The scam rarely looks like a scam. A closing is scheduled, everyone is moving fast, and an email arrives that reads exactly like your client: same signature, same tone, referencing the real matter. It says the wiring instructions have changed. The money leaves your trust account and it is gone in hours, usually through a chain of accounts that ends overseas.
Why law firms are the target
Attackers go where email instructions move large sums on deadlines. That is a law firm to the letter: trust accounts, closings, settlements, and a professional culture of responsiveness. They often compromise a mailbox weeks in advance, read quietly, and strike when a real transaction is in flight, which is why the fake email knows the details.
The prevention protocol
- Out-of-band verification, always: any new or changed payment instruction is confirmed by phone at a number you already have on file. No exceptions, including for partners in a hurry.
- Email authentication: SPF, DKIM, and DMARC configured so spoofed mail gets rejected instead of delivered.
- MFA on every mailbox, so a stolen password isn't a compromised account.
- Training with realistic simulations, because the last line of defense is the person reading the email.
- Monitoring for mailbox rules and logins that signal a quiet compromise before the strike.
If money already moved
Minutes matter. Call your bank and request a recall and a SWIFT/Fedwire trace, contact the receiving bank, file with the FBI's IC3 immediately, and invoke your incident response plan. Recovery is possible in the first hours and rare after the first days, which is exactly why the plan has to exist before you need it.
Your duty of technology competence covers this, and your clients' money depends on it. Book a 15-minute consult and we'll walk through how your firm handles payment instructions today, no pressure and no jargon.
Want this handled for you?
Grab the matching free checklist, or book a 15-minute consult and we'll map your next step.
