Back to blog
Business Email Compromise in Law and Accounting Firms: How Trusted Mailboxes Become the Attack

Written by
Brightside Team
Published on
Four days before completion, the buyer's solicitor replies to a thread that has been running for six weeks. The message sits in the right conversation, beneath forty earlier messages. It carries the firm's signature block, the matter reference, and a revised completion statement as a PDF attachment. The tone matches every previous email from that partner, because the partner wrote every previous email from that partner. Only one thing has changed since the last version of the statement: the account number the money should go to.
The buyer's finance team checks the sender address. It is correct. Their mail gateway checks the authentication record. It passes. Nothing about the message is forged, because nothing about it needed to be forged. Someone else is simply sitting inside the partner's mailbox.
This is the problem at the centre of law firm business email compromise, and better message inspection cannot solve it. When an attacker controls a genuine account, SPF, DKIM and DMARC all align. The thread history is real. The attachments are real. The writing style is real, because the attacker has six weeks of the partner's correspondence to imitate, or can simply quote it. Every signal a firm has trained its people to look for comes back clean.
The defense therefore has to move somewhere the attacker cannot follow: into the identity layer, where a stolen session can be detected and revoked, and into the payment and disclosure processes, where a single email is never sufficient authority to do something irreversible. What follows covers how these compromises work across law firms, accounting practices, tax advisories and consultancies, why advisers make unusually valuable targets, what the professional obligations look like on both sides of the Atlantic, and which controls actually reduce loss.
Key Takeaways
A genuinely compromised adviser mailbox passes SPF, DKIM and DMARC. Domain authentication is necessary, but it cannot detect an attacker operating through a legitimate account, so message inspection cannot be the primary control.
One partner or adviser mailbox can expose dozens or hundreds of separate client organizations at once. That makes a professional-services firm a supply-chain target, and makes its client list a ready-made distribution channel for onward attacks.
The fraudulent instruction often originates outside the firm entirely, from a compromised client, opposing counsel, agent or title company. A firm's own security posture does not determine its exposure.
Treat any mailbox compromise as cloud-identity compromise. The stolen identity usually also reaches document management, SharePoint, OneDrive, Teams, e-signature platforms and client portals.
The control that reliably stops loss is procedural, not technical: no new or changed payment instruction is ever executed on the strength of an email, verification runs by callback to a number already held in the matter file, and two people approve before funds move.
What Mailbox Compromise Looks Like in a Professional-Services Firm
"Mailbox compromise" describes at least five distinct situations, and firms that treat them as one thing tend to build controls that only address the least common of them.
Genuine account compromise is the case that defeats conventional defenses. An attacker takes control of a real Microsoft 365 or Google Workspace account belonging to a partner, associate, paralegal or finance administrator. The routes in are well documented: credential phishing, adversary-in-the-middle kits that relay a multi-factor prompt in real time, stolen session cookies, password reuse, infostealer malware sold on criminal markets, malicious OAuth application consent, device-code phishing, manipulation of a help desk into resetting multi-factor authentication, compromise of a managed service provider, and legacy authentication protocols that were never switched off. Once inside, the attacker sends mail as the professional, from the professional's account. There is no lookalike domain to notice and no spoofed header to catch.
Lookalike-domain impersonation is the older technique and remains common because it is cheap. The attacker registers a domain that resembles the firm's: a visually similar character substitution, an inserted hyphen, a pluralized name, a different top-level domain, or an appended word such as "legal," "group," or a city name. The registration is often paired with a cloned website, copied staff profiles, and reproduced engagement letters. This variant is detectable, which is precisely why sophisticated actors increasingly prefer the first one.
Client mailbox compromise inverts the usual assumption. The firm's systems are untouched. The attacker is inside the client's mailbox, watching a matter progress, and at the right moment sends the firm fraudulent instructions to release funds to a new account. Guidance from the Solicitors Regulation Authority describes incidents where the fraud originated in a client's compromised email rather than anything belonging to the firm. Every control a firm builds around its own identity infrastructure is irrelevant to this scenario.
Counterparty compromise works the same way one step further out. Opposing counsel, a property agent, a title company, an expert witness, a lender, an insurer or a transaction adviser is compromised, and the attacker exploits the communication chain that connects every participant in the matter. In a transaction with six organizations exchanging instructions, the weakest identity posture among them sets the effective security of the whole deal.
