
The American Bar Association (ABA), a leading legal industry body in the US, has reportedly contacted 1.5 million lawyers, who had accounts on its website, to inform them about a data breach that occurred last month.
In a statement on its website, the ABA claimed that it first noticed unusual activity on its network on March 17. However, it concluded that a threat actor had obtained unauthorized access even earlier, on March 6, before that.
An investigation revealed that usernames and hashed and salted passwords, which were used to access online accounts on the previous ABA website before 2018 or the ABA Career Center since 2018, were obtained by an unauthorized third party.
If the user never changed the password on the old ABA site, the password could have been the ABA’s default password assigned to the user. Users who did not update their passwords when the ABA changed its website login platform in 2018 were being reminded to do so, and any credentials reused on other non-ABA accounts could now be vulnerable to credential stuffing.
The association claimed that the ABA took precautions to lessen the possibility of a subsequent cyber-attack, including removing the unauthorized third party from the ABA network and reviewing network security configurations to address continuously evolving cyber threats.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543