BLOG ARTICLE
There is an alarming increase in cyber-attacks on law firms, globally. Learn the importance of taking proactive measures to protect both your firm and your clients.
Cybercriminals, having recognized the vulnerability of clients who rely on legal services, are increasingly targeting law firms — leading to a surge in impersonation cases around the world.
Impersonating a law firm involves creating a fake identity that looks just like an established, reputable legal practice. Cybercriminals use various and sophisticated tactics, such as spoofing email addresses, forging official documents, and setting up fake websites to convince their targets of their legitimacy. Some common methods include:
In November 2022, researchers identified a new BEC group named ‘Crimson Kingsnake’ who has impersonated several highly-respected international law firms — including Allen & Overy, Kirkland & Ellis and Deloitte — to trick recipients into approving overdue invoice payments.
Analysts at Abnormal Security, who first discovered Crimson Kingsnake activity in March 2022, report having identified 92 domains linked to the threat actor, all similar to genuine law firm sites.
The consequences of falling victim to law firm impersonation can be far-reaching. Some examples include:
Educate your teams and your clients. Train employees and clients to recognize the signs of impersonation attempts, including suspicious emails, websites, and phone calls. Encourage them to verify any communication or payment requests. Educate staff members on cybersecurity best practices and the dangers of phishing attempts.
Consider moving sensitive conversations to a secure portal. Email communication is an important tool for business but is an attack surface that is easy to exploit. Using a secure channel to communicate sensitive information can be useful.
Implement DMARC (you can test your current protection here). DMARC will verify the source of an email message and decide what to do with it. It’s an additional security check to ensure that only legitimate emails are sent from your domain, while you have full visibility on senders, too. This means you are able to see details like source countries, authorized vs unauthorized domains and more.
Regularly assess your cybersecurity. Conduct regular assessments of your law firm’s IT infrastructure to identify and address vulnerabilities. Implement robust security measures, including strong passwords and regular software updates.
Add two-Factor authentication. Two-factor authentication adds an extra layer of security to the login process, protecting the account even if the password is compromised.
Regularly audit your environment for suspicious logins. Most modern email platforms allow you to understand where the IP addresses of users that are logging into their systems are geo-located. This information can be very useful in identifying potential malicious actors – after all, if all your users are based in South Africa, for example, you shouldn’t be seeing logins from Iran or the United States or any other region for that matter.
The impersonation of law firms is a growing threat that can have severe consequences for individuals and businesses alike. By understanding the methods used by cybercriminals and implementing preventive measures, we can minimize the risks associated with law firm impersonation. Using a platform like Sendmarc gives you full visibility into your email sending environment so that you can actively defend and protect your domains – — and your clients.
DMARC requires continuous monitoring and updating to ensure maximum compliance and deliverability. Contact us to learn more about how we can help you achieve the highest and safest states of email security.
LATEST ARTICLES
Why SSO Is Essential for the Modern Business
Understanding DMARC policies – p=none, p=quarantine, p=reject
Protect Against Holiday Cybersecurity Threats