Shared and functional mailbox compromise is the quietly dangerous one. Accounts such as accounts@, payments@, completions@, billing@ or tax@ often carry broader visibility than any individual lawyer's mailbox, are accessed by several people, are rarely covered by the same conditional access rules, and attract far less monitoring attention than a named partner account. They are also the mailboxes through which payment instructions actually flow.
Why Advisers Are Worth More to an Attacker Than Their Clients Are
A compromised mailbox at an ordinary company gives an attacker one organization's correspondence. A compromised mailbox at a professional-services firm gives them something structurally more valuable, for four reasons.
Advisers combine information, authority and trust in a single account. Law firms and accounting practices routinely know that a company is about to be acquired, that a settlement has been agreed, that a completion is scheduled for Friday, that a client is about to move capital, that payroll or escrow funds are due, that a restructuring is imminent, or that a regulator has opened an investigation that has not been announced. The mailbox supplies both the intelligence and the credible means of acting on it. The UK's National Cyber Security Centre identifies the legal sector as attractive precisely because firms hold sensitive client information, valuable intellectual property and large sums of money.
Clients are conditioned to act on professional instructions. A request from outside counsel or an accountant carries an authority that the same request from an unfamiliar vendor would not. Attackers exploit that deference directly, and they exploit the ordinary texture of professional work to do it: genuine legal complexity that discourages questions, real deadlines, fear of delaying a completion, explicit confidentiality instructions that discourage checking with colleagues, the expectation that fees and disbursements must be paid promptly, and the entirely legitimate fact that transaction details do change late in a matter.
Professional workflows are email-dependent and cross organizational boundaries constantly. Drafts, evidence, invoices, bank details, tax records and approvals move by email between parties who have no shared IT environment and no common security baseline. That makes it genuinely difficult to establish what normal communication looks like, which is the foundation any anomaly detection depends on.
One mailbox exposes many clients. This is the difference that matters most. Compromise of a corporate employee exposes one organization. Compromise of a transactional partner or a tax principal can expose information belonging to dozens or hundreds of separate client organizations, along with the relationships, formats and timing needed to attack each of them convincingly. The firm becomes a supply-chain target, and its client list becomes a distribution channel.
Layered on top of all of this is custody. Conveyancing, litigation settlements, trust and client accounts, escrow, insolvency, probate, tax payments and corporate transactions mean that lawyers and accountants repeatedly hold or direct other people's money. The FBI's Internet Crime Complaint Center specifically warns that business email compromise targets buyers, sellers, real-estate attorneys, title companies and agents, with attackers monitoring proceedings and changing payment instructions at the moment the change will seem plausible.
How the Compromise Unfolds
The sequence below follows the same broad arc as business email compromise in any sector, but each stage has professional-services specifics worth knowing. It is consistent enough across incidents to be useful as a detection map, and the earlier stages leave the evidence that matters most.
Target selection. Attackers identify professionals through firm websites, bar and professional directories, court filings, conference programmes, transaction announcements and LinkedIn. The highest-value targets are predictable: managing partners, real-estate and conveyancing lawyers, litigation and restructuring partners, tax principals, client-account and finance personnel, executive assistants with delegated mailbox access, and IT administrators.
Initial access. The lure is tailored to the profession rather than to the individual's personality. A court filing notification, a secure client message, a data-room invitation, a revised contract, an invoice, a tax-authority notice, an e-signature request, a regulator or bar-association message, or a Microsoft 365 voicemail alert. Alternatively, no lure at all: credentials and session cookies harvested by infostealer malware are bought ready-made, which removes the phishing step entirely and means the firm may never receive a suspicious message.
Reconnaissance. This is the stage most firms miss, and it is often the longest. Having gained access, the attacker reads rather than acts, sometimes for weeks. They search the mailbox for terms that identify money in motion: wire, bank, settlement, closing, completion, escrow, trust, client account, remittance, invoice, acquisition, confidential, payroll, tax refund. They learn the firm's invoice format, its approval chain, which partner signs off what, and how a given client normally communicates.
Persistence and concealment. The attacker establishes a way back in and a way to stay hidden. Typical artefacts include inbox rules that move or delete replies containing finance keywords, forwarding to an external address, newly granted OAuth applications, an additional registered multi-factor method, and reuse of existing refresh tokens so that a password reset alone does not evict them. Microsoft's incident response teams have repeatedly documented threat actors using native mailbox features such as inbox rules and message routing to maintain covert access after identity compromise. Attackers may also register a lookalike domain at this stage and hold it in reserve, so the fraud can continue after the compromised account is locked.
