SwiftCybersecurity

Licensed & verified

Get Real Answers.
Fast.

Connect with a licensed private investigator near you in minutes, not days.

Swift matches your case to a credentialed private investigator licensed where you need results — then manages every step until it's resolved.

(877) 766-5087

No obligation — 100% confidential

State-licensed PIs only Licensed, local coverage Confidential intake

Business Email Compromise & Trust-Account Wire Fraud — For Law Firms

Law firms are a preferred target for business email compromise (BEC), and the reason is simple: on any given week a firm is moving other people's money — settlement proceeds, real-estate closing funds, estate distributions, retainers — through a client trust account, and it is doing it over email. An attacker gets into a mailbox, reads the thread on a live matter for days or weeks, and then, at exactly the right moment, sends wiring instructions that look like they came from the client, opposing counsel, the title company, or a partner. The funds leave. The forwarding rule that hid the attacker's replies is often still running when someone finally notices.

Swift Cybersecurity handles both sides of this for firms: remediation when it has already happened, and ongoing protection so it does not. We are a cybersecurity firm — our analysts do the incident response, forensics, and hardening in-house — and we bring in licensed private investigators when a matter needs work on the ground, such as tracing where the wire went and identifying the account holders for your bank, your carrier, and law enforcement.

If money is missing from your trust account, the clock is already running. The Financial Fraud Kill Chain, correspondent-bank freezes, and an FBI IC3 filing all have windows measured in hours, not days. Call before the paperwork is done — we can start containment and the recovery process the same day, and preserve the evidence you will need later.

The Bar Exposure — Even When a Vendor Was Compromised First

The most damaging law-firm BEC pattern is the one where your firm was the second domino. A title company, co-counsel, an e-discovery or e-filing vendor, an expert, a lender, or even the client is breached first. The attacker then uses that party's real email account and a real thread to walk into your firm — to phish a staff member, to slip a payoff-instruction change into a closing, or to get a reply-to address changed on a settlement. Because every message is coming from a legitimate, expected sender, it clears the usual gut check.

Firms often assume that if the intrusion started somewhere else, the ethical exposure started somewhere else too. It does not. Disciplinary authorities evaluate the lawyer's conduct, not the vendor's, and "we were defrauded" has repeatedly failed as a defense to the questions that actually get asked:

  • Safekeeping client property (Model Rule 1.15). Money that is supposed to be in the client trust account and is not is the lawyer's problem regardless of how it left. A trust-account shortfall generally must be cured immediately from the lawyer's own funds, and in many jurisdictions self-reported. Being tricked into sending the wire does not change the accounting.
  • Confidentiality (Model Rule 1.6(c)). The lawyer must make reasonable efforts to prevent unauthorized access to and disclosure of client information. If an attacker sat in your mailbox reading privileged material, the bar's question is whether your safeguards were reasonable — not whether the vendor's were.
  • Competence (Model Rule 1.1, Comment 8). Adopted in roughly forty states: a lawyer must keep abreast of the benefits and risks of relevant technology. Not knowing that wire instructions must be verified by voice to a known number, or that mailbox forwarding rules are an attack tool, is itself a competence issue.
  • Supervision of nonlawyers and vendors (Model Rules 5.1 and 5.3). Lawyers must make reasonable efforts to ensure that staff and outside vendors handling client funds or data behave in a way compatible with the lawyer's own obligations. A vendor being the point of entry can become a supervision finding against the firm.
  • Duty to notify the affected client (Model Rule 1.4; ABA Formal Opinion 483). After a data breach involving client information or funds, the lawyer has an affirmative duty to tell affected current clients what happened and what is being done. Delay or silence compounds the discipline far more than the breach itself.
  • Candor (Model Rule 8.4). Shading the timeline or the scope to a client, a court, opposing counsel, or bar counsel turns a security incident into a dishonesty charge — the category that ends careers.

The realistic downside stack is a bar grievance and discipline (from a private admonition to suspension or, for trust-account losses, disbarment), a malpractice claim from the client whose funds were taken, fee disgorgement, a hard conversation with your malpractice carrier, court sanctions if privileged material or a protective order was in play, and mandatory client and state data-breach notifications.

What actually moves the outcome is the forensic record. A clean, documented reconstruction — showing that your safeguards were reasonable, exactly how the attacker got in (including that the vendor was patient zero), that you contained it fast, that you notified affected clients promptly, and that you cooperated fully — is what turns a possible suspension into a closed file. That record is what we build.

