ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Ten Phishing Red Flags Every Law Firm Employee Should Know

A staff-friendly list of ten phishing red flags specific to law firms, from fake e-signature requests to spoofed court notices, plus what to do if you click.

3 min readBy Counsel Cyber Team

Phishing succeeds because it looks like work. For law firms, that means emails that mimic clients, courts, title companies, e-filing systems and the software your staff already uses all day. Attackers do not need to be clever when the message arrives in the middle of a busy afternoon and asks for something routine.

Here are ten red flags you can post by the break room coffee machine or build into your training.

The Ten Red Flags

1. Urgency or pressure

"Respond today or the matter is lost." Real deadlines exist in law, which is why attackers exploit them. Pressure is a signal to slow down and verify.

2. A sender address that does not match

The display name says "Judge's Clerk" or your managing partner, but the actual address belongs to an unrelated domain, or one that is a character off. Always check the full address.

3. Unexpected document-sharing or e-signature requests

"A document has been shared with you" or "Please review and sign." Attackers copy the look of familiar sharing and signature tools. If you were not expecting it, contact the sender through another channel before clicking.

4. Sign-in prompts after clicking a link

If a link sends you to a page asking for your Microsoft 365 or practice-management password, stop. Go to the service directly through a bookmark instead.

5. Changes to payment or banking details

Any email changing wiring instructions or invoice payment details is high risk. Confirm by calling a known number. This applies even if the email appears to come from a person you know.

6. Unusual attachments

Be cautious with unexpected attachments, especially compressed files, files that ask you to "enable macros" or "enable content," and PDFs that contain only a button or link.

7. Requests for secrecy

"Don't mention this to anyone yet" or "I'm in a meeting, just handle this." Secrecy is meant to stop you from verifying.

8. Odd requests from executives

A message from the managing partner asking you to buy gift cards, change a direct deposit or purchase something is a classic impersonation attempt. Real partners will not be upset when you check.

9. Generic or slightly off wording

Greetings like "Dear user," awkward phrasing or formatting that differs from the real sender can be clues. But polished text is no longer a reliable sign of safety, since attackers use better tools now, so do not rely on spelling alone.

10. Links that do not match their text

Hover over a link, or press and hold on a phone, to preview the real destination. If it does not match what the message claims, do not click.

Phone and Text Variants

Phishing is not limited to email. Watch for text messages claiming to be from the firm's IT department, voicemail messages asking you to call back, and QR codes in unexpected emails or mail. The same rules apply: verify through a known channel.

What to Do If You Clicked

Speed matters more than embarrassment.

  1. Disconnect from the network if you opened a suspicious file, but do not turn off the device.
  2. Report it right away to your IT provider or the designated contact.
  3. Change your password if you entered credentials, and tell IT so they can review your account and revoke sessions.
  4. Do not delete the email, because it helps with investigation.
  5. Note what happened, including the time, what you clicked and what you entered.

Firms that praise quick reporting uncover problems faster than firms that scold.

Making Training Stick

  • Keep sessions short and frequent rather than one long annual lecture.
  • Use examples from legal work.
  • Run simulated phishing emails and follow up with coaching, not punishment.
  • Include partners and executives.
  • Add a visible "Report phishing" button to email.

Technical Backing

Staff awareness is one layer. Email filtering, multi-factor authentication, endpoint protection and a wire verification process catch what people miss. No individual should be the only barrier between an attacker and client data.

How We Can Help

Counsel Cyber provides security awareness training, phishing simulations and email protection for law firms. If you would like a short, law-specific training session for your team, let us know.