ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Five Business Email Compromise Scams Aimed at Lawyers

Common business email compromise schemes aimed at law firms, including fake closing instructions and spoofed partner requests, and how to spot and stop each.

3 min readBy Counsel Cyber Team

Business email compromise, often shortened to BEC, is fraud carried out through email rather than malware. There may be no virus and no ransom note. A convincing message arrives, someone acts on it, and money or data goes to the wrong place. The FBI's Internet Crime Complaint Center has consistently ranked BEC among the costliest categories of internet crime it tracks, which is why its guidance is worth reading.

Law firms are attractive because they move large sums, communicate by email constantly and work under deadlines. Here are five common patterns and what to do about each.

1. The Changed Wiring Instructions

How it works: A criminal monitors or imitates communications on a real estate closing or settlement. Shortly before funds are due, "updated" wiring instructions arrive, appearing to come from the title company, the opposing counsel or the client.

Warning signs: A new bank, urgency, a request not to call, or an email address that differs by one character.

Defense: Verify every instruction by phone to a known number. Require two people for every wire. Warn clients at the start of the engagement.

2. The Spoofed Partner Request

How it works: An assistant or bookkeeper receives a message that appears to come from a managing partner: "I'm in a meeting and can't talk. Please send a payment to this account today," or "Buy gift cards for a client and send me the numbers."

Warning signs: Unusual requests, secrecy, the sender's name with a different address behind it, or phrases such as "sent from my phone" that mimic a real habit.

Defense: Teach staff that no payment or gift-card request is honored without voice or in-person confirmation. Make clear that checking is expected, and that partners will never be annoyed by it.

3. The Fake Vendor Change

How it works: An email from a vendor, court reporter, expert witness or landlord says its bank account has changed and asks that future payments go to a new account. The message may use real invoice details taken from a compromised mailbox.

Warning signs: Bank change requests, especially mid-relationship, and requests delivered only by email.

Defense: Create a vendor change procedure. Require a callback to a number on file, and a signed form where appropriate, before updating payment details in billing or accounting systems.

4. The Compromised Contact

How it works: A real mailbox belonging to a client, co-counsel or vendor is taken over. The attacker replies inside existing email threads, using the history to appear authentic, and inserts a malicious link or a payment change.

Warning signs: A familiar sender with unusual tone or timing, an unexpected request to log in to view a document, and a link that opens a login page you do not recognize.

Defense: Treat unexpected links and attachments with caution even from known senders. Verify surprising requests through a separate channel. Use email filtering that scans links and attachments.

5. The Fake Document Share

How it works: An email appears to share a document through a common cloud service. Clicking leads to a counterfeit sign-in page that steals credentials. With the stolen login, the attacker enters the real mailbox, watches deals and sets up hidden forwarding rules.

Warning signs: Unexpected share notices, login requests after clicking, and web addresses that do not match the service.

Defense: Enable MFA everywhere so stolen passwords alone are not enough. Teach staff to open shared documents by going to the service directly. Review mailbox rules for hidden forwarding.

Common Defenses That Cover All Five

  • Multi-factor authentication on every mailbox
  • Alerts for new forwarding rules and unusual sign-in locations
  • External-sender banners in email
  • DMARC on your domain, plus protection against lookalike domains
  • A written callback procedure for payments and banking changes
  • Short, recurring training with real examples
  • A no-blame channel for reporting suspicious messages and mistakes

If You Suspect You Have Been Targeted

Act quickly. Contact your bank immediately if money moved, report to the FBI at ic3.gov, notify your insurer, reset affected credentials and review mailbox rules. Speed matters most in the first hours.

The Duty Behind the Procedures

ABA Model Rule 1.6(c) calls for reasonable efforts to prevent unauthorized disclosure of client information, and Formal Opinion 477R discusses risk-based safeguards for communications. Checking and documenting your controls supports both.

Counsel Cyber helps law firms put layered defenses around email and train staff to recognize these schemes. If you would like to test your team with a simulated message, we can arrange it.