Our regular hours are Monday to Friday, 7am to 5pm MT. For emergencies we are 24/7 on the same number, and it is always answered by a person. Call (604) 813-7881 and ask Tony for your free 30-minute insurer readiness review. No pressure, no jargon.
Email takeover and wire fraud at law firms
A changed wire instruction, a few days before closing
Most wire fraud does not look like an attack. It looks like a normal email in a real file. Here is how it tends to go, why it works, and what usually helps.
Ask Tony for a free 30-minute insurer readiness review.
What you can count on
- HuntressManaged EDR on every computer we manage
- 24/7a person answers (604) 813-7881
- $55 to $110per PC per month for law firms
What happens
Illustrative, not a client story. This is a made-up sketch, built from public notices. It is not about a Benson Hunt client.
A small firm is acting on a purchase. A few days before closing, an email lands in the usual thread. The name, the signature and the file number all look right. It says the other side’s trust account details have changed, and asks for the funds to go to a new account.
The lawyer handling the file is busy and the closing date is close. The message sits right under earlier, genuine emails, so nothing feels off. The money goes out. A day or two later, the real lawyer asks where the funds are.
In many cases like this, someone had already got into one of the mailboxes in the thread, read along for a while, and waited for the right moment. They may also have set up a rule that hides replies, so the real people never see the questions.
The public notices behind this sketch
- A December 2024 notice from the Lawyers Indemnity Fund (LIF) describes a BC firm acting for a lender that wired over $4 million after fake instructions that appeared to come from the borrower’s lawyer. The call to verify was not made. The notice also warns that a fraudster can send the “verification” email too. Read the LIF notice
- In July 2025 the Canadian Anti-Fraud Centre described a Vancouver-area law firm that was tricked by spear phishing into wiring CAD $2.3 million to Hong Kong. The full amount was recovered. The same release reports $67.5 million in spear phishing losses in 2024 and estimates that only 5 to 10% of victims report. Read the CAFC release
A request that looks right
New account details, in a real thread, close to closing.
A call to a number you already had
Not a number from the email, and not a reply to the same thread.
Then release the funds
A second person signing off is a good habit too.
Why it happens
In plain words, and with nobody to blame.
A password is often enough
A stolen password, often taken through a fake sign-in page, can be enough to open a mailbox. From there someone can read live files and wait for the right moment.
It sits inside a real thread
A message in a real conversation, or from a mailbox that has really been taken over, does not feel like spam. Look-alike addresses can also pass at a quick glance.
Deadlines and busy days
Nobody skips the check on purpose. The call is simply the step that goes missing when a closing is close and the day is full.
What fixes it
No IT setup can promise to stop every fake instruction. The strongest habit is a firm procedure: confirm any new or changed payment details by phone, using a number already on file, and have a second person sign off. Our part is to make the mailbox harder to take over, and to build the rest of the foundation so a bad day stays a smaller bad day.
- Multi-factor sign-in on email. A stolen password on its own is far less useful. Coverage and method matter, so we look at which accounts and which kinds of sign-in are covered. A 2026 Sophos survey found MFA was on in some form in 97% of incidents that began with stolen credentials, a good reminder that it needs to be set up well. Sophos report
- Email anti-spoofing (SPF, DKIM and DMARC). We recommend all three, and we can set them up and check them for your firm’s domain. Together they make it much harder for someone to send email that looks as if it came from you. They can’t stop a criminal who has taken over a real mailbox, which is why the call to a known number still matters most.
- Awareness training for everyone. Short quizzes, a monthly report card, and management hears when someone fails a quiz. How our training works
- Patching, and Huntress Managed EDR with 24/7 monitoring. We recommend updating browsers, Office and Windows on a weekly schedule. Huntress Managed EDR runs on every computer we manage, and alerts go by email and SMS to our team, not just to a program sitting quietly.
- Microsoft 365 Business Premium, as standard for firms under 300 users. It brings Conditional Access, so a sign-in from an unexpected place or device can be challenged or blocked, and message encryption for sensitive email. What every law firm should have
- Backups kept apart. 3-2-1 backups, with the offsite copy held in Canada, in Vancouver, BC, so one bad day cannot reach every copy.
Questions we help you answer
These are the checks we like to go through together. Ask us which ones fit your firm.
- Can someone send email that looks as if it came from your firm’s own domain? The settings that speak to this are called SPF, DKIM and DMARC. We recommend all three and can set them up.
- Would anyone hear if a new forwarding rule or inbox rule appeared in a lawyer’s mailbox?
- Is there a filter that checks links and attachments before staff open them?
- Who may approve a change to payment details, and how do they confirm it?
- If a transfer goes to the wrong place, who calls the bank, the insurer and the law society, and in what order?
Where this meets the rules: in BC, the Law Society publishes steps to take after funds transfer fraud, including trust shortage reporting under Rule 3-74. In Alberta, the Law Society recommends email authentication, MFA and training, and ALIA says its universal cyber policy does not cover funds transfer fraud. This is IT guidance, not legal advice.
Why it matters, in plain words
The tech behind this page, and why it’s there. See all the plain guides.
Multi-factor sign in
Why a stolen password shouldn’t open a lawyer’s inbox
Passwords leak. A second check on a phone or a security key stops most stolen passwords from working.
Read more: Why a stolen password shouldn’t open a lawyer’s inbox
DNS filtering
Why a bad link can fail before the page loads
Every web visit starts with a lookup. Known bad sites are blocked right there, in the office and on laptops.
Business firewall
Why the internet company’s router isn’t a firewall
It connects you. A business firewall inspects traffic, stops known attacks and keeps guests off the firm’s network.
Read more: Why the internet company’s router isn’t a firewall
Email and wire fraud questions we hear
Can IT stop wire fraud completely?
No, and anyone who says so is promising too much. Wire fraud usually works through a person and a process, not a broken lock. Good IT makes mailboxes harder to take over and gives you alerts and backups. The call to a known number is still the step that matters most.
Is multi-factor sign-in enough?
It helps a great deal, but it is not magic. Some methods are easier to fool than others, and one forgotten account without it can be the way in. We look at coverage as well as the method.
What should someone do if they think they clicked something bad?
Tell someone straight away, even if it feels awkward. Early helps. Call us on (604) 813-7881, where a person answers 24/7 for emergencies. Then speak to your firm’s lawyer, your insurer and your bank about next steps, because those depend on what happened.
Do you set up email protection like DMARC?
Yes. We recommend SPF, DKIM and DMARC for every law firm, and we can set them up and check them for your firm’s domain. Ask us about your domain and we will walk you through what we would check and what it involves.
