How wire fraud happens to law firms, and the habit that stops it
The email looks right. It continues a real thread about a real closing, it uses the names everyone has been using for weeks, and it says the wiring instructions have changed. The money goes out, and by the time anyone calls to ask where it is, it has already been moved twice. This is business email compromise, one of the largest fraud categories in the country, with over $55 billion in reported losses (FBI IC3, 2024). Law firms are prime targets because they move client money on schedules announced by email. This guide covers how the scam actually works, the one habit that stops it, what the technology can and cannot do, and what to do in the first hours if a wire already went out.
How the scam actually works
The attacker gets into the conversation one of two ways. If the firm's domain has no email authentication, they do not need to break into anything: they send mail that simply claims to be from your address, and without the records that let a receiving server reject a forgery, it lands looking legitimate. The second way is taking over a real mailbox, usually with a phished password on an account that has no second sign-in step. That version is worse, because the fraud arrives from the genuine address, inside the genuine thread.
Either way, the attacker does not strike immediately. They read. They learn who handles payments, how the firm writes, and when the closing or settlement is scheduled. The fake instruction arrives near the deadline, when everyone is busy and a quick turnaround feels normal, and it often asks for exactly that: handle it today, no need to call.
Why law firms specifically
A criminal choosing targets wants three things: money that moves by wire, moves on predictable dates, and moves based on emailed instructions. Closings, settlements, and trust-account disbursements are all three at once. A wire is also the worst possible payment to get wrong, because it is fast, final, and hard to claw back, and the money at stake usually belongs to a client. One convincing email can do what no burglar could.
The habit: verify by phone at a number you already know
Before anyone sends funds or acts on a new or changed payment instruction, someone calls the other party and confirms it by voice. That is the whole control, and done right it defeats every version of the scam above. Done right means five things. Call a number you already have on file, from your own records, a prior invoice, or the signed engagement, never a number from the email itself. Confirm the account details out loud, digit by digit, with a person you know or can identify. Never reply to the email to confirm, because if that mailbox is compromised you are confirming with the criminal. If you cannot reach a trusted contact, the payment waits. And write it down: who you called, the number, the date, and who confirmed.
I give my law firm clients a one-page version of this procedure to post wherever payments are handled, because the habit only works if it survives a busy Friday afternoon. The procedure is aligned to FBI IC3 guidance on verifying payment instructions through a known second channel.
When to stop and call
Any one of these means the payment stops until a call has happened:
- A new payee, or a first-time wire to anyone.
- Any change to existing bank, account, or routing details.
- The instruction arrived by email, whoever it appears to be from.
- A request to rush the payment or keep it quiet.
- Payment directions from a client, title company, opposing counsel, or vendor.
The louder red flags are a last-minute change to wiring instructions, a sender who will only communicate by email, a slightly misspelled or look-alike address, and a new account at a different bank. But do not wait for a red flag to feel suspicious. The well-executed versions of this scam do not look suspicious, which is why the triggers above are mechanical rather than a judgment call.
Two more controls for trust-account wires
For transfers from the trust or escrow account, firms that move client funds routinely add two controls on top of the call-back. First, two-person authorization: no single person releases a trust-account wire alone, and a second authorized person confirms the call-back happened and the details match before funds move. Second, a dollar threshold: above a figure the firm chooses, for example $50,000, a partner or owner approves in addition to the phone verification. Neither requires software. Both turn one person's bad afternoon into something the process catches.
What the technology does, and does not do
Three DNS records, SPF, DKIM, and DMARC, tell the world which servers may send email as your firm, and they are what stops the first version of the scam, the outright forgery of your address. Multi-factor sign-in on every mailbox is what stops the second version, the takeover of a real account. Advanced mail filtering catches many of the look-alike domains in between. All of this is worth doing, and the records are checkable from outside your office in about a minute, which is why they are the first thing my free Security Check looks at. You can see a sample of what that looks like.
But be clear about what the technology buys you: it reduces how often the fake email reaches an inbox. It cannot make the number zero, because the convincing versions come from genuinely compromised mailboxes at the other side of the deal, which no setting of yours controls. The call-back habit is the layer that stops the loss when a fake gets through, and it is the one layer that works against every variant.
If a wire already went out
Speed decides most of what happens next, so this is measured in hours. Call your bank immediately, ask them to recall the wire and request a freeze on the receiving account. Report it at ic3.gov right away, regardless of the amount; wires reported fast can sometimes be frozen before the money moves on. Preserve every email and delete nothing, because the thread is the evidence. And before any more payment instructions go out, have someone check whether one of your own mailboxes was compromised, because if it was, the criminal is still reading.
FAQ
Can the bank get a fraudulent wire back?
Sometimes, if you move within hours. Call your bank first and ask for a recall and a freeze on the receiving account, then report it at ic3.gov regardless of the amount. Recovery gets sharply less likely with each passing day, which is why a suspected fraud is treated as an emergency and not a support ticket.
Does cyber insurance cover a rerouted wire?
That depends on your policy and is a question for your insurance agent. Many policies handle social engineering losses under a separate, lower limit than the headline coverage. The verification habit is the control that does not have a limit.
Do we need special software for this?
No. The call-back procedure is a phone and a habit. The technology side, email authentication, filtering, and multi-factor sign-in, reduces how often a fake reaches an inbox, but the habit works even before any of it is in place.
What does it cost to get the email side fixed?
Checking your email authentication records from the outside is part of the free Security Check, so finding out where you stand costs nothing. Work for businesses not on a plan is billed at $125 per hour, and larger projects are quoted up front so you approve the number before the work starts.
Want the wire-verification procedure on your wall? Setting up the habit and the email protections behind it is part of what I do for small law firms, and the free Security Check will tell you whether your domain can currently be forged. The check is free and you keep the report either way. What ongoing support costs is published in what IT support costs a small law firm in Florida.
About the author
Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.
