Few events in a law practice carry as much risk per minute as a wire transfer. Large sums, tight deadlines and anxious clients make closings and settlements ideal targets for fraud. The FBI's Internet Crime Complaint Center has repeatedly flagged business email compromise as a major source of losses, and real estate transactions are a recurring theme in its guidance.
The pattern is simple. An attacker gets into, or convincingly imitates, an email account involved in the deal. They send "updated" wiring instructions at the last moment. Someone follows them. The money is gone within hours.
A written procedure applied consistently is the best defense. Here is one you can adapt.
Principle: Never Trust Instructions Delivered by Email Alone
Anyone can fake a sender name, and a real account can be hijacked. The rule is that no payment instruction is acted on until it is verified through a second channel the firm already trusts.
Step 1: Collect Instructions Early and Securely
- Ask for wiring instructions at the start of the matter, not the day before closing.
- Use a secure portal or encrypted method where possible, rather than plain email attachments.
- Tell clients in writing, at engagement, how the firm will and will not communicate wiring details.
Warn clients up front
Include a short notice in engagement letters and closing emails: the firm will never change wire instructions by email, and the client should call the firm at a known number if anything looks different. Clients are also targeted, and an alert client is a strong safeguard.
Step 2: Verify by Phone, Using a Known Number
- Call the recipient using a number from your file, a prior verified conversation or an independent source, never one in the email that contains the instructions.
- Confirm the account name, the bank and the last four digits of the account number.
- Record who you spoke to, the date, the time and the number called.
Step 3: Require Two People
- One person prepares the transfer.
- A second person independently reviews the instructions and the verification record.
- For amounts above a threshold the partners set, require partner approval.
Splitting duties means one compromised person or one rushed afternoon is not enough to lose the funds.
Step 4: Treat Changes as Red Flags
Any change in instructions deserves extra scrutiny, particularly when it arrives close to closing or comes with urgency or secrecy. Common warning signs include:
- A new bank or a new account name
- Requests to send funds to an account under a different name
- Pressure to act quickly
- Slight differences in email addresses, such as an extra letter
- A request to avoid phone calls because someone is "traveling"
Step 5: Confirm Receipt
After sending, ask the recipient to confirm receipt of the exact amount. If something is wrong, minutes matter.
If You Suspect Fraud
Act immediately.
- Call your bank's fraud or wire department and request a recall.
- Contact the receiving bank if you can.
- File a report with the FBI's IC3 at ic3.gov and notify local law enforcement. The FBI has a process for rapid response to recent wire transfers, and speed matters.
- Notify your cyber-insurance carrier and, as appropriate, your malpractice carrier.
- Contact affected clients and counsel on notification duties.
Secure the Email Side Too
The procedure protects you even when email is compromised, but strong email security reduces the odds of that happening.
- Require MFA on every mailbox.
- Watch for suspicious forwarding rules, a common sign of compromise.
- Use filtering that flags lookalike domains.
- Train staff on what fraud looks like.
Test the Procedure
Once a quarter, run a short drill with a fake request and see whether staff follow the steps. Praise the people who catch it.
Counsel Cyber helps law firms harden email, set up alerts for suspicious activity and train staff on wire-fraud defense. If you would like help turning this into your firm's written procedure, we can work through it with you.