ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Fake Invoices and Vendor Email Compromise: Protecting Firm Accounts

Scammers do not only target trust accounts. Fake vendor invoices and changed bank details drain operating accounts, too. Here is how firms can defend them.

3 min readBy Counsel Cyber Team

When firms think about wire fraud, they usually picture a real estate closing or a trust account. Operating accounts are targets too, and the entry point is often accounts payable. A fraudulent invoice from a vendor you really use, or an email saying that the vendor has changed banks, can slip through a busy accounts-payable queue.

This type of scheme is often called vendor email compromise or payment diversion. The FBI's IC3 describes business email compromise broadly as a scheme in which criminals use email to trick organizations into sending money, and changed payment instructions are a recurring theme.

How the Scheme Typically Works

  1. A criminal gains access to a vendor's email, or creates a convincing look-alike account.
  2. They study real invoices and the vendor's habits.
  3. They send an invoice or a "banking update" that mimics the real thing.
  4. Your accounts-payable staff pays the new account.
  5. The real vendor later asks why payment never arrived.

The messages are often accurate in every detail except the bank account number.

Who Is at Risk in a Law Firm

  • Accounts payable staff, who process invoices from landlords, software vendors, court reporters, experts, e-discovery providers and consultants.
  • Office managers, who handle vendor relationships.
  • Partners, who may approve payments quickly when asked by email.
  • Reception and administrative staff, who may be asked to forward invoices.

Controls That Work

Verify every change to payment instructions

Any request to change bank details, even from a long-standing vendor, must be verified by calling a known number from your records, not one in the email. Record who verified, when and with whom.

Maintain a verified vendor master list

Keep a list of approved vendors with verified contact details and payment information. New vendors and changes require approval from someone outside the person entering the payment.

Separate duties

The person who adds or changes vendor bank information should not be the same person who approves or releases payment. Segregation of duties is one of the oldest fraud defenses and still one of the best.

Require dual approval above a threshold

Set a dollar limit above which two people must approve. Many firms also require dual approval for any first payment to a new account regardless of size.

Hold new accounts

Delay the first payment to a new or changed account long enough to complete verification, even if the sender is pressing for speed.

Use purchase orders or expected-invoice workflows

Pay invoices that match an expected engagement or order. An unexpected invoice for a service nobody remembers requesting deserves a question.

Strengthen email defenses

  • Multi-factor authentication on all mailboxes.
  • Filtering that flags look-alike domains and first-time senders.
  • External sender banners.
  • Monitoring for suspicious inbox rules.
  • Email authentication records for your own domain.

Train the Right People

Many security awareness programs focus on lawyers. For payment fraud, the key audience is accounts payable and the staff who assist partners. Use realistic examples such as an invoice that arrives from a familiar vendor with new bank details. Show how to verify, and make it clear that slowing down is encouraged.

Red Flags in Messages

  • New or changed bank details, especially a switch to a different bank or location.
  • Pressure to pay quickly or avoid late fees.
  • Requests to bypass normal procedures.
  • Slightly altered sender addresses or reply-to addresses.
  • Invoice formatting that differs subtly from past invoices.
  • Requests to communicate only by email and not phone.

If You Paid a Fraudulent Invoice

Act quickly. Contact your bank immediately and ask for a recall, notify law enforcement through the FBI's IC3, and alert your IT provider and cyber-insurance carrier. Preserve the emails. If client funds may be involved, consider your obligations under Model Rule 1.4 and the guidance in ABA Formal Opinion 483 with counsel. Check whether your insurance has social-engineering coverage, since it may have a sublimit or conditions.

Document the Procedure

Write a one-page accounts-payable verification procedure, and keep records of each verification. It supports training, audits and insurance applications.

How Counsel Cyber Helps

Counsel Cyber helps firms harden email, monitor for compromise and write payment-verification procedures that staff will actually follow. If you would like a payment-fraud readiness review for your accounts-payable process, we can walk you through it.