Swift Cybersecurity is a cybersecurity firm, not a law firm, and nothing here is legal or ethics advice. Rule citations are to the ABA Model Rules; your state's rules and your obligations may differ. Engage your own ethics counsel or bar counsel — we work alongside them and give them the facts they need.

Remediation — When It Has Already Happened

Contain and preserve — do not let anyone "clean up"

We lock down affected accounts, force credential resets, revoke active sessions and OAuth grants, and remove the hidden forwarding rules and reply-to changes the attacker left behind — while preserving mailbox audit logs, sign-in logs, and message traces under a litigation hold. Well-meaning IT cleanup is one of the most common ways firms destroy the evidence they later need for the carrier and the bar.

Protect the trust account and chase the wire

We help you engage your bank's fraud unit and the Financial Fraud Kill Chain, file with the FBI's IC3, and push for a correspondent-bank freeze and wire recall. Where funds have already moved through several accounts, a licensed private investigator we engage follows the trail and identifies account holders for your bank, insurer, and law enforcement.

Forensic reconstruction and scope

We establish how the attacker got in, whether an outside vendor was the origin, how long they had access, which privileged and client information was viewed or exfiltrated, and exactly which matters and clients are affected — in a report your malpractice carrier, your ethics counsel, and law enforcement can rely on.

Client notification and third-party support

We build the affected-client and affected-matter list and a factual, defensible incident summary your ethics counsel can turn into the client notices required under Rule 1.4 and Formal Opinion 483. We coordinate with your malpractice carrier and flag state data-breach-notification obligations, which in a growing number of states now reach law firms directly.

Bar and disciplinary support

If a self-report or a grievance response is required, we provide the documented timeline and technical narrative — what your safeguards were, what failed, what you did, and how fast — that lets you demonstrate reasonable conduct rather than argue it.

Close the hole

Every engagement ends with the specific changes that would have stopped this attack: MFA gaps, legacy authentication, weak conditional-access rules, the missing call-back step on wire instructions, and vendor practices that need to be in your engagement letters.

Ongoing Protection — So It Doesn't Happen Again

Almost every firm we remediate had the tools to prevent the loss and had not configured or watched them. An ongoing protection engagement closes that gap and keeps it closed:

  • Trust-account disbursement controls — a mandatory voice call-back to a previously known, independently sourced number for every disbursement and every change to payoff or wiring instructions, plus dual authorization above a threshold. This one control stops the large majority of law-firm wire fraud.
  • Email and identity hardening — enforced MFA, removal of legacy authentication, tuned conditional-access and anti-phishing policies, and DMARC, SPF, and DKIM set to actually reject spoofed mail.
  • Mailbox-rule and sign-in monitoring — alerting on the exact precursors to attorney BEC: new forwarding or reply-to rules, impossible-travel logins, mass downloads, and unfamiliar OAuth grants.
  • Vendor due diligence and the Rule 5.3 paper trail — security expectations for co-counsel, title and escrow companies, e-discovery and e-filing vendors, experts, and cloud providers written into your engagement terms, and a record that you supervised them.
  • Staff training on the scenarios that matter — closings, settlements, payoffs, and estate distributions, and the core lesson that the sender can be real and the thread can be real while the instructions are still fake.
  • An incident response plan the firm can run at 5 p.m. on a Friday — named roles, first calls, evidence-preservation steps, and notification triggers — plus periodic configuration and log review, and support for the security attestations your malpractice carrier or bank now ask for.

Pricing — Call for a Personalized Quote

Every engagement is scoped to the situation — how many mailboxes and matters were touched, whether trust funds are still recoverable, whether a grievance or malpractice claim is anticipated, which platform your firm runs, and what level of ongoing monitoring you want afterward. Because those factors vary so widely, we do not publish a flat rate.

Call (877) 766-5087 and a member of our team will walk through your situation and give you a personalized quote — for emergency remediation, ongoing protection, or both. If you are mid-incident, we can begin containment before the engagement paperwork is finished.

Get a Personalized Quote

Wire missing from your trust account? Call before you call the client.

We can start containment and the recovery process the same day, preserve the evidence you will need for your carrier and the bar, and work alongside your ethics counsel. Or, if nothing has happened yet, let's make sure it never does.

Call (877) 766-5087 for a Quote