News & Events

The $3 Billion Email: How Business Email Compromise Is Draining Law Firms, Medical Practices, and Accounting Firms

Closing day. An escrow wire is ready. The title company sends an email:

“Our banking information has changed. Please use the updated remittance instructions attached.”

The message looks right. The timing makes sense. The signature matches. The payment goes out.

Hours later, someone discovers the truth: the email came from an attacker.

The money is gone.

According to the FBI’s 2025 Internet Crime Report, the Internet Crime Complaint Center received 24,768 business email compromise complaints in 2025, with $3.046 billion in reported losses. BEC was the second-highest reported loss category, behind investment fraud.

Legal services remains one of the most heavily targeted sectors, accounting for roughly 18% of BEC incidents in commonly cited IC3 analyses. Law firm trust accounts, real estate disbursements, M&A escrow, accounting refunds, medical billing payments, and vendor invoices all present the same attractive opportunity:

High-value transactions. Tight deadlines. People who are trained to trust familiar relationships.

Wire transfer and ACH remain the dominant payment rails in BEC, appearing in 86% of BEC-related complaints, and the money is often gone within hours.

How Business Email Compromise Really Works

No ransomware. No dramatic server breach. No flashing warning on the screen.

Just identity, timing, and social engineering.

Business email compromise is a fraud scheme in which criminals manipulate business communications to convince someone to send money, change payment instructions, release sensitive information, or provide access to an account.

The attacker may:

  1. Spoof a legitimate domain
    The message appears to come from your firm, a client, or a vendor, but the technical sending address is forged.

  2. Use a lookalike domain
    smithlaw.com becomes smith-law.com.
    acmeaccounting.com becomes acmeaccounting.co.

  3. Compromise a real mailbox
    The attacker gains access to an actual Microsoft 365 account and quietly monitors conversations. They may wait weeks for the right closing, invoice, refund, or payroll event.

  4. Steal a session token
    Through adversary-in-the-middle phishing, an attacker can sometimes capture an authenticated browser session after a user completes MFA. The criminal may not need the password again because the stolen token tells Microsoft that the session is already trusted.

  5. Create urgency
    “The closing is at 3 p.m.”
    “The vendor needs payment today.”
    “Please keep this confidential.”
    “I’m in court and cannot take a call.”

This is why email security cannot be reduced to “we have spam filtering.” The question is not only whether a bad message reaches the inbox. It is whether your firm can prevent a believable message from changing the destination of a six-figure payment.

Attorneys and a finance administrator verifying wire instructions through a known phone number

Why Small Professional Firms Are Prime Targets

Predictable. Trust-based. Busy.

That combination is valuable to criminals.

A small law firm may handle trust-account disbursements, settlement proceeds, real estate closings, and client retainers. A medical practice may process claims payments, refunds, payroll, and vendor invoices. An accounting firm may manage client refunds, tax payments, payroll files, and sensitive financial instructions.

These firms also tend to have:

  • Lean administrative teams
  • Shared responsibilities during busy periods
  • Predictable billing and closing calendars
  • Employees who know clients and vendors personally
  • Limited separation between email, accounting, and payment duties
  • Owners or partners who can authorize transactions quickly

An attacker does not need to defeat every security control. They need to find one person who reasonably believes, “Yes, this sounds like something Margaret would send.”

That is the “Hey Margaret!” problem. A familiar name, a familiar tone, and a familiar deadline can bypass skepticism faster than a technical exploit.

The Regulatory, Ethical, and Insurance Exposure

A fraudulent wire is not only a financial loss. It can create questions about whether your firm took reasonable steps to protect client data and funds.

FTC Safeguards and GLBA compliance

For covered financial institutions under the FTC Safeguards Rule, your written information security program should address administrative, technical, and physical safeguards.

That includes a risk assessment, access controls, monitoring, encryption where appropriate, employee training, service-provider oversight, and an incident response plan. The program must also identify a qualified individual responsible for overseeing it.

Not every accounting firm is automatically covered simply because it provides accounting services. Coverage depends on the firm’s activities and regulatory status. However, GLBA compliance obligations, contractual requirements, state laws, and professional standards may still apply.

HIPAA compliance for medical practices

HIPAA does not categorically prohibit email. But medical practices must use reasonable safeguards and avoid unauthorized disclosure of protected health information.

An email account takeover can expose:

  • Patient diagnoses and treatment information
  • Insurance and claims records
  • Social Security numbers and payment information
  • Referral documentation
  • Communications with business associates

HHS guidance confirms that patients may request unencrypted email after accepting the risks, but that does not make ordinary email handling automatically safe. A practice still needs appropriate access controls, MFA, audit logging, workforce training, and secure transmission methods when the risk warrants them.

