ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Business Email Compromise Q&A for Law Firm Administrators

Straight answers to the questions administrators ask most about business email compromise, from how it works to what to do if funds have left.

4 min readBy Counsel Cyber Team

Business email compromise, usually shortened to BEC, is a category of fraud in which criminals use email to trick someone into sending money or sensitive data. The FBI's Internet Crime Complaint Center has long treated it as one of the most financially damaging types of cybercrime it tracks, and law firms, which handle large payments and trust funds, are natural targets. The following questions come up repeatedly when we talk with firm administrators.

What exactly is BEC?

It is fraud carried out through email impersonation or account takeover. Typical forms include a fake instruction to change payment details, a message that appears to come from a partner asking for an urgent transfer, a spoofed invoice from a vendor and a request from a "client" to redirect settlement funds.

Is it the same as phishing?

Related, not identical. Phishing steals credentials or installs malware, often through a link or attachment. BEC usually involves no malware at all, just persuasive words. But phishing often comes first: a stolen password gives the criminal a real mailbox from which to run BEC.

Why are law firms targeted?

Firms move large sums at predictable times, work under deadline pressure, communicate with many outside parties and often rely on email for instructions. A single successful fraud can be very profitable for the attacker.

How do criminals know so much about our deals?

Often because they have been reading someone's mailbox. After taking over an account, they monitor traffic, learn names and schedules and wait for a good moment. Sometimes it is your mailbox, and sometimes it is a client's, agent's or lender's.

What are the warning signs?

  • New or changed payment instructions.
  • Pressure to act quickly or keep things confidential.
  • A reluctance to talk by phone.
  • Slightly altered sender addresses or reply-to settings.
  • Odd grammar or tone from a usually polished sender, though many attacks are well written.
  • Requests that bypass normal approval steps.

What is the single most effective defense?

Verification by a separate channel. Any request to change payment details or send money should be confirmed by calling a known, previously verified phone number. It sounds simple because it is. The discipline is applying it every time, even for senior people and long-standing relationships.

What technical controls help most?

  1. Multi-factor authentication on every email account, which blocks many account takeovers.
  2. Email filtering to catch phishing and impersonation attempts.
  3. Email authentication (SPF, DKIM and DMARC) to make spoofing your exact domain harder.
  4. Alerts for suspicious mailbox rules, such as automatic forwarding to external addresses.
  5. Sign-in monitoring for unusual locations or impossible travel.
  6. Banking controls like dual approval and positive pay or similar services offered by your bank.

Does a good email filter solve it?

No. Filters catch many attacks, but a message from a compromised real mailbox may look completely legitimate. Technology narrows the odds; process closes the gap.

What should the written procedure say?

A one-page wire and payment procedure should state who can request and approve transfers, what documents must be on file, how details are verified, what to do when the verifier is unreachable and how to document the call. Keep it where staff can find it quickly.

What do we tell clients?

Tell them early and repeatedly that the firm will never change wire instructions by email and that they should call a known number to confirm anything unusual. Put the warning in engagement letters, closing instructions and email signatures for staff handling funds.

What if we think we sent money to a fraudster?

Speed is critical. FBI guidance generally advises:

  1. Call your bank immediately and ask it to attempt a recall.
  2. File a complaint with IC3.
  3. Notify your insurance carrier promptly.
  4. Preserve emails, headers and logs.
  5. Inform the managing partner and consult ethics counsel about client communication and any reporting duties.

The faster the bank is notified, the better the chance of recovering funds, though recovery is never guaranteed.

Will insurance cover it?

It depends on the policy. Social engineering and funds transfer fraud coverage often carries separate, lower limits and conditions, such as verification procedures. Ask your broker.

Who is responsible if a client sends money to the wrong account?

That depends on facts, contracts and law, and it is a question for counsel rather than a blog post. What is clear is that firms that can show a reasonable verification procedure and early client warnings are better positioned.

How often should we train?

Short, regular sessions beat a long annual one, and the finance and closing staff need scenarios specific to their roles. Drills that simulate a changed-instruction request are valuable.

How Counsel Cyber can help

Counsel Cyber helps law firms configure email defenses and build written payment verification procedures, and we train staff with realistic scenarios. If you would like a review of your own process, we are happy to start there.