For years, staff were trained to be skeptical of strange emails. Now there is a harder problem: voice and video that sound and look like a real person. Voice-cloning tools can imitate someone from a short audio sample, and video tools can alter faces in real time. Law firms publish plenty of material that could supply those samples, including webinars, podcasts, bar presentations and recorded interviews.
Fraud authorities have warned about this trend in general terms, and the FBI has issued public service announcements about criminals using AI-generated content to make scams more convincing. This briefing looks at the plausible risks to a law firm and the practical defenses that do not depend on spotting a fake by ear or eye.
How an attack might look
Consider a few hypothetical scenarios. They are illustrations, not reports of specific events.
- The urgent partner call. A bookkeeper receives a voicemail that sounds like the managing partner, asking for an urgent transfer to close a deal and to keep it confidential.
- The client who calls to change wire instructions. The caller sounds like a long-standing client. The email trail looks consistent. A closing is days away.
- The video meeting with a familiar face. A video call appears to include an executive or co-counsel, who instructs an employee to release funds or share documents.
- The password reset call. Someone phones the help desk, sounding like an attorney who is traveling, and asks to reset MFA on their account.
In each case, the attacker uses a familiar voice or face to defeat the instinct that says this must be real.
Why detection alone is not the answer
Audio and video fakes are improving, and humans are not reliable detectors, especially under time pressure. Telling staff to listen for odd pauses is a weak control. The more dependable approach is to design processes that remain safe even if the voice is perfect.
Controls that work
Callback to a known number
For any payment or change of instructions, hang up and call the person back on a number already in your records. Do not use a number provided during the suspicious contact. This is the same principle as in written wire-verification procedures.
Dual approval
Require a second authorized person for transfers and for sensitive changes. An attacker would need to deceive two people independently.
Pre-agreed verification phrases
For high-risk relationships, such as a managing partner and the finance staff, consider a shared code word or question that is never written in email. It is low-tech and effective, provided the phrase is kept private and changed if exposed.
Hardened help desk procedures
Your IT provider should verify identity before resetting passwords or MFA, using methods that do not rely on voice recognition, such as a callback to a registered number, a manager's approval or an in-person check. Ask your provider to explain its process.
No exceptions for urgency or secrecy
Instruct staff that any request combining urgency, secrecy and money triggers the verification process, even if it appears to come from a partner. Make clear that partners will not be offended. Better still, have partners say so explicitly.
Limit what is available to clone
You cannot avoid public appearances, but you can be thoughtful about how much high-quality audio of key people is published, and about posting travel plans or schedules that attackers can exploit.
Staff training
Add synthetic media to your security awareness program.
- Explain in plain terms that voices and video can be faked.
- Walk through the hypothetical scenarios above.
- Practice the callback procedure with role-playing.
- Reassure staff that following procedure is always right, even when it delays a partner's request.
Client communication
Tell clients how your firm confirms payment details and ask them to follow the same approach. Include a note in engagement letters that the firm will never change payment instructions based on a phone call alone.
Evidence and discovery concerns
Deepfakes may also raise authenticity questions for evidence in litigation. That is a separate subject for attorneys and not covered here, but firms advising clients should keep an eye on developments in evidence rules and court practice.
Policy additions
- Verification steps required for payment, credential and data requests received by voice or video
- A rule that identity cannot be established by voice alone
- A reporting channel for suspected impersonation attempts
- Periodic testing, such as a controlled test call to the finance team
Where we can help
Counsel Cyber incorporates impersonation scenarios into security awareness training and helps firms harden their help desk and payment procedures. If you would like to test your own team's response with a simulated call, we can arrange one.