Law firms often think of themselves as too small or too quiet to be interesting. Attackers see something different: a concentrated store of sensitive documents, a steady flow of money moving through trust and escrow accounts, and an office culture built on responding quickly to email. Understanding how an attacker views your firm is the fastest way to decide where to spend your next security dollar.
This post walks through what makes firms attractive, how attackers typically get in, and what to do about each path.
What attackers want from a firm
Confidential client information
A firm's files can include merger plans, litigation strategy, medical records, financial statements, and personal identifiers. That material has value for extortion, for insider trading, for identity theft, and for gaining leverage in disputes. Even a small family-law or estate-planning practice holds records that clients would be devastated to see exposed.
Money in motion
Real estate closings, settlements, and trust account disbursements create moments when large sums move on the strength of an email. The FBI's Internet Crime Complaint Center has repeatedly flagged business email compromise as among the costliest categories of cybercrime it tracks, and real estate transactions are a recurring theme in its guidance.
A pressure point for ransom
A firm that cannot reach its files has missed deadlines, upset clients, and potential ethics exposure. That pressure makes a ransom demand more tempting to pay, and attackers know it.
A path to someone else
Firms often hold credentials, shared portals, and trusted email relationships with larger clients. A compromised firm mailbox can be used to send convincing messages to those clients.
The common ways in
Most intrusions are not exotic. They tend to follow a short list.
- Phishing and credential theft. A realistic login page captures a password. Without MFA, that is often enough.
- Business email compromise. The attacker reads mail for days, learns the firm's rhythms, then inserts fraudulent payment instructions at the right moment.
- Unpatched internet-facing systems. Old VPN appliances, remote desktop exposed to the internet, and neglected servers are routinely scanned for.
- Reused or weak passwords. Credentials leaked from unrelated breaches get tried against law firm accounts.
- Compromised vendors. A tool or service provider with access to your environment becomes the bridge.
Matching defenses to the paths
Make stolen passwords useless
Enforce multifactor authentication on email, remote access, practice-management tools, and administrator accounts. Prefer app-based or hardware methods over text messages where you can. Conditional access rules that block sign-ins from unexpected countries add another layer.
Make email harder to abuse
Use filtering that inspects links and attachments, enable protections against spoofing of your own domain, and turn on alerts for suspicious mailbox rules, such as auto-forwarding to outside addresses. These rules are a classic sign of an attacker quietly watching a mailbox.
Make payment changes slow on purpose
Require a call-back to a known phone number before any change to wire instructions, and apply the rule to everyone, including partners. Speed is what the attacker is counting on.
Keep systems current
Patch on a schedule, retire anything that cannot be patched, and do not expose remote desktop directly to the internet. Ask your IT provider for a list of every service reachable from outside your network.
Watch for what slips through
Prevention fails sometimes. Endpoint detection and response with human monitoring, often called managed detection and response, shortens the time between a compromise and someone noticing it. Dwell time is what turns an incident into a catastrophe.
Plan for the bad day
Keep backups that an attacker cannot delete, write down who makes decisions during an incident, and know your carrier's hotline. The ABA has said in Formal Opinion 483 that lawyers have obligations to monitor for and respond to breaches, so confirm with your state bar what applies in your jurisdiction.
A hypothetical
Consider a hypothetical eight-attorney firm. A paralegal clicks a fake document-sharing link and enters her password. With no MFA, the attacker logs in, sets a hidden forwarding rule, and watches closing correspondence for a week. When a title company asks for payoff instructions, the attacker replies first. A call-back rule or an MFA requirement would have broken that chain at two separate points.
Where to start
Pick the three paths above that worry you most and verify your controls against each. Counsel Cyber offers security reviews that look at your firm the way an attacker would, and we are happy to talk through the findings in plain language.