Most email attacks against law firms succeed for a simple reason: the message looks like something the recipient expects. A client asking for a status update. A partner requesting a quick favor. A vendor announcing new payment details. Attackers study the legal workflow, and their messages blend into it.
You cannot train staff to catch every forgery by sight, and you should not ask them to. What you can do is teach a handful of signals and, more importantly, a habit: when a message asks for money, credentials or sensitive files, verify through another channel. This guide can be adapted for a ten-minute staff session.
Two kinds of fake
It helps to separate two ideas.
- Spoofing means forging the sender's display name or address so the message appears to come from someone you know.
- Account compromise means the attacker is in a real person's mailbox, so the message really does come from the legitimate address.
Spoofed messages can sometimes be spotted by close inspection. Compromised-account messages cannot, which is why behavior-based rules matter more than appearance.
Signals worth teaching
The sender
- The display name matches someone you know, but the address behind it does not. On a phone, tap the name to reveal the address.
- The domain is almost right: one letter swapped, a hyphen added, or ".co" in place of ".com."
- A reply-to address differs from the sender address.
- The message is marked as external but claims to be from a partner.
The request
- Urgency or secrecy: "Need this today, please do not discuss."
- A request to bypass normal procedure, such as skipping the callback.
- A change in payment details, especially close to a closing or settlement.
- A request for gift cards, a quick wire or a change of direct deposit information.
- An unexpected attachment or link to sign in to a document sharing service.
The tone and context
- Language slightly different from how the person normally writes.
- A message that arrives at an odd hour or while the person is known to be traveling.
- A thread you have not seen, or a reply to a conversation you were never in.
The habit that beats the forgery
Teach one rule: if an email asks you to move money, change payment details, share credentials or send sensitive files, confirm it by phone using a number you already have. Not the number in the message. Not a reply. A call, or an in-person check with the person.
Make this rule easy and blameless. Staff should never feel they are insulting a partner by confirming. Partners should say out loud that they want to be verified.
Handling links and attachments
- Hover over links to see the destination before you click. On mobile, press and hold.
- Be suspicious of any prompt to enter your Microsoft 365 password after clicking a link, even if the page looks right. Navigate to the site yourself instead.
- Treat unexpected attachments, particularly those that ask you to enable macros or content, as suspicious.
- If you accidentally clicked or entered a password, report it immediately. Speed limits damage.
Make reporting simple
Provide a one-click report button in Outlook or a dedicated address. Thank people who report, even when it turns out to be harmless. A firm where staff report freely finds problems faster than a firm where people stay quiet out of embarrassment.
Support staff with technology
Training works best alongside controls.
- Email filtering and impersonation protection that flags lookalike domains and display-name tricks.
- DMARC, SPF and DKIM configured for your domain, so others cannot easily forge your firm's address.
- Warning banners on external email.
- MFA on every mailbox.
- Alerts for new forwarding rules and unusual sign-ins.
Run short, realistic exercises
Phishing simulations can be useful when done with care. Keep them fair, resist trying to trick people with emotionally manipulative content, and focus on teaching. Track reporting rates, not just click rates. Use results to adjust training, never to humiliate individuals.
A ten-minute agenda
- Show two real-looking but fictional examples and ask what looks off.
- Explain the difference between spoofing and a compromised account.
- Teach the verify-by-phone rule.
- Show how to report a suspicious message.
- Remind everyone that urgent requests for money deserve extra care.
Next step
Counsel Cyber provides security awareness training for law firm staff along with email security configuration. If you want a short session tailored to your team's workflows, we can arrange one.