<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Passwords Archives | Continuing Legal Education (MCLE) in California, MCLE Los Angeles, CLE Orange County, Irvine &amp; San Francisco</title>
	<atom:link href="https://www.netforlawyers.com/topics/passwords/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.netforlawyers.com/topics/passwords/</link>
	<description></description>
	<lastBuildDate>Tue, 25 Aug 2026 23:14:43 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>
	<item>
		<title>Data Security for Law Firms is Non-Negotiable: Why the Recent Gmail Password Compromise Should Be a Wake-Up Call for Your Firm</title>
		<link>https://www.netforlawyers.com/books/data-security-for-law-firms-is-non-negotiable-why-the-recent-gmail-password-compromise-should-be-a-wake-up-call-for-your-firm/</link>
		
		<dc:creator><![CDATA[Mark Rosch]]></dc:creator>
		<pubDate>Tue, 28 Oct 2025 17:54:28 +0000</pubDate>
				<guid isPermaLink="false">https://www.netforlawyers.com/books/data-security-for-law-firms-is-non-negotiable-why-the-recent-gmail-password-compromise-should-be-a-wake-up-call-for-your-firm/</guid>

					<description><![CDATA[<p><sub>by Mark Rosch</sub></p>
<p><strong>Data Security is Non-Negotiable: Why the Recent Gmail Password Compromise Should Be a Wake-Up Call for Your Firm</strong></p>
<p>&#160;</p>
<p>One aspect of delivering top-tier legal service is the absolute security of client-confidential information. That&#39;s why the recent headlines about a massive collection of stolen data found online should be a wake-up call to law firms. This collection of stolen data contains millions of compromised email credentials, including a significant number of Gmail accounts.</p>
<p>&#160;</p>
<p>Google has clarified that its own systems were not breached. They maintain that the leak is a result of widespread <strong>&#34;infostealer&#34; malware</strong> harvesting credentials from individual infected devices. However, in the end, the distinction doesn&#8217;t matter when it comes to the potential for client-confidential information to leak beyond a law firm using tools where the log-in credentials have been compromised.</p>
<p>&#160;</p>
<p>The cybersecurity threat to law firm data is real, immediate, and squarely focused on any organization where attorneys and staff may use a personal Gmail for business correspondence, or, more critically, reuse their personal login for their professional accounts.</p>
<div align="center">
<hr align="center" size="0" width="100%" /></div>
<p><strong>The Unique Risk for Law Firms</strong></p>
<p>Law firms are no longer low-value targets; they are prime targets. Law firms maintain some of the most sensitive, privileged information imaginable: merger and acquisition (M&#38;A) strategies, intellectual property secrets, financial records, litigation tactics, personally identifiable information (PII), and more. This makes a compromised email address a potential <strong>major threat</strong> to a law firm&#8217;s (and individual attorney&#8217;s) attorney-client privilege and fiduciary duty.</p>
<ul>
<li><strong>&#8220;Credential Stuffing&#8221; is the Gateway:</strong> This is the most significant danger. If an employee uses the same password for their personal Gmail (now compromised) and their firm-issued account or a client portal (whether it is Gmail-based or&#160; not), hackers will use the leaked credentials to &#34;stuff&#34; them into a firm&#8217;s more valuable systems. A successful login gives them the keys to an organization&#8217;s data.</li>
<li><strong>Ethical and Regulatory Liability:</strong> The American Bar Association (ABA) Model Rule of Professional Conduct 1.6 (https://bit.ly/ABAROPC1-6 ) imposes an ethical obligation on lawyers to make &#34;reasonable efforts&#34; to prevent the unauthorized disclosure of client information. A failure to enforce basic security measures like unique passwords and Multi-Factor Authentication (MFA) can be seen as a violation, leading to disciplinary action, massive financial damages, and class-action lawsuits. Case settlements stemming from data breaches in the legal sector are already soaring into the millions.
