logo

Law firm insisted on one password to rule them all

ID: dd3dbc43-7555-53bc-a0e8-368135f7a3bb

STIX ID: report--dd3dbc43-7555-53bc-a0e8-368135f7a3bb

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2026-07-16

Date Updated: 2026-07-23

...
...

This PWNED column describes a law firm that relied on a single master admin password which allowed staff to impersonate any user (staff or client) by supplying an email address, exposing sensitive client information including health records. The firm's IT employee refused to implement a backdoor, but management mitigated the issue by indiscriminately promoting all users to system admin rather than fixing authentication and access controls, leaving significant privacy and security risks despite no reported exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.