The following is a hypothetical scenario. It is not a real firm or event, but it is built from the patterns the FBI's Internet Crime Complaint Center and other agencies describe in business email compromise cases. Walking through it step by step helps show where a firm can break the chain.
Consider a hypothetical eight-attorney firm that handles residential real estate closings alongside other work.
Day 1: The Quiet Compromise
A paralegal receives an email that appears to come from a document-sharing service, saying a closing package has been shared. She clicks, lands on a realistic sign-in page, and enters her Microsoft 365 password. The firm uses MFA, but the attacker's page also captures the code in real time and signs in immediately.
Nobody notices. The paralegal sees an error page and assumes the link was broken.
What could have stopped it
- Phishing-resistant MFA, such as passkeys or hardware keys, which a fake page cannot capture
- Email filtering that flags suspicious links and new sender domains
- Training that teaches people to reach shared files through bookmarks instead of email links
Days 2 to 9: Watching and Waiting
The attacker reads the paralegal's mailbox. He creates a rule that hides messages containing certain words, like "wire" and "instructions," by moving them to a rarely used folder. He studies upcoming closings, who the parties are, and how the firm writes.
What could have caught it
- Alerts for new inbox rules, especially ones that move or delete messages
- Sign-in monitoring that flags logins from unusual locations or new devices
- Managed detection and response watching identity activity around the clock
Day 10: The Strike
A buyer has a closing scheduled for the next morning. The attacker registers a domain nearly identical to the title company's and emails the paralegal's contact as the title company, with "updated wiring instructions." Meanwhile, from the paralegal's own mailbox, he sends the buyer an email with a different account number and a note about last-minute changes.
The buyer, conscientious and nervous, replies asking whether this is correct. The attacker's rule hides the reply from the paralegal, and he answers it himself.
What could have stopped it
- A firm rule that wiring instructions are never changed by email
- A warning in the engagement letter, repeated in closing instructions
- A mandatory callback to a known number before funds move, with a second person approving
Day 11: Discovery
The buyer wires funds. Later that day, the real title company asks why the money has not arrived. The firm realizes something is wrong.
The Response, Done Well
- Call the bank immediately to request a wire recall. Early action matters, and the FBI's guidance emphasizes it.
- Report to the FBI's Internet Crime Complaint Center at ic3.gov.
- Notify the cyber insurance carrier according to the policy's notice requirements.
- Contain the compromise: reset the paralegal's password, revoke active sessions, remove the attacker's inbox rules and check for other affected accounts.
- Preserve evidence such as logs and emails, and avoid wiping systems before investigators finish.
- Engage counsel and forensic help to determine what else the attacker accessed.
- Communicate with affected clients promptly and clearly. ABA Formal Opinion 483 discusses obligations after a data breach, and Rule 1.4 addresses communication. Consult ethics counsel on what is required.
- Review other matters the paralegal handled for similar exposure.
Lessons for Your Firm
- Treat mailbox compromise as a likely event, and design for detection and containment.
- Adopt phishing-resistant MFA, starting with staff who touch money.
- Alert on inbox rules, unusual sign-ins and mass forwarding.
- Make the callback rule non-negotiable.
- Warn clients repeatedly, in writing.
- Rehearse the response before a real one.
A Note on Blame
In this scenario, the paralegal did what many busy people would do. The failures were in system design: controls that relied on one person noticing one detail. Resilient firms build layers so one mistake does not become a loss.
Get Help Before You Need It
Counsel Cyber helps law firms deploy the controls above and run tabletop exercises based on scenarios like this one. If you would like to rehearse a response with your team, we can set that up.