Thread hijacking. The attacker waits for a genuine transaction to reach the right moment, replies inside the existing conversation, and changes exactly one thing. Everything surrounding that one change is legitimate, which is why recipients so often see no reason to question it.
Delay and suppression. After the money moves, the attacker works to consume the recovery window. The victim is told the payment is still processing, that the receiving bank is running compliance checks, that a corrected receipt will follow, or that the matter should not be discussed outside the deal team. Recall and freezing options degrade quickly, so every day of confusion is worth money to the attacker.
Expansion. The compromised firm then becomes infrastructure. Its mailbox is used to attack clients, opposing counsel, experts, auditors, insurers, banks and vendors, all of whom have a documented reason to trust it.
The Scenarios That Turn Access Into Loss
Access on its own costs nothing. These are the plays that convert it, and they map directly onto the workflows professional-services firms run every week.
Conveyancing and completion fraud. The attacker monitors correspondence among buyer, seller, both firms, agents, the title company and the lender, then issues replacement wire instructions shortly before closing. The supporting tactics are consistent: a claim that the firm has changed banks, a payment switched from cheque to wire, a revised completion statement, impersonation of the title company or attorney, and an instruction not to telephone because the lawyer is in court or in a hearing. Increasingly the email is followed by a voice call that confirms the new details. High value, predictable timing and a large cast of participants make property transactions one of the most established targets in this category.
Settlement-payment diversion. Once litigation settles, the attacker changes the account designated for settlement proceeds, opposing counsel's trust account, expert or mediator fees, class-action distributions or insurance payments. What makes settlements unusually exposed is ambiguity of ownership. With opposing counsel and multiple represented parties involved, it is often genuinely unclear which organization is responsible for verifying a payment instruction, and each party may assume another has done it.
Client-account and trust-account fraud. Here the attacker impersonates the client, asking the firm to release money to a new beneficiary, or compromises a firm employee with access to the client-account workflow. The regulatory consequences are distinctive: the Solicitors Regulation Authority requires firms to replace shortages in client accounts immediately upon discovery, including shortages arising from cyberattack. Being deceived does not, on its own, discharge the obligation.
Invoice and professional-fee diversion. Attackers replace the bank details on a genuine invoice, send a fabricated invoice from a compromised partner account, redirect payment of counsel or expert fees, alter the payment block inside a PDF, request payment to a "regional office" or an associated entity, or simply press for urgent settlement of an overdue bill. Accounting and consulting firms face the same exposure, and their invoices are often larger and recurring, which makes an altered account number harder to spot against a familiar pattern.
Tax and payroll fraud. Compromised accounting and tax-practice accounts are used to request W-2, W-9 or equivalent documents, payroll files, employee bank details, tax-portal credentials, changes to refund or payment accounts, and copies of identity documents. Guidance aimed at CPA firms notes that wire fraud exposure is heightened wherever a practice handles client money. Seasonality matters here in a way it does not elsewhere: filing deadlines compress judgment and normalize unusual requests.
Intelligence theft in transactional and contentious matters. Not every compromise is monetized through a payment. A due-diligence mailbox may hold transaction code names, valuations, financing terms, bid documents, board deliberations, regulatory strategy, data-room links, draft announcements and material nonpublic information. A litigation mailbox may hold legal strategy, witness identities, expert reports, settlement authority limits, internal-investigation findings and privileged communications. The monetization routes are insider trading, extortion, competitive intelligence, or better-targeted attacks on other participants. The harm here is strategic and often surfaces long after the access ends.
Client credential theft. The adviser's account is used as a launchpad. Fake data-room invitations, SharePoint and OneDrive links, e-signature requests, tax-portal login pages, Microsoft 365 authentication prompts, encrypted-message notifications and requests to install a "secure document viewer" all arrive from a genuinely trusted sender, which lifts engagement rates far above ordinary phishing. Once a client account falls, the attacker expands into the client's environment, and the firm has become the initial access vector for its own customer.
Internal partner and finance impersonation. A compromised partner account instructs the firm's own finance team to pay a confidential invoice, transfer funds ahead of a closing, change payroll details, send client files to a personal address, or keep a transaction quiet from colleagues. The confidentiality instruction is doing the real work: it pre-emptively disables the one control that would catch the fraud.
A documented campaign shows how quickly these stages can compress. Google's Threat Intelligence Group reported an ongoing campaign against US law firms in which an invoice-themed email was followed by a vishing call impersonating IT support, remote-access tooling was installed during a screen-sharing session, the attacker pivoted through virtual desktop infrastructure, harvested documents from legal document-management systems, and moved to extortion. According to that reporting, the full sequence could complete within a single business day, with searching, staging and exfiltration occurring in under an hour.
