Subnet Blog

Your Clients Trust Your Emails. Cybercriminals Know That.

Written by Ben Luks | 2 September 2026, 03:45:03 Z

A client receives an email from their lawyer. It comes from the correct email address. It appears in an existing conversation about a genuine matter. It references information the client recognises. The writing style seems familiar.

The email asks them to open a document, provide some information or perhaps follow updated payment instructions. Why wouldn't they trust it?

That question illustrates one of the more difficult cybersecurity challenges facing law firms. Email isn't simply another communication tool. It sits at the centre of the relationship between lawyers and their clients.

And if a cybercriminal can compromise that trusted communication channel, they may be able to exploit something far more valuable than an email account. They can exploit the trust the firm has already built with its clients.

The Most Convincing Fake Email Might Not Be Fake

Most people know what a stereotypical phishing email looks like. An unfamiliar sender. A suspicious link. Strange wording. An unexpected attachment. Those warning signs still matter. But consider a different scenario.

An attacker gains access to a lawyer's genuine Microsoft 365 account. They may now have visibility into previous correspondence, active conversations, contacts and potentially information about matters the lawyer is working on.

Instead of creating a fraudulent email from scratch, the attacker may be able to wait for the right opportunity and insert themselves into a legitimate conversation. The email address is genuine. The client relationship is genuine. The matter being discussed is genuine. Only the instruction is fraudulent.

Our previous article on cyber resilience in professional services highlighted this particular problem: when an attacker compromises a legitimate account, they can potentially inherit the credibility associated with that person's established relationships. For a law firm, where clients routinely exchange confidential and financially sensitive information with people they trust, that distinction matters.

Why Law Firms Present an Attractive Opportunity

Think about the information flowing through a typical legal mailbox.

  • Contracts.

  • Property information.

  • Personal identification.

  • Commercial negotiations.

  • Confidential correspondence.

  • Financial information.

  • Documents relating to disputes, transactions and settlements.

  • And, importantly, conversations involving people who may need to act quickly on instructions.

A cybercriminal doesn't necessarily need access to every system within a firm to cause significant harm. Access to the right mailbox at the right moment may be enough. That can create several potential scenarios.

Changing Payment Instructions

A client is expecting to make a payment as part of a legitimate transaction. An attacker who has been observing the email conversation waits until the appropriate moment before sending updated banking details.

Because the message comes from an account the client already trusts — and relates to a transaction they already expect — there may be little reason for the client to question it.

Impersonating Someone Senior

Attackers may also exploit hierarchy and urgency. An email appearing to come from a partner or senior lawyer could request that an employee urgently send information, approve something or deviate from a normal process. The more familiar the sender and context appear, the more convincing the request becomes.

Requesting Confidential Documents

Not every attack needs to involve money. An attacker could potentially use a compromised account to request sensitive documents or information from a client, colleague or external party. Again, the request becomes considerably more convincing when it appears within an established relationship.

Using a Real Matter as the Bait

Traditional phishing often requires an attacker to invent a plausible story. A compromised mailbox can potentially remove that problem. If an attacker understands that a particular transaction, dispute or matter is underway, the matter itself can become the pretext for the attack.

That is why compromised email can be so difficult to identify. The attacker doesn't necessarily need to manufacture trust. They may be able to borrow yours.

The Risk Goes Beyond Financial Loss

The obvious consequence of email compromise is financial. A fraudulent payment instruction can result in money being transferred to an attacker. But for law firms, the impact can extend considerably further.

What happens if confidential client information is exposed? What happens if an attacker sends fraudulent instructions from a lawyer's genuine account? What happens when a client discovers that a message they had every reason to trust was malicious?

Suddenly, an IT security incident becomes a client relationship issue, operational issue and reputational issue. There may also be questions about what information was accessed, how long the account was compromised, who needs to be informed and whether other clients or matters have been affected.

This is why email security cannot be treated purely as a spam-filtering problem. As we discussed in our broader guide to technology risk in law firms, email security is increasingly a business-critical control around a communication channel clients inherently trust. The existing Legal material also highlights protections around impersonation, payment instructions and email authentication as important areas for firms to review.

MFA Matters — But It Isn't the Entire Strategy

Multi-factor authentication remains an important security control. But firms should be careful about thinking of MFA as the finish line. Modern identity security requires several layers working together. That can include:

  • strong MFA and appropriate authentication policies;
  • monitoring for unusual sign-ins and account behaviour;
  • conditional access policies;
  • appropriate management of privileged accounts;
  • controls around suspicious mailbox rules and forwarding;
  • endpoint security;
  • email authentication and domain protection; and
  • processes for rapidly disabling or containing a compromised identity.

The objective is not simply to make an account harder to compromise. It is also to improve the firm's ability to identify unusual behaviour quickly if an account does become compromised.

Because the longer an attacker can remain inside a trusted account unnoticed, the more opportunity they potentially have to understand how the lawyer — and their clients — communicate.

Some Instructions Should Never Be Trusted on Email Alone

Technology controls are only part of the answer. There are certain requests where the safest response may be to deliberately introduce friction. A change to banking details is an obvious example.

If a client or staff member receives new payment instructions, firms can establish a process requiring those details to be independently verified using a known contact method — rather than replying to the same email or relying on contact information contained within it.

Similar processes may be appropriate for particularly sensitive document requests or unusual instructions. Yes, that adds another step. But that friction exists for a reason. The aim isn't to make every email difficult to action. It is to identify the small number of high-consequence actions where email alone should not be considered sufficient verification.

Staff Need to Recognise Context, Not Just Bad Spelling

Security awareness also needs to evolve with the threat. Telling people not to click suspicious links is useful, but it doesn't fully prepare them for a message that comes from someone they know.

A more practical approach is to teach people to recognise unusual behaviour and context. Why is this person asking me to do this? Is this how we normally change payment details? Why does this need to happen urgently? Should this person normally have access to this information? Is there another way I can verify the request?

That kind of judgement is particularly important in professional environments. The warning sign may not be an obviously fraudulent email address. It may simply be a legitimate person apparently asking for something they would not normally request.

Protecting Email Means Protecting Client Trust

There is an uncomfortable reality behind all of this. Law firms spend years establishing trusted relationships with their clients. A cybercriminal may only need access to one account to take advantage of that relationship.

That makes email security about much more than protecting inboxes. It means protecting identities. Monitoring for unusual behaviour. Making impersonation more difficult. Establishing verification processes around high-risk instructions. Preparing staff for attacks that use genuine context. And having a clear response plan if an account is compromised.

None of these measures will eliminate every risk. But together, they make it considerably harder for an attacker to turn a trusted communication channel into an attack vector.

One Question Worth Asking

There is a useful exercise law firm leaders and IT teams can conduct. Consider a client receiving an email tomorrow from the genuine account of one of your lawyers. The email relates to a real matter and contains a plausible but fraudulent instruction. What would stop the client — or someone within your firm — from acting on it?

If the answer relies entirely on somebody noticing that the email “looks suspicious”, there may be an opportunity to strengthen the process. Because in a modern email compromise, the message may not look suspicious at all.

It may look exactly like something the client has learned to trust. And that's precisely what makes it valuable to an attacker.