ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

When the Other Side's Hacked Inbox Puts Your Closing at Risk

Your firm can have excellent security and still be targeted through a compromised agent or client mailbox. Here is how to spot and defend against it.

3 min readBy Counsel Cyber Team

Many firms assume that wire fraud means someone hacked them. In practice, a large share of attempts never touch the firm's systems at all. The attacker compromises the mailbox of a real estate agent, a lender, a client, or opposing counsel and sends fraudulent instructions from a real account in a real conversation. Your firm's email security can be flawless and the email still arrives looking legitimate.

The FBI's Internet Crime Complaint Center describes business email compromise as a scheme where criminals gain access to or spoof legitimate business email to redirect payments. Closings, settlements and escrow disbursements are common targets because the participants are many, the amounts are large and the schedule is tight. This post focuses on the third-party side of the problem, which is the part firms most often overlook.

Why third-party compromise works so well

A compromised mailbox gives an attacker everything needed to be convincing: the real thread, real names, real timelines and the actual writing style. They often set up hidden rules that move incoming replies out of sight, so the real owner never sees the fraudulent messages or your responses. A look-alike domain is no longer necessary. The message is from the correct address.

That means "check the sender" is not enough advice. The sender is correct. The request is the problem.

Warning signs in the message itself

  • A change in payment instructions, however plausible the explanation.
  • Urgency tied to a deadline, bank cutoff or "last-minute" correction.
  • A request to avoid phone calls because the sender is traveling or in a meeting.
  • New account details from a different bank, state or account holder name.
  • A reply that ignores a specific question you asked but pushes the new instructions.
  • Slight changes in tone, formatting or signature compared with earlier messages.

What the firm can control

Make verification independent of email

The central rule is that any change to payment instructions is confirmed by a phone call to a number you already had before the change arrived. Not a number in the new email, not one in a signature block that arrived in the same thread. If you do not have a trusted number, obtain one from an independent source such as the original engagement paperwork or a publicly listed office line.

Tell everyone the rule in advance

At the start of the matter, send clients and counterparties a short notice: the firm will never change wire instructions by email, and any message suggesting otherwise should be reported by phone. Repeat it in the closing packet. Fraud succeeds when the first time people hear the rule is during the attack.

Use secure channels for sensitive details

Send wire instructions through a client portal or encrypted channel rather than as an attachment in a long thread. Fewer inboxes holding the information means fewer inboxes to compromise.

Require two sets of eyes

No outgoing wire from a trust or operating account should be released on one person's judgment. A second person confirms that the verification call occurred and was documented.

Watch your own side

Enforce multi-factor authentication on every mailbox, and review forwarding rules periodically. Attackers who reach your inboxes will do to your clients exactly what was done to the agent.

What to ask outside parties

You cannot control a title company or an agent's security, but you can ask.

  1. Do you require multi-factor authentication on email?
  2. How will you communicate any change in payment details?
  3. Who is the phone contact for verification?

Their answers also tell you how much extra care a given transaction deserves.

If something looks wrong

Pick up the phone and call the number you already trust. If funds have already moved, speed matters. The FBI's guidance generally advises contacting your bank immediately to request a recall, filing a complaint with IC3, and notifying your insurance carrier. Preserve the emails and headers and speak with your ethics counsel about client communication.

Build it into the file

Add a verification step to the closing checklist, with a field for the name of the person called, the number used, the date and the initials of the second approver. Checklists remove the guesswork when everyone is busy.

How Counsel Cyber can help

Counsel Cyber helps law firms set up email protections, MFA and written verification procedures, and trains staff to handle suspicious payment requests. If you would like us to review your wire process, we are glad to help.