Business email compromise, often shortened to BEC, is a fraud in which an attacker impersonates someone you trust, or takes over their actual mailbox, to trick you into sending money or sensitive information. The FBI's Internet Crime Complaint Center has repeatedly highlighted it as a high-loss category of cybercrime. Law firms are attractive targets because they move large sums, handle trust funds, and communicate constantly by email with clients, lenders and opposing parties.
Technology helps, but people are the last line of defense. This guide can be turned into a fifteen-minute training session for attorneys, paralegals, accounting staff and front desk personnel.
What BEC looks like at a law firm
BEC rarely contains a malicious attachment. The message is often plain text, politely worded, and short. Common scenarios include:
- A client or title contact sends "updated" wiring instructions.
- A partner asks an assistant to buy gift cards or send a quick payment while traveling.
- A vendor announces a new bank account for an outstanding invoice.
- Someone claiming to be opposing counsel sends a link to a shared document that requires a Microsoft 365 sign-in.
- A staff member asks payroll to change direct deposit details.
Each scenario relies on a believable request and a reason not to double-check.
Seven warning signs
- Urgency. The sender needs it today and says there is no time for questions.
- Secrecy. Phrases such as "keep this between us" or "do not call, I am in a meeting."
- A change of payment details. Any new account number or routing change.
- Slightly wrong sender details. A display name that matches a person, but an address that does not, or a domain that is one letter off.
- An unusual channel. A partner who never texts suddenly asks for something by text.
- A request that skips normal approvals. The usual second signature or review step is waived.
- A login page after a link. A shared document that asks you to sign in again.
No one sign is proof. Several together should stop you.
The pause-and-verify habit
The most effective training message is simple: when money or credentials are involved, verify through a different channel.
How to verify
- Call the person using a phone number you already have, not one in the email.
- If you cannot call, walk to their office or message them in a separate known channel.
- Do not reply to the suspicious message to ask whether it is genuine.
- Write down who confirmed what, and when.
Make it clear that verification is expected, not insulting. Attorneys should publicly support staff who pause a request, even when it turns out to be real.
Technical clues worth teaching
- Hover over links before clicking to see the real destination.
- Expand the sender address to see the full email, not just the name.
- Look for a "reply-to" address that differs from the sender.
- Treat external email banners as a cue to slow down.
- Be suspicious when a thread suddenly changes tone, grammar, or timing.
Also teach that a compromised account can send genuine-looking messages from a real address. If a colleague's email seems out of character, verify by another channel even though the address is correct.
Build the habit into procedure
Training works best when backed by firm rules:
- All wires and trust disbursements require two approvers.
- Any change to payment instructions must be verified by phone.
- New vendors are set up only after verification and approval.
- Staff may never be penalized for pausing a request, even from a partner.
Reporting without fear
If someone clicks or replies, speed matters more than blame. Provide a single, simple way to report: a button in the email client, a dedicated address, or a phone number for IT. Tell people what happens next. Early reports allow your IT team to reset credentials, remove malicious mailbox rules and warn others.
Include these steps in your incident plan: contact the bank if money moved, report to the FBI's IC3, notify your cyber insurer, and consider client notification obligations with counsel.
Keep it fresh
Run short refresher sessions each quarter, share anonymized examples of real attempts that reached the firm, and use simulated phishing messages to measure improvement. Avoid public shaming of anyone who fails a simulation.
How we can help
Counsel Cyber provides training sessions tailored to law firm staff, along with email protections that flag lookalike domains and suspicious mailbox rules. If you would like a session for your team, we can build one around the matters your firm handles.