What Changed in 2025 and 2026
Three assumptions that held a few years ago no longer do.
Account takeover has displaced crude spoofing as the preferred route. Attackers increasingly want authenticated access to the real mailbox rather than a convincing imitation of it. Adversary-in-the-middle kits, stolen session cookies, OAuth consent abuse and device-code phishing all bypass or circumvent conventional multi-factor authentication, as do help-desk calls engineered to reset it. The practical consequence for firms is that domain authentication has become necessary but insufficient. A correctly configured DMARC policy stops other people pretending to be your domain. It has nothing to say about an attacker operating from inside it.
Client relationships are being used as a distribution network. Threat actors increasingly treat advisers as intermediate objectives rather than final targets. The NCSC's legal-sector threat reporting describes groups fabricating email chains and targeting the business customers of major law firms. Once a trusted mailbox is under control, credential phishing delivered to that firm's client base converts at rates ordinary campaigns cannot approach.
Multi-channel confirmation has been weaponized. The standard advice for years was to confirm an unusual instruction through a second channel. Attackers adapted. A fraudulent instruction may now be reinforced by a telephone call, an SMS, a Teams or WhatsApp message, a cloned voice on the confirmation call, a fake receptionist who confirms the caller works there, a second compromised account, or a cloned website. The advice has not become wrong, but it has become insufficiently specific: the second channel only helps if the contact details for it were held independently before the request arrived.
Two newer developments sit alongside those shifts.
Generative AI has changed the economics rather than the mechanics. It helps attackers summarize long threads, identify decision-makers, extract bank details and transaction dates, reproduce professional tone, translate fluently, generate plausible legal or accounting documents, maintain several personas simultaneously, and tailor a lure to a specific matter. None of that is a new attack. What it removes is the labor that used to limit how many targets an attacker could pursue at this level of quality. The honest conclusion is that AI raises attack quality and volume while the underlying vulnerabilities remain identity compromise and misplaced operational trust.
AI email assistants introduce a new trust boundary inside the mailbox. Firms are adopting tools that summarize mail, draft replies, extract tasks and sometimes act through connected applications. Academic testing of email-agent systems found that malicious content in inbound messages could hijack agent behaviour, with the study reporting successful hijacking across all 1,404 tested instances under its experimental design. That is a laboratory result rather than a field failure rate, and it should be read as such. But the risk categories it points to are concrete for firms: an inbound email that instructs an agent to disclose other messages, automatic forwarding of privileged material, generation of fraudulent drafts, unauthorized calendar or document actions, and prompt injection concealed in an attachment or a quoted thread.
Scoping has changed too. A stolen mailbox identity is rarely confined to mail. It typically also reaches document-management platforms, SharePoint, OneDrive, Teams, client portals, e-signature systems, billing tools and practice-management applications, which is why an incident should be treated as cloud-identity compromise from the outset. Detection is harder than it looks: in one reported extortion campaign, attackers reused session cookies to retrieve files over direct HTTP requests, which logged as file access rather than file download, an event type most security teams treat as benign. Supplier concentration compounds the problem, because a single provider failure can hit many firms at once. The 2023 compromise of legal technology provider CTS was reported to have disrupted close to 80 conveyancing firms.
What the Numbers Do and Do Not Show
Statistics in this area are frequently stacked together as though they measure the same thing. They do not, and a firm making budget decisions deserves to know which is which.
Indicator | Figure | What it actually measures |
|---|---|---|
FBI IC3 BEC complaints, 2025 | 24,768 | Complaints reported to US law enforcement, all industries |
FBI IC3 BEC losses, 2025 | ~$3.05 billion | Reported adjusted losses, all industries, no law-firm breakdown |
Organizations experiencing attempted BEC in 2025 | 74%, up from 63% | AFP survey population; attempts, not successful frauds |
SRA cybercrime reports involving email | 83% | Historical SRA finding; reports made to the regulator |
SRA reports classified as email-modification fraud, 2020 | 68% | Historical; most common reported category that year |
SRA review of directly targeted firms | 23 of 30 incidents resulted in theft, over £4m of client money | Small sample of firms already known to have been targeted |
ABA respondents reporting a breach | 29% | 2023 TechReport; self-reported survey |
ICO fine against DPP Law, 2025 | £60,000, over 30GB compromised | Single enforcement action; delayed reporting was cited |
BEC and social-engineering share of Travelers cyber claims | Nearly half over five years | One insurer's claims experience, not incidence |
Law Society respondents holding cyber insurance | 28% | Survey population; indicates a coverage gap |
UK businesses identifying any breach or attack, 2025 | 43% | Economy-wide baseline; varies sharply with organization size |
The caveats matter as much as the figures. The FBI's numbers are all-industry US complaints, so they establish that this category is financially severe without telling you anything specific about legal or accounting exposure. Regulator and professional-body datasets use different reporting populations, different years and different definitions, so the SRA and ABA figures should never be read as comparable. And every number here understates reality, because firms have reputational, client-relationship and regulatory reasons not to report, which is a bias that runs in one direction only.
