Business email compromise, often shortened to BEC, is a fraud scheme in which an attacker gains access to or impersonates a trusted email account and uses it to redirect money. The FBI's Internet Crime Complaint Center has repeatedly flagged it as among the costliest categories of cybercrime it tracks. Law firms are natural targets because they handle large transfers on tight deadlines.
The scenario below is entirely hypothetical and describes a composite pattern, not a real firm or event. Its value is in seeing where each stage could have been interrupted.
Stage 1: The initial compromise
A paralegal at a hypothetical six-attorney real estate firm receives an email that appears to be a shared document from a title company contact. The link opens a page that looks like a Microsoft sign-in. She enters her password. The page may also capture the MFA code in real time, or the firm may not have required MFA.
Where it could be stopped: Email filtering that scans links, MFA methods that resist phishing, and training that teaches staff to open shared documents by navigating directly rather than from a sign-in prompt.
Stage 2: Quiet reconnaissance
The attacker signs in and does not touch anything at first. They read messages, learn who the firm's clients are, how closings proceed, who the escrow officers are and how the firm writes to them. They may search for terms such as "wire," "closing," "invoice" and "routing."
Where it could be stopped: Alerts for sign-ins from unusual locations or devices. Monitoring that notices unusual search activity or mailbox access patterns.
Stage 3: Hiding the tracks
The attacker creates inbox rules that move messages containing certain words into obscure folders, or forward copies to an outside address. This keeps the real people from seeing replies to the fraudulent messages.
Where it could be stopped: Alerts when new forwarding or deletion rules are created, and restrictions on automatic external forwarding. Many firms never review mailbox rules.
Stage 4: The fraudulent message
Days or weeks later, a buyer is about to wire closing funds. The attacker, using the compromised mailbox or a lookalike domain, sends the buyer a message from the firm: "Our wire instructions have changed. Please use the new account below." The email thread is real, the tone is right and the timing is believable.
Where it could be stopped: A firm policy and client advisory stating that the firm will never change wire instructions by email and that any such message should be confirmed by phone. Include this warning in engagement letters and closing instructions, and repeat it on the firm's website and email signature.
Stage 5: The money moves
The buyer sends the funds to the attacker's account. The attacker typically moves it again quickly, often through several accounts, which makes recovery harder with every hour.
Where it could be stopped: The buyer's callback to a known number before sending. This single step is the most effective defense in many BEC incidents.
Stage 6: Discovery
Someone notices when the real seller or lender says funds never arrived. The firm now faces an emergency.
What a firm should do immediately
- Contact the sending bank at once and request a recall or hold. Speed greatly affects any chance of recovery.
- Report to the FBI's IC3 and local law enforcement, which can help in some cases when reports are filed quickly.
- Lock down the compromised account: reset the password, revoke sessions, remove unfamiliar MFA methods and delete malicious rules.
- Notify the managing partner, your cyber insurance carrier and, as appropriate, outside counsel.
- Preserve logs and messages for investigation.
- Consider duties to clients and others. ABA Model Rule 1.4 and Formal Opinion 483 are common reference points, and state breach laws may apply.
Prevention in layers
No single control prevents this. Layers matter.
- MFA on every mailbox, with stronger methods for high-risk users.
- Email security that detects impersonation and malicious links.
- Alerts for forwarding rules and unusual sign-ins.
- A written callback procedure for every payment instruction.
- Client education about wire fraud, delivered early and often.
- DMARC, SPF and DKIM for your own domain.
- Tested incident response plan and cyber insurance.
- Regular training with realistic examples.
The lesson
In this hypothetical, the firm had several chances to interrupt the attack, and each of them was inexpensive compared with the loss. The attack succeeded not because of advanced technology but because small gaps lined up.
Next step
Counsel Cyber helps law firms close these gaps with email security, monitoring and wire-fraud procedures. If you would like to rehearse a scenario like this with your staff, we can facilitate a tabletop exercise.