Risk Management Alert: Threat actors accessing email accounts

The Law Society of Scotland has issued a fraud alert to warn of recent successful cyber attacks on law firm email accounts: see Fraud alert: Attackers access solicitor mailboxes (opens a new window).

A number of firms have recently been targeted by threat actors who have gained access to email accounts and have sent fraudulent emails to firm contacts. As the emails came from genuine accounts, they did not bear any of the telltale signs of a phishing attack; for example slight differences in the sender’s email address, making them much harder to spot.

Threat actors use successful infiltration of accounts in several ways, including sending emails with attachments or links that, if clicked on, will take the recipient to a site that can steal their credentials. Once they have infiltrated an email account, fraudsters can also identify when payments are due to be made and divert funds by sending alternative payment details.

The Law Society has highlighted the need to be vigilant and to ensure that all staff are aware of the risk of a potential cyber attack. If in doubt, do not click on links. Never accept bank details solely by email and always verify them by making contact with the sender another way. Ensure regular training for all staff on phishing and other cyber threats. It is also important to make sure your clients are aware of the risks. A sensible safeguard is to explain to clients that you will never send them bank details for payment by email, and that they should assume any such email is fraudulent.

The Law Society has an excellent Cybersecurity guide (opens a new window) with practical information and signposting to helpful resources.

At Lockton we have also produced a number of training resources to help firms combat the threat from cyber attacks. We have developed a course of three interactive e-modules covering phishing, social engineering, and online security. We also have a module focusing on payment fraud. Each module is free to access for all Scottish Law firms and provides 30 minutes of CPD:

Free interactive phishing e-learning modules (opens a new window).

Payment fraud e-learning module (opens a new window)

Finally, see our comprehensive resources on cyber risk: How to navigate cyber risks (opens a new window).

For more information on the information in this risk management alert, contact Matthew Thomson at matthew.thomson@lockton.com (opens a new window) or Anna Forsyth at anna.forsyth@lockton.com (opens a new window).