10 min read

The FBI Says Stop Texting. Here’s the Privilege Problem Nobody’s Discussing.

The Technology Blindspot

In a recent conversation, an attorney mentioned texting clients regularly. The obvious question: what information are you texting? Not just scheduling details, it turned out. Privileged information. Case strategy. Settlement figures. When I explained the FBI’s warning about the Salt Typhoon hack and compromised telecom networks, the response was immediate: “Hey, everyone does it. It’s a standard and convenient communication method. It’s not like my clients are targeted by nation-states or hackers.”

Denial is not a strategy.

Federal officials are urging Americans to abandon standard phone calls and text messages in favor of encrypted communications. In December 2024, CISA’s executive assistant director for cybersecurity Jeff Greene told reporters: “Our suggestion, what we have told folks internally, is not new here: Encryption is your friend, whether it’s on text messaging or if you have the capacity to use encrypted voice communication. Even if the adversary is able to intercept the data, if it is encrypted, it will make it impossible.”

Senator Mark Warner, chair of the Senate Intelligence Committee, has called the underlying breach “the worst telecom hack in our nation’s history,” noting it makes prior cyberattacks by Russian operatives look like “child’s play” by comparison. The scope keeps expanding: nine confirmed telecom carriers compromised as of late December 2024, with Recorded Future reporting additional intrusions into five more networks by January 2025. By January 2026, attackers had moved beyond telecom infrastructure to compromise email systems used by Congressional staff on House national security committees.

But there’s a question nobody in the legal profession is asking: if your client communications traverse these compromised networks, have you breached attorney-client privilege?

The Privilege Analysis

The answer depends on what you knew and when you knew it. Under the common law privilege framework, attorney-client communications lose protection when third parties access them, unless the attorney took reasonable precautions to maintain confidentiality. The question is whether using unencrypted communications over networks known to be compromised constitutes a failure to take reasonable precautions.

Before December 2024, attorneys could reasonably argue they had no specific knowledge their carriers were compromised. That defense evaporated when federal agencies publicly confirmed the breach and explicitly recommended abandoning standard telecommunications. Since that date, every attorney in the country has been on constructive notice that unencrypted calls and texts may be intercepted by foreign intelligence services.

“Everyone does it” is not a defense. “It’s convenient” is not a defense. The standard is reasonableness under the circumstances, and the circumstances changed the moment the FBI went public.

ABA Model Rule 1.6(c) requires lawyers to “make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation.” Comment 18 to the Rule clarifies that the reasonableness standard considers “the sensitivity of the information, the likelihood of disclosure if additional safeguards are not employed, the cost of employing additional safeguards, the difficulty of implementing the safeguards, and the extent to which the safeguards adversely affect the lawyer’s ability to represent clients.” When federal cybersecurity officials have publicly warned that your communication channel is compromised and recommended specific alternatives, continuing to use that channel for sensitive client communications tests the outer limits of “reasonable efforts.”

The same technology-choice-as-privilege-choice analysis that applies to email applies here with greater force, because the federal warning is now explicit. [See “The Email Disclaimer Delusion,” Morris Legal Technology Blog, 2025.]

The Difference Now

The specific threat actor matters less than the underlying reality: state-sponsored hackers maintained persistent access to telecommunications infrastructure enabling interception of unencrypted calls, messages, and metadata. According to the White House, attackers achieved “broad and full” access to vulnerable telecommunications infrastructure. In one documented case, a single compromised administrator account gave attackers access to over 100,000 routers. The attackers erased logs of their activities, and what logs remained left investigators unable to determine scope.

What makes this different from ordinary cybersecurity risk is the target list. Beyond telecom carriers, the operation compromised systems handling court-authorized access to communications used for law enforcement and intelligence investigations. That means the systems designed to enable lawful interception were themselves penetrated from outside. Attackers geo-located millions of individuals in the Washington D.C. area, identifying government targets for follow-on intelligence collection. By January 2026, they had breached email systems used by Congressional staff working on China policy, foreign affairs, intelligence, and military oversight.

For attorneys with clients involved in government contracts, national security matters, international transactions, technology transfers, or any matter touching regulatory agencies, the implications are direct. But the risk extends to any practice area. Foreign intelligence services collect information for competitive advantage across industries, not solely for espionage purposes. Client communications about mergers, litigation strategy, intellectual property, and business operations all hold value to sophisticated threat actors.

