The temporary disruption to Michigan's online bar exam Tuesday was the result of a cyberattack, officials said. But some test takers and experts aren't buying that explanation, saying it's more likely that the website of the outside vendor administering the test was simply overwhelmed at a critical moment.

Law graduates and attorney licensing entities were closely monitoring Michigan's exam, as it's the first-ever online bar exam—a route an increasing number of jurisdictions are taking amid the COVID-19 pandemic. At least 22 jurisdictions plan to give online bar exams in August and October. The Indiana Supreme Court announced Wednesday that the remote bar exam it plans to give Aug. 4 will be open book and delivered via email after remote administration software it initially planned to use failed tests.

Some of the more than 700 people taking the Michigan exam were locked out of the second of five test modules for close to an hour Tuesday when they couldn't retrieve the password they needed to get into the exam. The Michigan Board of Bar Examiners said after the test ended Tuesday that the password problem was caused by a deliberate cyberattack, or a distributed denial of service (DDOS) on ExamSoft, the vendor Michigan used to administer the test. (DDOS attackers disable servers by overwhelming them with traffic.)

"The first hour-long module was completed without incident; however, prior to the start of the second module, ExamSoft experienced a distributed denial of service (DDOS) cyber-attack that prevented some test takers from accessing their passwords," according to a statement from the board. "After a short delay for some applicants, ExamSoft was able to successfully thwart this attack, and at no time was any test taker data compromised."

But there is mounting skepticism of that explanation, with some exam watchers saying that placing the blame on an outside cyberattack could be an attempt by vendor ExamSoft to cover up design flaws in its testing software. Casey Cheney, a 2020 graduate of Wayne State University Law School who took the exam, said that candidates were able to access the password for the first module of the exam 35 minutes ahead of time, allowing traffic to the password site to be spread out. But the password for the second module—where the problem arose—was released just five minutes ahead of time and the rush of test takers to the password site may have swamped ExamSoft's server, he said.

"It could have been a coordinated DDOS attack, but we have yet to see any evidence of that, nor have we seen what this attack was even trying to accomplish," Cheney said Wednesday. "We also know that this is the first time ExamSoft has ever hosted a remote online bar exam, that it was beta-testing the software for it in May, and that it has a track record of failing when lots of people try to use the system at once."

Dallas-based ExamSoft issued a statement Tuesday evening that it was the victim of a DDOS attack five minutes before the second module of the exam was due to start. The company said it's the first time it has been targeted by a DDOS at the network level.

"This was a sophisticated attack specifically aimed at the login process for the ExamSoft Portal which corresponded with an exam session for the Michigan Bar," the statement said. "At no time was any data compromised by this attack. ExamSoft was able to successfully thwart this attack, albeit with a minor delay."

Asked for further comment Wednesday, the company said it's focusing on ensuring the security of future bar exams.

"While we will be adding additional technology to significantly shorten or eradicate any delay or disruption from this type of attack in the future, our system worked as designed and stopped the attack promptly and appropriately without any comprise of data or any software corruption," it said in a prepared statement.

Vania Smith, a recent graduate of Catholic University of America Columbus School of Law, said it's unclear what motive cyberattackers would have to launch a DDOS attack on the bar exam.

"What's the goal?" said Smith, who is organizing advocates for an emergency diploma privilege in Washington, D.C. "Why would someone want to attack the password retrieval site? There seems to be no explanation as to why such an action would benefit anyone."

Cheney noted that the bar authorities in Michigan initially said the delay was due to a "technical glitch" and only blamed a DDOS after the exam had concluded. "This reads like a PR stunt to me," he said. "Rather than 'ill-equipped exam-proctoring company mishandles online bar exam,' it becomes 'exam-proctoring company thwarts cyberattack attempting to foil online bar exam, no data compromised.'"

Whether the problems were due to a targeted cyberattack or a poorly designed system, Michigan's bar exam should serve as a red flag to other jurisdictions planning online exams, said Tom McMasters, a technology and data privacy lawyer who has been tracking the move to online bar exams. ExamSoft should have tested its software to ensure its servers could handle the demand from bar takers, and also taken steps to ward off potential DDOS attacks, he said.

"This wouldn't be particularly encouraging to me as a state bar examiner planning who is planning an exam on Oct. 5 and 6, when many states are doing that," he said. "You either have not enough server capacity or a back end that was not well-designed. The other choice is that there was a denial of service attack, which is a well-known kind of attack that anyone putting a server on the internet needs to be able to defend themselves against."

McMasters noted that Indiana postponed its one-day online bar exam from Tuesday to Aug. 4 after a July 24 test by vendor ILG Technologies failed. ILG had held a mock exam with all test takers to see if its system would hold up. "It did not work, but I applaud them for doing that," he said.

But the Indiana Supreme Court ultimately decided Wednesday to abandon its plan for a remotely proctored bar exam due to the ongoing technical problems.

"The software testing company, ILG Technologies, was unsuccessful in correcting the problems which prevented some users from logging onto the test and created typing delays for other applicants," the court wrote.

Now, the Aug. 4 exam will be open book, without proctoring. The Indiana Board of Law Examiners will email the test questions to candidates, and they will email back their responses.

It remains to be seen whether these early online bar exam issues will prompt other jurisdictions to modify their plans. Part of the problem is that remote testing companies like ExamSoft and ILG Technologies are rushing to create products that can meet the new demand brought on by the pandemic, McMasters said.

"Of course with COVID, the demand for this has gone through the roof," he said. "There are a few companies scrambling to meet this need in an extremely compressed time frame. These state bar examiners either don't have the technical capability or the interest to do the due diligence required to make sure these projects are proceeding as they need to.