Direct Answer
Business Email Compromise (BEC) is a cyberattack in which a criminal uses email to impersonate someone you trust or gains access to a legitimate email account and uses it to commit fraud, steal information, or compromise additional accounts.
For law firms, a BEC attack might involve a criminal monitoring an existing email conversation and inserting fraudulent wire instructions at the right moment. It may also be a payment request that appears to come from a partner, or an attacker taking over a client's email account.
A compromised account can also be used to send phishing emails to the victim's contacts in an attempt to take over their accounts.
Because an attacker may actually be sending messages from a legitimate email account, recognizing the sender does not necessarily mean the email is legitimate.
This article covers five ways law firms can reduce the risk of Business Email Compromise.
Why This Matters
Law firms routinely use email to communicate with clients, exchange documents, discuss confidential matters, approve payments, and provide instructions.
That makes access to an email account extremely valuable to an attacker.
Once inside an account, an attacker may be able to read existing conversations, learn how people communicate, identify clients and vendors, and send messages from the compromised mailbox. Attackers may also create forwarding rules or otherwise manipulate the mailbox to help conceal what they are doing.
This can make a BEC attack much harder to recognize than a phishing email from a stranger.
Editor's Insight
Many people think phishing means receiving a fake email that appears to come from someone they know.
BEC can be much more convincing.
The person whose name appears on the message may actually own the email account.
The attacker may be inside that person's mailbox.
That is why an unusual financial request or other sensitive instruction should be independently verified, even when the email comes from someone you know.
How Can a Law Firm Protect Itself From Business Email Compromise?
1. Understand How Business Email Compromise Happens
BEC can begin with a phishing email that tricks someone into entering their email password into a fraudulent website.
Sometimes attackers impersonate a legitimate sender with a similar-looking email address. In other attacks, they obtain the credentials for a real email account and gain access to the mailbox itself.
Once an account is compromised, an attacker may use it to:
- Send fraudulent wire or payment instructions
- Impersonate a partner or employee
- Send messages to clients from a law firm's real email account
- Use a compromised client's account to send instructions to the law firm
- Monitor an existing conversation and insert fraudulent instructions
- Email people in the victim's contact list and attempt to compromise their accounts
The important point is that the attack may come through an account you already trust.
2. Use Multi-Factor Authentication
A stolen password does not necessarily have to result in a stolen email account.
Multi-Factor Authentication (MFA) adds another requirement before someone can log in.
If an employee enters a password into a phishing website, MFA may prevent the attacker from using that password to access the Microsoft 365 account.
MFA is an important layer of protection against BEC, but it should not be the only one.
3. Verify Financial and Other Sensitive Requests
Law firms should establish procedures for independently verifying requests involving money or sensitive information.
Pay particular attention to:
- Wire-transfer instructions
- Changes to existing payment instructions
- Requests to send money to a different account
- Unexpected payment requests
- Requests for confidential or sensitive information
- Requests that bypass the firm's normal procedures
- Requests accompanied by unusual urgency
Do not rely on the email itself to perform the verification.
Call the person using a telephone number you already have or another trusted method established by your firm.
Never send wire transfers without verifying the request via phone call to an already trusted phone number.
4. Train Employees to Recognize Unusual Email Activity
Cybersecurity awareness training should teach employees that BEC does not always look like traditional phishing.
An email may contain the correct name, signature, writing style, and information about an existing conversation.
Instead of asking only, "Do I recognize the sender?", employees should also consider:
"Was I expecting this request, and does it make sense?"
If something does not make sense, verify it before acting.
5. Monitor for Suspicious Account Activity
Preventing account compromise is important, but law firms also need a way to identify suspicious activity when someone attempts to access an account.
Security systems can detect suspicious login attempts and other unusual account behavior.
SIEM can help by collecting and analyzing security information and alerting the IT provider to unusual mailbox activity, such as suspicious forwarding rules, unexpected external forwarding, and sent messages that the employee didn't send.
That gives the IT provider an opportunity to investigate suspicious activity rather than depending on an employee to notice that something is wrong.
A Real-World Example
An attorney received an email that appeared to come from a colleague.
She opened what appeared to be a PDF and entered her Microsoft 365 username and password into a fraudulent login page.
The attacker now had her password and immediately attempted to access the account.
MFA prevented the attacker from logging in, and the SIEM system issued an alert so the password could be changed.
Had the attacker successfully gained access to the mailbox, the account could potentially have been used to read email, communicate with other people from the legitimate account, or attempt further attacks.
Two different safeguards performed two different jobs.
MFA prevented the account takeover. SIEM made sure the attempted access did not go unnoticed.
Two Questions We Hear
If an email really came from someone's account, how are we supposed to know it isn't legitimate?
You may not be able to determine that just by looking at the sender.
That is why employees should pay attention to the request itself.
If someone you know asks you to transfer money, change payment instructions, provide sensitive information, open an unexpected document, or do something outside the normal way you work together, verify the request through a trusted communication method before acting.
Never send wire transfers without verifying the request via phone call to an already trusted phone number.
Isn't MFA enough to prevent Business Email Compromise?
MFA provides an important layer of protection, but law firms should not depend on one security control.
BEC can involve account compromise, impersonation, phishing, social engineering, and fraudulent payment instructions.
MFA should be combined with employee training, procedures for independently verifying sensitive requests, email security, monitoring, and other cybersecurity safeguards.
How Avenue M Helps
Avenue M Computers has provided IT and cybersecurity services to law firms in New York since 2010.
We help law firms implement layers of protection designed to reduce the risk of email account compromise and identify suspicious activity when it occurs.
These safeguards can include MFA, email security, EDR, SIEM, cybersecurity awareness training, and procedures for responding when suspicious activity is detected.
Technology can provide important protection, but employees also need to know when an email request should be independently verified.
Three Key Takeaways
- An email coming from someone you know does not necessarily mean the message is legitimate. The person's actual email account may have been compromised.
- Financial requests, changes to payment instructions, and other sensitive requests should always be verified by contacting the supposed sender through a communication method you already trust.
- MFA, monitoring, email security, and employee awareness provide different layers of protection against Business Email Compromise.
Related Articles
- Why Is Multi-Factor Authentication (MFA) Essential for Law Firms?
- What Is SIEM, and Why Do Law Firms Need It?
- How Often Should Law Firms Conduct Cybersecurity Awareness Training?
- What Is Calendar Invite Phishing, and How Can Law Firms Avoid It?
- What Should Every Law Firm Include in an Incident Response Plan?
- What Are the Biggest IT Mistakes Law Firms Make That Can Lead to Ransomware?
Technology should help your law firm practice law more securely, efficiently, and confidently, not become another distraction.