The Counterargument: Why This Matters Less Than You Think

The skeptic’s position deserves serious consideration: attorneys have always faced interception risks, from party-line telephones to fax machines to email. The legal profession has never required perfect security, only reasonable precautions appropriate to the circumstances. Most client communications do not involve matters of national security interest. The cost and friction of mandatory encryption could impede access to legal services, particularly for clients less comfortable with technology. And encrypted communications create their own problems for regulatory compliance, record retention, and litigation holds.

The access-to-justice dimension deserves the strongest version of its argument: if encrypted communication becomes the standard for sensitive client matters, attorneys serving lower-income populations face a practical barrier that their wealthier counterparts do not. A client without a smartphone data plan cannot download Signal. A client unfamiliar with two-factor authentication faces friction that reduces engagement with counsel at critical moments. These are not hypotheticals. They are documented obstacles in legal aid contexts. The counterargument does not justify ignoring the risk. It justifies differentiating the protocol — applying enhanced security to matters where the information warrants it, while maintaining accessible channels for lower-sensitivity communications.

These objections carry weight for routine matters where the sensitivity of information is low. They collapse when applied to communications that sophisticated adversaries would value. The question is not whether every text message requires Signal; it is whether attorneys handling sensitive matters can justify using communications channels that federal authorities have explicitly declared compromised. The standard is reasonableness, and reasonableness shifts when circumstances change. After December 2024, the circumstances changed.

The Law Firm Precedent

Sophisticated cyber threats to the legal profession are well documented. In June 2017, a senior associate at a DLA Piper office in the United States logged in on a Monday morning to find her system would not respond. Neither would her email. Neither would the document management system holding the closing files for a $340 million deal she was three days from finalizing. NotPetya had hit 15,000 DLA Piper computers across 40 countries simultaneously. She drove to the client’s office, borrowed a laptop, and closed the deal from a conference table that was not hers, using systems that were not hers, hoping nothing privileged had been exposed in transit. The deal closed. The post-mortem took months. DLA Piper spent 15,000 hours in IT recovery. Her experience was not unusual. It was documented.

Three years earlier, the Department of Justice had identified a different attack vector. In December 2016, DOJ indicted three individuals for hacking into the networks of at least two major law firms to steal information about pending mergers for insider trading. The scheme targeted firms handling significant M&A work, extracting confidential deal information before public announcement. The indictment alleged the hackers netted approximately $4 million in illegal profits from trading on stolen attorney-client communications. Then-U.S. Attorney Preet Bharara called the case “a wake-up call for law firms around the world.” Client files represent high-value targets because they aggregate material nonpublic information across multiple industries. Unlike attacking companies directly, breaching law firms provides one-stop shopping for deal intelligence.

Panama Papers offered the starkest example. Mossack Fonseca, a Panamanian law firm, suffered a breach that exposed 11.5 million documents totaling 2.6 terabytes of client data. The leak precipitated the resignation of Iceland’s Prime Minister, investigations across dozens of countries, and Mossack Fonseca’s closure in 2018. That firm’s failure was not merely technical; it failed to match its security measures to the sensitivity of its work.

Practice Area Implications

The telecom compromise creates differentiated risk across practice areas. National security, government contracts, and CFIUS work face the most direct exposure given the documented targeting of government officials and communications. M&A and securities practices handle time-sensitive material nonpublic information that historically attracts cybercriminals. International trade, export controls, and sanctions practices involve matters where foreign governments have direct intelligence interest. Intellectual property and technology transactions involve information with commercial and strategic value to state-sponsored actors.

Even practices that seem distant from national security concerns face exposure. Family law matters involving high-net-worth individuals can reveal financial information useful for intelligence targeting. Immigration practices may handle information about individuals of foreign government interest. Real estate transactions can implicate sensitive ownership structures. The common thread is that sophisticated threat actors collect broadly, then extract value from aggregated information.

What to Do Tomorrow

First, implement end-to-end encrypted communications for client matters involving sensitive information. Signal provides encrypted voice and text. Apple’s iMessage and FaceTime offer encryption for Apple-to-Apple communications. Microsoft Teams and Zoom offer encrypted options for professional communications. The specific platform matters less than establishing encrypted channels before they are needed.

Second, establish protocols for identifying matters requiring enhanced security measures. Not every client communication requires the same precautions, but the assessment should be deliberate rather than defaulting to convenience. Create intake procedures that flag matters involving government agencies, international transactions, publicly traded companies, high-profile individuals, or subjects of regulatory interest.

