Wire fraud against law firms is rarely sophisticated technology. It is sophisticated patience. The FBI's Internet Crime Complaint Center has long warned that business email compromise, in which criminals impersonate a trusted party to redirect payments, is among the costliest categories of cybercrime it tracks. Real estate closings are a favorite target because large sums move quickly and everyone expects emailed instructions.
Below is a hypothetical walkthrough. The firm and the people are invented, but every step reflects a pattern that law enforcement and security teams commonly describe.
A hypothetical closing
Consider a small firm handling a residential closing. A paralegal, an attorney, a buyer, a lender and a title contact are all on the email thread. Weeks earlier, an attacker gained access to the buyer's personal email account by guessing a reused password. They have been quietly reading messages ever since.
Step 1: The attacker watches
The attacker learns the closing date, the amount due, and the writing styles of everyone involved. They create a forwarding rule so they can read replies without being noticed. Nothing has been sent yet. This phase can last weeks.
Step 2: The lookalike appears
Two days before closing, a message arrives: "Please use these updated wiring instructions. Our earlier account had an issue." It may come from the buyer's real, compromised address, or from a lookalike domain that differs from the title company's by one character. The message mirrors the previous tone and even includes the right file number.
Step 3: Urgency and a plausible reason
The email says the usual account is being audited, and asks for the funds to be sent today. A small amount of pressure is usually enough. People who handle many closings are busy, and the request looks routine.
Step 4: The wire goes out
The paralegal prepares the wire, the attorney approves it, and the bank sends it. The money is moved from the receiving account within hours, often split across several accounts.
Step 5: The discovery
The real recipient calls days later asking where the funds are. By then, recovery is difficult. Prompt reporting to the bank and law enforcement improves the odds, but nothing is guaranteed.
Where the firm could have stopped it
Every step above includes a place where a simple control would have broken the chain.
- Account security. MFA and unique passwords on the buyer's account would have blocked the first break-in. Firms cannot control a client's email, but they can encourage safer practices at intake.
- Early warning to clients. A short letter at the beginning of the matter saying "we will never change wiring instructions by email; call us to verify" helps clients become part of the defense.
- Call-back verification. Any change to wiring instructions, or any first-time instructions, should be confirmed by phone using a number you already had on file, not a number from the new email.
- Dual control. Two people should review and release any wire, and at least one should check the receiving account against independently verified information.
- Domain and header checks. Staff should be trained to look at the full sender address, not just the display name, and to notice mismatched reply-to addresses.
- Mail rule monitoring. Your IT provider should alert on new forwarding rules in firm mailboxes.
Building a verification procedure
Write down a short procedure that anyone in the firm can follow:
- Confirm instructions verbally using a known phone number.
- Record who you spoke to, when, and what was confirmed.
- Require a second approver for every outbound wire.
- Treat any request to change instructions, speed up the wire, or avoid calling as a warning sign.
- Test transfers can help only if your bank and client agree, and they still do not replace verification.
What to do if you suspect fraud
Call your bank immediately and ask them to initiate a recall. Report the incident to the FBI's IC3 and notify your cyber insurer. Preserve emails and logs. Contact the client by phone. Consider your ethical obligations about client communication under Model Rule 1.4 and confirm requirements with your state bar and counsel.
Closing thoughts
The best wire-fraud defense is boring: a written procedure, a phone call, and a second pair of eyes. Counsel Cyber helps firms deploy email protections, monitor for suspicious mailbox rules, and train staff with realistic exercises. If you would like to pressure-test your own wire procedure, we can run through it with your team.