A Philadelphia story
The Tuesday the trust account almost left the building
the managing partner of a 14-lawyer firm on Market Street in Center City
It is the last Tuesday of the month and the firm's bookkeeper has a $640,000 settlement to wire out of the trust account by 4 p.m. The instructions came in that morning from opposing counsel, in the same email thread the two firms have used since March. The managing partner is in a deposition in Conshohocken and is not picking up.
Three weeks earlier the partner typed his email password into a page that looked like the court's e-filing portal. Nobody noticed, because nothing changed. Somebody in another time zone read his mail each night, learned the matter, learned the tone, and registered a domain one letter off from opposing counsel's. Then they waited for the settlement.
The bookkeeper prints the instructions and opens the bank portal. The beneficiary bank is in Texas, which is new, but the email explains that the client's firm changed banks. The amount is right. The matter number is right. It is 3:48 p.m.
Her finger is on the approve button when she decides to call opposing counsel at the number on the original engagement letter, and the receptionist tells her nobody there has sent new wire instructions.
What changes the ending
- Multi-factor authentication on each mailbox, so a stolen password alone does not hand the partner's inbox to a stranger (CIS 6 Access Control Management)
- Mail filtering that flags lookalike domains, and a firm rule that no wire instruction is accepted by email alone (CIS 9 Email and Web Browser Protections)
- Staff trained on the exact con, wire-change fraud, and thanked for the callback that costs two minutes (CIS 14 Security Awareness and Skills Training)