Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Blog post2026-08-02By Securing Your Law Firm

How Law Firms Get Hit by Wire Fraud — Even When No One Was Hacked

Learn how law firm wire fraud and business email compromise attacks happen, why email spoofing and public exposure matter, and what controls reduce risk for law firms.

When law firm leaders think about cyberattacks, they often picture ransomware, stolen passwords, or an intruder breaking into internal systems.

Yet many of the most expensive incidents never begin with a dramatic "hack."

In a large share of wire fraud events, there is no outage, no malware alert, and no obvious breach notification. Instead, an attacker sends a message that appears legitimate — and someone acts on it before the deception is discovered.

That is how many firms get pulled into business email compromise and payment diversion.

In this article:

  • Why business email compromise (BEC) specifically targets law firms, not just businesses in general
  • Why having Microsoft 365 doesn't mean your firm is actually protected against impersonation
  • The controls that meaningfully reduce this risk — and how to check your firm's exposure for free

Why Law Firms Are Prime Targets for Business Email Compromise

Law firms are not just targets because they use email. They are targets because their public profile and daily communications create a perfect environment for impersonation-based fraud.

Law firms sit at the intersection of trust, urgency, money, and sensitive information.

Attackers know that law firms regularly handle:

  • Real estate closings
  • Settlement proceeds
  • Escrow and trust-related communications
  • M&A transactions and corporate deal documents
  • Privileged or confidential client material

They also know a law firm email carries authority. A message that appears to come from a partner, administrator, or closing coordinator is likely to be taken seriously - and acted on quickly.

That combination makes law firms ideal targets for business email compromise (BEC) and impersonation-based fraud. The FBI reported $2.9 billion in BEC losses in 2023. Law firms aren't targeted because they're careless. They're targeted because their day-to-day communications involve exactly the kind of financial and confidential activity attackers want to exploit.

What a Law Firm Wire Fraud Attack Actually Looks Like

Most wire fraud incidents involving law firms don't begin with a dramatic, system-wide intrusion. They begin with confusion, timing, and trust.

A typical pattern looks like this:

  1. The attacker learns the names of attorneys, staff, clients, and practice areas.
  2. They monitor publicly available information, or information from a prior compromise elsewhere in the transaction chain.
  3. They send an email that looks like it came from the firm, or from someone the firm is working with.
  4. The message creates urgency - updated wiring instructions, a last-minute correction, a confidential payment matter.
  5. Someone follows the instruction before the deception is discovered.

Sometimes the attacker spoofs the firm's domain directly. Sometimes they register a lookalike domain close enough to pass at a glance. Sometimes they compromise another party in the transaction and simply step into an existing email thread.

What matters isn't the exact method. What matters is that the recipient believed the email was real.

Why "We Have Microsoft 365" Isn't a Complete Answer

Many firms assume they're protected because they use Microsoft 365 or another major cloud email platform. That assumption is understandable — and dangerous.

Microsoft 365 provides security tools. It doesn't automatically configure them to the level most law firms actually need.

Protections that often require deliberate setup and review include:

  • Multi-factor authentication (MFA) enforced across every mailbox, including admin accounts
  • Legacy authentication disabled, so older sign-in methods can't bypass MFA entirely
  • Anti-impersonation settings, which flag or block messages designed to look like they came from your own domain
  • Mailbox forwarding rule controls - this catches an attacker who's quietly auto-forwarding your email to themselves, reading everything without ever tipping you off
  • Audit logging, so there's a record to review if something does go wrong
  • Email authentication settings (SPF, DKIM, DMARC) that reduce the odds of your own domain being spoofed

Buying the platform isn't the same as securing the platform. For most firms, the real issue isn't whether these tools exist - it's whether they've been deliberately configured to reduce the specific kinds of fraud law firms are exposed to.

Wire Fraud Is a Professional Responsibility Issue, Not Just a Financial One

For a law firm, wire fraud quickly becomes more than an accounting problem. It can raise questions of:

  • Client trust
  • Professional responsibility
  • Reputation
  • Insurance coverage
  • Notification obligations

This isn't just a business risk - it's an ethics one. ABA Formal Opinion 477 establishes a duty of technology competence in safeguarding client communications, and Formal Opinion 483 addresses a lawyer's obligation to respond to - and in some cases disclose - a data breach or compromise. A wire fraud incident triggered by a spoofed email can implicate both. Clients generally don't distinguish between "the system was hacked" and "someone acted on a fraudulent email." They want to know why the message looked real, why the firm didn't catch it sooner, and what protections were supposed to be in place.

