The email arrives on the afternoon of closing day. Same thread everyone has been replying to for weeks. Same signature block. It says the payoff account details have changed — here are the updated wire instructions.
Someone at the firm wires the funds. The money lands in an account the attackers control, gets forwarded through two more banks within the hour, and is gone. The client’s money. From your trust account.
This is not an exotic attack. It’s the single most reliable way small and mid-sized law firms lose six-figure sums, and it works because it exploits the one moment when a large transfer is expected.
How the attackers actually get in
Wire fraud against firms almost never starts on closing day. It starts weeks earlier, one of two ways:
- A compromised mailbox. Someone at the firm — or at the title company, or opposing counsel — entered their email password on a fake login page. The attacker doesn’t announce themselves. They sit in the mailbox, set up a forwarding rule, and read. They learn the matter, the parties, the amounts, and the timing.
- A lookalike domain. The attacker registers a domain one character off from a real party’s — smithlaww.com instead of smithlaw.com — and joins the thread at the critical moment. On a phone screen, nobody notices.
Either way, the fraudulent email is informed. It references the right matter, the right people, the right figures. Generic spam filters don’t catch it, because it isn’t generic.
Why “we’re careful” isn’t a control
Every firm that has been hit believed its people were careful. Care fails at scale for boring reasons: closing day is busy, the email looks perfect, and the person processing the wire has done this a hundred times without incident.
Controls that actually work don’t rely on someone being suspicious at 4:45pm on a Friday:
- Verbal verification, every time, no exceptions. Any change to wire instructions gets confirmed by phone, on a number from the original engagement documents — never a number from the email requesting the change. Write it into the firm’s procedure so nobody has to be the hero who slows down a closing.
- MFA on every mailbox. Most mailbox compromises die here. If your firm’s email requires only a password, this is the single highest-return fix available.
- Email authentication, configured properly. SPF, DKIM and DMARC make your own domain much harder to impersonate — and flag inbound mail from lookalike domains. Most firms have these half-configured or not at all.
- Alerting on forwarding rules and unusual logins. Attackers who get into a mailbox set up auto-forwarding almost immediately. That event can be caught the minute it happens — if anyone is watching for it.
- Training built on real examples. Not an annual compliance video. Short, specific sessions using actual wire-fraud emails, so the pattern is familiar before it appears in a live thread.
What it costs when it goes wrong
The direct loss is only the start. Firms that wire client funds to attackers face malpractice exposure, bar complaints, breach-notification obligations if the mailbox held client data, and the conversation with the client whose money is gone. Cyber policies increasingly exclude social-engineering losses or cap them well below the typical transfer, and insurers ask — in writing — whether MFA and verification procedures were in place. “No” can void the claim.
Recovery is possible only in the first hours, and only sometimes. If a wire has just gone out to fraudulent instructions, call the sending bank’s fraud line and the FBI’s IC3 immediately — before anything else.
The fix is a project, not a product
None of the five controls above is expensive, and none requires new software your firm doesn’t already own — Microsoft 365 and Google Workspace include nearly all of it. What firms lack is someone who configures it, monitors it, and keeps it enforced as staff come and go.
That’s the job we do for firms across Los Angeles. Our IT support for law firms covers email security configured against exactly this attack, MFA enforced everywhere, monitoring that catches the forwarding rule the moment it’s created, and training your staff will actually remember on closing day.
Get a free email-security review → We’ll check your firm’s email authentication, MFA coverage and forwarding-rule exposure, and tell you in writing where the gaps are. No obligation — and if it’s already configured well, we’ll say so.
Want a straight answer about your own setup? Atomcase offers a free IT assessment — no obligation.
Get a Free IT Assessment → or call us: (321) 844-7711