JAY LEWIS FARROW

AT THE INTERSECTION OF LAW AND CYBERSECURITY EMERGES THE CONVERSION OF A LIFE’S WORK INTO THE DEFINED MISSION OF NACABAR CHAIRMAN JAY LEWIS FARROW

Jay Lewis Farrow, Chairman and Founder of the National Attorneys Cybersecurity Association (NACABAR)

A Life’s Work Gets Applied to the Unexpected and Defines a Vision and Mission

Jay Lewis Farrow’s career consistently operated at the intersection of law, evidence, data, institutional process, and public service. While attending law school, he was recruited to perform data analysis for a state governmental department and continued contributing to projects requiring statistical research, forensic review, and the careful evaluation of complex records.

His subsequent work included forensic fraud analysis for Chapter 7 panel trustees and other bankruptcy-court fiduciaries; more than two decades of litigation and law-firm operations; contractual and private working relationships involving state and federal departments and agencies; and confidential liaison support to individuals engaged in field operations. Those responsibilities required discretion, disciplined communication, pattern recognition, and the ability to recognize meaningful relationships among facts that initially appeared unrelated.

That experience may help explain how Farrow began to recognize that irregularities developing within his professional environment were not ordinary technical failures. Like most legal professionals, however, he initially operated within a deeply embedded culture of institutional trust. Electronic communications appearing to originate from courts, filing systems, professional organizations, and other judicially related infrastructure are ordinarily presumed authentic. Anomalies are therefore easily dismissed as isolated errors, administrative delays, or routine technology problems.

Then came a moment that could no longer be rationalized as a one-off event.

After that point, activity that had remained largely concealed across interconnected systems, professional networks, and trusted institutional relationships began producing a cascade of digital warning signals. As the broader pattern became detectable, it presented as a form of Advanced Persistent Threat activity not previously classified within the legal sector. There was no conventional ransom demand. Instead, the apparent objectives included disrupting access to courts, interfering with due process, controlling trusted communications, and influencing legal and judicial outcomes.

Once that previously unclassified pattern became visible, Farrow had to connect professional relationships and public-private networks that had historically operated along separate lines. Beginning in late 2024, he developed additional relationships within the broader Joint Cyber Defense Collaborative ecosystem and worked with intelligence analysts, forensic investigators, cybersecurity researchers, legal professionals, and public- and private-sector contributors.

Their work focused on documenting the activity, identifying recurring patterns across the digital ecosystem, evaluating real-world effects involving judicial cyber-infrastructure and communication systems, and maintaining situational awareness as the apparent operators recalibrated infrastructure, identities, delivery mechanisms, and attack surfaces in response to detection, reporting, and containment efforts.

Working with several independent expert teams operating within the broader JCDC ecosystem, Farrow contributed to published reports describing an attack architecture involving direct infiltration of professional computer networks, malicious footholds in judicial and court-adjacent cyber-infrastructure, misuse of stolen lawyer credentials, manufactured identities, adversary-in-the-middle activity, domain hijacking, cloud-service abuse, bulletproof hosting, and infrastructure associated with botnets previously addressed through federal injunctions. According to those reports, the combined use of these methods allowed sophisticated malicious activity to move through trusted legal and institutional systems while initially appearing to be ordinary professional traffic, authentic communications, administrative mistakes, or unrelated technical failures.

The work of nine independent expert teams, together with findings previously reported by JCDC strategic partners, converged around a threat model directed at severing trusted communications, disrupting access to courts, counterfeiting official-looking judicial notices, manipulating filing and service pathways, interfering with evidence preservation, and causing reputational injury through professional membership records, search results, and trusted media channels.

Through more than two years of documentation, investigation, field work, forensic analysis, and collaborative logistical operations, Farrow participated in mapping the recurring model described as cAPTure-to-Kill. Its purpose is not merely to compromise a device or steal information. It seeks to capture the legal threat—the attorney, law firm, client, evidence, or claim—and then diminish or eliminate its practical effectiveness by isolating the target, undermining credibility, obstructing access to decision-makers, and discouraging continued efforts to obtain justice.

