Wire fraud against law firms usually follows a simple pattern. A criminal gets into someone's email, or imitates a party convincingly, and sends changed wiring instructions just before money moves. The FBI's Internet Crime Complaint Center has long identified business email compromise as a costly category of fraud, and law firms handling closings, settlements and escrow funds are natural targets because they move large sums on tight schedules.
The best defense is not clever software. It is a written protocol that every person follows every time, with no exceptions for a rushed Friday afternoon. Below is a protocol you can adapt.
The principle: verify out of band
Never confirm wire instructions using the same channel that delivered them. If instructions arrived by email, verifying by replying to that email proves nothing, since the attacker may control the thread. Verify by calling a phone number you already had on file from an independent source.
The protocol
1. Collect instructions once, early
Gather wiring details at the start of the matter, not the day before closing. Use a secure client portal or a verified phone call rather than plain email. Early collection leaves time to verify without pressure.
2. Record a trusted number
At intake, write down the client's, lender's or title company's phone number from a source you trust, such as the engagement letter, a prior file, or an official website you looked up yourself. Never take the number from the email containing the instructions.
3. Call back to verify every wire
Before sending funds, a staff member calls the trusted number and reads the account details aloud, including the last four digits of the account number and the routing number. The other party confirms them verbally. Document the date, time, person spoken to, and who made the call.
4. Treat any change as a red flag
If instructions change at any point, restart the process from step 3 and escalate to a partner. Common warning signs:
- A sudden change of bank or account
- Urgency, pressure or "I am traveling, just email me"
- Instructions to a different name than the payee
- Small differences in the sender's email domain
- A request to keep the change confidential
5. Require two people for release
One person prepares the wire and a second person approves it, checking the verification record before release. The approver should not be the person who made the callback. Even in a small office, this can be a partner and an office manager.
6. Set a hold-and-confirm rule for new accounts
For a first-time payee or newly changed account, consider a short delay and an additional verification step. A few hours is cheap compared with the cost of a misdirected wire.
7. Warn clients up front
Tell clients at the start of every closing or settlement that your firm will never email changed wiring instructions, and that they should call you at a known number if anything looks off. Put this sentence in your engagement letter and the footer of closing-related emails. Fraudsters also impersonate the firm to the client, so the warning protects both directions.
Technical controls that support the protocol
Process matters most, but a few technical measures reduce the chance an attacker is inside your mailbox in the first place:
- Multifactor authentication on every email account, ideally phishing-resistant
- Alerts for new inbox forwarding rules, a favorite attacker trick
- Warnings on external email and lookalike domains
- Disabling legacy authentication in Microsoft 365
- Prompt review of unusual sign-in locations
If a fraudulent wire goes out
Speed is everything. Immediately contact your bank's fraud or wire department and ask for a recall, report to the FBI at IC3, and notify your cyber-insurance carrier according to your policy. Also contact the receiving bank through your bank. Then preserve the emails and logs, notify affected clients, and consult ethics counsel about your obligations. ABA Formal Opinion 483 addresses lawyers' duties after a data breach.
Practice before you need it
Run a drill. Send a staff member a realistic fake instruction change and see whether the protocol holds. Praise those who follow it, even if it annoys a client, and fix the gaps you find.
How we can help
Counsel Cyber helps firms harden email, set up alerts, train staff on wire-fraud red flags, and write a protocol that fits their workflow. If you would like us to review your current closing process, we can start with a short security review.