Most wire fraud against law firms does not involve sophisticated hacking. It involves an email that looks right, arrives at the right moment, and asks for a small change: new account number, new bank, new routing details. The defense that works best is also the least technical: pick up the phone and verify.
A call-back rule is a written procedure requiring that any request to send money or change payment instructions be confirmed by calling a known phone number before funds move. The FBI's Internet Crime Complaint Center has consistently advised verifying payment changes through a separate, trusted channel, and many cyber insurers ask about this kind of procedure on applications.
Why email alone cannot be trusted
An email can be spoofed to look like it came from a client, a title company, or your own managing partner. Worse, an attacker who has quietly broken into one real mailbox can reply inside a genuine thread, with the real history and the real signature. The message is not faked. It is real mail, sent by the wrong person. That is why technical filtering helps but cannot replace human verification.
What a good call-back rule says
Scope: what triggers it
- Any new wire instruction
- Any change to existing instructions, including a changed account number, bank name, or beneficiary
- Any request to send funds urgently or outside normal process
- Any internal request from a partner to move money by email or text
The verification step
- Stop. Do not reply to the email or use contact details in it.
- Look up the phone number from a trusted source: your file, a prior engagement letter, the party's official website, or a number you already used successfully.
- Call and speak to a person you can recognize or confirm through a verification detail.
- Read back the account number and bank name aloud.
- Record the call: who, when, number dialed, and who confirmed.
Second approver
For larger disbursements, require a second person to review the documentation and approve. The second person should see the call-back record, not just the request.
Common failure points
- Using the number in the email signature. If the attacker controls the email, they control the number.
- Calling once and never again. Verify each change, not just the first one.
- Exempting clients you know well. Attackers impersonate the people you trust most.
- Letting partners opt out. Attackers specifically impersonate senior people because staff hesitate to question them.
- Rushing at closing. Pressure is a feature of the scam, not a coincidence.
Make it stick
Get partner buy-in first
The rule only works if the managing partner follows it publicly. Include a sentence in the policy such as: "No exceptions, including for partners." Staff need explicit permission to say, "I need to verify this before I send it."
Tell clients up front
Put a short notice in engagement letters and closing instructions: the firm will never change wire instructions by email, and the client should call the firm's known number to confirm any instruction. This protects both sides, because attackers also impersonate firms to clients.
Practice with a drill
Run a short tabletop exercise. Hand staff a fake request mid-afternoon on a busy Friday and see what happens. Treat misses as chances to improve the process, not to blame individuals.
Support the process technically
- Enable multifactor authentication on all mailboxes so attackers cannot easily get in.
- Alert on forwarding rules and unusual sign-ins.
- Flag external email and lookalike domains.
- Keep a vetted contact list of verified phone numbers for frequent counterparties.
If something goes wrong
Speed matters. If you suspect a fraudulent transfer, contact your bank immediately and ask about a recall, then report to the FBI's IC3 and notify your insurer. Prompt action has historically improved the chance of recovering funds, although recovery is never guaranteed. Also review your obligations to clients and consult your state bar's guidance.
A short template to adapt
Write a one-page procedure with these headings: Purpose, Scope, Verification Steps, Approvals, Recordkeeping, Exceptions (none), and Reporting a Suspected Fraud.
Next step
Counsel Cyber helps law firms write these procedures, train staff, and add the email protections that make them harder to bypass. If your firm has no written call-back rule yet, we would be glad to help you draft one.