Free Resource · guide

How Do Law Firms Protect Trust Accounts and Settlements from Wire Fraud?

The control that stops a fraudulent settlement wire is a procedure, not a product: verify every payment instruction and every change to wiring details by phone, on a number your firm already had on file, never one supplied in the email that asked. Around that procedure you layer MFA on every account, email authentication, mailbox-rule monitoring, and training for everyone who touches money. Law firms are targeted because settlement timing is often visible to outsiders, opposing counsel and title companies are easy to impersonate, and trust-account money moves on the strength of an email.

The most expensive email a law firm ever receives looks completely routine. It arrives in a real thread, days before a settlement disburses or a closing funds, and it says the wiring instructions have changed. The sender is opposing counsel, or the title company, or the client. The account number is the only lie in it.

By the time anyone calls to ask where the money is, it has usually been moved through two more banks. Business email compromise is consistently among the most expensive crime categories the FBI’s Internet Crime Complaint Center tracks, and firms that move client money on email instructions are among its most natural targets. Here is how the attack actually works against a law practice, the procedure that defeats it, and what to do in the first hour if funds have already moved.

Why settlements and trust accounts draw this attack

Wire fraud against law firms isn’t opportunistic. It’s scheduled. Litigation activity, settlement announcements, and closing dates give an attacker something almost no other target offers: advance notice that a specific, large payment is about to move between specific parties who communicate by email. The attacker’s job is simply to get into the middle of that conversation before the money does.

Trust accounts raise the stakes further. The funds are the client’s, the duty to safeguard them is the firm’s, and Texas disciplinary rules don’t grade on the sophistication of the fraud. A firm that wires client funds to a criminal’s account still owes the client the money, and typically faces a malpractice claim and a bar grievance on top of the loss.

The three plays firms actually see

These are the recurring patterns across the industry, not any specific client’s story:

  1. The compromised counterparty. An attacker phishes their way into a mailbox at opposing counsel, a title company, or a client, reads quietly until disbursement is discussed, then sends revised wiring instructions from the genuine account. Replies are often hidden from the real owner by a forwarding rule the attacker planted. Every technical check passes, because the email is real. Only the account number changed.
  2. The lookalike domain. The attacker registers a domain one character off from a party in the matter and joins the thread at the moment instructions are expected. Under deadline pressure, with a cloned signature block and a plausible thread history, the swap goes unnoticed.
  3. The compromised firm mailbox. The attack runs in reverse: your firm’s mailbox is the one compromised, and your clients receive “updated instructions” from their own lawyer. The client takes the loss, and the firm inherits the breach notification, the relationship damage, and the question of how long the intruder was reading privileged mail.

The procedure that stops the wire

Every technical control below matters, but the one that reliably stands between a convincing email and a lost settlement is a rule simple enough to fit on an index card:

No funds move on emailed instructions alone. Every new payment instruction, and every change to existing instructions, is verified by phone on a number the firm already had on file before the request arrived. No exceptions, including for partners, including under deadline pressure.

The “no exceptions” clause is the load-bearing part. Attackers don’t schedule their emails for quiet weeks; they time them for the Friday afternoon a closing has to fund. A procedure with a deadline exception is a procedure the attacker controls.

The layers around the procedure

  • MFA on every account, especially email, so a phished password alone doesn’t hand over a mailbox full of privileged threads and settlement timing.
  • Email authentication (SPF, DKIM, DMARC) enforced, which shuts down the exact-domain spoofing plays and flags lookalikes.
  • Mailbox-rule monitoring, because the hidden forwarding rule is the attacker’s favorite tool, and it’s detectable the moment it’s created.
  • Advanced email filtering to shrink the volume of phishing that reaches the people who touch money.
  • Awareness training with legal-specific scenarios, so the person handling the disbursement recognizes the play on sight, not just in the annual training module.
  • Tested backups and an incident-response plan, so a compromise is an incident with a playbook instead of an improvisation. Our cybersecurity services bundle these controls, and a risk assessment will show you which are already in place at your firm and which aren’t.

The first hour, if money already moved

Speed matters more than blame. Call the sending bank’s fraud department and request a recall and freeze, and ask them to contact the receiving bank. File at ic3.gov immediately; the FBI’s recovery process is meaningfully more effective in the first hours. Preserve the original messages with full headers. Then assume the involved mailbox is still compromised: reset credentials, check for hidden rules, and keep all incident communication off that account. If your firm doesn’t have an IT partner to run that response, call one anyway. We take those calls from firms that aren’t clients yet.

Wire-fraud defense is one piece of what IT support built for law firms should cover, alongside the confidentiality, uptime, and documentation obligations the rest of your practice runs on. If you’d rather find the gap before an attacker does, we’ll walk your disbursement flow with you and show you exactly where it’s exposed.

Would a swapped account number get past your firm?

Tell us how settlement disbursements and wiring instructions move through your practice. We'll trace the path an attacker would take, show where a fraudulent instruction would slip through, and lay out the verification policy and email controls that close the gap.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

What makes law firms a bigger wire-fraud target than other businesses?

Predictable, visible money movement. Settlements, closings, and disbursements are often preceded by publicly visible litigation activity or known closing dates, so attackers know when money is about to move and who will be emailing about it. Add trust accounts holding client funds and the borrowed authority of an email from counsel, and firms sit at the exact intersection this crime exploits.

The wiring change came from opposing counsel's real email address. How?

Their mailbox was compromised, not spoofed. The attacker read the thread, waited for disbursement talk, and sent revised instructions from the genuine account, often with a hidden inbox rule hiding your replies from the real owner. This is why authenticity of the sender proves nothing about a payment instruction. Only an out-of-band callback does.

Is a misdirected settlement wire covered by malpractice insurance?

Sometimes, partially, and never comfortably. Coverage depends on your policy's social-engineering and cyber endorsements, sub-limits are often far below settlement size, and insurers examine whether your firm followed its own verification procedures. Written callback verification is both the defense and the thing your carrier will ask about. Confirm your coverage before you need it, not after.

What is the firm's exposure if trust-account funds are stolen?

The client's money is gone but the client is still owed it, so the firm typically faces making the client whole, a malpractice claim, a bar grievance under the trust-accounting and safekeeping rules, and the reputational damage of explaining the loss. Texas disciplinary rules treat trust funds as sacrosanct regardless of how sophisticated the fraud was. That asymmetry is why prevention is the only good outcome.

What should we do in the first hour if money already moved?

Call the sending bank's fraud department, request a wire recall and a freeze, and ask them to contact the receiving bank. File at ic3.gov, the FBI's Internet Crime Complaint Center, immediately, since recovery works best in the first hours. Preserve the emails with full headers, assume the involved mailbox is still compromised, reset credentials, and check for hidden forwarding rules before sending any email about the incident.

Will email filtering catch these messages?

Not reliably. A message sent from a genuinely compromised account at opposing counsel, a title company, or a client passes every technical check because it is technically legitimate mail. Filtering and authentication shrink the attack surface and stop the lookalike-domain plays, but the callback procedure is the layer that stops the loss.

How do we roll out callback verification without slowing down closings?

Make it a standing rule with no exceptions and no judgment calls: every new payment instruction and every change to existing instructions gets verified by phone on a previously known number before funds move. It adds minutes, not days, and clients and counsel increasingly expect it. The firms that get burned are the ones that made exceptions under deadline pressure, which is precisely the pressure attackers schedule around.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.