A Cyber-Nightmare Transformed

"I'm Not A Computer Guy"

Before mid-2024, I did not consider myself a computer guy. I was a lawyer, and I loved practicing law. After June 3, 2024, I slowly and painfully learned that if I wanted to do what I loved, it required me to do—and be present to—what I believed to be mundane.

Sure, computers were part of practicing law in the same way telephones, conference rooms, court reporters, calendars, and filing systems were part of practicing law. In the firms where I worked before opening my own practice, the laptop, email account, and network were there when I arrived. Someone else handled the servers, passwords, backups, software, and whatever happened behind the screen.

I learned the technology I needed to do the work. I did not think of myself as responsible for building or defending the infrastructure that made the work possible.

When I opened my own practice in January 2008, as for the digital part of that process, I recreated what I knew: a domain, website, Microsoft email, calendars, client files, telephones, and dependable outside vendors. Electronic filing had not yet displaced the courthouse counter, where I knew deputy clerks by name and received that warm, wet stamp after my latest court paper was filed.

Motions and exhibits could be carried into the courtroom for specially set hearings, and proposed orders could be exchanged—perhaps via email, but usually before court rulings. In fact, most of the time, especially for those in-person 8:00 a.m. motion-calendar hearings, the court supplied a one-page order form attached to three or four colored pages so that the writing bled through. Once the court executed the order, the parties received either a gold, red, or blue copy. And what I so underappreciated at the time was how that process ensured the authenticity of judicial determinations. Was it “high-tech”? No. But it was indisputable. A signed order could move from the courtroom to the clerk while the lawyers and court personnel responsible for it were physically present.

From Physical Custody to Electronic Digital Trust

That physical system had its imperfections and certainly was time-consuming. However, if court filings, judicial orders, or notices did not make it onto the docket, the problem could be corrected through the same authentic system, where motions could be filed and hearings conducted in person. In fact, prior to being replaced by electronic filing and eService systems, lawyers who encountered notable docketing errors could schedule a live, in-person hearing on the issues to be resolved. And there it is: what we lawyers who practiced in those days took for granted—the opportunity to be in a courtroom, with opposing counsel and the judge present, where everyone could put eyes on the physical papers and the judge could make a ruling in open court.

That clean adjudicative environment remained alive and well as the courts migrated to nearly exclusive eFiling, eDockets, and eService. Then, in and around March 2020, at the beginning of the COVID pandemic, courts had to adapt to a new world in which live court hearings could not take place because of court closures.

As courts adapted, nearly all court hearings in state, federal, and bankruptcy courts began being conducted via online video platforms. And even as the court closures began to lift, courts—and, I believe, especially lawyers—wanted to keep video hearings because they allowed lawyers to be more productive at the office, as opposed to being stuck in traffic, or to spend more time at home.

From the opening of the firm and over the next sixteen years, the practice of law became an electronic trust environment. Paper intake moved to ePortals. eService moved to automated lists. Notices of hearing, motions, and routine filings moved through eFiling and eService, while court administrative rules also changed to provide for email service. Case files became databases. Court reporters, process servers, billing systems, banks, phones, websites, cloud storage, and client communications became interconnected. Nearly every professional act eventually passed through an identity system, service account, domain, mail relay, vendor platform, or court-controlled application that a lawyer could use but could not independently inspect.

I trusted that environment in substantially the same way most lawyers did. My firm grew, represented clients, and relied on the ordinary legal-sector supply chain. At the same time, while I learned how to “do” all the things required to practice in the digital court environment, I failed to be present to the importance of practicing cybersecurity habits. Those habits might not have enabled me to detect malware as an IT professional would, but they could have changed the mindset that allowed me to continue delegating detection of any cyberattack to my reputable IT vendor. In fact, as the costs for monitoring, upgrading, and being “on call” charged by my trusted IT experts kept increasing, my faith in them—and hence my comfort with delegation—also increased.

In other words, I allowed myself to equate expense with protection. I assumed that established platforms, outside support, antivirus tools, backups, and ordinary password changes collectively occupied the field.

