th of March, the criminal defence law firm was fined £98,000 by the Information Commissioners Office (ICO).

The fine was released after a ransomware attack saw 60 court documents, including medical statements and witness statements, being published on the Dark Web in 2020.

In their ruling, the ICO found that Tuckers had broken the General Data Protection Regulation 2016 by not introducing multi-factor authentication for remote-access users. This is a responsibility for any business but this was a significant error on the part of a national law firm that holds highly sensitive and private data. Regarding this, the ICO stated, “Had MFA been used, it could have substantially supported Tuckers in preventing access to its network”.

The firm also delayed patching a critical vulnerability, believed to be in Citrix Application Delivery Controller (ADC). Citrix provided a patch for this vulnerability on the 19th of January, but Tuckers only installed it on June 2020, five months after it was released, and three months after the NCSC announced that organisations were required to install it.

NCSC ‘Cyber Essentials‘, for which TecSec is a Certification body, requires patches that are rated as ‘high’ or ‘critical’ should be applied within 14 days of the release of the patch. As Tuckers had failed to install a critical patch within 5 months of it being released, this represents a clear cyber security failure.

These were not the only failures cited by the ICO, as personal data stored on Tuckers’ archive server was not encrypted, and was later seized in the ransomware attack. They stated that “The Commissioner accepts that encryption of the personal data may not have prevented the ransomware attack. However, it would have mitigated some of the risks this attack posed to the affected data subjects.”

The criminal law firm failed a Cyber Essentials assessment in October 2019. The ICO stated that “Given the personal data that Tuckers should have not only have met, but surpassed the basic requirements of Cyber Essentials. The fact that some 10 months after failing Cyber Essentials it had still not resolved this issue is, in the Commissioner’s view, sufficient to constitute a negligent approach to data security obligations”.

Due to the considerable threat being faced by law firms, and UK firms generally, we are currently offering a free simulated phishing campaign, which organisations can use to determine their staffs’ ability to detect ransomware. This simulated campaign will be followed up with a free phishing training module.
In order to get your free phishing training, fill out our short dedicated page here: 
Free Training: Phishing Simulation – TecSec Services Ltd
Or contact us at 0114 223 8000, & info@tecsec.co.uk.