ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

A Wire Instruction Verification Checklist for Law Firm Staff

A practical call-back checklist your staff can follow before any wire leaves a trust or operating account, built to stop business email compromise.

3 min readBy Counsel Cyber Team

Wire fraud against law firms rarely looks like hacking. It looks like an ordinary email from a client, a lender or a title company with "updated" payment instructions. The FBI's Internet Crime Complaint Center has long described business email compromise as one of the costliest categories of cyber crime, and law firms are attractive targets because they hold large sums in trust for short periods.

The best defense is a written verification procedure that every person who touches money follows the same way, every time. This checklist is a starting point you can adapt to your firm.

Before the wire request is accepted

Treat every change as suspicious

Any new account number, new bank, new beneficiary name or change to routing details should trigger verification, no matter how routine the sender seems. Attackers often sit inside a compromised mailbox for days and copy the tone and timing of real conversations.

Collect instructions through a known channel

Whenever possible, get wire instructions during intake or engagement, in person, through a secure client portal, or by phone. Avoid accepting them as an attachment in a plain email thread.

The call-back step

  1. Use a phone number you already had. Pull it from your engagement letter, your practice-management record or a prior verified call. Never use a number in the email that requested the wire or in its signature block.
  2. Speak to a person. A voicemail is not verification. Confirm the bank name, the account holder name and the last four digits of the account number.
  3. Read back the amount and purpose. Ask the client or payee to confirm what the funds are for and when they expect them.
  4. Document the call. Record who you spoke with, the number dialed, the date, the time and the staff member who made the call.

Internal controls that back up the call

Require two people

One person prepares the wire and a second, separate person approves it. The approver should see the call-back documentation, not just the request. This dual control is one of the simplest ways to stop a single rushed or deceived employee from sending money to a criminal.

Set a cooling-off rule for changes

If instructions change shortly before a closing or disbursement, pause. Urgency is the attacker's main tool. A written rule that says changes require extra verification and a defined delay removes pressure from the individual employee, who can point to policy rather than argue with a demanding sender.

Confirm with the bank

Ask your bank which controls it offers: positive pay, payee name matching, dual authorization on the online portal, daily limits and call-back requirements for new beneficiaries. Turn on the ones that fit your workflow.

Warning signs to train staff to notice

  • A sender asks you to skip the usual call or says they cannot be reached by phone.
  • The email address differs by one character or comes from a free webmail account.
  • Reply-to addresses differ from the visible sender address.
  • The message insists on secrecy or extreme speed.
  • The new account is at a different bank or in a different state than before.
  • Grammar or tone shifts from earlier emails in the same thread.

What to do if a bad wire goes out

Speed matters. The FBI's IC3 guidance recommends contacting your financial institution immediately and asking it to initiate a recall, then filing a complaint with IC3. Call the bank's fraud or wire department rather than sending an email, and have the transaction details ready: date, amount, sending and receiving account information.

Separately, involve your cyber insurance carrier if you have a policy, and consider notice obligations to the affected client. ABA Model Rule 1.4 addresses communicating with clients about material developments, and your state bar may have additional guidance, so confirm with your own bar and counsel.

Put the checklist to work

A checklist only helps if people actually use it. Print it, add it to your accounting procedures, walk through it during onboarding, and run a short practice scenario twice a year. Include everyone who can see a payment request, including receptionists and paralegals.

Counsel Cyber helps law firms pair written wire procedures with technical protections such as email security filtering, multi-factor authentication and mailbox monitoring. If you would like a second set of eyes on your payment workflow, we are glad to review it with you.