ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Spotting Fake Wire Instructions: Red Flags for Closing Staff

A practical list of red flags in emails, invoices and phone calls that signal fake wire instructions, written for paralegals and closing staff.

3 min readBy Counsel Cyber Team

The people most likely to see a fraudulent wire request first are not partners or IT staff. They are the paralegals, closers, escrow assistants and accounting clerks who handle payment details every day. Training them to recognize red flags is one of the highest-value security investments a firm can make.

This guide is meant to be shared with those staff directly. It supports, but does not replace, a firm's written call-back procedure.

The Basic Pattern

Business email compromise follows a familiar script. A message arrives, apparently from a client, title company, lender or colleague, with new or changed payment instructions. It stresses urgency. If acted on, funds go to an account controlled by a criminal. The FBI's Internet Crime Complaint Center has published ongoing guidance on this scheme, and its advice repeatedly emphasizes confirming instructions through a separate, trusted channel.

Red Flags in the Message

Changes to established instructions

Any change to bank, routing or account details is a red flag by itself, even if the message looks perfectly normal. Treat all changes as unverified until you have confirmed them by phone.

Urgency and pressure

Phrases such as "wire today or the deal falls through," "I'm boarding a flight and can't talk," or "do not call, email only" are classic manufactured urgency. Requests to avoid phone contact are especially suspicious.

Slight differences in the sender address

Look closely at the sender's address, not just the display name. Attackers register domains that differ by one character, or add a word, such as a hyphen or an extra letter. On phones, long addresses are often hidden, so expand the sender details.

Reply-to mismatch

The visible sender may be legitimate while replies are directed to a different address. Check the reply-to field before you respond.

Unusual tone or phrasing

Messages that are slightly off in greeting, signature, punctuation or style may be written by someone else. Do not rely on this alone, because attackers who have read a real mailbox can imitate tone well.

New attachments with altered bank details

A familiar-looking invoice or wire form that suddenly has different account numbers deserves a call. Check PDF properties and compare against earlier versions.

Requests outside normal process

Examples: a client who has never asked for expedited funds asks you to wire to a third party, an executive requests a payment via text, or someone asks you to skip approval steps.

Account in an unexpected name or location

The receiving account is in a name that does not match the payee, or at a bank in a different region from the party. Check this against known information.

Red Flags in the Process

  • Instructions arrive by email but the usual contact method was a portal or phone
  • The sender cannot be reached at their normal phone number
  • The recipient asks to keep the transaction confidential beyond what is normal
  • A colleague is cut out of the loop
  • The message arrives just before a weekend or holiday when verification is harder

What to Do

  1. Stop. Do not send, change or confirm anything.
  2. Verify by phone using a number you already had, not the one in the message.
  3. Ask a second person to review any change.
  4. Document the verification in the file.
  5. Report the message to IT, using your firm's reporting button or address, even if you decided it was fake. Others may have received it.
  6. Do not reply to suspicious messages or click links.

If You Think You Already Sent It

Act immediately. Tell a supervisor, contact the bank to request a recall, and notify IT, the cyber insurance carrier and counsel. Report to law enforcement and the FBI's Internet Crime Complaint Center. Speed improves the odds of recovering funds, though recovery is not guaranteed. No one should be punished for reporting quickly; delays make things worse.

For Managers

  • Give staff explicit permission to pause any payment and make verification calls without asking
  • Keep a verified contact list for recurring counterparties
  • Run short practice exercises with fake requests
  • Praise people who catch scams
  • Make sure the firm's email security tools flag external senders and look-alike domains

A One-Page Checklist

Print this and keep it near the desk:

  • Is this a change to payment instructions?
  • Did I verify by phone with a known number?
  • Did a second person approve?
  • Is the sender address exactly right?
  • Is there pressure to hurry?
  • Have I documented the call?

Support From Counsel Cyber

Counsel Cyber builds email defenses for law firms and trains closing and accounting staff on exactly these scenarios. If you would like a printable checklist adapted to your firm's workflow, we can help.