Sality Is Disrupted. Its Victims Still Need Answers.
The good news arrived on September 1: an international operation had disrupted Sality, a botnet that had operated since 2003. The less comfortable news was embedded in the same announcement. Work to identify infected computers, notify victims, and help with remediation was continuing. Those are not ceremonial steps after the important work is finished. For the people whose computers were compromised, they are the important work. A successful takedown changes what an attacker can do next. It does not, by itself, establish what the attacker already did.
What the operation actually accomplished
The Justice Department describes an August 31 operation involving U.S. and European authorities, CrowdStrike, and the Shadowserver Foundation. U.S. authorities seized Sality-linked domains; partners in Bulgaria, Hungary, and Romania acted against additional domains. Shadowserver is working with internet service providers and incident-response teams on victim identification, notification, and remediation. This is an operational announcement, not a judgment establishing the losses of particular victims.
CrowdStrike's September 1 technical account says the botnet could distribute malicious software to more than 15,000 infected machines. Rather than depend on one central server, infected computers communicated through a peer-to-peer network. The disruption manipulated that network's peer lists and redirected connections to defender-controlled systems, cutting the operator off from new tasking. The company also published detection information and expressly identified infections as requiring remediation.
The distinction is easy to lose in a headline. Disrupting command traffic is a specific accomplishment. It is not synonymous with removing every malicious program, reconstructing every affected transaction, or determining whether a confidential file was accessed. The technical account supports the first proposition. A victim-specific investigation has to address the others.
The attacker and the victim have different finish lines
Public enforcement is rightly concerned with denying criminals infrastructure. An affected organization has a different question: can we trust this environment enough to keep working? Those questions overlap, but neither answers the other. A national operation can be successful while an individual business still faces an expensive, uncertain recovery.
Consider the difference between present control and historical access. Evidence that a criminal can no longer send instructions does not establish when the infection began. Nor does it identify which accounts, documents, or transactions were exposed during the interval. A firm that treats the takedown as the end of its inquiry may stop precisely where its own inquiry should begin.
Nothing in the cited announcements establishes that a particular law firm was infected. The professional relevance does not require inventing one. Lawyers advise organizations confronting this distinction, and they also hold information whose significance depends on context. A settlement position, an unfiled patent strategy, and an ordinary scheduling email are not interchangeable simply because all three occupy disk space.
The proper response is neither to assume catastrophe nor to announce safety. It is to define the unanswered questions and obtain evidence capable of answering them. That sounds less reassuring than a declaration that the threat has been neutralized. It is also more useful to the person who must decide whether to send the next confidential document.
Cleanup can compete with explanation
The immediate business incentive is to restore service. The investigative need is to understand what happened. Those aims should be coordinated before restoration eliminates the evidence needed for an explanation. The FTC's breach-response guidance recommends forensic assistance, documentation, and preservation of evidence during remediation. It also cautions that stolen credentials can leave systems vulnerable even after an attacker's tools have been removed.
For counsel, the useful instruction is not an improvised command to wipe a machine or to keep it running indefinitely. Qualified responders should determine containment and preservation steps together. The lawyer's contribution is to identify why the facts matter: affected representations, contractual commitments, potential notices, disputed payments, and decisions that will later need an evidentiary basis.
This is also where the vocabulary of closure needs discipline. A restored service, an eradicated infection, and a completed investigation are different deliverables. If a provider reports that the incident is resolved, ask which deliverable it means and what remains outside the work performed. A precise limitation is more valuable than a broad assurance that nobody can later explain.
A lawyer's disclosure question does not end with the repair ticket
ABA Formal Opinion 483, issued October 17, 2018, addresses lawyers' obligations after a data breach or cyberattack. It calls for reasonable monitoring, prompt efforts to stop a suspected or detected breach of protected client information, and investigation of what occurred. Its framework includes significant impairment of legal services, not only theft. It also distinguishes routine cyber events from material compromises that trigger further duties.
Under the opinion's analysis, disclosure to affected current clients is required when material client information was actually or reasonably suspected to have been accessed, disclosed, or lost. This is ABA guidance interpreting Model Rules, not a new nationwide statute. Applicable jurisdictional rules control, and statutory notification requirements require their own analysis. The opinion does not impose the same Model Rule 1.4 notice duty toward former clients, though other law or obligations may matter.
That is a reason to separate the legal decision from the technical ticket. The person who confirms that an application works again may have neither the evidence nor the assignment to decide whether a client needs information. Conversely, the existence of malware should not be described to a client as proof that a specific document was stolen when the investigation has not established that fact.
The defensible communication distinguishes what is known, what is reasonably suspected, and what remains under investigation. It should explain the significance for the representation without pretending uncertainty has disappeared. Waiting for an impossible level of certainty can be as misleading as treating every possibility as an established loss.
The last mile of an enforcement victory
Sality's disruption deserves attention because it shows what coordinated public and private action can accomplish against persistent criminal infrastructure. It also exposes a less visible allocation of work. Authorities and security researchers can remove the operator's ability to issue new commands. Each victim still needs an answer about its own exposure, recovery, and next decisions.
My practical conclusion is that organizations should budget for those answers as part of recovery, rather than treating investigation as an optional expense once the computers work. Without an explanation, management cannot know what it has fixed, counsel cannot reliably evaluate the consequences, and clients cannot make informed choices about the information they entrust to the firm.
The public announcement is a reason for relief. For an affected organization, it is not a closing letter.
General analysis, not individualized legal or incident-response advice. The cited announcements do not identify AI Esquire or any particular law firm as a Sality victim.
Sources and further reading
Primary and industry sources used to support this page. External guidance should be reviewed in context and for your jurisdiction.
- U.S. Department of Justice, Sality disruption announcementSeptember 1, 2026. Official account of the international operation, domain seizures, and continuing victim-assistance work.
- CrowdStrike, Inside the Sality Botnet Disruption OperationSeptember 1, 2026. Participating company's technical account; its measurements and operational conclusions are attributed to the company.
- FTC, Data Breach Response: A Guide for BusinessOfficial practical guidance on investigation, preservation, remediation, and communications, checked September 2, 2026.
- ABA Formal Opinion 483October 17, 2018. Lawyers' Obligations After an Electronic Data Breach or Cyberattack. Model Rules guidance; jurisdictional law controls.