American Bar Association Reports Data Breach Affecting 1.5 Million Accounts

The American Bar Association (ABA) confirms a data breach involving 1.5 million member accounts. While the stolen passwords were encrypted, the breach raises concerns over potential abuse of the credentials.

American Bar Association Reports Data Breach Affecting 1.5 Million Accounts

The American Bar Association (ABA) has disclosed a data breach affecting 1.5 million member accounts, providing a notice with details about the incident and recommendations for users. Detected in March, the breach involved usernames and encrypted passwords associated with accounts on the ABA's pre-2018 website and the career center website. While no personal or corporate information was accessed, the ABA is taking the security of user information seriously and implementing measures to prevent a recurrence.

The ABA has issued a notice explaining the incident and offering guidance to affected users. The association observed unusual network activity on March 17, 2023, and determined that an unauthorized third party had gained access to the network around March 6, 2023. The investigation identified that the attacker had acquired usernames and hashed and salted passwords used to access online accounts on the old ABA website prior to 2018 or the ABA Career Center since 2018.

The stolen passwords were not exposed in plain text but were hashed and salted, a process that adds random characters to the plain text password before converting it into cybertext on ABA systems. In many instances, the passwords may have been default passwords assigned by the ABA, which users may not have changed later. The ABA is notifying affected individuals out of caution.

Although the ABA changed its website log-in platform in 2018 and asked users to create new credentials, users who employed the same credentials to access the new ABA website are advised to update their passwords. The association is working to reduce the likelihood of future cyber-attacks by removing the unauthorized third party from the network and reviewing network security configurations to address evolving cyber threats.

The ABA encourages users to change any passwords similar to those involved in the breach and remain vigilant against unauthorized attempts to access their online accounts.

Customer Stories

See how leading enterprise in-house teams have scaled smarter with Legal.io's high-caliber flex talent.

More from Legal.io


McDonald’s Legal Chief Sees Pay Cut Amid Profit Drop, DEI Tensions

McDonald's legal chief Desiree Ralls-Morrison saw a 19% pay cut as executive incentives fell amid lower profits, while DEI practices face rising shareholder and political scrutiny.

Apr 07, 2025
Read More
Big Law Gears Up for Anticipated SEC Overhaul
Big Law Gears Up for Anticipated SEC Overhaul

Big Law firms anticipate more work in capital markets and cryptocurrency as the new U.S. administration shifts SEC priorities and eases regulations.

Nov 25, 2024
Read More
The NextGen Bar Exam Set to Debut in July 2026
The NextGen Bar Exam Set to Debut in July 2026

This new examination represents a shift from the traditional bar exam by emphasizing skills-based knowledge over content memorization.

Sep 03, 2023
Read More
Legal Market Data: Job Opportunities in Times of Pandemic
Legal Market Data: Job Opportunities in Times of Pandemic

A look into the legal job market, and how COVID-19 has affected job prospects for individuals seeking work, based on data from The US Bureau of labor statistics, Indeed, LinkedIn, and the Legal.io Community.

May 08, 2020
Read More
Ready to hire?

Schedule a free consultation to discuss your hiring needs.

Free 15-min consultation
Legal.io Platform
5 star reviews
Hiring made smarter

Easy-to-use platform for hiring legal talent, managing spend, and optimizing your panel — plus an average savings of 50%.

Need Immediate Help?

Submit a hiring request and let our experts handle the entire process for you.