<ul>
<li><strong><a href="https://bit.ly/3JrQDZC">Judge gives final OK to $8M settlement in Orrick data breach</a></strong></li>
<li><a href="http://bit.ly/4oH2X7o">Houser LLP $1.3 Million Data Breach Class Action Settlement</a></li>
<li><a href="https://bit.ly/4nnCElz">Law Firm Settles Data Breach Lawsuit: A Warning for Legal Professionals</a></li>
</ul>
</li>
</ul>
<p style="margin-left:1.0in;">&#160;</p>
<ul>
<li><strong>The Chain of Trust Breaks:</strong> Clients trust law firms with their most sensitive data. The reputational damage from a breach&#8212;even one originating from a single reused password&#8212;can be irreparable. Once trust is broken, it&#39;s virtually impossible to rebuild.</li>
</ul>
<div align="center">
<hr align="center" size="0" width="100%" /></div>
<p><strong>Your Firm&#8217;s Action Plan: Non-Negotiable Security Steps</strong></p>
<p>The news of this latest data breach is not a time for panic, but rather for decisive action. Law firms must immediately address the weakest link in their security chain: the human element and &#8220;password hygiene.&#8221;</p>
<ol>
<li><strong>Mandate Multi-Factor Authentication (MFA) Firm-Wide:</strong> The single most effective defense is Multi-Factor Authentication. MFA should be mandatory for <em>every</em> system: firm email, VPN, client portals, cloud storage network-connected voicemail systems, etc. A stolen password is useless if the attacker can&#39;t pass the second authentication step on a trusted device.</li>
<li><strong>Enforce Unique and Strong Passwords:</strong> No more re-using passwords. Period. Law firms should mandate the use of a secure password manager for all employees to generate and store complex, unique credentials for every service.</li>
<li><strong>Run an Immediate Credential Audit:</strong> Encourage or even mandate staff to use services like <strong><a href="http://bit.ly/47vcmrC">Have I Been Pwned</a></strong> to check any personal email addresses. Personal accounts should be checked whether or not those personal accounts are used for firm-related sign-ups, since many people reuse usernames and passwords across their work and personal accounts. If a personal account is compromised, the associated business accounts must have their passwords reset immediately.</li>
<li><strong>Security Awareness Training (Again):</strong> This is not a one-and-done event. Law firms should have regularly-scheduled training sessions focused on the <strong>dangers of credential reuse</strong> and <strong>phishing, </strong>and more specifically on <strong>infostealer malware</strong>. One emphasis of this training should be that hackers are not just targeting the firm&#39;s main server; they are targeting <em>firm</em> <em>employees</em> as individuals to gain access.</li>
</ol>
<p>&#160;</p>
<p>The digital landscape is ever-changing. Cybercriminals are persistent, and nation-state actors are actively targeting US law firms for corporate and national security intelligence. Lawyers&#8217; professional obligations demand that data security is treated with the same rigor and dedication law firms apply to their most complex legal cases.</p>
<p>&#160;</p>
<p>No matter the cost of proactive security, it is always negligible when compared to the cost of a data breach.</p>
<p>&#160;</p>
<p>The post <a href="https://www.netforlawyers.com/books/data-security-for-law-firms-is-non-negotiable-why-the-recent-gmail-password-compromise-should-be-a-wake-up-call-for-your-firm/">Data Security for Law Firms is Non-Negotiable: Why the Recent Gmail Password Compromise Should Be a Wake-Up Call for Your Firm</a> appeared first on <a href="https://www.netforlawyers.com">Continuing Legal Education (MCLE) in California, MCLE Los Angeles, CLE Orange County, Irvine &amp; San Francisco</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fwww.netforlawyers.com%2Fbooks%2Fdata-security-for-law-firms-is-non-negotiable-why-the-recent-gmail-password-compromise-should-be-a-wake-up-call-for-your-firm%2F&#038;title=Data%20Security%20for%20Law%20Firms%20is%20Non-Negotiable%3A%20Why%20the%20Recent%20Gmail%20Password%20Compromise%20Should%20Be%20a%20Wake-Up%20Call%20for%20Your%20Firm" data-a2a-url="https://www.netforlawyers.com/books/data-security-for-law-firms-is-non-negotiable-why-the-recent-gmail-password-compromise-should-be-a-wake-up-call-for-your-firm/" data-a2a-title="Data Security for Law Firms is Non-Negotiable: Why the Recent Gmail Password Compromise Should Be a Wake-Up Call for Your Firm"><img src="https://www.netforlawyers.com/wp-content/uploads/2026/07/share_save_342_32.png" alt="Share"></a></p><p><sub>by Mark Rosch</sub></p>
<p><strong>Data Security is Non-Negotiable: Why the Recent Gmail Password Compromise Should Be a Wake-Up Call for Your Firm</strong></p>
<p>&nbsp;</p>
<p>One aspect of delivering top-tier legal service is the absolute security of client-confidential information. That&#39;s why the recent headlines about a massive collection of stolen data found online should be a wake-up call to law firms. This collection of stolen data contains millions of compromised email credentials, including a significant number of Gmail accounts.</p>
<div class="read_more_link"><a href="https://www.netforlawyers.com/books/data-security-for-law-firms-is-non-negotiable-why-the-recent-gmail-password-compromise-should-be-a-wake-up-call-for-your-firm/"  title="Continue Reading Data Security for Law Firms is Non-Negotiable: Why the Recent Gmail Password Compromise Should Be a Wake-Up Call for Your Firm" class="more-link">Continue reading &rarr;</a></div>
