A last-minute bank change can put client funds and a firm’s reputation at risk. The strongest response combines independent payment verification, separate approval and secure communications, with a clear stop point when something does not check out.

A closing deadline. A changed account. A convincing callback.
The original ThinkSwift article describes a clerk at a buyer’s law firm receiving an urgent email the day before closing. It appeared to come from the seller’s office and asked for a last-minute change to the wire instructions.
The clerk called the seller’s lawyer and reached voicemail. Someone then called back, posed as that lawyer and confirmed the change. According to the account, client funds were sent the next day to an account controlled by criminals.
The source describes attackers compromising both email and telephone communications through social engineering. It does not identify the firm, provide a loss amount or link to an independent incident report. Those details should be treated as the source’s account, rather than a verified case finding.
The practical lesson: a believable message followed by an incoming call does not establish that new banking instructions are genuine. The verification method must be independent of the suspicious request.
The account illustrates deadline pressure and a gap in verification. It does not establish whether anyone was negligent, and there is no need to make that judgment to improve the process.
Why legal transactions attract impersonation attempts
Law firms handle sensitive correspondence, transaction deadlines and transfers involving client funds. A criminal who learns enough about a matter can build a request that appears routine: the right names, a plausible closing date and a bank change framed as urgent.
Business email compromise (BEC) can involve an imitation address or a genuinely compromised mailbox. A message in an existing conversation can therefore look credible without being authorized. The FBI’s BEC guidance describes impersonation, targeted phishing and access to legitimate payment conversations as parts of these schemes.
The scale is substantial, but the statistics need context. The FBI’s 2023 Internet Crime Report recorded roughly US $2.9 billion in reported BEC losses. That is a dated complaint-based figure across organizations and individuals, not a Canadian law-firm loss total or proof that law firms are disproportionately affected.

Separate verification from approval
Verification checks whether the instruction is authentic. Approval decides whether an authenticated payment should be released. Calling an external lawyer is not, by itself, dual authorization by two people inside your firm.
What each payment control needs to establish| Control | Purpose | What it cannot prove alone |
|---|---|---|
| Email review | Identify inconsistencies and unexpected changes. | That a real mailbox is uncompromised. |
| Independent verification | Confirm identity and banking details through an established route. | That a new inbound caller is genuine because caller ID looks right. |
| Second approval | Have another authorized person review the payment and verification record. | That instructions are valid if both reviewers rely on the same unverified email. |
If the telephone system itself may be compromised, repeating the same call is not an independent check. Escalate to the responsible lawyer and establish a separate trusted method, such as an in-person confirmation, before releasing funds.
Make changed instructions a stop point
Build a short procedure staff can follow under pressure. Adapt it to the firm’s trust-account obligations and banking controls.
- Pause the transfer. Treat new or changed banking details as requiring fresh verification.
- Use a trusted contact route. Obtain the number from an established file record or reliable directory, not the change request or its attachments.
- Verify the person and details. Confirm who issued the instructions and the intended payee and account information.
- Record the check. Retain the instructions, contact method, person reached, date and confirmation outcome.
- Require a separate review. Have an authorized colleague check the verification evidence and payment details before release.
- Escalate uncertainty. If identity or instructions cannot be confirmed, keep the transfer on hold and involve the responsible lawyer.
LAWPRO’s practicePRO funds-transfer checklist provides a useful reference, including trusted-number verification and stopping when instructions change. A deadline should trigger escalation, not an exception to the check.
Support the workflow with security and training
Reduce opportunities for account takeover
Use MFA for email and administrative access, prioritizing phishing-resistant methods where supported. Review suspicious sign-ins, forwarding rules and unauthorized mailbox access. Protect telephone administration and review unexpected forwarding or routing changes with your provider.
Filter suspicious messages, but keep the payment checks
Email filtering and impersonation detection can reduce exposure. They cannot establish that every payment request is legitimate, particularly when a trusted external account has been compromised. Technical controls and verification procedures need to work together.
Practise the difficult moment
Use short exercises involving urgent bank changes, an unavailable contact and pressure from a senior colleague. Staff should know who can stop a transfer and whom to call next. Include lawyers and approvers in the exercise, not only support staff.
Verizon’s 2024 Data Breach Investigations Report found a non-malicious human element in 68% of breaches in its dataset. Its phishing exercise analysis also showed that users who fell for a test could act in under a minute. These are historical cross-industry findings, not a measure of your firm’s staff or a reason to assign blame.
Read our guide to passkeys for businesses when planning stronger account protection.

Act immediately if a transfer looks wrong
Contact the sending bank through a trusted channel as soon as fraud is suspected. Ask its fraud team to attempt a recall or freeze and coordinate with the receiving institution. Speed matters, but recovery is not guaranteed. The FBI recommends immediate contact with the financial institution.
In parallel, alert the responsible partner and incident-response lead. Preserve the original messages, headers, payment instructions, transaction references and call records. Have the technical team investigate and contain any compromised accounts while preserving relevant evidence.
Notify the appropriate insurers promptly under their reporting requirements. Ontario lawyers can use LAWPRO’s fraud reporting guidance. Coordinate police and Canadian Anti-Fraud Centre reporting, and have the responsible advisers determine any client, privacy, regulatory or contractual notifications required.
Use a trusted communication route for incident coordination if normal email or phone systems may be affected. Do not wait for a complete technical investigation before contacting the bank.
Protect client trust before the next closing
Explain payment-verification procedures at the start of a matter. Tell clients how to contact the firm independently and what to do if they receive changed instructions. Make clear that a short verification delay is part of protecting their money.
Review the full workflow with the people who use it: the clerk preparing the transfer, the lawyer responsible for the matter, the second approver and the IT team. Test what happens when the expected contact cannot be reached or the normal communication channel is unavailable.
ThinkSwift can help review email and account security and support practical staff awareness work. Pair that technical review with payment procedures set by the firm’s responsible professionals. For the financial side of incident planning, see why cyber insurance is only one part of resilience.
Questions answered
01Is a callback enough to verify new wire instructions?
An incoming callback alone is not enough. Use an independently established contact route, confirm identity and the payment details, and document the outcome. If the channel itself is suspect, stop and arrange a separate trusted method.
02Does a genuine email address mean the request is safe?
No. An attacker may control the real account. Treat unexpected banking instructions as requiring independent verification even when the message appears inside an existing conversation.
03What if the closing deadline is minutes away?
Escalate to the responsible lawyer and keep the payment on hold until the required checks are complete. Define this escalation path in advance so staff do not have to improvise.
04Can email security prevent every wire fraud attempt?
No. It can reduce malicious messages and account compromise, but cannot guarantee the authenticity of every payment instruction. Maintain independent verification and separate approval.
05Will insurance reimburse a fraudulent transfer?
That depends on the policy, conditions and facts of the loss. Review relevant coverage and reporting requirements with your broker or insurer before an incident, and report suspected losses promptly.
Strengthen the controls behind every transfer.
Talk through ways to protect your firm’s accounts, communications and payment process with ThinkSwift.
Talk it through