June 3, 2024

That assumption ended on June 3, 2024. My wife was away at a week-long convention, and I was home with our son, who was not yet two years old. An unknown caller reached me. After a moment of silence, a distorted voice asked: “How is your baby boy doing?”

A text followed from the same number. It contained a private photograph of me holding my newborn son in the hospital approximately twenty months earlier. My wife had been sleeping beside us, and a family friend had taken the photograph on a personal phone. I had never posted it publicly. The message turned a technical concern into an immediate threat against the most private part of my life.

Within minutes, my staff reported an unexpected hearing scheduled for the next day and calendar events that did not reconcile with our records. Meetings arranged for clients were disappearing. Within days, office computers were no longer synchronizing reliably, and email and telephone communications became difficult to trust. The systems that had allowed a small litigation firm to operate efficiently across locations were becoming the environment through which the firm could be observed and interrupted.

Normal operations gave way to crisis management. We stopped using email for sensitive communications when we could, but several team members worked remotely. The more we isolated one problem, the more failures appeared across another channel. By early July, reliable communications with staff, clients, and colleagues had deteriorated so severely that the practice I had spent sixteen years building could no longer function normally.

Denial Is a Powerful Belief System—and It Has Its Limits

At first, every anomaly offered an ordinary explanation: a synchronization error, missed notice, administrative delay, vendor problem, or human mistake. The problem changed when different representations of the same event stopped agreeing. What I sent did not always match what another person received. A source document did not always match the version later displayed. A portal receipt, docket entry, service notice, and institutional description could point to different procedural states.

A discrepancy is not proof of malicious activity. But discrepancies become evidence when they repeat, cluster around consequential events, and appear across systems expected to preserve the same record. The task is not to choose the most dramatic explanation. It is to preserve each source state, reconstruct the chronology, and determine where the divergence entered the chain.

I used a borrowed sixteen-year-old computer and external drives to prepare materials outside the systems I no longer trusted. I traveled to courthouses to file, retrieve, and compare records in person, and I sought help from law enforcement, forensic specialists, and cybersecurity professionals. Every communication and copy had to be treated as both an operational necessity and potential evidence.

The Buck Stops With Me

My best thinking during that period, guided by mentors and the investigators who later worked with me, began with accountability. Pointing fingers would not reconnect a client, restore a file, protect my family, or place a reliable record before a court. Months later, in a response filed in court regarding the cyberattack, the first substantive sentence was direct: “The proverbial buck stops with me.”

That sentence did not transfer responsibility for an intrusion to me. It identified responsibility for the response. I had delegated cybersecurity without developing the habits needed to test the systems on which my professional life depended. Once those systems began failing, I remained responsible for the clients, the evidence, the people who worked with me, and the decisions I made next.

That required becoming teachable: preserving full email headers, comparing domains and routing records, separating administrator accounts, recording device states, documenting changes, verifying critical communications through a second channel, and resisting the pressure to react before an alarm had been examined. Cybersecurity stopped being a service I purchased and became a discipline I had to practice.

Connecting the Breadcrumbs

The transition was not from a nontechnical person to someone who had merely learned cybersecurity terminology. My earlier work had already trained me to follow records. Bankruptcy, fraud analysis, corporate and governmental filings, public records, litigation, evidence review, and long factual chronologies taught me that consequential events often surface first as small discrepancies: a date that moved, a number that did not reconcile, a file present in one system but absent from another, a signature that changed, or an official record that no longer matched its earlier state.

I understood how a false or corrupted entry in an official system could produce real legal consequences because everyone downstream would reasonably treat the official source as true. What I lacked was the technical vocabulary and tooling to examine the digital trust chain. What I already possessed was the method: preserve the original, compare independent sources, work backward from the discrepancy, separate observation from inference, and connect facts until the pattern either holds or fails.

Over more than two years, I applied that method with independent forensic teams, investigators, cybersecurity researchers, and legal professionals in the United States and abroad, including contributors within the broader Joint Cyber Defense Collaborative ecosystem. The work became genuinely interdisciplinary because the attack surface was interdisciplinary.