The useful signal is not any individual figure. It is that email-based fraud is consistently the dominant reported attack category in the legal sector, that attempted attacks are rising year over year, and that insurers see social engineering as roughly half their cyber claims experience.
Professional Duties After a Compromise: US and UK
Obligations differ by jurisdiction, and firms operating across both need to track them separately. Nothing below is legal advice, and application to a specific incident is a matter for counsel.
In the United States, the ABA Model Rules and their commentary support a duty of technological competence. A lawyer does not guarantee perfect security, but is expected to make reasonable efforts appropriate to the circumstances. Model Rule 1.6 requires reasonable efforts to prevent unauthorized access to information relating to a representation, with reasonableness assessed against the sensitivity of the information, the likelihood of disclosure without safeguards, the cost and difficulty of implementing them, and the extent to which they would hinder the representation. That framing matters, because it means highly sensitive matters may require stronger protection than ordinary email provides, and a uniform firm-wide standard may not discharge the duty for every matter.
ABA Formal Opinion 483 addresses what happens after a breach. It distinguishes a material breach from every minor security event, and describes obligations that can include stopping the intrusion, restoring systems, making reasonable efforts to determine what occurred, and notifying current clients where material client information was compromised, in sufficient detail for the client to make informed decisions about the representation. Former clients may sit under different ethical rules, though statutory, contractual and common-law notification duties can still apply.
In the United Kingdom, the Solicitors Regulation Authority expects firms to manage information-security risks, protect client money, report material incidents promptly, and remedy client-account shortages. The obligation to replace a shortage arises on discovery, and the fact that an employee was deceived or that the fraud originated in a client's mailbox does not automatically remove it. Separately, the Information Commissioner's Office fined DPP Law £60,000 in 2025 following a cyberattack that compromised more than 30 gigabytes of data which later appeared on the dark web, with the enforcement reasoning citing both inadequate measures and delayed reporting. That case is worth reading as a warning about response conduct specifically: how a firm classifies and reports an incident is itself a source of regulatory exposure.
Some obligations cut across both jurisdictions. Data-protection duties may be triggered independently of professional rules, under UK GDPR, state breach-notification laws, sector-specific privacy legislation or contractual provisions. Privilege and work-product questions do not resolve themselves: compromise does not automatically waive privilege, and the analysis turns on jurisdiction, the reasonableness of safeguards, the speed of remediation, the scope of disclosure and applicable evidence rules, which is why privilege counsel should be involved early and why distribution of compromised material should not be widened unnecessarily. Supervisory duties extend beyond lawyers to assistants, contractors, managed service providers, e-discovery vendors, cloud providers, temporary lawyers and offshore support teams, meaning a security failure can raise professional-responsibility questions without anyone at the firm having clicked anything.
Civil exposure is developing alongside regulatory exposure. In July 2026, WilmerHale faced a proposed class action following an alleged data breach, an allegation the firm disputes and which remains unresolved. Whatever its outcome, it illustrates that follow-on private litigation is now a realistic consequence of a legal-sector incident.
The Controls That Actually Reduce Loss
Start from a framing that changes prioritization: a professional-services firm's email domain functions as a security credential for its clients. Controls therefore have to work in two directions at once, protecting the firm from fraudulent instructions it receives, and protecting clients and counterparties from fraudulent instructions that appear to come from the firm. Most firms build only the first half.
1. Make authentication phishing-resistant, starting with the roles that matter. Prioritize partners, finance and client-account staff, executive assistants, IT administrators, transaction lawyers, tax and payroll staff, and temporary or remote personnel. Deploy FIDO2 security keys or passkeys, block legacy authentication outright, apply conditional access and managed-device requirements, use risk-based sign-in policies, restrict who can register new authentication methods, separate administrative accounts from daily-use accounts, and monitor sessions and tokens rather than just logins. Push-based multi-factor authentication should not be treated as the strongest available control, because it is defeated by fatigue, by adversary-in-the-middle phishing and by session theft.
