ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

The Wire Fraud Call-Back Rule: How to Build It and Enforce It

A call-back rule is the single cheapest defense against fraudulent wire instructions. Learn how to write it, train staff, and keep partners from skipping it.

3 min readBy Counsel Cyber Team

Most wire fraud against law firms does not involve sophisticated hacking. It involves an email that looks right, arrives at the right moment, and asks for a small change: new account number, new bank, new routing details. The defense that works best is also the least technical: pick up the phone and verify.

A call-back rule is a written procedure requiring that any request to send money or change payment instructions be confirmed by calling a known phone number before funds move. The FBI's Internet Crime Complaint Center has consistently advised verifying payment changes through a separate, trusted channel, and many cyber insurers ask about this kind of procedure on applications.

Why email alone cannot be trusted

An email can be spoofed to look like it came from a client, a title company, or your own managing partner. Worse, an attacker who has quietly broken into one real mailbox can reply inside a genuine thread, with the real history and the real signature. The message is not faked. It is real mail, sent by the wrong person. That is why technical filtering helps but cannot replace human verification.

What a good call-back rule says

Scope: what triggers it

  • Any new wire instruction
  • Any change to existing instructions, including a changed account number, bank name, or beneficiary
  • Any request to send funds urgently or outside normal process
  • Any internal request from a partner to move money by email or text

The verification step

  1. Stop. Do not reply to the email or use contact details in it.
  2. Look up the phone number from a trusted source: your file, a prior engagement letter, the party's official website, or a number you already used successfully.
  3. Call and speak to a person you can recognize or confirm through a verification detail.
  4. Read back the account number and bank name aloud.
  5. Record the call: who, when, number dialed, and who confirmed.

Second approver

For larger disbursements, require a second person to review the documentation and approve. The second person should see the call-back record, not just the request.

Common failure points

  • Using the number in the email signature. If the attacker controls the email, they control the number.
  • Calling once and never again. Verify each change, not just the first one.
  • Exempting clients you know well. Attackers impersonate the people you trust most.
  • Letting partners opt out. Attackers specifically impersonate senior people because staff hesitate to question them.
  • Rushing at closing. Pressure is a feature of the scam, not a coincidence.

Make it stick

Get partner buy-in first

The rule only works if the managing partner follows it publicly. Include a sentence in the policy such as: "No exceptions, including for partners." Staff need explicit permission to say, "I need to verify this before I send it."

Tell clients up front

Put a short notice in engagement letters and closing instructions: the firm will never change wire instructions by email, and the client should call the firm's known number to confirm any instruction. This protects both sides, because attackers also impersonate firms to clients.

Practice with a drill

Run a short tabletop exercise. Hand staff a fake request mid-afternoon on a busy Friday and see what happens. Treat misses as chances to improve the process, not to blame individuals.

Support the process technically

  • Enable multifactor authentication on all mailboxes so attackers cannot easily get in.
  • Alert on forwarding rules and unusual sign-ins.
  • Flag external email and lookalike domains.
  • Keep a vetted contact list of verified phone numbers for frequent counterparties.

If something goes wrong

Speed matters. If you suspect a fraudulent transfer, contact your bank immediately and ask about a recall, then report to the FBI's IC3 and notify your insurer. Prompt action has historically improved the chance of recovering funds, although recovery is never guaranteed. Also review your obligations to clients and consult your state bar's guidance.

A short template to adapt

Write a one-page procedure with these headings: Purpose, Scope, Verification Steps, Approvals, Recordkeeping, Exceptions (none), and Reporting a Suspected Fraud.

Next step

Counsel Cyber helps law firms write these procedures, train staff, and add the email protections that make them harder to bypass. If your firm has no written call-back rule yet, we would be glad to help you draft one.