How Phishing Gets Into Law Firms and How to Stop It

A realistic wire-fraud near miss at a small firm shows how convincing modern phishing looks, and the simple human checks that caught it before the money left trust.

A padlock resting on a laptop keyboard beside a stack of client files
Jump to section
  1. The Email That Looked Like the Client
  2. Why Urgency Is the Real Red Flag
  3. The Phone Call That Saved the Trust Account
  4. Teaching Staff to Pause and Verify
  5. Reporting a Suspicious Message Without Shame

It was a Thursday afternoon in the middle of a real estate closing, and the email looked exactly like the client. Same name in the signature, same casual sign-off she always used, even the same slightly-too-large font. It asked the firm to send the deposit to a new account because her regular one was "under review." The clerk had the wire form half filled in before something made her stop.

That pause is the whole story. Nobody caught this with fancy software. A person noticed that something felt off, picked up the phone, and saved a trust account from a five-figure hit. Here is how the near miss unfolded, and what the firm changed afterward so it would not depend on luck the next time.

The Email That Looked Like the Client

Modern phishing is not the clumsy "Dear Valued Customer" message from a decade ago. The email that landed in the closing file had been sitting downstream of a compromised inbox for weeks. The fraudster had read the real thread between the client and the firm. They knew the file number, the closing date, the lawyer's first name, and the exact tone the client used.

What they changed was small. The reply-to address was off by one character, a lowercase L swapped for a capital I. On a phone screen, at speed, nobody would catch it. The body did only one thing: it moved the money to a different account. Everything else was copied from a genuine message.

Note. Business email compromise rarely arrives as a random spam blast. The most dangerous version comes from inside a real conversation the criminal has already been reading. Treat any change to payment details as a fresh event that must be verified, no matter how familiar the thread looks.

This is why "does it look legitimate" is a weak test. It looked completely legitimate. It was supposed to. The question that actually protects you is different, and it has nothing to do with how the message looks.

Why Urgency Is the Real Red Flag

Read the email again and the tell is not the address, it is the pressure. New account, needed today, closing at risk, please confirm quickly. Fraud runs on urgency because urgency shuts down the part of your brain that verifies. A busy clerk in the middle of a closing is exactly the target.

So the durable rule is not about spelling or logos. It is this: any message that combines money moving with a reason to hurry is suspicious until proven otherwise. That covers wire changes, "the partner needs this paid before end of day," gift-card requests, and a supposed vendor updating their banking. The specific bait changes. The urgency does not.

The email did not need to be perfect. It only needed you to be busy. The lesson from every wire-fraud file

Train people to hear urgency as a cue to slow down, not speed up. The scammer is counting on the opposite. If your staff learn one reflex, make it that the words "quickly" and "new account" in the same email mean stop, not go. Our companion piece on spotting phishing at a firm walks through more of these tells, and the broader legal tech and AI category has related reading on keeping client data safe.

The Phone Call That Saved the Trust Account

Back to Thursday. The clerk stopped, not because she spotted the character swap, but because the request broke a rule the firm had set months earlier: no change to payment details goes through without a callback to a known number. Not the number in the email. The number already on file.

She called the client's cell, the one saved in the matter file long before this email existed. The client answered, confused, and said she had not sent anything and her account had not changed. That was it. The wire never went out. The firm reported the compromised thread, warned the client to secure her own email, and closed on time using the correct account two days later.

Tip. Verify payment changes using contact details you already held before the request arrived, never the phone number or link inside the suspicious message. A criminal who controls the email will happily answer the number they put in it.

One callback beat a very good forgery. That is worth remembering when you are tempted to solve this problem with a purchase. Tools help, but the control that actually stopped the loss was a human one, made cheap and automatic by a written rule.

Teaching Staff to Pause and Verify

A rule only works if everyone knows it and nobody feels silly using it. The firms that get this right build the pause into their normal workflow so it does not depend on any single person being sharp on a bad day.

  • One written rule for money. Every change to banking or payment details triggers a callback to a pre-existing number. Put it on the wall, put it in the closing checklist, put it in the trust procedures.
  • Two sets of eyes on trust movements. A second person confirms the destination before anything leaves the trust account. See our note on billing and trust for how firms structure that review.
  • Turn on multi-factor everywhere. Most inbox takeovers start with a stolen password. Our guide to MFA for the whole firm covers the rollout without the pain.
  • A short quarterly refresher. Ten minutes, real examples, no jargon. People forget, and the fraud gets better, so repeat it.

None of this requires a big budget. It requires that verification is the default, and that the person who slows down a transaction is thanked, not scolded. If you keep matter contacts and payment details organized in one place, such as the client and matter records in A1 CMS, the "known number" is always right there when a clerk needs to check.

The message saysWhat to actually do
New account, wire it todayCall the number on file, confirm the change in person or by voice
Reply-to looks slightly oddDo not reply; open a fresh email to the address you already have
Partner needs a payment urgentlyConfirm face to face or by direct call, never by return email
Vendor updating their bankingVerify through a previously known contact before paying anything

Reporting a Suspicious Message Without Shame

The clerk did one more thing that mattered: she told the lawyer immediately, out loud, without worrying about looking overcautious. That culture is what made the difference. In firms where people fear being blamed for a "false alarm," reports get buried, and the one time it is real, nobody speaks up until the money is gone.

Make reporting boring and safe. A person who forwards a fishy email to the right inbox, or simply says "this feels wrong," should get a thank you every single time, even when it turns out to be nothing. You want a hundred false alarms, because the hundred-and-first is a wire fraud you just stopped. If a real click happens, a calm, blameless response also gets you into your backup and recovery plan faster, because people are not busy hiding the mistake.

Warn. If a payment has already gone out to a fraudulent account, speed is everything. Call your bank at once to attempt a recall, preserve the email and headers, and notify your law society if trust funds are involved. The first hour matters more than the next week.

The firm in this story did not have better software than anyone else. It had one written rule, a phone, and a culture where slowing down was allowed. That is genuinely most of the defence. Pick the single rule that fits your firm, the callback for any money change, and make it non-negotiable this week. If you want to go further, read up on keeping client information safe in cloud tools, and when you are ready to tighten the rest of your setup, the knowledge base has practical checklists to work through. Phishing gets in through people, and people, trained to pause, are exactly how you keep it out.

The A1 CMS Team

Editorial desk

Notes, guides, and product thinking from the people building A1 CMS.

Run your firm on one calm platform

Matters, billing, trust accounting, client portal, and automation, together in A1 CMS. Try it free, no card required.