Closing day. An escrow wire is ready. The title company sends an email:
“Our banking information has changed. Please use the updated remittance instructions attached.”
The message looks right. The timing makes sense. The signature matches. The payment goes out.
Hours later, someone discovers the truth: the email came from an attacker.
The money is gone.
According to the FBI’s 2025 Internet Crime Report, the Internet Crime Complaint Center received 24,768 business email compromise complaints in 2025, with $3.046 billion in reported losses. BEC was the second-highest reported loss category, behind investment fraud.
Legal services remains one of the most heavily targeted sectors, accounting for roughly 18% of BEC incidents in commonly cited IC3 analyses. Law firm trust accounts, real estate disbursements, M&A escrow, accounting refunds, medical billing payments, and vendor invoices all present the same attractive opportunity:
High-value transactions. Tight deadlines. People who are trained to trust familiar relationships.
Wire transfer and ACH remain the dominant payment rails in BEC, appearing in 86% of BEC-related complaints, and the money is often gone within hours.
How Business Email Compromise Really Works
No ransomware. No dramatic server breach. No flashing warning on the screen.
Just identity, timing, and social engineering.
Business email compromise is a fraud scheme in which criminals manipulate business communications to convince someone to send money, change payment instructions, release sensitive information, or provide access to an account.
The attacker may:
-
Spoof a legitimate domain
The message appears to come from your firm, a client, or a vendor, but the technical sending address is forged. -
Use a lookalike domain
smithlaw.combecomessmith-law.com.acmeaccounting.combecomesacmeaccounting.co. -
Compromise a real mailbox
The attacker gains access to an actual Microsoft 365 account and quietly monitors conversations. They may wait weeks for the right closing, invoice, refund, or payroll event. -
Steal a session token
Through adversary-in-the-middle phishing, an attacker can sometimes capture an authenticated browser session after a user completes MFA. The criminal may not need the password again because the stolen token tells Microsoft that the session is already trusted. -
Create urgency
“The closing is at 3 p.m.”
“The vendor needs payment today.”
“Please keep this confidential.”
“I’m in court and cannot take a call.”
This is why email security cannot be reduced to “we have spam filtering.” The question is not only whether a bad message reaches the inbox. It is whether your firm can prevent a believable message from changing the destination of a six-figure payment.

Why Small Professional Firms Are Prime Targets
Predictable. Trust-based. Busy.
That combination is valuable to criminals.
A small law firm may handle trust-account disbursements, settlement proceeds, real estate closings, and client retainers. A medical practice may process claims payments, refunds, payroll, and vendor invoices. An accounting firm may manage client refunds, tax payments, payroll files, and sensitive financial instructions.
These firms also tend to have:
- Lean administrative teams
- Shared responsibilities during busy periods
- Predictable billing and closing calendars
- Employees who know clients and vendors personally
- Limited separation between email, accounting, and payment duties
- Owners or partners who can authorize transactions quickly
An attacker does not need to defeat every security control. They need to find one person who reasonably believes, “Yes, this sounds like something Margaret would send.”
That is the “Hey Margaret!” problem. A familiar name, a familiar tone, and a familiar deadline can bypass skepticism faster than a technical exploit.
The Regulatory, Ethical, and Insurance Exposure
A fraudulent wire is not only a financial loss. It can create questions about whether your firm took reasonable steps to protect client data and funds.
FTC Safeguards and GLBA compliance
For covered financial institutions under the FTC Safeguards Rule, your written information security program should address administrative, technical, and physical safeguards.
That includes a risk assessment, access controls, monitoring, encryption where appropriate, employee training, service-provider oversight, and an incident response plan. The program must also identify a qualified individual responsible for overseeing it.
Not every accounting firm is automatically covered simply because it provides accounting services. Coverage depends on the firm’s activities and regulatory status. However, GLBA compliance obligations, contractual requirements, state laws, and professional standards may still apply.
HIPAA compliance for medical practices
HIPAA does not categorically prohibit email. But medical practices must use reasonable safeguards and avoid unauthorized disclosure of protected health information.
An email account takeover can expose:
- Patient diagnoses and treatment information
- Insurance and claims records
- Social Security numbers and payment information
- Referral documentation
- Communications with business associates
HHS guidance confirms that patients may request unencrypted email after accepting the risks, but that does not make ordinary email handling automatically safe. A practice still needs appropriate access controls, MFA, audit logging, workforce training, and secure transmission methods when the risk warrants them.
