ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

The Call-Back Rule: One Habit That Stops Most Wire Fraud

A verified phone call to a known number before any wire instruction change is the simplest defense against business email compromise. Here is how to enforce it.

3 min readBy Counsel Cyber Team

If a law firm could add only one rule to its wire process, it should be this: never send or change a payment on the basis of an email alone. Verify by phone, using a number you already trusted before the request arrived. It sounds almost too simple, and yet this single habit defeats the core move of business email compromise.

The FBI's Internet Crime Complaint Center has consistently reported business email compromise among the highest-loss categories of cybercrime it tracks, and its guidance on prevention centers on verification through a second channel. Law firms, which handle closings, settlements, escrow and retainers, are natural targets.

Why Email Alone Cannot Be Trusted

Attackers have several ways to make a payment instruction look genuine:

  • Compromised mailbox. The attacker reads real conversations and replies inside the thread from a real account.
  • Spoofed or look-alike domains. An address that differs from the real one by one letter is easy to miss on a phone.
  • Impersonated executives or clients. A short message that says "I need this wired today" creates urgency.
  • Altered invoices. A genuine invoice is edited to change the bank details.

In each case the email looks plausible, and the checks on the message itself are unreliable. The reliable check is outside the compromised channel.

What the Call-Back Rule Says

A good written rule is short:

  1. Any request to send funds to a new account, or to change existing instructions, must be verified by phone before action.
  2. The phone number must come from a source independent of the request: your file from the start of the matter, a prior verified call, or a directory the firm already trusted. Never use a number in the email asking for the change.
  3. The person making the call speaks to someone known to the firm, if possible, and confirms the account details out loud.
  4. A second person approves the transfer above a set threshold.
  5. The verification is documented in the file with date, time, who was called and who approved.
  6. No one may waive the rule because of urgency, seniority or client pressure.

Common Ways the Rule Fails

Using the number in the email

If the attacker supplies the number, the attacker answers the call. Always use an independent number.

Treating it as optional for good clients

Longtime clients and familiar title companies are the ones whose accounts get compromised and impersonated. The rule applies to everyone.

Letting urgency override it

Deadlines are exactly the pressure attackers manufacture. Build the rule so that urgency triggers more care, not less.

Verifying once and never again

A verified instruction at the start of a matter does not guarantee later emails are real. Re-verify when anything changes.

Calling only the sender

If the sender's mailbox is compromised, the "sender" might not know about the request. Call the person at the independent number and ask about the specific instructions.

Make It Easy to Follow

  • Collect and record verified phone numbers at intake, along with preferred contacts at title companies and lenders
  • Tell clients in your engagement letter that you will never change wire instructions by email, and ask them to call you to confirm
  • Put the call-back step on the trust disbursement checklist as a required field
  • Use your practice management or accounting software to require a second approver
  • Train anyone who can initiate or approve payments, including receptionists and assistants

If a Fraudulent Wire Is Sent

Time matters. Contact your bank immediately and ask for a recall, notify law enforcement, and file a report with the FBI's Internet Crime Complaint Center. Call your cyber insurance carrier and counsel as well. The faster the bank is alerted, the greater the chance of recovering funds, although recovery is never guaranteed.

Tie It to the Rest of Your Defenses

The call-back rule works alongside email security that flags impersonation, MFA on every mailbox, and security awareness training. Rule 1.15 trust accounting obligations in your state add another reason to treat these steps as required procedure; check your jurisdiction's rules.

Testing the Habit

Once a year, run a drill with a harmless fake request and see whether staff follow the process. Reward people who stop it.

How Counsel Cyber Helps

Counsel Cyber helps law firms write wire verification procedures, configure email defenses, and train staff with realistic examples. If your current process depends on good intentions rather than a documented rule, we can help you tighten it.