Most training on email fraud teaches people to watch for strangers: unfamiliar names, odd addresses, urgent demands. But some of the most damaging fraud comes from people your firm knows well. A court reporter, a title company, an expert witness, or a client has their email account taken over, and the attacker uses that real account, with its real history, to send altered payment details or malicious links to everyone in the contact list.
This pattern is sometimes called vendor email compromise, and it is a variation on the business email compromise schemes the FBI's Internet Crime Complaint Center warns about. Because the message arrives from a genuine address inside an existing thread, ordinary instincts and many filters do not flag it.
How it unfolds
- An attacker steals a credential at a third party, often through a phishing page.
- They read the mailbox quietly to learn who pays whom and how invoices look.
- They create rules to hide replies and sometimes register a lookalike domain.
- At the right moment, they send a message in an existing conversation: "Our bank has changed, please use these details for the next payment."
- Money leaves, and the fraud is discovered days later when the real vendor asks about the invoice.
Firms are exposed in both directions. A vendor's compromise can target your accounting staff, and your own mailbox compromise can be used to target your clients.
Signs worth noticing
- A change to payment method, bank, or account number, especially close to a due date
- An unusual request to switch from check to wire or to pay a different entity
- Slightly altered tone or phrasing, new urgency, or reluctance to talk by phone
- A reply-to address that differs from the sender, or a domain off by a letter
- An invoice that matches a real one but with a changed attachment
None of these is proof alone. The point is to treat the category of request, not only the sender, as risky.
The verification routine
For anything that changes where money goes
- Do not reply to the email or use contact details inside it.
- Call a number you already had on file, not one in the message.
- Confirm the specific change, and read the new account details back aloud.
- Record who you spoke to and when.
- For larger amounts, require a second internal approval.
Keep a verified vendor list
Maintain a short register of frequently paid parties with verified phone numbers and payment details. When something changes, you have a trustworthy reference rather than a forwarded email thread.
Make the process neutral
Verification is not an accusation. A script helps: "We verify all payment changes by phone for everyone. It protects both of us." Professional counterparties usually appreciate it.
Protect your side of the relationship
- Tell clients and vendors how you communicate payment details. For example, say in engagement letters that you will never change wire instructions by email.
- Secure your own mailboxes with MFA, alerts for forwarding rules, and monitoring for unusual sign-ins.
- Set up domain protections such as SPF, DKIM, and DMARC so criminals have a harder time spoofing your domain.
- Watch for lookalike domains. Some services monitor newly registered domains that resemble yours.
If you suspect it happened
Act quickly.
- Contact your bank right away and ask about a wire recall or hold.
- Report to the FBI's IC3 and notify law enforcement as your bank advises.
- Tell your insurer and counsel.
- Alert the vendor or client whose account may be compromised, by phone, so they can secure their systems.
- Preserve emails, headers, and logs.
Early reporting has often improved the chance of recovering funds, though recovery is never guaranteed.
Lessons for firm culture
Create an environment where the receptionist, the bookkeeper, and the junior associate all feel they can say, "I need to verify this." Fraud depends on hierarchy and hurry. Leaders who thank people for pausing do more than any filter.
Where we fit
Counsel Cyber helps law firms combine procedures, training, and technical email protections into a coherent defense against both direct and vendor-based fraud. If you want a review of your payment verification practices and email settings, we would be glad to help.