My Dog vs. Elite Lawyers (Part 2): The 5-Year PDF Vulnerability Exposing Global Corporations
We thought Taylor Wessing made a manual mistake. We were wrong. It's an automated, firm-wide catastrophe affecting Pfizer, Just Eat, SAP, Chubb, and Valve.
The redaction script utilized by Taylor Wessing compiles using an outdated library (Aspose.PDF for .NET 20.8) which is also known to suffer from unpatched Remote Code Execution (RCE) flaws.
After publishing the first piece revealing how Taylor Wessing accidentally leaked 830 pages of sensitive Steam user data, we realized something fundamental about corporate lawyers: they are generally too self-important to manually draw black boxes on 800+ pages. No, they didn't do it manually. They used a script. And that's when the joke stopped being funny, and became a systemic, global cybersecurity crisis.
The Cheap Software Behind the Elite Facade
Forensic metadata extraction of Taylor Wessing's 830-page response revealed a processing time of exactly 36 seconds. This is the smoking gun: they didn't redact manually; they used an automated, flawed script.
To save money on proper, enterprise-grade data sanitization software, their systems rely on a generic, outdated library: Aspose.PDF for .NET 20.8. The core issue is that their script uses this outdated software to draw black vector rectangles (using re/f operators in the PDF code) over text coordinates instead of properly sanitizing and deleting the underlying text layer.
The Blast Radius: Whose Data Did Taylor Wessing Process?
We tested other files processed by Taylor Wessing for unrelated clients. They contained the exact same metadata, the exact same vulnerability, and the exact same flawed redaction script.
This vulnerability has likely been present in documents processed by Taylor Wessing since 2019. Based on their public client lists and our forensic findings, we have to ask a terrifying question regarding the data they have processed over the last five years:
- What about the millions of gamers in the Valve (Steam) ecosystem?
- What about the global GDPR compliance documents of Just Eat?
- What about the European data transfers for tech giants like SAP and Vinted?
- What about the sensitive incident reports for Chubb Insurance (where Taylor Wessing sit on their "Cyber Incident Response Team")?
- What about the highly confidential clinical data handled by Pfizer?
If Taylor Wessing used this same cheap script to "redact" documents for these corporations, they didn't hide anything. They intentionally disclosed it.
⚡️ No-Install Lifehacks (How to Check)
- The "Select All" Hack: Open the PDF in your browser. Press
Ctrl + A(Select All), thenCtrl + C(Copy), and paste it into Notepad. If the redaction is fake, the hidden text will paste right along with it. - The "Blind Search" Hack: Press
Ctrl + Fand search for common characters like "a" or "1". If the browser registers a hit and highlights the black box—the text layer is still alive.
🛠️ Safe Offline Auditing
- LibreOffice Draw: Open the PDF, click the black box, and press Delete to reveal the text underneath.
- Adobe Acrobat Pro: Use the "Edit PDF" tool to simply drag the black shapes out of the way.
Do not upload sensitive legal documents to random online PDF editors — you might be committing a data breach yourself. Only use local software.
A Legal Reminder: The 72-Hour Rule
We strongly advise Taylor Wessing to audit every single PDF they have ever sent. Under GDPR Article 33, once a data controller becomes aware of a personal data breach, they are legally mandated to notify the competent supervisory authority within 72 hours. Attempting to sweep this under the rug will only trigger maximum regulatory penalties. The clock is ticking.
