This week's most relevant threat for small law firms did not come through email. It came through a direct message on social media, and it shows how one link can lead to two different attacks. According to a breakdown from a security operations team, an attacker sent a single direct message with a link to what appeared to be a shared document. Mac users who clicked through were routed toward information stealing malware built to harvest saved passwords and browser data, while Windows users were routed toward a legitimate remote access tool repurposed to give the attacker hands on control.
This attack targets a channel most firms are least prepared to defend. Social media and direct messaging typically sit outside a firm's email security filters and endpoint monitoring, and a single click from a normal looking contact could hand an attacker either client portal credentials or full remote access to a workstation holding case files and trust account records.
Rule 4-1.6 requires reasonable efforts to prevent unauthorized access to client information, and a malware infection that steals credentials or grants remote access is precisely the kind of risk that duty is meant to prevent. Recommendation 25-1 calls for a documented cybersecurity assessment, not an informal assumption that the firm is covered.
This is exactly the kind of gap ArisGate exists to close for solo and small Florida law firms. If you are not certain your firm's devices and messaging channels are covered, schedule a free security audit this week.