Fraudulent bank calls to law firms – how to protect yourself

Fraudulent bank calls to law firmsFraudulent bank calls to law firms have increased in recent months. It’s not a new phenomenon but it is one of a variety of methods criminals are using successfully.

In my previous article on global ransomware attacks, I gave a few pointers about how to protect your practice. For this subject, protecting yourself is much more down-to-earth. So how does the scam operate? Firstly, you need to understand the criminal slang – phishing, vishing, smishing and spoofing.


This is when you receive a fraudulent email alerting you to a problem. Generally, the email looks genuine and may lead you to a website that looks exactly like your bank’s website. You can check out the validity of the email in several ways. Hover your mouse over the link and URL details. This allows you to determine if it is genuine by showing you the real link or the fraudulent one. Open up a new web page in your browser and go to the website via that route or directly contact the sender. However, do not use the contact details or links provided in the email. If in any doubt, just don’t click on the link.


Vishing or voice-phishing, occurs when you receive a telephone call from someone purporting to be from your bank. The aim is to obtain confidential details, passwords or to convince you to make a monetary transfer.

In many instances the criminals claim to be from your bank’s Fraud department. They may tell you there is a problem with your account and ask you to confirm some payments. In most instances, the calls sound completely genuine. The caller usually has details about you, your business address, bank details and even the names of colleagues. The intent of the call is to create fear in your mind and to get you to act quickly to prevent financial loss.


Smishing, or SMS-phishing is the mobile phone equivalent of vishing. The criminals use it less against law firms, but it does happen. Again, the method encourages you to ring a number or follow a link for further details. This will then request password and account information.


This is where it gets really tricky. In essence, the criminals imitate genuine telephone numbers or email addresses to gain your confidence. You will see a telephone number that you recognise as being your bank in your caller display. For email, you could receive one that seems to come from someone senior in the business requesting payments to be made.

How to protect your firm.

1. Ensure your team knows how to defend against a phone scam.

  • Never give out banking passwords or security codes to anyone on the phone even if you believe you are talking to the bank.
  • Do not trust your phone’s caller display to identify a caller accurately.
  • Check callers by phoning the bank yourself using the known number.
  • Remember that the bank will never call you to ask you to transfer money to a so-called safe account.
  • Remember that the bank will never ask you for banking passwords, user numbers or other sensitive information.

2. Ensure your team knows how to defend against an email scam.

  • Provide a documented process for all employees to follow.
  • This should ensure email requests to set up or amend payment details are verified as genuine.
  • Use known contact details other than email to make these checks and apply the same rigour to both internal and external emails.
  • Consider how you communicate with individual clients who are sending funds, so that clients can be sure that they are sending their money to the correct account.
  • Consider encrypting emails and providing clear, initial instructions about how payment details will be provided or amended.
  • Payment methods and bank account details should be agreed at the outset of transactions.

And finally, protect all PCs with quality anti-virus software and ensure it is updated regularly. Upgrade all operating systems and software to the latest versions the minute they become available.

Conveyancing firms: beware the Friday rush!

Fraudulent bank calls to law firms affect the whole industry. However, conveyancing firms are being singled out as key targets. These firms are always very busy on Fridays and particularly before bank holidays. Clients wish to complete before the weekend and legal staff come under immense pressure. The fraudsters are aware of this.

Targeting conveyancing firms on these particular days can catch stressed people when they are distracted or off-guard. Not only the financial damage but also the firms’ reputations can be seriously damaged.

As another bank holiday approaches, it is worthwhile reminding all conveyancing employees of the threat.

The Law Society of Scotland recently published a series of short alerts on this subject which you can read by clicking this link. In addition, if you believe you have discovered an attempted fraud or have fallen victim to one, report the details immediately to the authorities on The Action Fraud Website.

Mike O’Donnell, May 2017.

Global ransomware attacks: how can you protect your law firm?


© LawWare Limited 1995-2019


Join over 450 law firms across the United Kingdom.

Our clients range from small start-up legal practices to multi-partner, multi-site firms.

Another great customer service experience from LawWare. My laptop had to be stripped back to factory settings as part of a repair - taking hours! In contrast, restoring LawWare took one phone call to the support team and I was up and running in 6 minutes. If only everything was so easy!

VI pensions Law Ltd.
Vanessa Ingram

As the first commercial user of LawWare back in 1998, we have had no hesitation in remaining with the product through its development. We thoroughly recommend it to any firm looking for a practice management system.

Alastair Hart & Co.
Alastair Hart

The helpdesk is exceptionally good. Whatever the query there is always a human being there to help. No leaving messages or being advised to go to a website. The best computer service for solicitors I have ever used!

South Forrest
Irene Yule

The linking of documents and casefiles saves so much time! I have experience of several accounts packages and I like that LawWare is simple to use and easy to learn. Support is quick and effective and staff are helpful and courteous.

Sprang Terras
Fiona Allison

I have worked with a number of Case Management providers over the years but have not come across anything with the attention to detail and thoroughness of LawWare. My colleagues and I have not been disappointed.

Brymer legal Ltd.
Professor Stewart Brymer

I can’t imagine trying to be a law firm in the 21st Century without 21st Century IT systems. Having a ‘single system’ that underpins all the work, whether we are in the office or out, is an integral part of what we are building.

Sneddon Morrison
Eric Lumsden

The level of support is the main benefit using this system.  The system itself once you have had training is simple and easy to use. We have a great relationship with LawWare and the ongoing support is second to none.      

Linda George Family Law
Sharon Rodger

Significant preparation was required to configure and import the data from our old firm. We had to get all clients onto the new system and then learn how to use it. We just find it very easy to use, much easier than our old system.

Scanlon Ewing
Maureen Ewing

Being a busy litigator with a growing firm it is incredibly useful to be able to view my files from any location with some form of internet connection. I am a fan, and want to keep working with LawWare to make a good product great.

Helix Law Limited
Jonathan Waters

The switch to the new LawCloud system, which is still on-going, has gone very well. We found the LawWare team without exception to be very helpful and knowledgeable. All queries are followed up and dealt with promptly.

Cullen Kilshaw
Ross Kilshaw

interested in

Explore LawWare

Connect With Us