When a law firm sends or receives a wire, a single changed account number can mean a total loss. The criminals behind these schemes do not need to break into a bank. They only need to convince someone at the firm, or a client, to trust a convincing email. The FBI's Internet Crime Complaint Center has repeatedly warned about business email compromise, including schemes targeting real estate closings and escrow transactions. A written verification procedure, followed every time, is the most effective single defense.
Here is a procedure you can adapt. It is general guidance, not legal advice, and your own counsel and title or escrow partners may have additional requirements.
The principle
Never rely on the channel that delivered the instructions to confirm them. If instructions arrive by email, the confirmation must happen by phone, using a number the firm already knew and trusted before this transaction began.
Step 1: Collect instructions early and in a controlled way
- Ask clients for wire instructions at the start of the matter, not the last day.
- Provide a secure client portal or encrypted method for sending them, instead of ordinary email.
- Warn clients up front, in the engagement letter and in the opening email, that the firm will never change payment instructions by email and that they should call before sending money.
Step 2: Verify by callback
- Look up the phone number from an independent source: your own file from intake, the party's official website, or a previously verified directory. Never use a number in the email or on the instruction document itself.
- Call and speak with a person you can identify. Read back the account name, bank, routing number and the last four digits of the account number.
- Ask the recipient to confirm each detail, and record the date, time, person and number used.
- For any change to previously verified instructions, treat it as a red flag and repeat the full callback with a second staff member listening where practical.
Step 3: Require two people
Separate the person who requests the wire from the person who approves it. The approver independently reviews the verification record before releasing funds. Do not let a managing partner's urgency override the control. Fraudsters often impersonate partners and claim a deadline.
Step 4: Check the bank side
- Confirm that the account name matches the payee.
- Use the bank's own verification features, such as payee-matching or positive pay, where available.
- Set daily limits and dual approval in your online banking.
- Enable multi-factor authentication for all banking users, and use dedicated, hardened workstations for treasury functions if feasible.
Step 5: Watch for red flags
- A last-minute change in account details
- Pressure to act urgently or secretly
- A sender address that is one character off, or a reply-to that differs from the sender
- Requests to send funds to a different state, an unrelated company or a personal account
- A client who suddenly cannot be reached by phone
- Tone or phrasing that differs from the person's earlier messages
- Instructions sent by a forwarded or "new" email address
Step 6: Prepare for the client side
Fraudsters also impersonate the firm to clients, sending fake payment instructions for fees or settlement funds. Tell clients how the firm communicates about money, and remind them before every closing. Consider adding a line to your email signature reminding them never to act on emailed changes without calling.
If you suspect a fraudulent transfer
Speed is critical. The FBI's guidance emphasizes contacting your bank immediately to request a recall and filing a complaint with IC3 as soon as possible. A reasonable response plan includes:
- Call your bank's fraud department at once and ask for a wire recall.
- Contact the receiving bank through your bank if possible.
- Notify the FBI through IC3 and, if appropriate, your local FBI field office.
- Preserve all emails and logs, and do not delete anything.
- Notify your cyber-insurance carrier or broker. Many policies have notice deadlines.
- Involve your IT provider to find out how the email account was compromised, and reset credentials and review mailbox rules.
- Consider your obligations to affected clients. Model Rule 1.4 addresses communication, and ABA Formal Opinion 483 discusses obligations after a data breach. Confirm with your state bar and counsel.
Put it in writing
Write the procedure on one page, post it near the people who handle wires, and review it at least annually. Train new hires on day one. Test it occasionally by simulating a changed-instruction email and seeing whether staff follow the callback step.
Counsel Cyber helps law firms put verification procedures in place, secure their email environments and train staff using realistic scenarios. If you want a review of your current wire process, we can walk through it with you.