By David Chernitzky, CEO, Armour Cybersecurity · Serving Toronto and organizations across North America · Last updated August 26, 2026
Quick Answer
Business email compromise attacks against law firms exploit the trusted financial relationships between lawyers and clients. Settlement funds, real estate escrow, and trust account distributions move on the basis of email instructions. Attackers who compromise a lawyer’s inbox or convincingly spoof a firm’s domain can redirect those funds to fraudulent accounts before anyone detects the fraud. Law firm BEC produces direct losses, real professional responsibility exposure, and reputational damage, and the controls that prevent it are well understood.
Key Takeaways
- BEC attacks against law firms target the financial flows that pass through trust accounts, settlement funds, and real estate escrow, often resulting in six-figure losses from a single incident.
- Real estate transactions are the highest-volume BEC target in the legal sector because of the large funds involved, tight closing timelines, and established email-based instruction workflows.
- Attackers monitor compromised email accounts for days or weeks before acting, timing the fraudulent wire instruction to coincide with a legitimate transaction to maximize credibility.
- Email authentication controls (DKIM, SPF, DMARC) and out-of-band wire verification procedures are the primary defences that interrupt these attacks before funds are transferred.
- Professional responsibility obligations require prompt notification to affected clients when a BEC attack results in a loss, alongside whatever regulatory breach notification may apply.
Why Are Law Firms the Preferred Target for Financial BEC?
Law firms occupy a unique position in financial transactions. They hold client funds in trust, facilitate settlement payments in litigation, manage real estate closing escrow, and transmit wire instructions that move significant sums on the basis of professional authority. Clients and counterparties extend a level of trust to wire instructions from a law firm that they would not extend to instructions from an unknown party, and those trusted financial relationships are exactly what BEC attackers exploit.
An email that appears to come from the managing partner of the firm handling a client’s real estate closing, or from the opposing counsel in a settlement, carries an inherent authority that makes the recipient less likely to question a change to wire instructions. The social engineering does not need to be sophisticated when the professional relationship provides the credibility.
The financial opportunity is also scale-appropriate. A residential real estate closing moves hundreds of thousands of dollars. A commercial transaction or litigation settlement may move millions. BEC attacks are more resource-intensive than mass phishing campaigns, so attackers select targets where the expected return justifies the investment. Law firms managing significant financial flows are precisely this type of target.
How Do BEC Attacks Against Law Firms Actually Work?
Inbox Compromise and Monitoring
The most effective BEC attacks begin with legitimate access to a lawyer’s inbox. Phishing campaigns that harvest lawyer credentials, or credential stuffing against legal practice management platforms with reused passwords, give attackers authenticated access to email accounts. Rather than acting immediately, experienced attackers monitor the inbox for days or weeks to understand the ongoing matters, identify upcoming transactions, and learn the communication patterns of the lawyer and their clients.
When a transaction nears completion, the attacker uses the compromised account to send instructions to the client or counterparty that redirect the payment. Because the email comes from the legitimate account, it bypasses email filtering and carries the full weight of the lawyer’s professional identity. The change to wire details is framed as a routine banking update or a last-minute correction, timed to coincide with the urgency of a closing deadline.
Domain Spoofing and Lookalike Addresses
Where direct inbox compromise is not achieved, attackers create email addresses that impersonate firm domains. A domain like smithlaw.com may be spoofed as smith1aw.com, smithlaw.co, or smithlaw-llp.com, with addresses that appear to be from partners or administrative staff when viewed quickly. These impersonation emails are effective when the recipient is focused on a transaction deadline and reading on a mobile device where the full sender address is often not visible.
DMARC enforcement, which configures the firm’s email domain to instruct receiving servers to reject or quarantine emails that fail authentication checks, prevents spoofing of the firm’s own domain. It does not prevent lookalike domain registration, but it eliminates the most direct form of impersonation. Firms that have not implemented DMARC enforcement allow their domain to be spoofed in emails to clients with no technical barrier.
Real Estate Transaction Fraud
Real estate transactions are the dominant BEC scenario in the legal sector by volume. The pattern is consistent: an attacker monitors communications between the real estate lawyer and the client or counterparty, identifies the closing date, and sends fraudulent wire instructions that redirect the purchase price or mortgage proceeds to a controlled account. The instructions are timed to arrive close to the closing, when urgency makes careful verification less likely.
Recovery of funds transferred in real estate BEC is possible but time-sensitive. Banks can attempt to recall wire transfers if contacted immediately, but the window is typically measured in hours. Funds transferred to domestic accounts are often quickly moved offshore, making recovery increasingly unlikely as time passes. Having a response procedure that includes immediate bank contact is a critical component of incident response for law firms handling real estate matters.
What Controls Prevent BEC at Law Firms?
Email authentication is the foundation. DKIM, SPF, and DMARC records, properly configured and set to an enforcement policy, prevent attackers from sending emails that appear to come from the firm’s domain. Many law firms have partial email authentication that passes basic checks but does not enforce DMARC rejection or quarantine, leaving the domain effectively unprotected against spoofing. Email security hardened against BEC starts with a full authentication audit that identifies and closes these gaps.
Multi-factor authentication on firm email and practice management platforms eliminates the value of harvested credentials. A phished password alone cannot access an MFA-protected inbox. For law firms using Microsoft 365 or Google Workspace, MFA enforcement is a configuration setting that requires a management decision to implement but protects every partner and staff email account at once.