If unsecured PHI is breached, the HIPAA Breach Notification Rule may require notification to affected individuals, HHS, and potentially the media.
Law firm cybersecurity and professional duties
For law firms, confidentiality and competence are not optional security goals. They are professional obligations.
The American Bar Association’s cybersecurity guidance connects technology competence with a lawyer’s duty to protect client information. A compromised mailbox may expose privileged communications, settlement details, trust-account records, and confidential business information.
If client information was accessed or reasonably suspected to have been accessed, the firm may need to investigate promptly, communicate appropriately, and help the client make informed decisions.
Cyber insurance requirements
Many cyber insurance policies now require MFA and defined email security controls for relevant accounts. But the exact requirement depends on the policy, insurer, application, endorsements, and security warranty.
Coverage may also distinguish between:
- Social engineering fraud
- Funds transfer fraud
- Crime coverage
- Computer fraud
- Business email compromise
Do not assume a cyber policy will reimburse a fraudulent wire. Review the language before an incident occurs.
Controls That Actually Reduce BEC Risk
Technology helps. Process closes the gap.
Your controls should include:
-
Phishing-resistant MFA where possible
Use FIDO2 security keys or passkeys for high-risk accounts. Number matching is stronger than simple push approval, but SMS should not be your primary protection for sensitive access. -
Conditional access
Restrict sign-ins by device health, location, risk level, application, and user role. Block legacy authentication. -
DMARC, DKIM, and SPF enforcement
Configure these correctly and move DMARC towardp=rejectafter monitoring legitimate senders. This reduces domain spoofing. -
External sender warnings
Make messages from outside your organization visibly different. A warning will not stop every scam, but it creates a useful pause. -
Link and attachment analysis
Use sandboxing or detonation to inspect suspicious files and links before they reach users. -
Mailbox-rule monitoring
Alert on new forwarding rules, hidden inbox rules, suspicious deletions, and unusual sign-in activity. -
Out-of-band payment verification
Any new or changed payment instruction requires a callback to a phone number already on file. Never use the number included in the email. -
Dual approval for high-value transfers
Separate payment preparation from payment approval. Set thresholds appropriate to your firm’s risk. -
Simulated invoice-change training
Employees should practice identifying realistic vendor, client, escrow, refund, and payroll fraud, not generic “click the bad link” exercises.

Internal Controls: Pros and Cons
You may be tempted to handle this internally.
Pros: You retain direct control, avoid a recurring service fee, and can tailor procedures to your firm.
Cons: Internal controls often depend on one or two employees remembering the process every time. Training costs money. Staff turnover creates gaps. Alerts go unreviewed during tax season, trial preparation, month-end close, or a medical practice’s busiest billing cycle.
That is the difference between owning a written policy and operating a managed control environment.
Your accounting firm IT, medical practice IT, or managed IT for law firms program should continuously enforce the policy, not simply explain it after a loss.
If You Think You Have Been Hit
Move immediately. Do not wait for certainty.
-
Contain the account
Disable the suspected account, revoke sessions, reset credentials, remove malicious mailbox rules, and isolate affected endpoints. -
Call the bank immediately
Ask for a wire recall, freeze, or Financial Fraud Kill Chain intervention. The recovery window is measured in hours. -
Preserve evidence
Keep original messages, headers, login alerts, mailbox rules, payment instructions, call records, and transaction details. -
Notify the appropriate parties
Follow your incident response plan, policy requirements, regulatory obligations, and client-notification procedures. -
Engage counsel and your insurer
Counsel can help direct the investigation. Your policy may require prompt notice, approved vendors, or insurer consent. -
Report the crime
File with IC3 and provide complete transaction information. -
Fix the root cause
Do not stop at changing a password. Determine how access occurred, whether tokens were stolen, what data was viewed, and which payment process failed.
Final Word
Business email compromise is not a problem reserved for large corporations. It is particularly dangerous for firms where one email can move client money, disclose sensitive records, or create an ethical and regulatory crisis.
You need more than antivirus. More than a spam filter. More than a policy in a shared folder.
You need layered email security, endpoint security, identity controls, verified payment procedures, documented response plans, and continuous monitoring. You need predictable costs, clear accountability, and evidence that the controls are working.
That is the value of a qualified managed services provider. With the right outsourced IT partner, your firm can combine cybersecurity, IT support for small business, compliance documentation, IT audit readiness, ransomware protection, and business continuity planning into one managed program.
A PC of Mind helps professional services firms make technology a strategic advantage instead of a source of uncertainty. Contact us to discuss a practical BEC protection plan for your firm.