2. Monitor for persistence, not just for intrusion. The artefacts that reveal a compromise are often more detectable than the compromise itself. Alert on new forwarding addresses, suspicious inbox rules, unusual delegated access, newly consented OAuth applications, newly registered authentication methods, sign-ins from unfamiliar devices or infrastructure, mass mailbox searches, bulk downloads from document systems, access to dormant client matters, and deletion or relocation of finance-related replies. Integrate email, identity and cloud-application logging so these signals can be correlated rather than viewed in isolation.
3. Secure the domain, and be clear about what that buys you. Deploy SPF, DKIM and DMARC with alignment and enforcement, monitor for lookalike domains, watch brand and certificate registrations, defensively register the highest-risk variants, and publish a clear route for clients to report impersonation. This materially reduces direct spoofing. It does nothing against a genuinely compromised account, and it should never be presented internally as though it does.
4. Take bank details out of ordinary email workflows. Provide account information once, at engagement, through a verified channel. State in writing that details will never change by email. Require telephone or portal verification before a first payment. Consider digitally signed payment instructions, structured e-invoicing or payment links. Prevent staff from sending account details inside editable documents, and record which client contacts are authorized to receive or confirm payment information. The Law Society's guidance points in the same direction: obtain account details directly from the firm through a trusted channel and treat any claimed change as suspicious by default.
5. Write verification rules that cannot be waived. This is the single highest-value control in this article, and it works precisely because it does not depend on anyone spotting anything. Every new or changed payment instruction requires:
Independent verification before any funds move.
A telephone number already held in the matter-management system, never one supplied in the message that changed the instruction.
Two-person internal approval.
Separation between the person who receives an instruction and the person who releases payment.
A documented record of the callback, including who was contacted and when.
Enhanced review whenever a change is marked urgent or confidential.
Verification of the account holder's name where banking tools support it.
Escalation, not accommodation, when a client or professional resists verification.
That last point deserves emphasis. Attackers push back on verification, and a genuine client rarely objects to a thirty-second call. Resistance to verification is a signal, not an inconvenience.
6. Harden client and trust accounts. Dual authorization, transaction limits, separate credentials for payment initiation and release, no shared finance logins, daily reconciliation, beneficiary whitelisting, cooling-off periods before funds go to a new payee, alerts on account changes, restricted remote payment authorization, and immediate escalation of any reconciliation difference.
7. Segment matters by sensitivity. Not every matter warrants the same protection. Mergers and acquisitions, litigation against sophisticated or state-linked adversaries, public-company investigations, sanctions work, intellectual-property disputes, high-value property transactions, restructuring, whistleblower matters and politically exposed or high-profile clients justify additional measures: matter-specific code names, restricted workspaces, mandatory hardware keys, a prohibition on personal accounts and devices, secure client portals, separate communication channels, and reduced retention and export permissions.
8. Manage the supply chain that can reach your communications. Assess every provider with access to firm identities, mail or client material: managed service providers, cloud hosting, document-management vendors, e-discovery firms, legal-process outsourcers, transcription and translation services, court reporters, payroll and accounting providers, and AI vendors. Contract terms should cover multi-factor and privileged-access requirements, incident-notification deadlines, evidence preservation, subprocessor disclosure, audit rights, log availability, secure deletion, cooperation with client notification, responsibility for compromised credentials, and access revocation on exit.
9. Warn clients at matter opening, and again before the money moves. Tell clients the firm's official domain, the verified telephone number, how payment instructions will be provided, that the firm will not change bank details by email, that they must call before transferring funds, that urgency and confidentiality never override verification, and how to report a suspicious message. A warning buried in an engagement letter signed months earlier will not be recalled at completion. Repeat it immediately before any high-value payment.
10. Rehearse by role and workflow, not by calendar. Generic annual phishing training does not prepare a client-account administrator for a revised completion statement or an executive assistant for a confidential partner instruction. Useful simulations mirror the actual scenarios: a compromised client mailbox, a genuine partner account under attacker control, a settlement-account change, a fake data-room or e-signature invitation, a request from opposing counsel, and a telephone call that supports a fraudulent email. Aim the training at the rule rather than the tell, because spotting the message is often impossible: email alone never authorizes an irreversible action.
