ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Spotting Business Email Compromise: Red Flags for Legal Staff

Business email compromise rarely looks suspicious at first glance. Train legal staff on the technical and behavioral red flags that reveal a fraudulent message.

3 min readBy Counsel Cyber Team

Business email compromise, often shortened to BEC, covers a family of scams where a criminal uses email to trick someone into sending money or sensitive information. The FBI's Internet Crime Complaint Center has consistently ranked it among the costliest categories of cybercrime it tracks. Law firms see it because money moves through them and because trusted email threads are the setting for it.

No single trick catches every case, so staff need to learn the patterns. This post lists red flags, grouped by what to look at.

How BEC typically unfolds

There are a few common versions:

  • Impersonation of an executive or partner, asking an assistant to make an urgent purchase or payment
  • Vendor or payee change, where a supposed supplier sends new bank details
  • Closing or settlement fraud, where a criminal inserts changed wire instructions into a real transaction
  • Account takeover, where the criminal controls a genuine mailbox, so the message really does come from the person
  • Payroll diversion, where someone asks HR to change direct-deposit details
  • Invoice fraud, where a fake invoice mirrors a real one

Red flags in the message itself

Behavioral signals

  • Urgency and pressure: "Needs to go out today," "I'm in a meeting, can't talk"
  • Secrecy: "Keep this between us"
  • Unusual requests: gift cards, a new bank account, a change of payment method
  • Change in tone or style, even slight: unusual greetings, odd phrasing, or missing signature details
  • Reluctance to use a phone: a refusal to talk, or unusual explanations
  • Last-minute changes to instructions close to a closing or deadline

Technical signals

  • Lookalike domains: a letter swapped, such as "rn" for "m," or a different ending like .co instead of .com
  • Display name versus address mismatch: the name looks right but the actual address is different
  • Reply-to address that differs from the sender
  • External sender warnings on a message that claims to be internal
  • New email thread that starts as a "Re:" of a conversation you never had
  • Unexpected links or attachments asking you to sign in to view a document

Signs a real mailbox was taken over

When the criminal has a real account, the message passes many visual checks. Clues include:

  • A message sent at an unusual time for that person
  • Language that doesn't match the person's usual style
  • Instructions to move to a different channel, or to ignore earlier instructions
  • A forwarded or replied-to thread in which the attacker has quietly deleted messages
  • Hidden inbox rules that forward or delete mail, which IT can detect

If you suspect takeover, contact the person by phone and tell IT immediately.

What to do when something seems off

  1. Stop. Do not reply, click or pay.
  2. Verify by phone using a number you already have, not one in the message.
  3. Report the message to IT or the designated contact using your reporting button or process.
  4. Do not forward it to many colleagues, which spreads risk. Report it once.
  5. If you already acted, report immediately. Quick reporting is the best chance to recover funds, and the FBI IC3 encourages prompt reporting.

Make it easy to do the right thing

  • Provide a one-click "report phishing" option
  • Create a written call-back procedure for payments
  • Let staff know that nobody will be penalized for verifying a request, even from a partner
  • Share real, anonymized examples so people see how convincing these look

Technical controls that support staff

  • MFA on all email accounts, preferably phishing-resistant for key roles
  • Impersonation protection for partners and finance staff
  • External sender banners
  • SPF, DKIM and DMARC for your domain
  • Alerts for new mailbox forwarding rules
  • Blocking of lookalike domains and newly registered domains where possible

Test the habit

Short simulated scenarios help the procedure feel normal. For example, send a mock request from a "partner" for an urgent payment, and see whether staff verify. Offer positive feedback for those who do.

Where Counsel Cyber fits

We provide email security configuration, mailbox monitoring and staff training designed around legal workflows. If you would like a BEC readiness review, we can help.