A summary of the ACS:Law data leak

On 24 September 2010, an archive of emails from London-based law firm ACS:Law was leaked onto the internet. The archive was unencrypted, and had been obtained as part of an ongoing campaign by internet activists to expose the firm’s copyright enforcement practices. The emails contained a great deal of personal information — which I won’t repeat here — but suffice it to say, this information was of a highly personal nature (IP addresses, filenames, names, postal addresses). ISPs were quick to respond:

“Our first concern is with our customers but we have been obliged to respond to court orders requiring that we disclose customer data. However, there is increasing evidence that there are deep concerns regarding the integrity of the process being used by rights holders to obtain customer data from ISPs for pursuing alleged copyright infringements.

We need to have further confidence that the initial information gathered by rights holders is robust and that our customers will not be treated unfairly. We are urgently exploring how this can be assured, including through the assistance of the courts.”

The only surprising aspect of this incident is that a data breach of this magnitude has not occurred sooner. Under the Digital Economy Act 2010 (UK), ISPs will be required to collate and transmit these kinds of data routinely, which will only increase their frequency. Soon after the leak, Privacy International announced that it would take legal action against the firms breach of sensitive personal details. Whether the Information Commissioner or SRA will intervene remains unclear at this stage. Ironically, the information pertained to internet subscribers alleged to have downloaded infringing films and music from P2P networks. The data themselves are now widely available on most P2P networks.

Given how lucrative the copyright enforcement business is proving for the firms concerned, it’s also unsurprising that another firm should offer to fill the void left by ACS:Law.