Consider a hypothetical 12-attorney firm handling real estate and probate matters. This is an invented scenario, not a description of a real firm, but it follows a pattern that security professionals see regularly. Walking through it step by step shows where simple controls make the difference.
How It Begins
On a Tuesday morning, a paralegal receives an email that appears to be a shared document notification. The link leads to a page that looks like a Microsoft 365 sign-in. She enters her email and password. The page then redirects to a real document, so nothing seems off.
In reality, the page was run by an attacker, who now has her credentials. Because the firm has not enforced multi-factor authentication for every user, the attacker signs in from another country within minutes.
What the Attacker Does Next
The attacker does not announce the intrusion. Instead:
- Reads the mailbox to learn who the paralegal works with, how the firm communicates, and what deals are in progress.
- Creates an inbox rule that moves messages containing words like "wire" or "payment" into a rarely-used folder, hiding replies from the paralegal.
- Searches for contacts, such as clients, title companies and lenders.
- Sends messages from the real account to clients and others, with another link or a changed set of payment instructions.
Because the messages come from a legitimate firm mailbox in a thread the recipient already knows, they are far more convincing than a spoofed address.
How the Firm Finds Out
Two days later a client calls, confused about an email asking her to send her closing funds to a different account. The firm realizes something is wrong. At this stage the firm must act quickly.
Immediate Response
Contain
- Reset the paralegal's password and revoke active sessions
- Enable MFA on the account
- Remove malicious inbox rules and any forwarding addresses
- Check for unauthorized app consents or added devices
- Review sign-in logs for other accounts showing similar activity
Call for help
- Notify the IT provider and the cyber insurance carrier, following the policy's notice requirements
- Involve counsel who handles breach response
- If funds were sent, contact the bank immediately and report to law enforcement; the FBI's Internet Crime Complaint Center takes reports of business email compromise, and early action can matter
Preserve evidence
Keep logs and copies of malicious messages. Avoid deleting anything that may be needed for the investigation.
Determine scope
Which mailboxes were accessed? What client information was in them? Which messages did the attacker send? The answers affect notification decisions. ABA Formal Opinion 483 discusses a lawyer's duties after a data breach, and Model Rule 1.4 concerns communication with clients, so the firm should decide with counsel how and when to notify those affected. Confirm obligations under your state's law.
Communicate
Contact affected clients and counterparties by phone, using known numbers, and warn them to disregard the fraudulent instructions. Prepare a plain, factual statement.
What Would Have Prevented or Reduced It
- MFA on every account. Phishing-resistant methods are better still. Even a stolen password would not have been enough on its own.
- Email security filtering that detects credential-harvesting links and external impersonation
- Conditional access policies that block sign-ins from unexpected countries or unmanaged devices
- Alerting on inbox rules and impossible-travel logins so that someone sees the problem on day one, not day three
- A call-back policy for any payment instruction change, using a known phone number, never the one in the email
- Security awareness training with practice reporting of suspicious messages
- A tested incident response plan so that the first hour is calm rather than chaotic
Lessons for Firm Leaders
- The attacker's goal was patience and access, not a dramatic crash
- One missing MFA enrollment created the opening
- Detection speed mattered as much as prevention
- The cost was not only the technology response but also client trust
Make Your Own Walkthrough
Pick an employee at your firm and ask: if this person's mailbox were compromised right now, how would we find out, what could the attacker see, and what would we do in the first hour? Writing down the answers exposes gaps.
Working With Counsel Cyber
Counsel Cyber helps law firms enforce MFA, deploy account monitoring, and rehearse exactly this scenario in a tabletop exercise so the real thing is a practiced response.