Law Firms Remain Vulnerable to Wire Transfer Scams, as Liability and Breach Costs Grow
A lawsuit against Holland & Knight alleging the firm didn't do enough to prevent a wire transfer scam echoes a similar case involving Dentons.
July 28, 2020 at 02:08 PM
5 minute read
The original version of this story was published on The American Lawyer
The most striking thing about the recent cyber scam lawsuit filed against Holland & Knight—which alleges that the firm mistakenly sent $3 million to a fraudulent account in Hong Kong—may lie not in the dollar figure, but the frequency of similar alleged attacks against firms.
"These attacks are super common," said Lewis Brisbois Bisgaard & Smith data security partner Christopher Ballod about wire transfer scams. "The number is big, but I will tell you I have a few cases that are above [$1 million transferred] right now. Above a million is uncommon, but I wouldn't even categorize it as rare."
Law firms are at an even greater risk of cybersecurity liability this year, with scores of law firm employees working from home as well as data-related regulatory laws and subsequent enforcement actions both trending upward.
Ballod, who advises companies and law firms that have suffered data breaches, said he's already seen a massive uptick in breaches, involving wire transfers and other types of cyber fraud.
"We're extremely busy," Ballod said. "There's a simple principle at play: If you broaden the attack surfaces, you'll have more attacks at play," he added, referring to the increased risk from more network entry points.
According to the recent lawsuit against Holland & Knight, the law firm was hired to oversee a $3 million stock sale. But amid the deal, scammers intercepted emails between the firm and plaintiffs. They then assumed the plaintiff's identity and asked that the wire be sent to an account based in Hong Kong instead of the original account.
The plaintiffs, the Sorenson Impact Foundation and the James Lee Sorenson Family Foundation, allege that Holland & Knight did not call to verify the account change, nor did they secure a medallion guarantee—a guarantee from a financial institution—as put forth in the merger agreement between the firm and involved parties. For that, the plaintiffs are alleging breach of contract and negligence and that the firm breached its fiduciary duties.
In a previous a statement on the lawsuit, Holland & Knight spokeswoman Olivia Hoch said the firm's "information technology system was not compromised in any way." She added that the plaintiffs were not clients, and "the firm acted on wiring instructions received from the plaintiff's email system by providing the instructions to the paying agent."
The allegations are eerily similar to a case involving Dentons' Canadian arm in 2017. According to a court ruling in that case, Dentons mistakenly sent $2.5 million to a fraudulent Hong Kong-based account after scammers breached emailed communications and assumed the identity of the company receiving the money.
Behind the assumed identity, scammers told the firm that their original account was being audited and directed Dentons to send the money to a new, Hong Kong-based account.
In that case, Dentons called the recipient to confirm the account change but didn't get through and left a voicemail. The scammers then forged documents and authorisation letters and sent them to the firm. Although they never got a call back from the real recipients, the firm sent the money anyways.
In a previous statement on the case, Dentons Canada spokeswoman Neetisha Seenundun said that the firm has not been targeted by the phishing scheme at any other point, and that the firm provides "extensive training" to its lawyers and employees on cybersecurity issues.
In wire transfer scam cases, the bad actors leverage what cybersecurity experts call the "human firewall" by manipulating employees and lawyers to hand over their credentials. These sorts of vulnerabilities circumvent technology by targeting employees who, for one reason or another, let their guard down or forgot their training.
Many scams could likely be avoided if a lawyer calls to verify over the phone the transfer information, as is best practice, Ballod said. While working from home may increase general cybersecurity liability, attacks like a wire transfer scheme can happen regardless of whether an employee is at home or in the office, cybersecurity experts add.
Total Costs
Looking at cybersecurity liability in general, security firm LogicForce found last year that, despite recent strides, the legal industry "remains very vulnerable to cybersecurity attacks." Less than the majority of law firms surveyed implement advanced data protection techniques such as multifactor authentication or full disk encryption on all devices, its 2019 report found. Only about half of the companies surveyed have an executive-level IT specialist.
The litigation costs resulting from a cybersecurity lapse can be substantial. In cases of wire fraud where multiple parties are at some fault—a law firm for not calling for verification and the intended recipient's email security measures being breached—both sides usually come to a compromise before litigation.
In other cases, failure to contain a breach can lead to class action lawsuits, unaffordable legal malpractice premiums or harm to the firm's reputation.
With the rise of data privacy laws in Europe and the U.S., potential liability now increasingly includes regulatory and compliance litigation, said David Shonka, a data privacy partner at Washington, D.C., firm Redgrave. The California Consumer Privacy Act, or CCPA, began enforcement July 1. The law lays out breach reporting requirements, noncompliance fines and allows California consumers a way to bring private actions for data breaches.
Europe has long had its own privacy laws. Brazil and India have also passed similar versions as well. And Shonka said there's indications that more states will adopt similar laws.
Read More
Holland & Knight Sued Over Botched Wire Transfer
Dentons Lawyer Wired $2.5 Million to Scam Bank Account in Elaborate Con
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllUK Sanctions Regime Put to the Test as Supreme Court Hears First ‘De-Designation’ Case Brought by Billionaire
Paul Weiss Says Progress Means 'Embracing the Uncomfortable Reality'
5 minute readLaw Firms Mentioned
Trending Stories
- 1'A Death Sentence for TikTok'?: Litigators and Experts Weigh Impact of Potential Ban on Creators and Data Privacy
- 2Bribery Case Against Former Lt. Gov. Brian Benjamin Is Dropped
- 3‘Extremely Disturbing’: AI Firms Face Class Action by ‘Taskers’ Exposed to Traumatic Content
- 4State Appeals Court Revives BraunHagey Lawsuit Alleging $4.2M Unlawful Wire to China
- 5Invoking Trump, AG Bonta Reminds Lawyers of Duties to Noncitizens in Plea Dealing
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250