ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Business Email Compromise Red Flags in Law Firm Inboxes

Learn the technical and behavioral signs of business email compromise in law firm mailboxes, and what to check the moment something looks wrong.

3 min readBy Counsel Cyber Team

Business email compromise, often shortened to BEC, is a category of fraud in which an attacker uses email to trick someone into sending money or sensitive information. The FBI's Internet Crime Complaint Center has repeatedly highlighted BEC as a high-loss form of cyber crime. Law firms are frequent targets because they hold client funds, handle closings and settlements, and communicate constantly with outside parties.

Most BEC attacks leave clues. This post covers what to look for, both in individual messages and in the mailbox itself.

Two flavors of BEC

Spoofing and lookalikes

The attacker sends a message from a fake address that resembles a real one, such as a domain with one letter changed, or uses a display name matching a partner or client. Nothing inside your systems has been breached.

Account takeover

The attacker actually logs into a real mailbox, often after stealing a password through phishing. From inside, they read conversations, learn who pays whom and when, and then insert themselves at the right moment. These attacks are harder to detect because the messages come from a legitimate account.

Message-level red flags

  • A request to change payment instructions, especially close to a closing or disbursement
  • Urgency, secrecy or reluctance to talk by phone
  • A sender who suddenly cannot take calls, is "in a meeting" or "traveling"
  • Slightly different email address, reply-to address or domain
  • Tone or phrasing that differs from the person's normal style
  • Requests for gift cards, payroll changes or W-2 style information
  • Replies that ignore earlier questions in the thread
  • Unexpected attachments or links to shared documents

None of these proves fraud. Together, they justify a phone call to a number you already have.

Mailbox-level red flags for IT and administrators

If an account has been taken over, the mailbox itself often shows evidence:

  1. New inbox rules, especially ones that forward mail externally, move messages to obscure folders such as RSS feeds, or mark messages as read. Attackers use these to hide their activity.
  2. Sign-ins from unusual locations or devices, or impossible travel between sign-ins.
  3. New multi-factor methods added to the account.
  4. Unexpected delegates or permission changes on mailboxes or calendars.
  5. Newly authorized third-party apps with access to mail.
  6. Sent items the user does not recognize.
  7. Large numbers of messages deleted around the time of a fraud attempt.

Ask your IT provider whether alerting is turned on for these events. Detection works best when it is automatic.

What to do the moment something looks wrong

  1. Stop. Do not send the payment or reply to the message.
  2. Verify by phone using a number from a trusted source.
  3. Report internally to IT and a partner, even if you are unsure.
  4. Preserve evidence. Do not delete the message. Forward it as an attachment to IT.
  5. If you suspect account compromise: reset the password, revoke active sessions, review inbox rules and MFA methods, and check for forwarding.
  6. If money has moved: call your bank's fraud department immediately, file a report with IC3 and notify your cyber insurance carrier per your policy.

Speed is critical, because recalls are most likely to succeed soon after the transfer.

Preventive controls

  • MFA on all mailboxes, ideally phishing-resistant
  • Alerts for new forwarding rules and unusual sign-ins
  • Disabling legacy authentication
  • External email banners and lookalike-domain protection
  • SPF, DKIM and DMARC for your own domain, which helps prevent others from impersonating you
  • Dual approval and call-back verification for payments

Training the humans

Give staff real examples, using anonymized or hypothetical messages, and rehearse the response steps. A paralegal who knows exactly whom to call in ninety seconds is a stronger control than any filter.

Client communication

If a compromise might expose client information, ABA Model Rule 1.4 addresses communicating with clients, and Formal Opinion 483 discusses obligations following a data breach. Consult your ethics counsel and confirm local notification rules with your state bar.

Where we can help

Counsel Cyber monitors for the mailbox warning signs above and helps firms respond quickly when something looks off. If you would like us to check your email configuration against these indicators, we can run a focused review.