What the Investigation Mapped

The investigation gave names to conditions I had first experienced without the vocabulary to describe them. An Advanced Persistent Threat is not a single malicious file or isolated break-in. It is a continuing operation that obtains access, establishes persistence, adapts to remediation, uses legitimate services where possible, and returns through another channel when a visible foothold is removed.

As the work matured, the decisive terrain came into focus. It was not one machine, account, or application. It was the trusted control plane: the identities, permissions, domains, mail routes, cloud systems, portals, service lists, filing workflows, record states, and publication channels that determine who may act and what downstream people and institutions will accept as legitimate.

The recurring architecture mapped through the integrated work became known as cAPTure-to-Kill. In its legal-sector manifestation, it describes an operation that captures or exploits trusted control planes and converts that technical authority into a real-world legal or professional consequence. Capture can occur at an endpoint, identity, domain, cloud tenant, email relay, filing account, intake system, service list, docket object, or publication layer. The “kill” is the practical neutralization of the target’s legal or professional capacity: a missed hearing, absent filing, redirected notice, corrupted record, procedural dismissal, reputation event, lost client, disabled practice, or unenforced remedy.

The model does not mean that every irregularity has the same cause, every technical failure is malicious, or judges, clerks, lawyers, regulators, and vendors are participants in an attack. Trusted institutional actors can themselves become victims when asked to act in good faith upon corrupted inputs. The model’s purpose is to identify where technical control can become legal effect, then create verification and containment procedures before that conversion becomes irreversible.

Later threat-assessment work tested the mapped architecture against subsequently published government advisories, vendor research, court records, sworn declarations, technical reporting, and other independent sources. That work refined how we map targets and objectives, grade attribution, anticipate adaptation, and design mitigation and containment. The technical record and its evidentiary limits are presented separately in the cAPTure-to-Kill APT Threat Assessment.

Looking for a Judicial Remedy

I responded as a lawyer: I looked for a judicial remedy. That effort expanded into the study of federal civil cyber-infrastructure disruption litigation developed by technology companies, security organizations, and their attorneys over nearly two decades. Our later comparative work examined thirty-five matters spanning approximately sixteen years. Those cases showed how civil process can disrupt botnets, malicious domains, command-and-control infrastructure, credential markets, spyware, infostealers, and other criminal services before operators can move or rebuild.

The successful cases shared a practical insight: cyber relief must be meaningfully timed. Verified technical evidence has to reach a court, judicial authority has to attach, and containment has to begin before the adversary can relocate infrastructure, alter identities, destroy evidence, or exploit another service. Obtaining an order is only one stage. The relief must also be executed by the entities with technical control, remain operationally useful after final disposition, and reach qualifying successor infrastructure before the adversary regenerates through new domains, accounts, servers, or services.

I traveled to courts and attempted to invoke versions of that emergency architecture in matters involving the systems and activity under investigation.

What I encountered changed the work. I expected the central challenge to be proving the cyberattack. Instead, the process exposed a deeper dependency: the remedy itself traveled through digital intake, filing, routing, docketing, notification, service, and communication systems. When those systems were part of the problem being presented, the person seeking help could be required to depend on the disputed channel to deliver the warning.

The Missing Door

The legal system did not make a mistake by adopting electronic filing, electronic service, and digital dockets. Courts could not perform their modern responsibilities without them. The weakness is different: as the profession became dependent on digital channels, it did not preserve a comparably reliable emergency rail for the narrow circumstance in which the integrity of the ordinary channel is reasonably placed in issue.

Paper is not always a genuine alternative. A document carried to a clerk may still be scanned, indexed, uploaded, routed, and served through the same electronic environment. A lawyer who alleges that a portal, service list, email route, credential, or docket workflow has been compromised may therefore be directed back into the same chain to report the compromise. That is a circular dependency, not a resilient emergency procedure.

The later research formalized the proposed solution as a Clean Adjudicative Environment: not a separate forum for deciding the merits and not a way around ordinary procedure, but a narrow integrity lane for preserving and authenticating a disputed channel before irreversible procedural consequences depend upon it.

