ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Phishing at Law Firms: Common Lures and How to Train Against Them

Law firm phishing relies on urgency, authority and familiar workflows. See the lures staff meet most often and how to train people to spot them.

3 min readBy Counsel Cyber Team

Attackers do not need to be clever to succeed against a law firm. They need one person, on one busy afternoon, to click a link or approve a login. The lures they use are tailored to legal work: documents to review, court notices, e-signature requests and invoices from vendors you actually use.

Understanding the common patterns is the first step toward training staff to spot them.

Lures staff meet most often

Shared document links

A message says a colleague or client has shared a file through a familiar service. The link leads to a fake login page that harvests credentials. Because attorneys share documents all day, these blend in.

E-signature and court notices

Fake requests to sign a document or a supposed notice from a court or agency exploit deadline anxiety. Real courts and e-filing systems have predictable behaviors, so teach staff what those look like.

Executive impersonation

A message appears to come from a managing partner asking an assistant to buy gift cards or handle an urgent payment. Short, polite and urgent is the pattern.

Invoice and payment changes

A vendor, client or opposing party "updates" payment details. This is the doorway to wire fraud and should always trigger a call-back.

Voicemail and "missed call" messages

Messages claiming a voicemail awaits often hide credential-stealing links.

IT impersonation

An email, text or call claims to be from IT or Microsoft and asks for a code or a password. Real IT teams do not ask for your MFA code.

QR codes and text messages

Phishing continues to move beyond email. A QR code on a letter or a text about a package can lead to the same fake login.

Why smart lawyers still fall for them

Intelligence is not the issue. Attackers exploit speed, authority and routine. Attorneys are trained to respond quickly to clients and courts, and assistants are trained to follow partner requests. A message that fits an existing workflow gets less scrutiny.

Training that works

Keep it short and frequent

A ten-minute session each month beats a two-hour lecture each year. Use real examples that resemble your firm's email, and update them as lures change.

Run simulated phishing

Send harmless test messages, then give immediate feedback to anyone who clicks. Track trends, not individuals, and never shame anyone. The goal is a culture where people report suspicious messages quickly.

Teach a simple routine

Give staff a short checklist they can remember:

  1. Pause. Urgency is a warning sign.
  2. Check the sender and the real address, not only the display name.
  3. Hover over links before clicking, and open sites by typing the address yourself when possible.
  4. Verify requests for money, credentials or sensitive files through a separate channel.
  5. Report it with one click, even if you are not sure.

Make reporting effortless

Install a report-phishing button in the mail client. Thank people who report, including those who report mistakes. An employee who clicks and says so immediately gives you a chance to contain the problem.

Technical controls that back up training

Training reduces risk but cannot eliminate it, so combine it with:

  • Email filtering for malicious links and attachments
  • Multi-factor authentication, preferably phishing-resistant
  • Banners marking external email
  • Blocking or flagging newly registered lookalike domains
  • Rapid account lockdown procedures when someone reports a click

Supervision and expectations

ABA Model Rules 5.1 and 5.3 address supervising lawyers and nonlawyer staff, and training is a practical way for firm leaders to show reasonable oversight. The rules do not prescribe a program, so build one that fits your size and confirm expectations with your state bar.

Measuring progress

Track the percentage of staff completing training, the click rate on simulations, the report rate, and the time from report to response. Improvement in reporting speed matters more than a perfect click rate.

Where we come in

Counsel Cyber provides security awareness training tailored to law firms, along with email filtering and phishing simulations. If you would like to see how your staff responds to realistic lures, we can set up a controlled simulation and walk through the results with you.