Farrow and his collaborators ultimately translated the expert findings and the mapped complexity of the cAPTure attack model into predictive frameworks and practical educational materials. Those materials address the continuing risks presented by latent compromises within judicial and court-adjacent digital systems and became the foundation for a Technology CLE course designed specifically for legal professionals.

The course emphasizes cyber-resilience habits and repeatable professional routines: verifying trusted communications, recognizing docket and email anomalies, preserving evidence, using out-of-band reporting channels, and escalating concerns while meaningful mitigation and containment remain possible. Its purpose is to help attorneys, law firms, courts, and other interested institutions identify advanced attacks early enough to protect clients, careers, reputations, businesses, and families—and to preserve access to justice before a technical compromise becomes an irreversible legal outcome.

In July 2026, The Florida Bar approved NACABAR as a CLE provider and accredited its first Technology CLE course, with Jay Lewis Farrow as Featured Speaker. Live and live-cast presentations are scheduled to begin in August 2026, bringing the findings, detection methods, and resilience practices developed through the investigation directly to the legal professionals and institutions they were created to serve.

At the intersection of law, forensic analysis, field operations, data, institutional process, public service, and cybersecurity, the separate strands of Farrow’s life’s work ultimately converged into a clear purpose. The mission extends beyond documenting a particular attack or teaching technical detection – it is to build cultures of awareness, community, connection and cyber-cyber-resilency amongst attorneys, law firms, courts, investigators, cybersecurity professionals, public institutions, and other professionals such that no one is alone and no one is left behind.

Jay Lewis Farrow

Founder and Chair, National Attorneys Cybersecurity Association (NACABAR).

EXPERIENCE CATEGORY SUMMARY

Cyber Threat Intelligence Analyst | Legal-Sector Cybersecurity Consultant | Digital Forensics Analyst | Incident Response Analyst | Threat Researcher | OSINT / Cyber Investigator | Cyber Risk Analyst | Litigation-Support Cybersecurity Consultant | Court / Portal Integrity Analyst | Cybersecurity Training Lead for Law Firms | Legal Infrastructure Security Advisor | Cybersecurity Writer / Threat Intelligence Writer

STRATEGIC CYBER DEFENSE & PUBLIC-PRIVATE COLLABORATION

CISA Public-Private Cyber Defense Initiative / JCDC-Associated Forensic & Field Work | 2024 – Present

▸ Supported cyber-threat reporting, evidence organization, and forensic narrative development through federal law-enforcement reporting channels and private cyber-defense relationships.

▸ Worked with seasoned cybersecurity contributors, investigators, and public-private sources to organize evidence involving suspected intrusions into state and federal e-filing/e-service systems, court-adjacent portals, law-firm domains, and legal communications.

▸ Participated in investigation, research, and pattern mapping; converted raw artifacts and legal events into usable cyber-forensic chronology.

▸ Traveled to courts and file rooms to hand-file, retrieve, compare, and document physical, internal, and public docket artifacts, including sealed-file workflows and out-of-band anomalies.

Confidential Public-Safety / Field-Operations Support Context | c. 2017 – 2025

Seven-year private-sector support posture involving individuals working with federal law-enforcement field operations; operational identities, agency details, and sensitive specifics are intentionally withheld.

NATIONAL ATTORNEYS CYBERSECURITY ASSOCIATION (NACABAR.ORG)

Founder & Chairman | March 2025 – Present


Founder & Chairman | March 2025 – Present
Founded and leads a nonprofit platform focused on cybersecurity awareness, resilience, and support for attorneys, law firms, legal professionals, and court-adjacent stakeholders. NACABAR is the training/publication platform for this work. For more information about NACABAR.ORG, visit: https://nacabar.org/about-nacabar/

REPRESENTATIVE EXPERT CYBER-SECURITY WORK PRODUCT & REPORTS

Work ProductRole / Investigative Scope
Cyber-N.E.T. Forensics Integrated e-Forensic Report 

Principal drafter/final editor and investigative/logistical coordinator. Participated in evidence review and pattern mapping for the cAPTure APT: endpoint artifacts, court filings and dockets, DNS/MX/SOA/registrar histories, Florida Bar and e-filing portal indicators, judicial-communication anomalies, email metadata, synchronized update windows, C2 infrastructure overlays, MITRE mapping, attribution findings, and containment recommendations.  A copy of the full Cyber-N.E.T. Forensics Integrated Report is available at:  https://cyberlawlibrary.org/reports/cyber-n-e-t-forensics-expert-report/
Cryptographic Cyber-Defense Group Expert Report 