Third, document your security decisions. When a bar complaint or malpractice claim questions your precautions, the relevant inquiry will be whether you made reasonable choices based on available information. Contemporaneous documentation of your risk assessment and security measures provides evidence of deliberate professional judgment.

Fourth, train your staff. The most sophisticated encryption is useless if assistants default to unencrypted channels for convenience. Model Rule 5.3 extends supervisory responsibility to nonlawyer assistants’ conduct. Firm policies must be accompanied by training and enforcement.

Fifth, talk to your clients. Many will have their own security requirements and may already use encrypted communications. Client expectations around security should be part of engagement discussions, documented in retention agreements where appropriate.

The Principle at Stake

Abraham Lincoln observed that a lawyer’s time and advice are his stock in trade. The digital age adds one item to that inventory: the confidentiality of the channel through which that advice travels.

The attorney I described at the start of this piece was not wrong that most attorneys still use unencrypted channels for sensitive client communications. She was wrong about what that fact means. “Everyone does it” describes a current practice, not a professional standard. The relevant question is not what her peers are doing. The question is what the evidence now requires.

Before December 2024, a reasonable attorney could argue that standard telecommunications carried a reasonable expectation of privacy. That argument is no longer available. Federal agencies publicly confirmed the breach, publicly named the channel, and publicly recommended the remedy. Since that date, every attorney in the country has constructive notice that unencrypted calls and texts may traverse infrastructure a foreign adversary controls.

The attorney who acts this week does not have to justify a choice made in ignorance. She gets to document a professional judgment made in direct response to available evidence. That is not a small distinction. In a bar proceeding, in a malpractice deposition, in a client conversation where privilege is challenged, the attorney who can show a deliberate security protocol adopted when the risk became known stands in a materially different position than the attorney who assumed “everyone does it” was a sufficient answer.

The FBI issued its warning so attorneys could close that gap. Signal is free. The protocol takes an afternoon. The evidence is public record. What happens next is a professional decision, not a circumstance. Make it a deliberate one.

About the Author

JD Morris is Co-Founder and COO of LexAxiom, an AI platform for the business of law. He holds a Master of Legal Studies from Texas A&M University School of Law, a Master of Engineering from George Washington University, and dual MBAs from Columbia Business School and UC Berkeley Haas. He writes the Morris Legal Technology Blog under the series banner “The Technology Blind Spot.” Connect with him on LinkedIn at http://www.linkedin.com/in/jdavidmorris, on X at @JDMorris_LTech, or on Bluesky at @JDMorris-ltech.bsky.social.

References

1. ABA Model Rule 1.6(c) and Comments 18-19 (Confidentiality of Information).

2. ABA Model Rule 5.3 (Responsibilities Regarding Nonlawyer Assistants).

3. ABA Formal Opinion 477R (2017) — Securing Communication of Protected Client Information.

4. ABA Formal Opinion 483 (2018) — Lawyers’ Obligations After an Electronic Data Breach or Cyberattack.

5. California State Bar Formal Opinion 2015-193 (e-Discovery and Technology Competence).

6. NBC News (Dec. 3, 2024) — “U.S. officials urge Americans to use encrypted apps amid unprecedented cyberattack” (Jeff Greene quote verified).

7. CyberScoop (Dec. 27, 2024) — “White House: Salt Typhoon hacks possible because telecoms lacked basic security measures.”

8. Recorded Future / CyberScoop (Feb. 2025) — “Salt Typhoon remains active, hits more telecom networks via Cisco routers.”

9. Bank Info Security (Jan. 9, 2026) — “Salt Typhoon Hackers Hit Congressional Emails in New Breach.”

10. CISA/NSA/FBI Joint Advisory (Dec. 3, 2024) — Enhanced Visibility and Hardening Guidance for Communications Infrastructure.

11. United States v. Iat Hong et al., S.D.N.Y. (Dec. 2016) — Law Firm Hacking and Insider Trading Indictment.

12. The Conversation (Nov. 5, 2025) — “What is Salt Typhoon? A security expert explains” (Sen. Mark Warner quote).

13. Morris, JD. “The Email Disclaimer Delusion.” Morris Legal Technology Blog, 2025.

Leave a Reply

Discover more from The Technology Blind Spot

Subscribe now to keep reading and get access to the full archive.

Continue reading