A workable sequence for firms starting from a standing start:
Horizon | Priorities |
|---|---|
First 30 days | Mandate independent callback for every new or changed payment instruction; prohibit bank-detail changes made on email alone; enable multi-factor authentication everywhere and phishing-resistant methods for privileged users; audit mailbox forwarding, rules and OAuth grants; review administrator and client-account privileges; create a finance-security escalation route; warn clients on active transactions; confirm published bank details are consistent across all official channels; test your bank-recall and incident-response contacts before you need them. |
Within 90 days | Move partners, finance staff and administrators to passkeys or security keys; deploy DMARC enforcement and lookalike-domain monitoring; integrate email, identity and cloud-application logging; classify matters by sensitivity; update engagement letters and completion communications; run role-specific simulations; review cyber and professional-indemnity coverage together; assess managed service provider and document-management security; introduce dual authorization and new-beneficiary controls. |
Within 6 to 12 months | Replace email-based payment instructions with verified portal workflows; implement privileged-access management; establish continuous monitoring for high-risk cloud identities; exercise a compromised-partner scenario with clients and banks; map every provider that can reach client communications; add contractual incident-notification requirements; create secure channels for the most sensitive matters; measure verification compliance, reporting rates and access-revocation times. |
The First Hour, the First Day, the First Week
Recovery odds fall steeply with time, so the response sequence should be ordered by what preserves recoverability rather than by what feels urgent.
First 15 minutes. Stop any pending transfer. Contact the sending bank's fraud team and request recall, a hold, or beneficiary-bank intervention. Preserve the suspicious message with full headers and attachments. Contact the apparent sender through a channel you already trusted. Notify internal security, finance, the general counsel and firm leadership. Disable or isolate the suspected account, and revoke active sessions and refresh tokens, not just the password.
First hour. Check mailbox rules, forwarding and delegated access. Review newly registered authentication methods and OAuth grants. Establish when access began and which sign-ins were suspicious. Search for messages containing payment or credential requests. Determine whether clients or counterparties received malicious mail. Preserve Microsoft 365, Google Workspace and document-system logs before retention windows expire. Contact your insurer and incident-response provider. Report significant financial fraud to law enforcement, which the FBI stresses materially improves the chance of freezing funds.
First day. Identify every affected matter and client. Determine whether privileged or regulated information was reached. Notify clients through independently authenticated channels, and instruct recipients not to rely on any previously supplied payment instructions. Reset affected credentials and remove persistence mechanisms. Block lookalike domains. Review access to document-management and collaboration platforms. Assess regulator, professional-body, data-protection and contractual reporting duties, and consider whether courts or opposing parties require notification.
The following days. Complete forensic scoping. Establish whether funds can be recovered. Document the timeline. Revalidate every active payment instruction across the firm, not only the one that failed. Review comparable transactions that occurred during the compromise window. Conduct the privilege and legal-duty analysis. Notify former clients where legally required. Run a genuine lessons-learned exercise, update engagement letters and client warnings, and test the revised controls through a tabletop before assuming they work.
Questions the Profession Has Not Settled
Several important questions have no settled answer, and firms should plan around the uncertainty rather than assume a favourable resolution.
Who bears the loss? Candidates include the client whose mailbox was compromised, the firm, the individual who approved the transfer, the bank, a managed service provider, an insurer, or a counterparty that supplied the instruction. Courts have reached fact-specific outcomes based on contract terms, negligence, causation, security practices and whether verification procedures were reasonable. There is no universal rule assigning loss to whoever's mailbox was breached, which is precisely why documented verification procedures matter beyond their preventive value.
Is multi-factor authentication enough? Firms describing themselves as secure because multi-factor authentication is enabled may still be exposed to adversary-in-the-middle phishing, session theft, OAuth consent, prompt fatigue, help-desk resets, legacy protocols and unmanaged personal devices. The debate has moved from whether authentication exists to whether it is phishing-resistant and whether sessions and tokens are monitored.
Are client portals genuinely safer? They reduce domain spoofing and centralize authentication, but they introduce weak portal passwords, shared accounts, convincing fake portal invitations, misconfigured permissions, third-party provider risk, excessive document retention and support-desk recovery paths. A portal is safer only when it is paired with strong authentication and a verified onboarding process.
Must every incident be disclosed to clients? Over-notification creates unnecessary alarm and can complicate privilege. Under-notification prevents clients from protecting themselves and creates ethical and regulatory exposure. ABA Formal Opinion 483 uses materiality and effect on client information rather than requiring notice for every blocked phishing attempt.