Out-of-band verification for wire instructions is the procedural control that stops attacks that bypass technical controls. A firm policy that requires phone confirmation to a known client number before executing any wire transfer, particularly where instructions arrive by email and involve a change from previously established banking details, interrupts the BEC workflow at the critical moment. The phone call must go to a pre-established number, not a number provided in the suspicious email.
Phishing simulation and staff training calibrated to legal sector attack patterns give lawyers and staff the recognition skills to identify impersonation attempts. The scenarios that matter most in legal practice, client impersonation during a closing, opposing counsel wire redirect, urgent senior partner request, are different from generic corporate phishing scenarios and require training content specific to the profession. Armour delivers these controls as part of a managed cybersecurity programme built for law firms, so email authentication, MFA, verification procedure, and training operate as one system rather than four disconnected fixes.
What Happens After a BEC Attack Succeeds?
When a BEC attack results in a fraudulent wire transfer, the immediate response determines how much of the loss is recoverable. The first call must be to the firm’s financial institution to initiate a wire recall. The second is to law enforcement, as the FBI’s Internet Crime Complaint Center can coordinate with FinCEN and overseas counterparts to attempt fund recovery. Both calls must happen within hours, not days, which is why a documented incident response for law firms plan that names who calls the bank and who calls law enforcement is worth more than any single control once funds are moving.
Professional responsibility obligations require prompt notification to the affected client. The duty of communication under ABA Rule 1.4 and equivalent Canadian Law Society rules requires keeping clients informed of matters affecting their representation, and a BEC attack that results in loss of client funds is clearly such a matter. These professional responsibility obligations mean the notification must be prompt and must include an accurate description of what occurred and what steps are being taken.
Privacy breach notification may also apply if the inbox compromise that enabled the BEC attack resulted in unauthorized access to client information beyond the specific transaction. PIPEDA and state data breach notification laws require notification when personal information is accessed without authorization. Legal counsel and cybersecurity advisors should be engaged immediately to assess the full scope of notification obligations.
Frequently Asked Questions
Are we liable to clients for funds lost in a BEC attack?
Liability exposure in BEC losses depends on jurisdiction, the specific circumstances, and whether the firm had implemented reasonable controls. Firms that lacked basic email authentication controls, did not enforce MFA on email accounts, and had no wire verification procedures may face professional negligence claims. Firms with documented controls that were circumvented through sophisticated attacks are in a better position, though not necessarily free from claims. Professional liability insurance and malpractice coverage should be reviewed specifically for BEC scenarios before an incident occurs.
What should our wire transfer policy include?
An effective wire transfer policy for a law firm specifies: all wire instructions must be confirmed by phone to a pre-established client number before execution; changes to banking details in existing matters require elevated verification including senior sign-off; email alone is never sufficient authorization for a wire transfer; and the verification record must be documented in the matter file. The policy must be followed consistently, not just drafted and filed. Armour’s vCISO service helps firms develop and operationalize these procedures.
How do we know if a lawyer’s email has been compromised?
Indicators of inbox compromise include: unexpected password reset attempts, login activity from unfamiliar locations or devices, email forwarding rules that were not set by the account owner, client reports of suspicious emails appearing to come from the lawyer, and emails found in Sent Items that the lawyer did not send. Most email platforms provide login activity logs that can reveal unauthorized access. Continuous monitoring of email platform security logs, included in a managed cybersecurity programme, detects these indicators before they result in fraud.
Can cyber insurance cover BEC losses at a law firm?
Social engineering and BEC coverage varies significantly across cyber insurance policies. Many policies require specific endorsements for social engineering fraud, and coverage limits for BEC losses may be lower than for other covered events. Some policies require documented controls, such as callback verification procedures, as a condition of BEC coverage. Reviewing your policy specifically for social engineering coverage terms, with input from a cyber insurance advisor, before a BEC attempt is essential. Armour’s cyber insurance advisory service helps firms understand their coverage and close the gaps before an incident.
The Bottom Line
Law firm BEC works because the money is real, the deadlines are tight, and a wire instruction from a lawyer carries authority that a stranger’s never could. Attackers sit inside a compromised inbox, wait for a closing, and send the redirect at the exact moment urgency overrides caution, and once the wire leaves, recovery is a race measured in hours. The defence is not exotic: enforce DMARC so the firm’s domain cannot be spoofed, put MFA on every mailbox, and make out-of-band callback verification a hard rule for every wire, especially any change to banking details. Pair that with training built on real legal scenarios and a response plan that starts with the bank and the FBI’s IC3. Armour Cybersecurity helps law firms protect client funds with law firm cybersecurity services and incident response built for the legal sector, so a single well-timed email never becomes a six-figure loss and a call the firm dreads making to its client.
About the author
David Chernitzky is the CEO and Co-Founder of Armour Cybersecurity, a Toronto-based firm that protects organizations across North America from advanced cyber threats. He brings more than 25 years of cybersecurity and military cyber intelligence experience, having served as an officer in an elite technology unit before co-founding Armour. Armour’s team of military-intelligence veterans and senior advisors serves 260+ clients across 52+ industries with a 97% client retention rate. Learn more about Armour Cybersecurity.



