TL;DR: Business email compromise fools staff into paying a fraudster instead of the real recipient, and law firms are a favourite target because of the sums moving by email during conveyancing. Ensure your emails are secure with the right cybersecurity.
What is business email compromise for law firms?
Business email compromise works because the email looks exactly like the ones you deal with every day. A criminal accesses a real account or builds a fake one that looks close enough to pass, then sends a payment instruction or a change of bank details dressed up as something routine. This can be also be known as phishing.
Law firms rarely see this at random. Fraudsters time it to land right before a large transfer, when staff feel the most pressure to act fast.
How does a business email compromise scam work?

Fraudsters study how your firm communicates and wait for the right moment before slotting a request into an existing conversation. These are the forms it usually takes.
Impersonated partner instructions
A fraudster accesses or fakes a partner’s account and asks staff to process an urgent payment, timed for when the real partner can’t be reached to confirm it.
Altered bank details before completion
Just before a property transaction completes, the client receives an email claiming your bank details changed. The new account belongs to the fraudster, and the money moves before anyone checks.
Fake supplier invoices
A supplier’s account gets compromised, and an invoice arrives through the usual channel with new payment details. It looks routine, which is why it works.
Lookalike email domains
Fraudsters register a domain almost identical to yours, swapping a letter or adding a hyphen. On a phone screen, it reads as genuine.
Why do fraudsters target law firms?
Law firms sit higher up the target list than most businesses, and it comes down to how money moves through the job. Conveyancing work moves large sums of client money against tight deadlines, and probate matters carry the same exposure. That combination makes law firms a better target than most businesses, since a single successful attempt during a completion can outweigh months of smaller scams elsewhere.
The Solicitors Regulation Authority (SRA) flags cyber risk as an ongoing concern for this reason, and the damage goes beyond the immediate loss. A firm that loses a client’s deposit to fraud faces reputational harm that takes far longer to repair than the payment itself.
How can you prevent it at your firm?
None of these fixes cost much or take long to set up. They just need to become routine.
Verify bank detail changes by phone
Call a number you already hold on file, never one from the email itself, and confirm the change directly with the person you think sent it.
Ask your IT provider to lock down your email settings
There are technical settings that stop criminals sending email that looks like it came from your domain. They take an afternoon to put in place and close off one of the most common routes into a BEC attack, so ask your IT provider to check they’re switched on.
Add a pause for high value transfers
A short delay or a second sign off on large payments gives staff a moment to question something that feels wrong, instead of acting on instinct under deadline pressure.
Train staff to spot the pattern, not just the email
Teach staff to notice unexpected urgency and pressure to skip the usual checks, not just to look for a badly written scam.
What should you do if you suspect business email compromise?

Stop the payment if it hasn’t gone through, and call your bank immediately if it has. Banks can sometimes recall a transfer within the first few hours, but that window closes fast. Report the incident to Action Fraud and check if the same attempt touched other accounts or matters.
Tell your IT provider as soon as you notice anything, even without certainty. A quick check of your email logs confirms if someone accessed the account or simply spoofed it, and that changes what happens next.
How Labyrinth Technology helps law firms guard against business email compromise
Being a target isn’t something you can opt out of, but how exposed you stay is within your control. We help law firms across the UK put the right controls in place. That starts with Microsoft 365 configured properly and your network secured through WatchGuard, backed by a disaster recovery plan ready for anything that slips through. Get in touch and we’ll walk through where your firm’s exposure sits today.
Setting up email authentication takes an afternoon, and a missed fraud alert on completion day can cost a client their entire deposit. Fix it before the next transfer goes out, not after.






