American Bar Association breach exposed credentials of 1.4 million members

Organization
American Bar Association
Exploit
Hacking
Industry
Professional Association

The American Bar Association began notifying members in April 2023 that an intruder had obtained login credentials from its systems. BleepingComputer reported that 1,466,000 members were affected.

According to the association's own notification letter, filed with the California Attorney General, the ABA observed unusual activity on its network on 17 March 2023 and activated its incident response plan, retaining outside cybersecurity experts. The investigation determined that an unauthorised third party had gained access on or about 6 March. On 23 March the ABA identified that usernames and hashed and salted passwords had been acquired.

The affected credentials were those used to sign in to the old ABA website before 2018 or to the ABA Career Center from 2018 onward. The association stressed that passwords were not exposed in plain text, but acknowledged that in many instances members had never changed a default password originally assigned to them by the ABA.

The ABA said it removed the unauthorised third party from its network and reviewed its network security configurations. It urged members to change any password reused elsewhere and to stay alert to attempts to access their accounts, and said it had received no reports that the stolen information had been misused.

A proposed class action, Troy v. American Bar Association, was filed on 21 April 2023. ClassAction.org reported that the case was dismissed on 30 April 2024 after the court found the plaintiffs had not identified which specific security measures the ABA failed to adopt.

Sources