The most expensive email a law firm ever receives looks completely routine. It arrives in a real thread, days before a settlement disburses or a closing funds, and it says the wiring instructions have changed. The sender is opposing counsel, or the title company, or the client. The account number is the only lie in it.
By the time anyone calls to ask where the money is, it has usually been moved through two more banks. Business email compromise is consistently among the most expensive crime categories the FBI’s Internet Crime Complaint Center tracks, and firms that move client money on email instructions are among its most natural targets. Here is how the attack actually works against a law practice, the procedure that defeats it, and what to do in the first hour if funds have already moved.
Why settlements and trust accounts draw this attack
Wire fraud against law firms isn’t opportunistic. It’s scheduled. Litigation activity, settlement announcements, and closing dates give an attacker something almost no other target offers: advance notice that a specific, large payment is about to move between specific parties who communicate by email. The attacker’s job is simply to get into the middle of that conversation before the money does.
Trust accounts raise the stakes further. The funds are the client’s, the duty to safeguard them is the firm’s, and Texas disciplinary rules don’t grade on the sophistication of the fraud. A firm that wires client funds to a criminal’s account still owes the client the money, and typically faces a malpractice claim and a bar grievance on top of the loss.
The three plays firms actually see
These are the recurring patterns across the industry, not any specific client’s story:
- The compromised counterparty. An attacker phishes their way into a mailbox at opposing counsel, a title company, or a client, reads quietly until disbursement is discussed, then sends revised wiring instructions from the genuine account. Replies are often hidden from the real owner by a forwarding rule the attacker planted. Every technical check passes, because the email is real. Only the account number changed.
- The lookalike domain. The attacker registers a domain one character off from a party in the matter and joins the thread at the moment instructions are expected. Under deadline pressure, with a cloned signature block and a plausible thread history, the swap goes unnoticed.
- The compromised firm mailbox. The attack runs in reverse: your firm’s mailbox is the one compromised, and your clients receive “updated instructions” from their own lawyer. The client takes the loss, and the firm inherits the breach notification, the relationship damage, and the question of how long the intruder was reading privileged mail.
The procedure that stops the wire
Every technical control below matters, but the one that reliably stands between a convincing email and a lost settlement is a rule simple enough to fit on an index card:
No funds move on emailed instructions alone. Every new payment instruction, and every change to existing instructions, is verified by phone on a number the firm already had on file before the request arrived. No exceptions, including for partners, including under deadline pressure.
The “no exceptions” clause is the load-bearing part. Attackers don’t schedule their emails for quiet weeks; they time them for the Friday afternoon a closing has to fund. A procedure with a deadline exception is a procedure the attacker controls.
The layers around the procedure
- MFA on every account, especially email, so a phished password alone doesn’t hand over a mailbox full of privileged threads and settlement timing.
- Email authentication (SPF, DKIM, DMARC) enforced, which shuts down the exact-domain spoofing plays and flags lookalikes.
- Mailbox-rule monitoring, because the hidden forwarding rule is the attacker’s favorite tool, and it’s detectable the moment it’s created.
- Advanced email filtering to shrink the volume of phishing that reaches the people who touch money.
- Awareness training with legal-specific scenarios, so the person handling the disbursement recognizes the play on sight, not just in the annual training module.
- Tested backups and an incident-response plan, so a compromise is an incident with a playbook instead of an improvisation. Our cybersecurity services bundle these controls, and a risk assessment will show you which are already in place at your firm and which aren’t.
The first hour, if money already moved
Speed matters more than blame. Call the sending bank’s fraud department and request a recall and freeze, and ask them to contact the receiving bank. File at ic3.gov immediately; the FBI’s recovery process is meaningfully more effective in the first hours. Preserve the original messages with full headers. Then assume the involved mailbox is still compromised: reset credentials, check for hidden rules, and keep all incident communication off that account. If your firm doesn’t have an IT partner to run that response, call one anyway. We take those calls from firms that aren’t clients yet.
Wire-fraud defense is one piece of what IT support built for law firms should cover, alongside the confidentiality, uptime, and documentation obligations the rest of your practice runs on. If you’d rather find the gap before an attacker does, we’ll walk your disbursement flow with you and show you exactly where it’s exposed.