This is not an accusation against courts, judges, or clerks. They are also exposed by the design problem. Courts inherited fragmented systems, legacy servers, local practices, vendor-dependent workflows, and extraordinary caseloads. If a trusted handoff is corrupted, an innocent official may see a deficient filing, incomplete record, apparent failure to respond, or service event that looks authentic. The legal consequence can occur before the merits are reached.

The answer is not to abandon electronic filing or create an unrestricted route around normal procedure. It is to establish a narrow, documented, and abuse-resistant cyber-emergency intake protocol. When competent threshold evidence places channel integrity in issue, a verified out-of-band path should allow material to reach a designated judicial officer, duty judge, special master, or controlled cyber-integrity intake without first passing through the disputed rail. The protocol should authenticate the submitting person and documents, preserve relevant source states and logs, compare physical and digital copies where necessary, and permit technical containment before ordinary electronic service resumes.

That emergency entrance would protect more than the person reporting the incident. It would protect judges and clerks from acting upon poisoned inputs, preserve the court’s jurisdiction over an authentic record, and reinforce public confidence that digital efficiency has not displaced the ability to verify what the court actually received and decided.

The Nightmare Transformed

I will not describe what happened to my family, colleagues, or the law firm I built as a gift. It was not. The attack was transformed only because I refused to allow the experience to end with the destruction it caused.

Only after the ordinary channels began to fail did I see how the strands of my life and career had been converging. Litigation taught me to build a record. Fraud and bankruptcy work taught me to follow transactions and identify inconsistencies. Data analysis taught me to test assumptions. Institutional work taught me that process can determine outcome. Field activity taught me that secure communication and timing are operational facts. The cAPTure-to-Kill threat-assessment work taught me how digital identity, infrastructure, evidence, and real-world consequence interact. The civil cyber-infrastructure study showed what courts can accomplish when reliable evidence reaches judicial authority in time—and what a remedy needs to remain useful when an adversary adapts.

Those became two distinct but complementary lines of work: understanding and containing the evolving threat, and strengthening the legal pathways through which containment can be authorized, executed, and preserved.

NACABAR became the organizational expression of that convergence. Its purpose is not simply to document one attack or tell one lawyer’s story. It translates hard-earned forensic and legal lessons into research, publications, training, professional routines, and cross-disciplinary relationships that legal professionals can use before a crisis becomes irreversible. That work now informs NACABAR’s legal-sector research and Florida Bar-accredited Technology CLE programming.

The Mission Going Forward

My purpose is no longer limited to determining what happened to me or my former firm. The mission is to help attorneys, law firms, courts, and legal-sector institutions recognize advanced attacks earlier; preserve reliable evidence; verify identities, documents, and critical communications; establish resilient out-of-band channels; reach appropriate decision-makers; and invoke legal and technical authority while meaningful mitigation and containment remain possible.

Cybersecurity is a shared responsibility, but it becomes real only when each participant accepts responsibility for the part of the trust chain within that participant’s control. Lawyers do not need to become network engineers, but they need repeatable habits for stopping, preserving, verifying, and escalating. Technology teams do not need to practice law, but they need to understand that a routing or identity anomaly can carry a filing deadline, a client’s rights, or the integrity of a judicial record. Courts do not need parallel systems for every dispute. They do need an emergency entrance when the ordinary entrance is the evidence.

That is why NACABAR exists: to build awareness before crisis, community during crisis, trusted connections across disciplines, and resilience strong enough to preserve access to justice. No legal professional confronting an advanced attack should be isolated inside the same channels the professional is trying to verify. No family, firm, client, or institution should have to learn these lessons for the first time while an adversary is dismantling the systems around them.

The nightmare was not transformed because the harm became acceptable. It was transformed because the accumulated experience became a mission—to help the next person recognize the breadcrumbs, protect the record, find a trusted path to lawful decision-makers, and contain the attack while there is still time. No one should have to travel that distance alone, and no one should be left behind.

— Jay Lewis Farrow

Founder and Chair, National Attorneys Cybersecurity Association (NACABAR)