Holidays are good for firms and good for fraudsters. Offices are thin, partners are traveling, and the usual second person who would approve a wire is out of the country or out of reach. Attackers know that, and they time their messages for the days when verification feels inconvenient.
If your firm is open at all this week, whether staff are in the office or working remotely, a few deliberate steps can keep a slow week from becoming an expensive one.
Why Holidays Raise the Risk
- Fewer eyes. The colleague who would notice an unusual request is not there.
- Pressure to move. Year-end closings, settlements and tax deadlines create urgency that attackers exploit.
- Delayed detection. A compromised mailbox might not be noticed for days.
- Distracted staff. People answering email from a phone or a relative's kitchen are less likely to inspect an address carefully.
- Reduced IT coverage. Some providers and internal staff are less available.
Before the Holiday Starts
- Confirm the approver list. Decide who may authorize wires and who covers if the usual approver is away. Do not let "just this once" exceptions appear.
- Pause nonessential disbursements if you cannot staff the verification process.
- Tell clients early. Remind clients that the firm will never change wiring instructions by email and that they should call a known number to confirm anything unusual.
- Check your after-hours contacts. Make sure staff know how to reach IT and leadership for suspicious activity.
- Review mailbox rules and forwarding on key accounts for anything unexpected.
- Confirm MFA is enforced for all accounts that remain active over the holiday.
During the Week
Keep the callback rule
Any new or changed wiring instruction must be confirmed by a phone call to a number you already have on file, with a second person approving the release. No exceptions for urgency, travel or a persuasive explanation.
Watch for the holiday scripts
- "I'm traveling and cannot take calls, please send the funds by email confirmation."
- "The bank is closed, so use this alternate account."
- A "partner" asking staff to buy gift cards or urgently process a payment
- Fake shipping or e-card notifications that lead to credential theft
- Fraudulent invoices that match real vendors, but with new bank details
Report quickly
If anything seems off, send it to IT immediately. A short report on a holiday is better than a long investigation afterward.
After a Suspicious Event
If you think money has moved to a fraudulent account, time matters. Contact your bank right away and ask for a recall of the wire. File a report with the FBI's Internet Crime Complaint Center at ic3.gov, and notify your cyber insurance carrier. Preserve emails and logs. Rule 1.4 and ABA Formal Opinion 483 discuss communication with clients after incidents involving their information or funds, so involve firm leadership and ethics counsel quickly.
Protect Payroll and Vendor Payments Too
Fraudsters also request changes to direct deposit information or vendor banking details. Require confirmation by phone or in person for any change, and apply the same two-person rule.
For Partners Traveling
- Use the firm's secure email and avoid public Wi-Fi without a VPN or similar protection
- Lock your devices and enable remote wipe
- Do not approve payments from a phone without the verification step
- Stay reachable for urgent approvals, or formally delegate
One Page Is Enough
Put these steps on a single page and send it to everyone before the holiday. A short reminder at the right moment works better than a long policy no one reads.
Quick Reminders for Staff
Post a short note where people will see it: verify by phone, never by reply; slow down when a message demands speed; and report anything odd right away. Short reminders at the right moment tend to beat long policies nobody reads.
Support
Counsel Cyber helps firms strengthen wire-fraud controls and email security, and can review your closing workflow before the busy season. If you would like a quick check, get in touch.