<p>The post <a href="https://www.netforlawyers.com/books/data-security-for-law-firms-is-non-negotiable-why-the-recent-gmail-password-compromise-should-be-a-wake-up-call-for-your-firm/">Data Security for Law Firms is Non-Negotiable: Why the Recent Gmail Password Compromise Should Be a Wake-Up Call for Your Firm</a> appeared first on <a href="https://www.netforlawyers.com">Continuing Legal Education (MCLE) in California, MCLE Los Angeles, CLE Orange County, Irvine &amp; San Francisco</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Google Introduces New Feature to Chrome Browser &#124; Warns of Hacked Passwords</title>
		<link>https://www.netforlawyers.com/books/google-introduces-new-feature-to-chrome-browser-warns-of-hacked-passwords/</link>
		
		<dc:creator><![CDATA[Mark Rosch]]></dc:creator>
		<pubDate>Tue, 10 Dec 2019 19:28:54 +0000</pubDate>
				<guid isPermaLink="false">https://www.netforlawyers.com/books/google-introduces-new-feature-to-chrome-browser-warns-of-hacked-passwords/</guid>

					<description><![CDATA[<p><a href="https://blog.google/products/chrome/better-password-protections/" target="_blank">Google is rolling out a new feature for its Chrome Web browser</a> that will inform users if the passwords they enter for the sites they are visiting has been compromised in a major, known data breach.</p>
<p>Google first introduced this <a href="https://security.googleblog.com/2019/02/protect-your-accounts-from-data.html" target="_blank">technology in early 2019 as the Password Checkup extension</a>. In October 2019, it became a part of the <a href="https://passwords.google.com/" target="_blank">Password Checkup in your Google Account</a>, where you can conduct a scan of your saved passwords anytime. It has evolved to offer warnings as you browse the web in Chrome.&#160;</p>
<p>While this is a useful feature, and the integration with the Chrome browser makes it seamless, one important point that most coverage ignores or downplays is that the browser can only check passwords that the user is storing in their Google account as part of Chrome&#39;s built-in Password Manager. If you&#39;re using a separte password manager (e.g., LastPass, 1Password), Chrome&#39;s Password Checkup feature will not be able to access your stored passwords to check them.</p>
<p class="rtecenter"><img alt="Google Chrome Password Check" src="https://www.netforlawyers.com/sites/default/files/*Chrome Password Check.png" style="width: 400px; height: 128px;" /></p>
<p>Similarly, if you have set up a passphrase to encrypt the passwords stored in your Google account (recommended) the Password Checkup feture cannot acces them to check them.</p>
<p>The post <a href="https://www.netforlawyers.com/books/google-introduces-new-feature-to-chrome-browser-warns-of-hacked-passwords/">Google Introduces New Feature to Chrome Browser | Warns of Hacked Passwords</a> appeared first on <a href="https://www.netforlawyers.com">Continuing Legal Education (MCLE) in California, MCLE Los Angeles, CLE Orange County, Irvine &amp; San Francisco</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fwww.netforlawyers.com%2Fbooks%2Fgoogle-introduces-new-feature-to-chrome-browser-warns-of-hacked-passwords%2F&#038;title=Google%20Introduces%20New%20Feature%20to%20Chrome%20Browser%20%7C%20Warns%20of%20Hacked%20Passwords" data-a2a-url="https://www.netforlawyers.com/books/google-introduces-new-feature-to-chrome-browser-warns-of-hacked-passwords/" data-a2a-title="Google Introduces New Feature to Chrome Browser | Warns of Hacked Passwords"><img src="https://www.netforlawyers.com/wp-content/uploads/2026/07/share_save_342_32.png" alt="Share"></a></p><p><a href="https://blog.google/products/chrome/better-password-protections/" target="_blank">Google is rolling out a new feature for its Chrome Web browser</a> that will inform users if the passwords they enter for the sites they are visiting has been compromised in a major, known data breach.</p>
<p>Google first introduced this <a href="https://security.googleblog.com/2019/02/protect-your-accounts-from-data.html" target="_blank">technology in early 2019 as the Password Checkup extension</a>. In October 2019, it became a part of the <a href="https://passwords.google.com/" target="_blank">Password Checkup in your Google Account</a>, where you can conduct a scan of your saved passwords anytime. It has evolved to offer warnings as you browse the web in Chrome.&nbsp;</p>
<p>While this is a useful feature, and the integration with the Chrome browser makes it seamless, one important point that most coverage ignores or downplays is that the browser can only check passwords that the user is storing in their Google account as part of Chrome&#39;s built-in Password Manager. If you&#39;re using a separte password manager (e.g., LastPass, 1Password), Chrome&#39;s Password Checkup feature will not be able to access your stored passwords to check them.</p>
<div class="read_more_link"><a href="https://www.netforlawyers.com/books/google-introduces-new-feature-to-chrome-browser-warns-of-hacked-passwords/"  title="Continue Reading Google Introduces New Feature to Chrome Browser | Warns of Hacked Passwords" class="more-link">Continue reading &rarr;</a></div>
<p>The post <a href="https://www.netforlawyers.com/books/google-introduces-new-feature-to-chrome-browser-warns-of-hacked-passwords/">Google Introduces New Feature to Chrome Browser | Warns of Hacked Passwords</a> appeared first on <a href="https://www.netforlawyers.com">Continuing Legal Education (MCLE) in California, MCLE Los Angeles, CLE Orange County, Irvine &amp; San Francisco</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
