Skip to content

Insights

How Law Firms Can Reduce Business Email Compromise Risk

BEC is one of the biggest cyber threats to Australian law firms. Here is how to protect your firm trust account and client communications.

Business email compromise (BEC) is one of the most financially damaging cyber threats facing Australian law firms. Unlike ransomware — which is visible and immediate — BEC often goes undetected until funds have already moved. By then, recovery is difficult.

This article explains how BEC works in a legal practice context, why law firms are a high-value target, and what you can do to reduce your exposure.

How BEC Targets Law Firms

BEC in a legal context usually takes one of the following forms:

  • Conveyancing trust account fraud: Attackers monitor or intercept email exchanges in a property transaction and impersonate either the solicitor or the client to change the bank account details for settlement funds. This is one of the most common and costly BEC attacks on Australian law firms.
  • Invoice redirection: Attackers impersonate suppliers or other solicitors to redirect payment for disbursements, counsel fees, or other invoices to a fraudulent account.
  • Client instruction impersonation: Attackers impersonate clients (using spoofed or compromised email addresses) to issue instructions — including fund transfers, changes to instructions, or requests for sensitive documents.

Australian context: The Australian Cyber Security Centre (ACSC) and the Australian Federal Police have both identified BEC as a significant and growing threat to professional services firms in Australia. Law firms with conveyancing practices are considered high-priority targets.

Why Law Firms Are Attractive Targets

Several characteristics make law firms particularly attractive:

  • High-value transactions — property settlements, commercial transactions, and trust distributions involve large sums
  • Email-driven practice — most client and counterparty communication happens via email
  • Time pressure — legal deadlines create pressure to act quickly without verifying
  • Trust in email as a communication channel — legal professionals are trained to act on written instructions

Technical Controls

Technical controls reduce the likelihood that fraudulent emails reach your inbox and that your domain can be impersonated.

DMARC, DKIM, and SPF

These three email authentication standards work together to verify that email claiming to come from your domain was actually sent by you — and to instruct receiving mail servers on what to do if it wasn’t. A DMARC policy set to “reject” means spoofed emails using your domain are blocked before they reach the recipient.

  • SPF: specifies which mail servers are authorised to send email from your domain
  • DKIM: adds a cryptographic signature to outbound email that recipients can verify
  • DMARC: ties SPF and DKIM together and specifies a policy (none, quarantine, or reject) for emails that fail

Advanced Email Filtering

Standard spam filters are not sufficient to catch BEC. Advanced filtering with impersonation detection can identify emails that display names that match known contacts but come from different domains — a common BEC technique.

External Email Warnings

Displaying a warning banner on all inbound email from outside your organisation is a simple and effective reminder that can prompt staff to pause before acting on unexpected instructions.

Process Controls

Technical controls alone are not enough. Process controls address the human element.

  • Out-of-band verification for payment changes: Any change to bank account details or payment instructions received by email must be verified by telephone — using a number from your records, not from the email. This single process change eliminates the majority of trust account fraud.
  • Dual approval for large transfers: Implement a requirement for a second approver on trust account disbursements above a defined threshold.
  • Client verification procedures: Establish a process for verifying client identity when acting on instructions, particularly for property transactions.
  • Staff training: Ensure all staff — including legal assistants and support staff who handle payments — understand how BEC works and what the firm’s verification procedures are.

What To Do If You Suspect a BEC Attack

If a payment has already been made to a fraudulent account:

  1. Contact your bank immediately — financial institutions may be able to recall funds if contacted quickly
  2. Contact your IT provider to secure any compromised accounts and investigate the extent of access
  3. Report to the Australian Federal Police (cybercrime.gov.au) and the ACSC via ReportCyber
  4. Notify your professional indemnity insurer
  5. Consider your obligations under the NDB scheme if personal information was involved

Next Steps for Your Firm

Start with DMARC implementation and an out-of-band payment verification procedure. These two changes address the most common attack paths with relatively low effort.

For a full assessment of your firm’s email security posture, SouthCore offers confidential IT reviews for Melbourne law firms.

RELATED READING

Related Resources

Related

IT Support for Law Firms in Melbourne

Managed IT and cyber security built around the specific needs of Melbourne law firms.

Learn more

Related

IT Support Checklist for Law Firms in Melbourne

A comprehensive IT checklist for Melbourne legal practices.

Learn more

Better IT starts with a conversation.

Tell us what you need. Let’s find a way forward.