Principal drafter/final editor. Built the cryptographic-counterfeit communications analysis: DKIM/SPF/DMARC and relay-path review, endpoint-to-email correlation, Florida e-service artifacts, Bar and court communications, compromised-service-channel indicators, and authentication evidence showing how messages can appear technically valid while operationally counterfeit. A copy of the Cryptographic Cyber-Defense Group Expert Report is available at:  https://cyberlawlibrary.org/reports/1861/
Bridge-Gate E.S.S. / Restricted-Access Portal Solutions Report

Principal drafter/final editor. Analyzed CM/ECF, legacy .dcn and .sso infrastructure, SMTP relay behavior, restricted-access portal workflows, sealed-case intake, internal-vs-public docket divergence, physical file-room artifacts, missing notices, and procedural consequences of portal compromise. This report is not part of the public record at this time, but a non-confidential executive summary can be made available upon request.
ORACLE Logistics Team Avatar / Persona Reports

Principal drafter/final editor. Documented identity-layer manipulation, synthetic or placeholder legal actors, reputation laundering, compromised professional credentials, forged institutional communications, service-list contamination, and recovery-path risk in legal proceedings. This report is not part of the public record at this time, but a non-confidential executive summary can be made available upon request.
Sinkhole / Domain Suppression Report

Principal drafter/final editor. Analyzed registrar-level sinkholing, clientHold status, DNS trust degradation, Route 53/cloud routing, email deliverability loss, website takedown effects, de-indexing, backlink decay, and professional digital-identity disruption. This report is not part of the public record at this time, but a non-confidential executive summary can be made available upon request.
Federal Court Cyber-Infrastructure Audit Report/ V.E.R.I.T.A.S. Analysis of CM/ECF and Legacy Server/Endpoints

Principal drafter/final editor. Audited sealed-case intake and federal docket irregularities, including missing docket-entry numbers, malformed or off-docket orders, filing-fee and service anomalies, internal court URLs, and discrepancies among physical, internal, and public records. This report is not part of the public record at this time, but a non-confidential executive summary can be made available upon request.

CORE LOGISTICAL AND FORENSIC OPERATIONS

High-Trust Security InventoryMap people, online personas, professional credentials, email, domains, DNS/MX records, portals, vendors, cloud storage, professional accounts, service lists, financial rails, legal/regulatory workflows, and legacy systems.
Legal-Sector Incident ResponseSupport law firms, attorneys, legal departments, litigation-support vendors, and professional organizations facing compromised credentials, spoofed notices, suspicious service-list changes, portal anomalies, vendor-payment fraud, confidentiality exposure, or the need for out-of-band verification paths.
Avatar / Persona IntegrityReview legal actors, court-adjacent contacts, lawyer directory footprints, firm branding changes, bar/public-record anomalies, and communications patterns for synthetic, placeholder, or unauthorized personas. Selected Reading: How Advanced Cyberattacks Exploit Lawyer Directories, Search, and Social Profiles by lead author Jay Lewis Farrow.
Meaningfully Timed AttributionIdentify attribution evidence while containment still matters through creating signature infrastructure maps, DNS/MX timelines, header/relay analysis, portal anomaly maps, IOCs/IOAs, preservation plans, and escalation recommendations.

EXPERIENTIAL TRAINING MODULES/PEN-TESTING/SIEM EXERCISES

Court Notice Authentication DrillVendor Email / Wire Instruction Fraud
Service-List Integrity ExerciseAttorney Credential Compromise Tabletop
Portal Login & MFA Recovery AttackAvatar / Placeholder Counsel Detection
Executive Impersonation & Urgency TrapDNS / Email Trust Basics for Legal Staff
Incident Preservation Under PressureStop-Verify-Escalate Protocol

SELECTED PUBLISHED ARTICLES BY JAY LEWIS FARROW

EDUCATION 

University of Miami School of Law – Juris Doctor, Cum Laude, 2002 | University of Florida – B.A., Political Science and Government, 1999