That's part of why cybersecurity for law firms can't be treated as a generic IT problem. The consequences reach well beyond technology, into the same ethical duties that govern the rest of the practice.

What Controls Actually Reduce This Risk

No control eliminates fraud risk completely, but some meaningfully reduce it. For law firms, the most important ones usually include:

  • Strong email identity controls – Your firm should have protections in place so attackers can't easily send emails that appear to come from your real domain.
  • Multi-factor authentication – If an attacker steals a password, MFA makes it much harder for that password alone to become a live compromise.
  • Mailbox monitoring and forwarding rule review – Attackers who gain access to an account often create hidden forwarding rules so they can quietly monitor communications for weeks without being noticed.
  • A clear wire instruction verification process – Financial instructions should never be changed solely by email. A known-phone-number callback process is one of the simplest, most effective safeguards available.
  • Better visibility into public exposure – Many firms don't know what an attacker can already see: spoofing gaps, lookalike domains, exposed infrastructure, or other public signals that make impersonation easier.
  • Staff awareness that fits legal workflows – Generic phishing training isn't enough. Staff need to understand how fraud specifically shows up in closings, settlements, and client communications.

Where DMARC Fits In

This is where the technical side matters - but only in service of a business outcome.

One of the most important controls for preventing direct spoofing of your law firm's domain is DMARC, working alongside SPF and DKIM. You don't need to become an email engineer to understand the business purpose:

  • It helps stop fake messages sent as your firm.
  • It reduces the chance that a client receives a forged message using your real domain.
  • It strengthens your answer to clients and insurers asking how you reduce impersonation risk.

For most attorneys, the key point is simple:

Setting up and enforcing DMARC correctly - without accidentally blocking your own legitimate mail — is exactly the kind of configuration work email hardening is built around.

What Insurers and Corporate Clients Are Increasingly Asking

The pressure isn't only coming from attackers.

Corporate clients, cyber insurers, and outside counsel guidelines increasingly force firms to answer questions like:

  • How do you secure firm email?
  • What controls reduce impersonation risk?
  • Do you use MFA - and is it enforced, or optional?
  • Can you document your security program?
  • What's your process for handling sensitive client communications?
  • How do you prevent fraudulent payment instructions?

A firm that can't answer those questions clearly is in a weaker position, both commercially and defensively - and cyber insurers are increasingly requiring MFA attestation at renewal, with gaps meaning higher premiums or a denied claim at the worst possible moment.

That's why the best security work for law firms isn't just about applying controls. It's about applying them in a way that can be documented and defended to a client or a carrier.

What Your Firm Can Check Right Now

Even without a full technical review, a managing partner or administrator can ask a few useful questions today:

  • Can someone explain how our firm prevents spoofed emails?
  • Are wire instruction changes ever accepted by email alone?
  • Is MFA enforced for every mailbox, including administrators?
  • Do we know whether attackers could impersonate our domain?
  • Do we know whether lookalike domains have been registered?
  • Could we answer a client security questionnaire confidently?
  • If an incident happened tomorrow, do we have a documented response process?

If the answer to several of those is "not sure," that doesn't mean your firm is negligent. It means you probably need a clearer picture of your current exposure.

The Real Issue Isn't Paranoia - It's Visibility

Most law firms don't ignore security because they don't care. They ignore specific risks because they don't have visibility into how those risks actually show up in practice.

That is why public exposure matters. An outside-in view can reveal email spoofing gaps, lookalike domains, exposed infrastructure, and other signals that make impersonation easier. In other words, a firm's OSINT footprint is often the first place attackers look before they ever attempt a payment diversion or a convincing spoofed message.

Start With a Free Proprietary Exposure Review

Wire fraud attacks against law firms are effective because they exploit trust, timing, and normal legal workflows. They don't always require a dramatic hack - only a believable message arriving at the wrong moment.

The firms that reduce this risk most effectively aren't necessarily the ones with the most technology. They're the ones who understand the threat clearly, put the right controls in place, and can document those controls in a way clients and insurers understand.

If you're not sure whether your firm's public posture makes impersonation easier, that's exactly what a free Proprietary Exposure Review is meant to answer. We check the public signals attackers use - including email spoofing risk, lookalike domains, and exposed infrastructure — without touching anything private. No login, no system access, no sales pitch.

This article is informational and does not constitute legal or compliance advice.