Does cyber insurance weaken incentives? Critics argue it encourages firms to treat security as a transferable financial risk. Supporters note that insurers increasingly require multi-factor authentication, tested backups, endpoint controls and incident plans, raising baseline security across the market. Coverage disputes remain common where social engineering, voluntary transfer, professional services and cyber exclusions overlap, and cyber and professional-indemnity policies should be reviewed together rather than separately.
Can firms monitor without undermining privacy? Communication analytics can detect abnormal sign-ins, forwarding, relationship changes and payment language. Extensive content inspection may conflict with employee privacy, client confidentiality, works-council obligations and proportionality principles. Purpose-limited monitoring focused on security-relevant metadata and events is the more defensible position.
Brightside AI: Rehearsing the Scenarios That Actually Reach Your People
Scope first, because it matters more than any feature list. Simulation and training do not prevent account takeover, and nothing in this section substitutes for phishing-resistant authentication, session monitoring or the payment controls described above. If an attacker controls a partner's mailbox, no amount of awareness training will make the resulting email look wrong. What training can do is prepare the specific people who receive these requests to run the verification step anyway, and to report what they see.
That is where Brightside AI, a Swiss security awareness training platform, fits this particular threat model. Its phishing simulation templates are organized by department fit, with Legal & Compliance and Finance & Accounting among the available categories, alongside attack type, vendor type and geography. That lets a firm aim a campaign at the departments where these requests actually land, rather than sending one generic corporate lure to everyone. Simulation difficulty is aligned to the NIST Phish Scale and graded from least to very difficult, which gives a firm a recognized reference for how demanding a given simulation is.
The vishing simulator is the piece that maps most directly onto the trends described earlier. Its Hybrid Attack combines a voice call with a trackable phishing email as one coordinated workflow, which is the multi-channel pattern that now reinforces fraudulent payment instructions and the same shape as the IT-helpdesk calls documented in campaigns against law firms. Custom voice cloning, built from a one to two minute recording, allows a firm to rehearse the scenario where a familiar voice calls to confirm a wire. On the reporting side, the Report Phishing add-on for Gmail and Google Workspace offers one-click reporting over an encrypted channel, with real threats routed to the security team with full headers intact and reported simulations credited to the employee, using least-privilege access to only the message being reported.
Try our vishing simulator
Experience the most advanced voice phishing simulator built for security teams. Create scenarios, test voice cloning, and explore automation features.
Frequently Asked Questions
How can we tell whether an email came from a compromised account rather than a spoofed one?
Often you cannot tell from the message itself, which is the core difficulty. A spoofed message usually fails or misaligns domain authentication, or arrives from a lookalike domain that survives inspection. A message from a compromised account passes authentication because it is genuine. The distinguishing evidence sits in identity and mailbox telemetry rather than content: unfamiliar sign-in locations or devices, new inbox rules, forwarding changes, newly consented applications, and newly registered authentication methods.
What is the correct way to verify a change to wire or bank instructions?
Telephone the client or firm on a number you already held in the matter file before the request arrived, never a number contained in the message that changed the instruction. Speak to a named person you can identify, document who you spoke to and when, and require a second person to approve before funds move. Treat urgency, confidentiality instructions and resistance to the callback as reasons to escalate rather than reasons to proceed.
Who bears the loss when funds are sent to a fraudulent account?
There is no universal rule. Outcomes have turned on contract terms, negligence, causation, the security practices of each party and whether verification procedures were reasonable, so responsibility is determined case by case. UK firms should note separately that the Solicitors Regulation Authority expects client-account shortages to be replaced immediately on discovery, including those caused by cyberattack, regardless of where the fraud originated.
Do we have to tell clients about every security incident?
No. For US firms, ABA Formal Opinion 483 applies a materiality standard, tied to whether material client information was compromised and whether the client needs the information to make decisions about the representation, rather than requiring notice for every blocked phishing attempt. Data-protection law, contractual notification clauses and regulator reporting duties operate independently of the ethical rules and may require disclosure even where the ethical threshold is not met.
Is multi-factor authentication enough to prevent mailbox compromise?
No. Adversary-in-the-middle phishing, stolen session cookies, OAuth consent abuse, prompt fatigue, help-desk reset manipulation, legacy authentication protocols and unmanaged personal devices all defeat or bypass conventional multi-factor authentication, particularly push-based methods. Phishing-resistant authentication using FIDO2 keys or passkeys, combined with session and token monitoring, is a materially stronger position.


