*/
© Artur Widak/NurPhoto/Shutterstock © Lev Radin/Shutterstock
Strong passwords and multi-factorial authentication are no longer enough. Sam Thomas sets out three further security measures barristers should be taking to thwart the ever-increasing threat from international hackers
The world is a tumultuous place. International crises. Economic turmoil. Polarised politics. In a world in which there are clear and obvious dangers, cyber security may seem very much secondary. But cyber threats continue to increase.
On 31 March 2026, Google identified that hackers linked to North Korea had breached Axios, behind-the-scenes software, in an attempt to steal log-in information that could enable further cyber operations. The North Korean affiliated group, UNC1069, had placed malware within Axios, a widely used JavaScript library that is commonly used in online applications and web-service functions.
Explaining the extent of the potential hack, Tom Hegel, a senior researcher at SentinelOne, said: ‘Every time you load a website, check your bank balance, or open an app on your phone, there’s a good chance Axios is running somewhere in the background making that work… You don’t have to click anything or make a mistake… The software you already trust did it for you.’
Within 24 hours of the attack by the North Korean group, a pro-Iran hacktivist group linked to Iran’s intelligence services, the Handala Hack Team, released personal information of FBI Director Kash Patel. The leak consisted of personal emails purportedly from Patel’s Gmail account. Part of a campaign of psychological warfare, the attack was designed to force targets to divert their time and resources from ongoing operations against Iran.
Such tactics are not limited to high-ranking US Officials. The attack on the FBI Director followed the leak of personal information related to employees of the defence and aerospace contractor Lockheed Martin, who were contacted by telephone and threatened that details of their families’ and children’s location would be shared online.
Threat actors know that counsel have access to sensitive personal data which could potentially be used to intimidate or blackmail others. Alternatively, counsel may be involved in providing advice directly to the state, or commercial entities associated with the state, and could themselves be targets.
These ever-increasing threats mean that previous cyber security measures, like strong passwords and multi-factorial authentication, are no longer enough. This article suggests three further security measures that could, and perhaps should, be adopted to hinder the progress of a determined international hacker.
At the beginning of 2025 the concept of ‘zero trust security models’ encompassed the concept of ‘never trust, always verify’ (see ‘Cyber strategies for 2025’, Counsel, January 2025). But with the increase in state-sponsored cyber attack (also predicted as a threat for 2025), and the sophistication of these attacks, ‘zero trust’ should be expanded beyond correspondence and communication into the apps and programs we are using. The North Korean corruption of Axios demonstrates that even trusted programmes, like the Google browser, could now be a point of weakness.
Finding a browser that values privacy can mitigate these risks. Brave and Opera are two of the strongest options for privacy. Unlike ‘Big Tech’ alternatives like Google Chrome, these browsers are designed not to collect information such as your location, browsing history or online activity. Further, neither Brave nor Opera feed your data into adverts or sell data to third parties for profit.
Privacy-first browsers may also come with additional privacy options such as built-in ad and tracker blockers that eliminate intrusive pop-ups, which not only disrupt your online experience, and on mobile browsers can quickly drain your data, but can also act as gateways to phishing attacks. If your browser prevents the pop-ups it can also prevent malware that may piggyback through these pop-ups.
Brave and Opera are open-source, which means anyone can verify their code/logging practices. Some privacy-first browsers also aim to stop fingerprint-based tracking; Brave’s fingerprint randomisation, for example, deliberately makes you appear different to different websites, making it virtually impossible for trackers, your internet service provider or other web services to build an online profile of you.
Deliberately randomising your location may seem like an action adopted by a threat actor or hacker, or the person who is doing something illegitimate or illegal, rather than a security conscious barrister. However, actions which obscure one’s personal data inhibit profiling. Similarly both Brave and Opera come with a built-in virtual private network (VPN). VPNs add an extra layer of privacy by encrypting your browser traffic. Investing in a VPN may now be an essential element to cyber security.
Public Wi-Fi is inherently insecure. It is unlikely that the local library is seeking to steal your data but the very fact that it is ‘public’, and can be accessed by anyone, means that it is an open and unsecured network. In addition to not knowing with whom you are sharing the network, public Wi-Fi will often lack the same encryption as private networks which render them susceptible to tampering or impersonation.
Man-in-the-middle attacks (MITM) allow a threat actor to position themselves between your device and the public Wi-Fi router, intercepting all communications and gaining access to sensitive information like emails, passwords and financial details. A MITM attack may slow the Wi-Fi speed but not to a noticeable level. You will effectively be sending everything to a third party and will remain entirely unaware throughout.
Alternatively, in an ‘evil twin’ attack, a hacker can pretend to be the public Wi-Fi network. This fake network imitates a legitimate public Wi-Fi hotspot and again gives the operator unrestricted access to your private information.
