SE Security

August 3, 2026
BY PHILIP ROBB
7 MIN READ

All posts

Wire Fraud at a Law Firm: Stopping Business Email Compromise

How attackers impersonate a partner or opposing counsel to reroute a closing wire, why the money is usually gone once it clears, and the controls that stop it.

A closing is set for Friday. Thursday afternoon an email arrives that looks like it came from opposing counsel, with updated wire instructions. New bank, new account number, apologetic note about a last-minute change. Somebody at the firm sends the funds.

That is business email compromise, and it is the crime most likely to take real money out of a small law firm. Not ransomware. A convincing email about a wire.

Why law firms get picked

Attackers follow the money and the calendar. A firm handling closings, settlements, or estate distributions moves large sums on a schedule outsiders can see from the docket.

Then there is the trust account. Once IOLTA funds leave on bad instructions, the firm is on the hook. That is a malpractice claim and a bar problem before it is an IT problem.

How they get inside the conversation

Two ways, and the second one is worse.

Lookalike domains. The attacker registers a domain one character off from the firm or from opposing counsel. smithlawtx.com becomes smith1awtx.com. On a phone screen, nobody catches it.

A real mailbox. Someone’s credentials got phished months ago. The attacker sits in the mailbox reading matter files, learning who signs off on what, and waits for a wire to line up. Then they reply inside a real thread from the real address. Nothing about the message is fake, because the account is not fake.

The second one defeats every “look for typos” training slide the firm has ever run. The email is written in the partner’s voice because the attacker read six months of the partner’s email.

The money is gone faster than the discovery

A domestic wire settles in hours. By the time the client calls asking why the funds never arrived, the money has usually moved through a receiving account and out.

There is a recall process. The FBI runs a kill-chain procedure through its IC3 complaint system that can freeze funds, and it works far better when the report goes in the same day rather than after a weekend of internal discussion.

What actually stops it

None of this is exotic. It is four controls and one rule the firm will not break.

Call-back verification on every wire. Any change to payment instructions gets verified by phone, at a number the firm already had on file, before the money moves. Not the number in the email signature. The number from the engagement letter or the title company’s website. This is the highest-value control on the list, and it costs nothing but a phone call.

Phishing-resistant MFA on email. App-based or hardware-key MFA on every mailbox, including the managing partner’s. Text-message codes are the weakest form still in wide use.

External-email banners. A visible tag on any message originating outside the firm makes a lookalike domain obvious in a thread that otherwise looks internal. Cheap to turn on, and it works on a phone screen.

Mailbox rule monitoring. After a takeover, the first move is usually a hidden inbox rule that files the victim’s replies away so the real user never sees the thread. Alerting on new forwarding and auto-delete rules catches an intrusion with no other symptom.

Written into the process, not just the training

Training reduces click rates. It does not remove the pressure a paralegal feels at 4:45 on a closing day when a partner appears to be asking for something urgently.

So the call-back rule goes in the firm’s WISP, with a named backup approver, and it applies to the managing partner like everyone else. A rule anyone can override under pressure is not a control. It is a suggestion.

If it already happened

Order of operations, same day:

  1. Call the sending bank and ask for a recall or hold in writing.
  2. File at ic3.gov with the wire details, and call the local FBI field office.
  3. Notify the carrier. Most policies have a short reporting window.
  4. Preserve the mailbox. Do not delete the messages or the rules, because they are the evidence of how the intrusion happened.
  5. Reset credentials and revoke active sessions across every account, not only the one that sent the email.

Where we come in

We build the email and identity controls that make this attack hard: phishing-resistant MFA, external banners, mail-rule alerting, and lookalike-domain monitoring. They take an afternoon to deploy and they sit under the firm’s WISP as documented process.

If nobody has checked the firm’s email security since the last vendor left, start with the free Cyber Score. It takes about two minutes, looks at what an attacker can see about your domain from outside, and emails you a written report. When you want someone in the building going through the mailboxes and the wire process, the IT Blueprint Assessment covers that. Written punch list, no obligation. Public number: (806) 370-4700.

Common questions

Is business email compromise covered by cyber insurance?

Sometimes, and often under a separate sublimit that is much smaller than the main policy limit. Social engineering and funds-transfer fraud are frequently carved out into their own coverage. Read the endorsement before assuming a wire loss is covered.

Does DMARC stop this?

It stops attackers spoofing the firm’s own domain. It does not stop a lookalike domain, and it does nothing about an attacker logged into a real mailbox. Worth configuring, not sufficient on its own.

Who should approve a change to wire instructions?

Two people, one of whom made a verification call to a previously known number. Written into the process so the answer never depends on who is in the office that day.

01 Start here

Find out where you actually stand.

Like a credit score, but for your business's cybersecurity.

It is free and takes about two minutes. You get a grade and a written report by email.

Owner-operated in Lubbock · (806) 370-4700

Call Get Score