Researchers disclosed a chain of severe flaws in RA-MICRO's cloud-based legal software that exposed highly sensitive law-firm and client data, including downloadable backups, weakly encrypted archives, embedded credentials, broken authentication, and multiple paths to account takeover. According to the Chaos Computer Club (CCC), some backups were protected only with obsolete ZipCrypto, enabling decryption through a known-plaintext attack and revealing court files, internal notes, correspondence, contact data, and credentials for IMAP mailboxes and Germany's beA legal communications system.
The reported issues extended beyond backup exposure to include credentials in public JavaScript, installation scripts, and backend source code, reconstruction of the JWT signing secret, plaintext password storage, creation of administrator accounts via an apparent test-account mechanism, subdomain takeover, and exposure of private TLS keys through an API. CCC said researchers had reported initial vulnerabilities in 2025 and later uncovered broader weaknesses, while a separate report indicated police were called out overnight in connection with a zero-day incident tied to the case, underscoring the seriousness of the vendor's security failures and the legal risks faced by independent researchers in Germany.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The Chaos Computer Club published details of multiple severe security failures affecting RA-MICRO, describing exposure of sensitive legal and client data, credential leaks, and several paths to administrative compromise. The disclosure highlighted negligent security practices and the legal risks faced by independent researchers in Germany.
In August 2025, researchers reported a wider range of RA-MICRO flaws, including exposed backups, weak encryption, embedded credentials, broken authentication, account takeover paths, and other severe weaknesses. The CCC handled communication with the vendor because the researchers feared legal risks under German anti-hacking laws.
According to the CCC, the first vulnerabilities affecting RA-MICRO were reported in May 2025. These issues were part of a broader set of severe security failures in the legal-tech platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.