Avoiding public Wi-Fi networks by using your mobile phone as a hotspot may be a solution. However, this may not be possible in certain situations. Poor network coverage, remote locations or inside buildings with Wi-Fi but bad reception may require that you use the public Wi-Fi. In these circumstances, a VPN can negate MITM or evil twin attacks.
A VPN encrypts your network traffic by routing it through a secure tunnel, scrambling the data and making it unreadable to third parties. Even if a threat actor intercepts your personal data this will be encrypted and without value.
While privacy-first web-browsers may have in-built VPNs these may not be the best option. Anti-virus software providers, like ESET, now also provide a VPN as part of their protection package. Alternatively, a separate VPN may be appropriate. Ask yourself whether simplicity or functionality is important before making your choice.
It is very tempting simply to ‘accept all cookies’ on every occasion. However, malicious cookies, often found on untrustworthy or bogus websites, can be used to steal sensitive information, including your email address and even banking details. The ‘zero trust’ approach is to reject cookies on any site where you are sharing personal data. Alternatively, enter browser settings and either block cookies, clear them or both. Most browsers, including Google Chrome, also let you specifically block third-party cookies or clear stored cookies and cached data.
Third-party cookies are particularly concerning as these are not directly created by the site you are visiting but come from external sources such as advertisers and analytics companies. Third-party cookies are unlikely to come directly from malicious actors but this is far more likely than receiving malware from first-party cookies, generated by the site you are visiting. This is particularly the case when the primary site visited is well-known and well protected; think Google or BBC. However, given the rise in state-sponsored cyber threats, rejecting all cookies, using a privacy-first browser and a VPN are security measures worth taking.
Pictured top left: In early April 2026, Handala Hack Team, linked to Iran’s intelligence services, targeted FBI Director Kash Patel. The leak consisted of personal emails purportedly from the FBI Director’s Gmail account. Top right: In late March 2026, Google discovered that North Korean affiliated group UNC1069 had placed malware within Axios, behind-the-scenes software commonly used in online applications and web-service functions.
The world is a tumultuous place. International crises. Economic turmoil. Polarised politics. In a world in which there are clear and obvious dangers, cyber security may seem very much secondary. But cyber threats continue to increase.
On 31 March 2026, Google identified that hackers linked to North Korea had breached Axios, behind-the-scenes software, in an attempt to steal log-in information that could enable further cyber operations. The North Korean affiliated group, UNC1069, had placed malware within Axios, a widely used JavaScript library that is commonly used in online applications and web-service functions.
Explaining the extent of the potential hack, Tom Hegel, a senior researcher at SentinelOne, said: ‘Every time you load a website, check your bank balance, or open an app on your phone, there’s a good chance Axios is running somewhere in the background making that work… You don’t have to click anything or make a mistake… The software you already trust did it for you.’
Within 24 hours of the attack by the North Korean group, a pro-Iran hacktivist group linked to Iran’s intelligence services, the Handala Hack Team, released personal information of FBI Director Kash Patel. The leak consisted of personal emails purportedly from Patel’s Gmail account. Part of a campaign of psychological warfare, the attack was designed to force targets to divert their time and resources from ongoing operations against Iran.
Such tactics are not limited to high-ranking US Officials. The attack on the FBI Director followed the leak of personal information related to employees of the defence and aerospace contractor Lockheed Martin, who were contacted by telephone and threatened that details of their families’ and children’s location would be shared online.
Threat actors know that counsel have access to sensitive personal data which could potentially be used to intimidate or blackmail others. Alternatively, counsel may be involved in providing advice directly to the state, or commercial entities associated with the state, and could themselves be targets.
These ever-increasing threats mean that previous cyber security measures, like strong passwords and multi-factorial authentication, are no longer enough. This article suggests three further security measures that could, and perhaps should, be adopted to hinder the progress of a determined international hacker.
At the beginning of 2025 the concept of ‘zero trust security models’ encompassed the concept of ‘never trust, always verify’ (see ‘Cyber strategies for 2025’, Counsel, January 2025). But with the increase in state-sponsored cyber attack (also predicted as a threat for 2025), and the sophistication of these attacks, ‘zero trust’ should be expanded beyond correspondence and communication into the apps and programs we are using. The North Korean corruption of Axios demonstrates that even trusted programmes, like the Google browser, could now be a point of weakness.
Finding a browser that values privacy can mitigate these risks. Brave and Opera are two of the strongest options for privacy. Unlike ‘Big Tech’ alternatives like Google Chrome, these browsers are designed not to collect information such as your location, browsing history or online activity. Further, neither Brave nor Opera feed your data into adverts or sell data to third parties for profit.
Privacy-first browsers may also come with additional privacy options such as built-in ad and tracker blockers that eliminate intrusive pop-ups, which not only disrupt your online experience, and on mobile browsers can quickly drain your data, but can also act as gateways to phishing attacks. If your browser prevents the pop-ups it can also prevent malware that may piggyback through these pop-ups.
