← Articles
RIPOSTE research · 2025

Even the Smartest Hackers Fall Back on Phishing: Why Law Firms Need to Wake Up to Supply Chain Sneak Attacks

In the high-stakes world of cybersecurity, you'd think the most dangerous threats come from cutting-edge AI viruses or zero-day exploits straight out of a sci-fi thriller. But here's the plot twist: even the most sophisticated cybercriminals often start with the basics—like a sneaky email or a smooth-talking phone call. The latest alert from Australia's ASD's ACSC (Australian Signals Directorate's Australian Cyber Security Centre) shines a spotlight on this reality, targeting online code repositories used by developers. But don't tune out if your firm isn't knee-deep in coding projects. This isn't just a techie problem—it's a stark reminder of how supply chain vulnerabilities can ripple into any organisation, including law firms that rely on third-party software for case management, document automation, or client portals.

Let me break it down for you, no binary code required.

The Sneaky Entry Points: Same Old Tricks in New Packaging

The ACSC reports a surge in attacks on online code repositories—think GitHub or similar platforms where developers store and share software code. Threat actors (that's hacker-speak for bad guys) are slipping in through doors we've all been warned about:

Phishing or Vishing: Fake emails or phone calls tricking someone into clicking a malicious link or handing over login details.

Social Engineering: Manipulating people into divulging sensitive info, like posing as IT support to extract a password.

Compromised Credentials or Tokens: Reusing stolen logins from previous breaches or hijacked authentication keys.

Infected Software Packages: Downloading "free" tools that come pre-loaded with malware.

Sound familiar? These are the exact same tactics that prey on law firms every day. Remember the 2023 MOVEit breach that exposed millions of records, including legal data? It started with a simple vulnerability in a widely used file-transfer tool—classic supply chain compromise. Or how about the countless ransomware hits on firms via phishing emails disguised as urgent court filings? Sophisticated? Absolutely, in execution. But predicated on the most human of weaknesses: trust and haste.

Once inside, these actors don't deploy flashy malware. Instead, they abuse everyday tools—like open-source scanners—to hunt for "secrets" buried in code: API keys, passwords, cryptographic tokens. They leak them publicly, flip private repos to public view, or tamper with packages to poison the well for downstream users. The result? Attackers gain a blueprint of your internal systems, bloating your attack surface and paving the way for tailored, devastating follow-ups.

For law firms, this translates to real nightmares. Your vendors' software (billing systems, e-discovery tools) could be the weak link, exposing client confidences or enabling lateral movement into your network. And if your team uses off-the-shelf apps without scrutiny? You're one infected update away from a data leak that might make headlines.

Why This Matters More Than Ever for Legal Pros

Cyber threats don't discriminate by industry. The ACSC's alert underscores a universal truth: the "supply chain" isn't just factories and widgets anymore—it's software ecosystems that power everything from your CRM to cloud storage. A breach in a developer's repo can cascade like dominoes, hitting everyone who integrates that code. Law firms, with their treasure troves of sensitive data, are prime targets. According to recent reports from cybersecurity firms like CrowdStrike, over 60% of breaches involve supply chain elements, and phishing remains the top initial vector.

The sophistication lies not in the tools, but in the persistence. These actors aren't reinventing the wheel; they're driving stolen cars through unlocked gates. It's a wake-up call: Your multi-million-dollar firewalls are only as strong as the people clicking "yes" on that dubious attachment.

Your Action Plan: Defend Like It's 2025 (Because It Is)

The ACSC doesn't leave us hanging—they've got solid mitigation steps. I've adapted them here for a non-dev audience, focusing on what law firms can action today:

Audit Your Digital Footprint: Review recent software installs, logins, and vendor updates. Look for odd activity in your tools—think unexpected file changes or unfamiliar processes. If something feels off, call in your IT pros or a trusted advisor.

Vet Your Vendors Ruthlessly: Before adopting new software (or updating old), demand proof of security audits. Stick to verified providers and scan downloads for red flags. Remember: Free isn't always worth it if it comes with strings (or malware).

Train Your Team on the Human Firewall: Roll out regular awareness sessions on phishing, vishing, and social engineering. Make it relatable—use scenarios like "fake client emergencies" instead of abstract code talk. Tools like simulated phishing tests can turn skepticism into vigilance.

Hunt for Hidden Leaks: Use built-in security features in your platforms (e.g., GitHub's secret scanning) to flag exposed credentials. If your firm dabbles in custom apps, enable these now.

Rotate and Secure Secrets: Change any potentially exposed passwords, keys, or tokens immediately. Implement multi-factor authentication (MFA) everywhere—it's your simplest force multiplier.

The Bottom Line: Don't Wait for the Fallout

Cybersecurity isn't about being a tech wizard—it's about outsmarting the opportunists who bank on your oversight. Even elite hackers lean on phishing because it works. So, ask yourself: What have *you* done lately to detect and defend against these entry-level exploits? A quick audit? A team drill? If not, today's the day.

At RIPOSTE, we're all about bridging the gap between legal smarts and cyber savvy. Reach out for a no-obligation chat on hardening your firm's defences. Stay vigilant—your clients are counting on it.

This post is inspired by the latest ACSC alert. For the full details, check it out here.

Sources

  1. ASD's ACSC Annual Cyber Threat Report 2024–25 (cyber.gov.au)
  2. CISA — #StopRansomware: CL0P exploitation of MOVEit Transfer (AA23-158A)
About the author

Cameron McCollum — Director & Founder, RIPOSTE. He spent two decades in Australian Army intelligence — serving as Head of Intelligence on operations across the Asia-Pacific and Afghanistan — before building and leading the cyber-risk program at Lexon Insurance. He holds Master's degrees in Cyber Security Operations and Business (UNSW) and is an ISO/IEC 27001 Lead Implementer.

RIPOSTE helps organisations turn analysis like this into action.

Talk to us