October is Cybersecurity Awareness Month, making it a good time for law firms to revisit one of the most common cybersecurity threats their employees face: phishing.
For years, people were told to identify phishing emails by looking for obvious warning signs such as poor grammar, misspelled words, strange formatting, or awkward language. While those clues can still appear, relying on them alone is no longer enough.
Modern phishing messages can be polished, professional, and highly convincing. They may reference a real attorney, client, transaction, vendor, or internal business process. With AI making it easier to generate natural-sounding messages quickly, even a well-written email may deserve a second look.
The question employees should ask is no longer simply:
“Does this email look fake?”
A better question is:
“Is this person asking me to do something unusual?”
The Warning Signs Have Changed
Consider this scenario.
An employee receives an email that appears to come from a partner at the firm:
“I’m tied up. I need this wire sent immediately. Don’t call — I can’t answer.”
The email address may look right. The writing may sound professional. The request may even reference a legitimate matter.
The danger becomes clearer when you focus on the behavior of the request, rather than the appearance of the email.
Here are several elements law firm employees should learn to recognize.
1. Urgency
Phishing attempts often create pressure to act immediately.
A message may say a payment must be sent right away, a document needs to be opened before a deadline, or an account will be locked unless the recipient responds.
Urgency is effective because it reduces the amount of time people spend thinking about the request.
When a message pushes an employee to move unusually fast, that should be a signal to stop and verify.
2. Pressure to Bypass Normal Procedures
A particularly important warning sign is a request to ignore the firm’s established process.
Examples might include:
- Sending a wire without the usual approval.
- Changing banking information without confirming it.
- Providing confidential information through an unfamiliar method.
- Skipping a required phone verification.
- Being told not to contact the person making the request.
Legitimate requests should still be able to withstand normal verification procedures.
3. Unexpected Financial Changes
Law firms frequently handle money, settlement funds, invoices, retainers, and client transactions, which makes financial requests especially important to verify.
Employees should be cautious when a client suddenly provides new wire instructions, a vendor changes its banking information, or someone requests that money be sent to a different account than usual.
Even when the email looks legitimate, a financial change should be confirmed through a trusted channel.
4. Requests for Credentials or Confidential Information
Phishing is not limited to stealing money.
Attackers may also try to obtain usernames, passwords, documents, client information, access codes, or other sensitive data.
A request for credentials or confidential information that seems unusual—or that arrives through an unexpected channel—should trigger verification before anything is shared.
5. Instructions Not to Verify
One of the strongest warning signs may be an attempt to discourage verification.
Messages such as:
“Don’t call me.”
“I’m unavailable.”
“Just take care of this now.”
should receive additional scrutiny when paired with a sensitive or unusual request.
An attacker benefits when an employee feels that confirming the request would be inconvenient or inappropriate.
Create a Simple Verification Procedure
Law firms do not need an overly complicated policy to reduce this risk.
Start by defining which requests require additional verification. Financial transactions, changes to payment instructions, requests for credentials, and releases of confidential information are good places to begin.
Then determine how employees should verify those requests.
That could mean calling a phone number already stored in the firm’s records, contacting the person through a trusted internal channel, or following an established approval process.
Most importantly, employees should know that they have permission to stop before acting.
A simple statement can become an effective cybersecurity habit:
“Before I do this, I’m going to verify it.”
As phishing messages become more convincing, slowing down and verifying unusual behavior can be more valuable than trying to decide whether an email simply “looks fake.”
Cybersecurity Awareness Month is an excellent opportunity to make that expectation clear across your law firm.