ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Anatomy of a Closing-Day Wire Fraud Attempt and How to Stop It

A walkthrough of how a hypothetical wire-fraud scam unfolds against a law firm, where it can be stopped, and the verification steps every firm should require.

3 min readBy Counsel Cyber Team

Wire fraud against law firms follows a pattern. The details change, but the structure rarely does. Walking through a hypothetical case shows where a firm can break the chain, and why the weakest link is usually a rushed human, not a failed piece of software.

The FBI's Internet Crime Complaint Center (IC3) has described business email compromise for years as a major source of financial loss, and real estate transactions and law firm trust accounts are well-known targets.

A Hypothetical Scenario

Consider a hypothetical six-attorney firm handling a residential closing. Weeks earlier, an attacker phished a real estate agent's email password. The attacker quietly read messages, learned the closing date, the title company and the names involved, and set up a mailbox rule to hide replies.

Two days before closing, the buyer receives an email that appears to come from the law firm. The domain is one letter off from the real one. It says there has been a change to the wiring instructions and asks the buyer to use a new account. It sounds urgent and professional, and it quotes accurate details from the deal.

The buyer wires funds to the new account. By the time anyone notices, the money has moved through several accounts.

Where the Chain Could Have Broken

1. Stolen email credentials

Multi-factor authentication on every mailbox, including those of staff, would have made the initial phishing far less likely to succeed. This is the single highest-value control against account takeover.

2. Look-alike domains

Email security tools can flag messages from new or look-alike domains. Registering obvious variants of your own domain also helps, though it cannot cover every possibility.

3. Hidden mailbox rules

Monitoring for suspicious inbox rules and unusual sign-in locations is a detection control that catches attackers who are already inside.

4. The buyer's trust

This is where a firm's process matters most. If every client is told at the start of the matter how wiring instructions will be delivered and that they will never change by email, a change request becomes a red flag instead of a routine update.

Procedures Every Firm Should Adopt

  1. Give wire warnings at intake and again before closing. Written, in plain language, saying that your firm will never change wiring instructions by email.
  2. Verify by phone using a known number. Never use a phone number from the email in question. Use a number already on file.
  3. Require dual approval for outgoing wires above a set threshold, with a second person independently confirming the instructions.
  4. Use a secure portal for exchanging instructions instead of plain email attachments.
  5. Hold first-time payees. Add a mandatory delay and extra verification for any new account.
  6. Train staff to slow down. Urgency is the attacker's main tool. Make it acceptable, even expected, to pause.

If It Happens Anyway

Speed matters. The FBI's IC3 guidance emphasizes contacting your bank immediately to request a recall of the transfer and filing a complaint promptly. Notify the receiving bank through your own, call law enforcement and preserve email logs. Then consider your professional obligations, including client communication under Model Rule 1.4 and the issues discussed in ABA Formal Opinion 483 on data breaches. Your malpractice and cyber-insurance carriers often have notice requirements, so read those policies in advance.

Make It Part of the Culture

Attackers count on routine. A closing involves many emails, many parties and constant deadline pressure, which makes one more "updated instructions" message feel ordinary. Consider adding a standing line to your closing checklist that reads, in effect, "wire instructions confirmed by phone with a known number, by whom, on what date." A signed-off checklist item turns an informal habit into a record, and it gives a paralegal a reason to stop a transaction that feels rushed. Also review who in your firm can initiate and release wires, and remove access from anyone who does not need it.

Controls fail when the person at the keyboard feels pressure to hurry. Practice with simulated phishing and mock wire-change requests so staff know exactly what to do. Celebrate people who catch suspicious messages.

How Counsel Cyber Helps

Counsel Cyber deploys email security, multi-factor authentication and mailbox monitoring built specifically for law firm wire-fraud risk, and we help write the client-facing warnings and internal procedures. If you would like a wire-fraud readiness review, reach out and we will walk through your process with you.