When firms think about payment fraud, they usually picture a closing or a settlement. But the operating account is a target too. Criminals send fake invoices, impersonate vendors and ask accounts payable staff to update bank details. The amounts may be smaller than a trust wire, but the fraud is easier to attempt and often less guarded.
The FBI's Internet Crime Complaint Center describes business email compromise as including schemes in which fraudsters pose as vendors or suppliers and request changes to payment details. Law firms pay many vendors: landlords, court reporters, expert witnesses, e-discovery providers, software companies and contractors. Each relationship is an opening.
How the schemes work
The fake invoice
A message arrives with a professional-looking invoice for a service the firm may or may not have used. If the amount is modest and the vendor name is plausible, it may be paid without scrutiny.
The bank-detail change
An email, apparently from a known vendor, says the company has changed banks and asks you to update the payment details. The next payment goes to the criminal.
The compromised vendor
Sometimes a real vendor's email is compromised, and the fraudster sends invoices from the genuine address. The message looks authentic in every technical way.
Internal impersonation
A message that appears to come from a partner tells the bookkeeper to pay an invoice quickly and discreetly.
Duplicate and inflated invoices
Not all fraud is external. Weak approval processes also allow errors and internal misconduct, and the same controls help.
Controls for accounts payable
1. Maintain an approved vendor list
Only pay vendors on a list that someone with authority has reviewed. New vendors require approval and a documented onboarding process, including verification that the business exists and a confirmed contact.
2. Verify every bank-detail change
Treat any change to payee bank details as high risk. Call the vendor at a phone number already on file, speak with a known contact, and confirm details. Do not use contact information supplied in the change request. Record who you spoke with and when.
3. Separate duties
The person who sets up or edits vendor details should not be the person who approves payments or reconciles the account. Even in small firms, a partner or office manager can provide the second review.
4. Match invoices to work
Require a purchase order, engagement or manager approval confirming that the service was requested and received. Fake invoices rely on staff assuming someone else ordered the service.
5. Use dual approval for payments
Set thresholds above which a second approval is required, and consider extra scrutiny for first payments to new payees.
6. Use bank tools
Ask your bank about payee matching, positive pay for checks, ACH debit blocks and filters, and alerts for new payees. Review limits.
7. Reconcile promptly
Review statements monthly or more often. Quick discovery improves chances of recovery.
Email-level protections
- Multi-factor authentication on all mailboxes, especially accounting staff
- Alerts on forwarding rules and unusual sign-ins
- External sender banners
- Lookalike-domain monitoring
- SPF, DKIM and DMARC on your own domain
Training the accounting team
Give accounts payable staff specific training: examples of fake invoices, bank-change scams and executive impersonation. Make clear that they will be supported, never blamed, when they pause a payment to verify. A culture that rewards caution defeats urgency.
If a fraudulent payment is made
- Contact your bank immediately and request a recall.
- Report to IC3 and consider local law enforcement.
- Notify your cyber insurance or crime policy carrier, since coverage and notice requirements differ by policy.
- Check whether the compromise exposed other systems or information.
- Document the timeline.
Why it matters ethically
If operating funds are lost, the firm bears the loss, but a compromised mailbox may also expose client communications. ABA Model Rule 1.6(c) addresses reasonable efforts to protect client information, and Rule 5.3 addresses supervising nonlawyer staff such as accounting personnel. Confirm any additional expectations with your state bar.
Quick checklist
- Vendor list approved
- Callback for bank changes
- Dual approval above a threshold
- Separate vendor setup from payment
- Bank protections on
- Monthly reconciliation
- Annual training
How we help
Counsel Cyber helps law firms secure email accounts and train accounting staff to resist invoice and vendor fraud. If you would like us to review how payment requests flow through your office, we can start with a short assessment.