4 Phishing Tactics That Dupe the Legal Profession
Hackers are studying lawyers' practice areas, social media presence and their firm's hierarchies to craft subtle but destructive phishing schemes, cybersecurity experts say.
August 21, 2019 at 03:41 PM
4 minute read
The original version of this story was published on Legal Tech News
Phishing attacks are prevalent in all industries, and the legal profession is no different.
However, unlike other industries, lawyers possess a plethora of information regarding their clients that makes attorneys an attractive target for hackers. Likewise, hackers are studying their lawyer targets to understand how to craft an attachment file or link that is just too compelling or too run-of-the-mill for a lawyer to ignore.
The list below highlights some of the legal industry-specific phishing tactics hackers are leveraging to gain access into lawyers' sensitive data files.
Accessing the cloud
Last week, managed detection and response company eSentire Inc., in collaboration with the International Legal Technology Association, released the "Threat Intelligence Spotlight: Legal Industry" report that tackled "phishing lures" specific to the legal industry.
The report found phishing schemes regarding Adobe's cloud service are unique to the legal industry because of lawyer's heavy reliance on PDFs.
ESentire data visualization leader Keegan Keplinger explained hackers leverage attorneys' Adobe account by sending an email notifying lawyers of an update that requires their Adobe log-in credentials. Unbeknownst to the lawyers, they've submitted their password and username into a fraudulent site, and now a hacker has access to their data stored on the Adobe cloud service.
Faking credit card inquiries
ESentire's report also highlighted American Express phishing scams are also found more commonly in the legal profession.
Moreover, lawyers and law firms are more susceptible to this phishing scheme because lawyers are usually thought of as high-income earners or work for a firm that has a credit card, said eSentire vice president and industry security strategist Mark Sangster.
Generally, someone will send a fake AMEX payment confirmation request to a lawyer or law firm and obtain access to their credit card accounts, Sangster explained.
Exploiting law firms' hierarchy
Not all phishing attacks are tech exhaustive. Instead, someone can impersonate a high-ranking partner and email an administrative-level staffer and make a demand. Their email isn't vetted for authenticity because the staffer hopes to appease a high-ranking employee, said Joshua Crumbaugh, CEO of cybersecurity company PeopleSec.
"Law firms are some of the worst at hierarchy, and some of my experiences has been with information technology and any support staff that has a subordinate role and they tend to be very afraid to ask questions of partners in the firm," Crumbaugh said. "This is unique to law firms. In general they've got to empower their lower-level and support staff to be confident with asking those questions and saying, 'No, that's not part of the policy.' "
Spear phishing
To be sure, law firm websites' bios and social media are good tools for obtaining clients and networking, but they also provide hackers with information to make a convincing phishing email tailored to a lawyer's interests, said cybersecurity experts.
That type of spear phishing could come as an email about news affecting his practice group or other interests.
The tailored communications are an attempt to "try to put something in that email that would get them to click the link or attachment," said Adam Levin, chairman of CyberScout, an identity and data protection company. While the content may appear innocent, the lawyer has clicked a link or downloaded a file that contains malware that infects the firm's systems.
Additionally, someone can send a realistic demand or request tailored to a current client's legal matter. Stoked by the rush to help their client, lawyers may unsuspectingly transfer cash or sensitive data to a hacker, Crumbaugh added.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllThe Right Amount?: Federal Judge Weighs $1.8M Attorney Fee Request with Strip Club's $15K Award
Kline & Specter and Bosworth Resolve Post-Settlement Fighting Ahead of Courtroom Showdown
6 minute read12-Partner Team 'Surprises' Atlanta Firm’s Leaders With Exit to Launch New Reed Smith Office
4 minute readMorgan Lewis Shutters Shenzhen Office Less Than Two Years After Launch
Trending Stories
- 1Perkins Coie Lures Former Longtime Wilson Sonsini Tech Transactions Partner
- 2‘The Decision Will Help Others’: NJ Supreme Court Reverses Appellate Div. in OPRA Claim Over Body-Worn Camera Footage
- 3MoFo Associate Sees a Familiar Face During Her First Appellate Argument: Justice Breyer
- 4Antitrust in Trump 2.0: Expect Gap Filling from State Attorneys General
- 5People in the News—Jan. 22, 2025—Knox McLaughlin, Saxton & Stump
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250