BlackFlag Advisory is an OSINT and cyber-GRC practice — so when Tranche 2 turned Australia’s law firms into custodians of their clients’ most sensitive data on 1 July 2026, we wanted to know one thing: how well are they guarding it?
We took 20 of the country’s best-known commercial firms and looked at them exactly as an attacker would — from the outside, nothing touched, using only what is already public — to see what a threat actor eyeing seven years of fresh passports, source-of-wealth and beneficial-ownership data would find.
Every firm left a door open. Most left several. Fifteen of the twenty already had staff logins in criminal hands before we looked at anything else. Not one of the twenty came through clean.
What We Did
Everything here is passive. We did not touch, log into or interact with a single firm’s systems. We mapped only what any outsider can already see — DNS and mail records, certificates, exposed subdomains, public breach and infostealer datasets, web archives and the public web itself. It is the same outside-in view a regulator, an insurer at renewal, or an attacker choosing a target already has. No permission is required to see it, because the firms are publishing it.
The sample is 20 of Australia’s best-known commercial law firms — the tier that handles the property, corporate and trust work that brings them squarely inside Tranche 2. We report every finding de-identified and in aggregate. This is a study of a sector’s posture, not a call-out of any one firm.
The Three That Bite
Staff credentials, already exposed — 15 of 20. The single most important finding. Across the sample we recovered 168 sets of employee credentials sitting in infostealer and breach datasets — logins harvested from infected machines and dumps, circulating in the markets attackers actually shop in. The worst three firms carried 57, 51 and 19 sets each. This is the foothold that exists before an attacker does anything clever.
Impersonation infrastructure, standing ready — 12 of 20. These firms had lookalike domains that were not just registered but configured to send email — 113 in total, one firm alone accounting for 36. That is the machinery of a convincing fraud: a domain a client’s eye skims over, wired to deliver a fake settlement instruction or a change-of-account request that appears to come from the firm.
Admin doors facing the street — 8 of 20. An administrative or login interface reachable from the open internet, when it should sit behind a VPN or an IP allow-list. One firm had both its live admin panel and its pre-production (UAT) admin login public — the test environment, usually the softer one, advertised alongside the real thing.
The Chain That Matters
Any one of these, on its own, is a shrug. A missing header. A stale credential. A domain someone registered. The story is in the combination — and eleven of the twenty firms combined confirmed credential exposure with either a missing browser-side protection or email authentication left short of enforcement. That is not a checklist of unrelated gaps; it is a sequence.
Read together, the pattern describes a firm where an attacker has a plausible route: a leaked credential or an exposed panel to get in, a weak page or a spoofable channel to work with, and a convincing lookalike to reach the client at the other end. We have confirmed the ingredients at each stage. We have not demonstrated entry — and we make no such claim. But the loaded chain is the point, and for a custodian of KYC and settlement data, the worst case at the end of it is client funds redirected and identity documents gone.
Where They Did Well
It would be dishonest to write only the failures. Email authentication — the thing most people assume law firms get wrong — was the sample’s strongest area: sixteen of the twenty enforced SPF, and twelve were at full DMARC reject. Every firm, when we checked properly, published a privacy policy. These are not slapdash organisations. That is exactly what makes the rest of the picture worth attention: these are well-resourced, well-run firms, and the exposure is there anyway — because it lives on the outside edges that internal security programmes rarely look at.
The Tranche 2 Problem
Here is why the timing matters. From 1 July 2026, the AML/CTF “Tranche 2” reforms make many of these firms AUSTRAC reporting entities. To comply, they must now collect and retain a concentrated store of their clients’ most sensitive data — identity documents, source of funds, source of wealth, beneficial ownership, politically-exposed-person status — and keep it for seven years.
This is not our inference. In the sample, firms document it themselves: two of the privacy policies we read — both updated within weeks of commencement — itemise exactly this. Passports and identity documents. Source of wealth. Beneficial owners over 25 per cent. PEP screening. Seven-year retention for AML/CTF records. The firms are telling their clients, in writing, what treasure they now hold.
And this sector is not starting from a clean sheet: legal, accounting and management services already sit among the most-breached sectors in the country, with 81 notifications to the OAIC in 2025. A cohort already reporting breaches at volume has just been made custodian of far more of exactly the data attackers want.
What This Means
For the firms, the uncomfortable read is that none of this required sophistication to find. A passive scan, an afternoon, no system touched. If we can see it, so can anyone — and the firms that treat the external exposure as seriously as the AML enrolment are the ones that will not be explaining a breach of client identity data to a board, an insurer and a regulator at the same time.
For their clients, the point is simpler: the firm holding your passport and your source-of-funds evidence is a target now in a way it was not last month. It is a fair question to ask them what they can see of their own outside edge.
And it points at the broader gap. The bodies meant to lift this sector’s posture are stretched: one regulator absorbing tens of thousands of newly-captured entities, compliance that leans heavily on self-assessment. Independent, outside-in assurance is not a competitor to that system — it is the checking the system cannot currently do at scale.
A Note on Method
Two disciplines run through everything above. First, confirmed versus probable: credential exposure and email posture we read directly and report as fact; anything inferential we hedge or leave out. Second, exposed versus breached: we report the openings, never a claim of entry we cannot show. The findings are de-identified and aggregated by design — the value is the pattern across a sector, not a spotlight on any firm. Where a specific, serious exposure exists, the responsible path is a quiet word to the firm, not a paragraph in an article.
Sources
The scan data is BlackFlag Advisory’s own passive OSINT assessment. Regulatory context is drawn from primary sources; confirm current dates and scope against AUSTRAC directly.
- Department of Home Affairs — Overview of the AML/CTF Amendment Act (Tranche 2)
- Law Society of NSW — When legal services trigger Tranche 2 AML/CTF obligations
- OAIC — Data breach notifications increase to all-time high in 2025 (legal & accounting among top sectors)
- OAIC — About the Notifiable Data Breaches scheme
Frequently asked questions
Did BlackFlag access any of the firms’ systems?
No. The assessment was passive OSINT only — it used publicly available data and did not touch, log into or interact with any firm’s systems. It is the same outside-in view a threat actor, a regulator or an insurer already has.
Are the law firms named?
No. All findings are reported de-identified and in aggregate. This is a study of a sector’s posture, not a call-out of individual firms. Where a firm has a serious, specific exposure, the right course is quiet disclosure to that firm, not publication.
Does “exposed” mean the firms were breached?
No. Exposure is not entry. A reachable admin interface is not a breached one; leaked credentials in a dataset are not proof of current access. We report confirmed exposure — the openings an attacker would work with — not exploitation.
What is Tranche 2 and why does it matter here?
From 1 July 2026, AML/CTF “Tranche 2” reforms make many law firms AUSTRAC reporting entities. They must now collect and retain sensitive client identity and source-of-funds data for seven years — making them larger custodians, and larger targets, exactly as this assessment was run.