ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Ten Warning Signs a Law Firm Email Account Has Been Compromised

Early detection limits damage from a hijacked mailbox. Learn the signs administrators and staff should watch for and the steps to take in the first hour.

4 min readBy Counsel Cyber Team

A compromised email account rarely announces itself. The attacker wants to stay quiet, read mail, learn how the firm handles payments and wait for the right moment. For law firms the stakes are high, since a single mailbox may hold privileged communications, wire instructions and client identifiers. The faster a firm notices, the less an intruder can do.

The FBI's Internet Crime Complaint Center has long warned about business email compromise, in which criminals take over or imitate legitimate accounts to redirect money. Knowing the signs gives staff a way to raise a concern before it becomes an incident.

Ten warning signs

  1. Mail rules you did not create. Attackers often add inbox rules that forward messages outside the firm or move replies into hidden folders like RSS Feeds or Archive so the real user never sees them.
  2. Sent items you do not recognize. Messages in the sent folder, or bounce notices for emails the user never wrote, suggest someone else is sending.
  3. Colleagues report odd messages. Clients or coworkers say they received a strange link or request that appeared to come from you.
  4. Unexpected sign-in alerts. Notifications of logins from unfamiliar locations, devices or at odd hours deserve attention, even if the alert seems to be a mistake.
  5. Repeated MFA prompts you did not trigger. A stream of approval requests can mean someone has your password and is hoping you tap approve. Treat it as a sign your password is known.
  6. Password reset emails you did not request. These can mean someone is probing accounts.
  7. Missing or deleted messages. Attackers sometimes delete evidence such as security alerts or warnings from clients.
  8. Changed settings. Altered signature text, new connected apps, a changed recovery phone number or added delegates on the mailbox are all red flags.
  9. Oddly timed replies in existing threads. A message that slips into a real conversation about a closing or settlement and changes payment instructions is a classic pattern.
  10. A slower or strange login experience. On its own this is weak evidence, but combined with anything above it is worth reporting.

What to do in the first hour

Speed matters more than perfection. If anyone suspects a compromised account:

  1. Report it immediately to IT or your provider by phone, not by email from the possibly compromised account.
  2. Reset the password from a clean device, and revoke active sessions so the attacker is signed out.
  3. Check MFA methods and remove any phone numbers or authenticator apps the user does not recognize.
  4. Inspect mailbox rules, forwarding and delegates and remove anything suspicious. Record what you find before deleting it, since it is evidence.
  5. Review sign-in logs for dates, locations and which applications were used.
  6. Warn the affected people. If fraudulent messages were sent, tell recipients not to act on them.
  7. Pause any pending payments connected to that mailbox until instructions are re-verified by phone.

Preserve evidence and assess exposure

Keep logs, screenshots and copies of malicious messages. Your provider can determine what the attacker accessed, which affects whether client notification is needed. ABA Formal Opinion 483 discusses lawyers' duties when a breach occurs, including monitoring for breaches and notifying current clients when material client information is involved, and state laws can add their own notification requirements. Involve your attorney, your cyber insurance carrier and counsel familiar with breach notification early, and confirm obligations in your jurisdiction.

Reduce the chance it happens

  • Enforce MFA for every account, preferring authenticator apps or security keys over text messages.
  • Block legacy authentication protocols that do not support MFA.
  • Enable alerts for new inbox rules and external forwarding.
  • Use email filtering that detects impersonation and malicious links.
  • Train staff to recognize phishing and to report quickly without fear of blame.
  • Require phone verification of any change to payment instructions.

Make reporting easy

The most valuable habit is reporting early. Many compromises are found because an assistant noticed something odd and said so. Give people a short phone number or an alias for reporting, praise those who raise concerns even if they turn out to be false alarms and never criticize someone for clicking a link and then reporting it.

A hypothetical example

Consider a hypothetical eight-attorney firm where a paralegal enters credentials on a fake sign-in page. The attacker creates a rule forwarding any message containing "wire" to an outside address. Three weeks later a legitimate closing email is altered. If the firm monitored for new forwarding rules, it would have received an alert the day the rule was created, and the later fraud would have had no foothold.

How we can help

Counsel Cyber monitors Microsoft 365 for exactly these signals as part of our managed security services for law firms. If you are not sure whether anyone would notice a rule like the one above, ask us for an email security review.