Brave and Opera are open-source, which means anyone can verify their code/logging practices. Some privacy-first browsers also aim to stop fingerprint-based tracking; Brave’s fingerprint randomisation, for example, deliberately makes you appear different to different websites, making it virtually impossible for trackers, your internet service provider or other web services to build an online profile of you.
Deliberately randomising your location may seem like an action adopted by a threat actor or hacker, or the person who is doing something illegitimate or illegal, rather than a security conscious barrister. However, actions which obscure one’s personal data inhibit profiling. Similarly both Brave and Opera come with a built-in virtual private network (VPN). VPNs add an extra layer of privacy by encrypting your browser traffic. Investing in a VPN may now be an essential element to cyber security.
Public Wi-Fi is inherently insecure. It is unlikely that the local library is seeking to steal your data but the very fact that it is ‘public’, and can be accessed by anyone, means that it is an open and unsecured network. In addition to not knowing with whom you are sharing the network, public Wi-Fi will often lack the same encryption as private networks which render them susceptible to tampering or impersonation.
Man-in-the-middle attacks (MITM) allow a threat actor to position themselves between your device and the public Wi-Fi router, intercepting all communications and gaining access to sensitive information like emails, passwords and financial details. A MITM attack may slow the Wi-Fi speed but not to a noticeable level. You will effectively be sending everything to a third party and will remain entirely unaware throughout.
Alternatively, in an ‘evil twin’ attack, a hacker can pretend to be the public Wi-Fi network. This fake network imitates a legitimate public Wi-Fi hotspot and again gives the operator unrestricted access to your private information.
Avoiding public Wi-Fi networks by using your mobile phone as a hotspot may be a solution. However, this may not be possible in certain situations. Poor network coverage, remote locations or inside buildings with Wi-Fi but bad reception may require that you use the public Wi-Fi. In these circumstances, a VPN can negate MITM or evil twin attacks.
A VPN encrypts your network traffic by routing it through a secure tunnel, scrambling the data and making it unreadable to third parties. Even if a threat actor intercepts your personal data this will be encrypted and without value.
While privacy-first web-browsers may have in-built VPNs these may not be the best option. Anti-virus software providers, like ESET, now also provide a VPN as part of their protection package. Alternatively, a separate VPN may be appropriate. Ask yourself whether simplicity or functionality is important before making your choice.
It is very tempting simply to ‘accept all cookies’ on every occasion. However, malicious cookies, often found on untrustworthy or bogus websites, can be used to steal sensitive information, including your email address and even banking details. The ‘zero trust’ approach is to reject cookies on any site where you are sharing personal data. Alternatively, enter browser settings and either block cookies, clear them or both. Most browsers, including Google Chrome, also let you specifically block third-party cookies or clear stored cookies and cached data.
Third-party cookies are particularly concerning as these are not directly created by the site you are visiting but come from external sources such as advertisers and analytics companies. Third-party cookies are unlikely to come directly from malicious actors but this is far more likely than receiving malware from first-party cookies, generated by the site you are visiting. This is particularly the case when the primary site visited is well-known and well protected; think Google or BBC. However, given the rise in state-sponsored cyber threats, rejecting all cookies, using a privacy-first browser and a VPN are security measures worth taking.
Pictured top left: In early April 2026, Handala Hack Team, linked to Iran’s intelligence services, targeted FBI Director Kash Patel. The leak consisted of personal emails purportedly from the FBI Director’s Gmail account. Top right: In late March 2026, Google discovered that North Korean affiliated group UNC1069 had placed malware within Axios, behind-the-scenes software commonly used in online applications and web-service functions.
Strong passwords and multi-factorial authentication are no longer enough. Sam Thomas sets out three further security measures barristers should be taking to thwart the ever-increasing threat from international hackers
The age of criminal responsibility, extreme weather and conflict resolution – plus, new protocol for reporting bullying at the Bar
By David Green
Mário Barroso, Head of R&D and Method Development at AlphaBiolabs, examines the forensic science underpinning hair drug testing, its evidential scope and limitations, and why it remains the gold standard for evidencing patterns of drug use in family proceedings
Unlocking your aged debt to fund your tax in one easy step. By Philip N Bristow
Clement Cowley, Partner at The Penny Group, discusses the upcoming changes to pensions and Inheritance Tax and the potential impact on your financial future
Save the Children UK is the latest charity to benefit from a £500 donation from AlphaBiolabs via the company’s Giving Back initiative
Can reflective practice – a staple in other professions – meaningfully support the Bar? Emma Cross reports back from last year’s pilot
Does your constitution comply? The Harman Report provides impetus to update yours – and the sooner the better. Scott Leonard explains how
A decade of reviews and research has disrupted accepted thinking in the search for causality. Suicides following abuse have overtaken domestic homicides. Is the law keeping up? Professor Susan Edwards KC (Hon) examines recent cases and the obstacles to successful prosecution
Why every major sporting event needs an anti-corruption policy. By Louis Weston
At least not that way, says Richard Paige