It’s a gray Tuesday afternoon in Red Bank, New Jersey, inside a small law firm just off Broad Street, where the carpet shows its age and the coffee machine hums out of habit. Five attorneys work behind half-closed doors. An office manager remembers carbon paper. And Marianne, a senior paralegal who has outlasted most of the furniture, moves through the office with the quiet confidence of routine. At precisely 3:14 p.m., she opens an email from a title attorney the firm has trusted for years. The tone is familiar, the wording reassuring. The subject line—“Updated Wire Instructions – Please Confirm”—asks for nothing unusual. Marianne exhales, replies, and moves on.
What Marianne doesn’t know is that the email isn’t coming from the title attorney at all. Days earlier, the title attorney’s mailbox was compromised, quietly and without disruption. An attacker slipped into the middle of an active conversation, reading prior messages, learning the cadence, and waiting. When the moment was right, they replied on the attorney’s behalf, requesting a subtle change to the wire instructions. No spelling errors. No urgency that felt out of place. Just a calm, professional request that looked exactly like the dozens Marianne had seen before.
Over the next day and a half, the exchange continues. The wire instructions change—just slightly—redirecting funds to a Chase Bank account, explained as a temporary processing issue. It sounds reasonable because it’s engineered to. Marianne prints the email and walks it to Robert’s office. Robert, the managing partner, has trusted Marianne’s judgment for more than twenty years. She explains the change—she always does—and he nods, approving it without concern. No one picks up the phone. No one independently confirms the change with the title agency. At 10:02 a.m. the next morning, a six-figure wire leaves the firm’s trust account and vanishes.
The call comes after lunch. The real title attorney asks when the funds will be sent—because nothing has arrived. The office grows quiet. Chase confirms the transfer but can’t reverse it. By the end of the day, the truth is unavoidable: the money is gone, divided and moved within hours. There was no malware, no locked screens, no breach of the firm’s internal systems. The failure lived entirely in process—specifically, the absence of a second verification step when money was involved.
What follows is a realization more sobering than the loss itself. This wasn’t a sophisticated technical attack; it was a patient manipulation of trust. A simple phone call to confirm the change would have stopped it. A policy requiring out‑of‑band verification for wire changes would have stopped it. Scenarios like this are no longer rare—they are quietly repeating themselves in law firms every day. Rekall Technologies helps law firms identify these exact gaps and put safeguards in place before an ordinary email becomes a six‑figure lesson that can’t be undone.
Frequently Asked Questions
What is Business Email Compromise (BEC)?
BEC is a targeted scam where attackers impersonate a trusted contact — usually via spoofed email, compromised mailbox, or lookalike domain — to trick someone into wiring money or sharing sensitive data.
How common is BEC for law firms?
Law firms are among the highest-risk targets because they routinely handle large client trust accounts and real estate closings. FBI IC3 data shows BEC losses exceed 2.9 billion dollars annually across all industries, with legal a major share.
What’s the average loss from a BEC attack?
Reported BEC losses average around 125,000 dollars per incident, but real estate and legal-sector wire fraud cases regularly exceed 500,000 dollars.
Does cyber insurance cover BEC?
Many policies now exclude social engineering or require a specific ‘fraudulent funds transfer’ endorsement. Read your policy carefully — coverage is often capped at 100,000 to 250,000 dollars.
Can MFA prevent BEC?
MFA on email blocks most account-takeover attacks, which is one of the three main BEC paths. But it doesn’t stop lookalike domain attacks or compromised vendor inboxes — defense in depth is required.
What should a firm do immediately after suspected BEC?
Contact your bank within 24 to 72 hours to attempt fund reversal, file an FBI IC3 report, preserve email evidence (don’t delete), notify cyber insurance, engage forensic IT, and reset all related credentials.
