Wire-Fraud Defense for Law Firms: A Payment Verification Playbook
A straightforward procedure for verifying wire instructions, stopping email-account fraud, and responding when a payment may have gone to an impostor.
The dangerous wire-fraud email often looks ordinary. It arrives in an existing thread, uses the right names, mentions a real transaction, and asks for one small change: send the money to a different account.
That is why “look for bad grammar” is not a control. An attacker who has entered a client’s, lawyer’s, broker’s, or vendor’s mailbox can study the conversation and wait for the moment when money is expected.
The FBI’s guidance on business email compromise recommends independently verifying changes in account information and payment procedures. For a law firm, that needs to be a written routine rather than a reminder people hear once a year.
Make one rule non-negotiable
Never approve new or changed payment instructions through the same communication that delivered them.
Call a known person using a number already in the firm’s records or obtained from an independent, trusted source. Do not use the phone number in the email requesting the change. Read back the receiving bank, account name, and enough account digits to confirm the destination.
This rule applies even when the message appears to come from a partner, client, title company, opposing counsel, or long-standing vendor. A convincing identity is part of the attack.
Use two people for consequential payments
For wires and other high-risk transfers, separate preparation from release. One person enters the payment. Another checks the matter, payee, amount, verification record, and bank details before authorizing it.
Set a dollar threshold if necessary, but do not assume smaller payments are harmless. Criminals may begin with a modest transfer to test the process.
The second approver should not simply compare the bank screen with the fraudulent email. The point is to compare both with an independently verified instruction.
Decide what counts as a red flag
Staff should stop and verify when they see:
- new or changed bank details;
- urgency, secrecy, or pressure to bypass a normal step;
- a request to move the conversation to a new address or phone number;
- a slightly altered domain name;
- an unexpected attachment or sign-in page;
- a payment instruction that conflicts with the engagement or closing process; or
- a colleague who asks to defeat a control “just this once.”
None proves fraud. Each is a reason to slow down.
Protect the mailbox behind the transaction
Payment controls work better when email accounts are difficult to take over. Require phishing-resistant MFA where available, especially for administrators and anyone handling client funds. Review automatic forwarding rules, mailbox delegates, recent sign-ins, and recovery methods. Attackers sometimes create a forwarding or deletion rule so the real parties never see replies.
Do not approve unexpected push notifications. Use a password manager so staff are less likely to enter credentials into an imitation sign-in page. Limit administrator privileges and remove departed users promptly.
Tell clients how the firm handles instructions
At the beginning of a matter that may involve transfers, give clients a clear warning:
- the firm will not change wire instructions solely by email;
- the client should verify instructions using a known telephone number;
- last-minute changes are a fraud signal; and
- the client should call immediately if anything seems inconsistent.
Repeat the warning shortly before the transfer. A notice in a long engagement letter months earlier is easy to forget when a transaction becomes urgent.
Keep a verification record
For each payment, record:
- who supplied the instructions;
- how the firm obtained the verification phone number;
- who called and who answered;
- the date and time;
- which details were read back;
- who prepared and approved the transfer; and
- the bank’s confirmation.
This record helps prevent shortcuts and gives the firm a reliable chronology if something goes wrong.
If a transfer may be fraudulent
Speed matters. Do not wait for an internal investigation to finish.
- Call the sending financial institution immediately and ask it to contact the receiving institution and begin its fraud-recall process.
- Contact the FBI through IC3 and follow local law-enforcement and insurer requirements.
- Preserve the messages, headers, logs, payment records, and relevant devices.
- Secure affected accounts, revoke sessions, reset credentials from a known-clean device, and inspect forwarding and recovery settings.
- Notify the firm’s insurer, bank, ethics or breach counsel, and affected clients as the circumstances require.
- Continue checking for related changes in other matters. One discovered transfer may not be the only attempted one.
Do not conduct sensitive incident communications through an email account that may still be compromised.
The best defense is wonderfully unglamorous: a known phone number, a second person, and a rule that urgency never cancels verification.
Primary reference
This article is general information for legal professionals, not legal advice or an ethics opinion. Rules of professional conduct vary by jurisdiction—consult yours.