Many small firm partners believe attackers are only interested in banks and big retailers. The reality is less comforting. Law firms hold confidential information about clients' finances, disputes, deals and personal lives, they move large sums of money through trust accounts, and they work under deadlines that make people act quickly. Those traits make them attractive, whatever their size.
Understanding what attackers want helps you decide which controls deserve attention first.
Four Things Attackers Want From a Law Firm
1. Money, directly
The most common route is business email compromise. An attacker gains access to an email account or convincingly impersonates a client, a title company or opposing counsel, then redirects a payment. Closings, settlements and retainer payments are all opportunities. The FBI's Internet Crime Complaint Center has repeatedly highlighted business email compromise as one of the costliest categories of internet crime reported to it.
2. Leverage through ransomware
Ransomware gangs encrypt a firm's files and demand payment to restore them. Law firms are attractive because being unable to access files can stop work at once, and because many attackers also steal data first and threaten to publish it. A firm facing missed court deadlines and confidentiality concerns has strong reasons to pay quickly, and attackers know it.
3. Information about clients
Some attackers seek specific information: merger plans, litigation strategy, intellectual property, or personal data of high-net-worth clients. Firms can be a softer route to the same information than the clients' own better-defended systems. A firm may be targeted because of who its clients are, not because of anything about the firm itself.
4. Access to someone else
Compromised law firm accounts can be used to send convincing phishing messages to clients and contacts. A message from a real attorney's real mailbox carries trust that a spoofed address does not.
How Attackers Usually Get In
Sophisticated zero-day exploits are rare in small-firm incidents. The usual routes are more mundane:
- Phishing and credential theft, often with a fake Microsoft 365 login page
- Password reuse from earlier breaches at other sites
- Missing multi-factor authentication on email or remote access
- Unpatched systems, especially internet-facing software and old VPN devices
- Exposed remote desktop services
- Compromised vendors or remote support tools with weak controls
- Social engineering of staff by phone or email
CISA's guidance for small organizations consistently emphasizes the same basics: MFA, updates, backups, and training.
What This Means for Your Defenses
Mapping attacker goals to controls helps prioritize:
- To stop payment diversion: call-back verification for wire instructions, email security that flags impersonation, and MFA on every mailbox
- To limit ransomware damage: tested, separated or immutable backups; endpoint detection with active monitoring; fast patching; limited admin rights
- To protect client information: access controls based on need, encryption, careful vendor choices, and logging so you can tell what was accessed
- To resist account takeover: MFA, conditional access, alerting on suspicious logins, and staff who know how to report a suspicious message
A Note About Size
A small firm does not need an enterprise security operation, but it does need the basics done consistently. Attackers often use automated tools that scan for weaknesses across thousands of organizations. The weakest firms in the pool get hit first, regardless of how interesting their clients are.
Questions Worth Asking This Month
- If an attacker took over one attorney's mailbox today, how quickly would we know?
- Could anyone in the firm be tricked into changing wire instructions without a verification call?
- If every file server were encrypted tonight, how long would recovery take, and have we tested that?
- Which clients would be most embarrassed or harmed if their information leaked, and how is that data protected?
- Do we know every vendor with access to our systems?
If the honest answer to several of these is "we do not know," that is a useful finding in itself.
Starting Point
ABA Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information, and ABA Formal Opinion 483 discusses obligations after a breach. Together they make it worthwhile to understand the threats before choosing defenses. Check your state bar's guidance for specifics.
Counsel Cyber focuses exclusively on the law firm threat picture. If you want a plain-English assessment of where your firm is most exposed, we offer a security review that ranks risks by what attackers actually do.