Lawyers are not careless people. They are busy, they receive a high volume of email from strangers by design, and they are trained to respond promptly to clients and courts. Those habits are exactly what phishing attackers study. A message that would fail a basic test in another industry can look entirely plausible in a law office.
This guide describes the red flags that matter most, and how to turn them into training your people will remember.
Why Law Firms Are Attractive Targets
Firms handle sensitive information, move large sums through trust accounts and communicate constantly with outside parties. The FBI's IC3 has repeatedly highlighted business email compromise as a persistent problem across industries, and the legal profession's reliance on email makes it an obvious fit for these schemes. Attackers do not need a technical exploit. They need one person to click.
Red Flags Lawyers and Staff Commonly Miss
The "shared document" lure
A message says a colleague, client or court has shared a document and asks you to sign in to view it. The link leads to a fake login page that captures your password. Because document sharing is routine in legal work, this lure succeeds often. Red flags include unexpected shares, unfamiliar sender names, and a login page whose web address does not match the service.
The urgent request from a partner
An email appears to come from a managing partner asking for a quick favor: buy gift cards, send a wire, share a document, or call a number. The sender's display name matches, but the actual address does not. Urgency and secrecy, such as "I am in a meeting, do not call," are tell-tale signs.
The new client inquiry
A prospective client emails with a large, attractive matter and sends a check or a document to "review." The attachment may carry malware, or the check may be counterfeit, leaving the firm exposed when it wires back an overpayment.
Look-alike domains
An address that differs from a real one by a single character, such as a swapped letter or an extra hyphen, is easy to overlook on a phone screen.
Replies inside real threads
If an attacker has compromised someone's mailbox, they can reply inside an existing conversation with a malicious link. The message looks like a continuation because it is one. A sudden change in tone, a link that was not part of the earlier discussion or changed payment details should prompt a call.
Fake security alerts and MFA fatigue
Messages claiming your account is locked, or a flood of unexpected approval prompts on your phone, aim to wear you down. Never approve a prompt you did not initiate.
QR codes and text messages
Phishing is no longer limited to email. Text messages and QR codes in emails or on printed material can lead to the same fake login pages.
Habits That Defeat Most Phishing
- Pause before acting on any message that creates urgency.
- Verify out of band. Call a known number, never one from the message.
- Hover before clicking, and navigate to important sites yourself instead.
- Check the sender's actual address, not just the display name.
- Report, do not delete. A quick report lets your IT team protect everyone else.
- Use a password manager, which refuses to fill credentials on look-alike sites, a built-in warning.
- Use multi-factor authentication everywhere, ideally phishing-resistant methods for the most sensitive accounts.
Making Training Stick
Keep sessions short and recurring
Frequent brief sessions beat an annual lecture. Use real examples drawn from legal practice.
Run simulated phishing exercises
Simulated messages measure risk and provide teachable moments. Frame them as learning, not punishment. People who fear blame stop reporting.
Reward reporting
Thank people who report suspicious messages, including false alarms. A culture of quick reporting often stops an attack in its early minutes.
Include everyone
Partners, lawyers, paralegals, reception and billing staff all need training. Supervisors' responsibilities under Model Rules 5.1 and 5.3 include reasonable measures to ensure staff conduct is compatible with professional obligations.
Technical Safeguards Behind the Training
Training reduces risk but cannot eliminate it. Pair it with email filtering that flags external senders and look-alike domains, multi-factor authentication, conditional access policies, and monitoring for unusual sign-ins and inbox rules.
How Counsel Cyber Helps
Counsel Cyber provides security awareness training and simulated phishing tailored to law firms, along with the email protections that back it up. If you would like to see where your team stands today, we can run a baseline exercise.