A law firm's trust account holds money that belongs to someone else. Settlement proceeds waiting to disburse, retainers not yet earned, closing funds in transit. That's exactly what makes it the most attractive target in the building, and fraudsters have learned that the fastest way into it runs through the firm's email.
When the money disappears, the loss is only the first problem. A drained trust account is a bar-discipline event. Client funds are governed by strict trust accounting rules in every state, and the lawyer whose account was compromised faces the disciplinary inquiry regardless of who committed the theft.
The Numbers Behind the Threat
The FBI's Internet Crime Complaint Center recorded 21,442 business email compromise complaints in 2024, with reported losses of $2.77 billion, making BEC the second-costliest crime category it tracks. BakerHostetler's 2025 Data Security Incident Response Report, drawn from more than 1,250 incidents its team handled in 2024, found fraudulent fund transfers totaling $109 million, a 211% increase over the prior year, with the average fraudulent wire climbing to $1.26 million. The same report found that fraudulent transfers took a median of 18 days to discover, compared to 3 days for other incident types. By the time anyone notices, the money has usually moved several times.
Law firms specifically are absorbing more of this than they report. The American Bar Association's 2024 Legal Technology Survey found that 39% of firms experienced a security breach in the past year, and that 56% of breached firms lost confidential client data. Only 34% of firms maintain an incident response plan, down from 42% the year before. Coalition's 2025 Cyber Claims Report found that 60% of its 2024 claims began with business email compromise or funds transfer fraud, and that recovery odds drop sharply when the fraud isn't reported within 72 hours.
How the Fraud Actually Works
A fraudster compromises an email account, at the firm, at a client, or at a counterparty like a title company, usually through an ordinary phishing message. Then they watch. They learn which matters involve money movement, when a settlement is disbursing, when a closing is scheduled, what the firm's payment instructions look like, and how the lawyers write.
When the moment arrives, the fraudster inserts altered wire instructions into a real transaction. The email comes from a genuine account or a lookalike domain one character off. The amount is right, the matter reference is right, the timing is right. The bookkeeper or paralegal processing it has no reason for suspicion, and the funds go to an account the fraudster controls. Real estate practices are hit hardest because closings combine large transfers with hard deadlines; the FBI's 2024 IC3 report recorded 9,359 real estate fraud complaints with losses over $173 million.
Why the Bar Makes This Worse Than a Theft
A business that loses money to wire fraud has a financial problem. A law firm that loses client trust funds has a professional one. Every state's rules of professional conduct hold lawyers responsible for safeguarding client property, and ABA Model Rule 1.15 makes no exception for lawyers who were themselves defrauded. Disciplinary authorities have suspended and disbarred lawyers whose trust accounts were emptied by fraud the lawyer failed to catch, on the reasoning that the safeguarding obligation includes reasonable security.
The client whose funds vanished must still be made whole, which for an uninsured firm means the partners pay personally. The state bar may open an inquiry regardless of restitution. And the malpractice and cyber insurance carriers will both ask what controls were in place, with the answer determining whether the loss is covered. The ABA survey found that only 40% of firms carry cyber liability insurance at all.
What Actually Protects the Account
The technical controls are the same ones that stop business email compromise everywhere. Multi-factor authentication on every email account and banking portal means a stolen password alone doesn't hand over the firm's identity. Email security filters the phishing messages that start the scheme, and monitoring catches the signs of a compromise in progress, the login from an unfamiliar location, the forwarding rule nobody created, the mailbox suddenly being read from two places.
The process controls matter just as much. Any wire instruction, and any change to one, gets verified by phone against a number the firm already had, never one supplied in the email requesting the transfer. Disbursements above a threshold require two people. Trust account activity gets reconciled promptly, because an 18-day discovery time is fatal to recovery and a same-day discovery is not. Staff who handle money get trained on what these schemes look like, since they, not the lawyers, usually process the fatal email.
Where a Managed IT Partner Helps
A managed service provider can run the technical side of this defense as an ongoing, proactive service. The provider can enforce multi-factor authentication across email and financial systems, run the filtering and monitoring that catch account takeovers early, and maintain the logging that shows an investigator, a carrier, or a disciplinary authority exactly what happened and what protections were in place. That documentation matters twice: it helps prevent the loss, and it demonstrates the reasonable efforts the bar expects if something happens anyway.
For a small or mid-sized firm without dedicated IT staff, that combination is difficult to maintain internally, and the stakes are measured in the firm's license, not just its ledger.
If you're not confident your firm's email and banking access are protected against the account takeovers behind trust account fraud, or that a fraudulent wire instruction would be caught before the money moved, a Network Discovery might be in order. We'll assess how your systems are secured, where your accounts are exposed, and whether your controls would satisfy the questions that follow an incident.
Ready to take the next step? Contact the Connecting Point team today to discuss your organization's needs.
Fill out our Network Discovery Form to get started!
970.356.7224 | www.CPcolorado.com | sales@CPcolorado.com
Connecting Point is a trusted IT solutions provider based in Greeley, Colorado, helping businesses across Northern Colorado and beyond navigate technology decisions with confidence.