If unsecured PHI is breached, the HIPAA Breach Notification Rule may require notification to affected individuals, HHS, and potentially the media.

Law firm cybersecurity and professional duties

For law firms, confidentiality and competence are not optional security goals. They are professional obligations.

The American Bar Association’s cybersecurity guidance connects technology competence with a lawyer’s duty to protect client information. A compromised mailbox may expose privileged communications, settlement details, trust-account records, and confidential business information.

If client information was accessed or reasonably suspected to have been accessed, the firm may need to investigate promptly, communicate appropriately, and help the client make informed decisions.

Cyber insurance requirements

Many cyber insurance policies now require MFA and defined email security controls for relevant accounts. But the exact requirement depends on the policy, insurer, application, endorsements, and security warranty.

Coverage may also distinguish between:

  • Social engineering fraud
  • Funds transfer fraud
  • Crime coverage
  • Computer fraud
  • Business email compromise

Do not assume a cyber policy will reimburse a fraudulent wire. Review the language before an incident occurs.

Controls That Actually Reduce BEC Risk

Technology helps. Process closes the gap.

Your controls should include:

  1. Phishing-resistant MFA where possible
    Use FIDO2 security keys or passkeys for high-risk accounts. Number matching is stronger than simple push approval, but SMS should not be your primary protection for sensitive access.

  2. Conditional access
    Restrict sign-ins by device health, location, risk level, application, and user role. Block legacy authentication.

  3. DMARC, DKIM, and SPF enforcement
    Configure these correctly and move DMARC toward p=reject after monitoring legitimate senders. This reduces domain spoofing.

  4. External sender warnings
    Make messages from outside your organization visibly different. A warning will not stop every scam, but it creates a useful pause.

  5. Link and attachment analysis
    Use sandboxing or detonation to inspect suspicious files and links before they reach users.

  6. Mailbox-rule monitoring
    Alert on new forwarding rules, hidden inbox rules, suspicious deletions, and unusual sign-in activity.

  7. Out-of-band payment verification
    Any new or changed payment instruction requires a callback to a phone number already on file. Never use the number included in the email.

  8. Dual approval for high-value transfers
    Separate payment preparation from payment approval. Set thresholds appropriate to your firm’s risk.

  9. Simulated invoice-change training
    Employees should practice identifying realistic vendor, client, escrow, refund, and payroll fraud, not generic “click the bad link” exercises.

Medical practice staff reviewing an email security alert and payment record

Internal Controls: Pros and Cons

You may be tempted to handle this internally.

Pros: You retain direct control, avoid a recurring service fee, and can tailor procedures to your firm.

Cons: Internal controls often depend on one or two employees remembering the process every time. Training costs money. Staff turnover creates gaps. Alerts go unreviewed during tax season, trial preparation, month-end close, or a medical practice’s busiest billing cycle.

That is the difference between owning a written policy and operating a managed control environment.

Your accounting firm IT, medical practice IT, or managed IT for law firms program should continuously enforce the policy, not simply explain it after a loss.

If You Think You Have Been Hit

Move immediately. Do not wait for certainty.

  1. Contain the account
    Disable the suspected account, revoke sessions, reset credentials, remove malicious mailbox rules, and isolate affected endpoints.

  2. Call the bank immediately
    Ask for a wire recall, freeze, or Financial Fraud Kill Chain intervention. The recovery window is measured in hours.

  3. Preserve evidence
    Keep original messages, headers, login alerts, mailbox rules, payment instructions, call records, and transaction details.

  4. Notify the appropriate parties
    Follow your incident response plan, policy requirements, regulatory obligations, and client-notification procedures.

  5. Engage counsel and your insurer
    Counsel can help direct the investigation. Your policy may require prompt notice, approved vendors, or insurer consent.

  6. Report the crime
    File with IC3 and provide complete transaction information.

  7. Fix the root cause
    Do not stop at changing a password. Determine how access occurred, whether tokens were stolen, what data was viewed, and which payment process failed.

Final Word

Business email compromise is not a problem reserved for large corporations. It is particularly dangerous for firms where one email can move client money, disclose sensitive records, or create an ethical and regulatory crisis.

You need more than antivirus. More than a spam filter. More than a policy in a shared folder.

You need layered email security, endpoint security, identity controls, verified payment procedures, documented response plans, and continuous monitoring. You need predictable costs, clear accountability, and evidence that the controls are working.

That is the value of a qualified managed services provider. With the right outsourced IT partner, your firm can combine cybersecurity, IT support for small business, compliance documentation, IT audit readiness, ransomware protection, and business continuity planning into one managed program.

A PC of Mind helps professional services firms make technology a strategic advantage instead of a source of uncertainty. Contact us to discuss a practical BEC protection plan for your firm.