ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Phishing at Law Firms: Five Myths and What Is Actually True

Five common misconceptions about phishing at law firms, from 'our filter catches it' to 'only juniors fall for it,' with practical corrections for each.

3 min readBy Counsel Cyber Team

Phishing is old news, which is part of the problem. Firm leaders hear about it so often that they assume they understand it, and assumptions create gaps. Here are five common beliefs about phishing in law firms, and what security teams and government agencies generally say instead.

Myth 1: "Our email filter catches it"

Reality: Filters stop a great deal of unwanted mail, but none are perfect. Attackers test messages against filters, use compromised legitimate accounts, send from newly registered domains, and use links that look harmless when scanned and turn malicious later. Some messages are plain text with no link or attachment at all, such as a short request to change payment details.

Filtering is an essential layer, not a guarantee. Pair it with staff training, MFA, mailbox monitoring and verification procedures for payments.

Myth 2: "Only careless or junior people fall for it"

Reality: Phishing succeeds against careful people because it targets moments, not intelligence. A partner heading into court, an accountant at month-end, or a paralegal handling a closing is busy, and the request looks routine. Senior people are often targeted deliberately because their accounts have more access and their messages carry authority.

Treat phishing resistance as a system property. Controls like MFA and call-back verification protect everyone, including the most experienced attorney who simply made a mistake.

Myth 3: "Phishing always looks sloppy"

Reality: Poor spelling used to be a giveaway. Today, messages can be polished, and tools that generate fluent text are widely available. Attackers also clone the real branding of services like Microsoft 365, DocuSign and shared document platforms. A fake sign-in page may look indistinguishable from the real one.

Teach staff to look at context and behavior rather than polish:

  • Was this expected?
  • Does it create urgency or fear?
  • Does it ask for credentials, money or an unusual action?
  • Does the sender address and link destination match what they claim?

Myth 4: "MFA makes us immune"

Reality: MFA blocks a huge share of account takeovers, and every firm should use it. But some phishing kits relay credentials and one-time codes in real time, and attackers also use "push fatigue," repeatedly sending approval requests until a user accepts one. CISA has encouraged organizations to adopt phishing-resistant MFA where feasible, such as hardware keys and passkeys.

Use number matching for authenticator prompts, disable weaker methods where possible, and train staff to deny and report any unexpected prompt.

Myth 5: "If nothing was entered, no harm was done"

Reality: Clicking a link can still expose a device to malicious downloads or capture information about your browser. Opening an attachment can run code. And a person who thinks they got away with a click often says nothing, which gives an attacker time.

Create an environment where staff report mistakes immediately. A same-day report might allow IT to reset a password, review the account and block the sender before anything spreads.

What is actually true: the realistic defense

Layered controls

No single control wins. Combine email filtering, link and attachment protection, MFA, endpoint detection, restricted privileges and tested backups.

Verification procedures

For anything involving money or credentials, a call to a known number defeats most attempts. Write the procedure down and apply it to partners too.

Training that sticks

Short, regular sessions beat long annual ones. Use real examples and simulations, and focus on the principle of pausing and verifying. Avoid humiliating individuals; people hide mistakes in blame-heavy cultures.

Reporting and response

A visible report button, quick triage and feedback to the reporter reinforce the habit. Tell staff what happened to their report. When people see their reports matter, they send more.

Account monitoring

Attackers who succeed often create inbox rules to hide replies or forward mail. Alerting on new forwarding rules and unusual sign-ins catches compromises early.

Why law firms are especially attractive

Firms hold confidential information, move client funds and communicate with many outside parties, which provides cover for fraudulent requests. The ABA's Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized access to client information, and phishing defenses are a practical part of that effort.

A quick self-check

  1. Do we enforce MFA on every email account?
  2. Can staff report a suspicious message with one click?
  3. Do we have a written call-back rule for payment changes?
  4. Do we monitor for new mailbox forwarding rules?
  5. When did we last train staff, and did we measure results?

If any answer is "no" or "not sure," you have an immediate priority.

Counsel Cyber builds layered email protection and law firm focused training programs. If you would like a candid assessment of your phishing defenses, we are glad to review them with your team.