In this blog

phishing attacks law firms

Why Law Firms Are Prime Targets for Phishing Attacks

A law firm’s inbox holds things few other businesses ever touch in one place: privileged client communications, unfiled merger details, litigation strategy, trust account information, and personal records spanning years or decades. That concentration of sensitive, high-value information is exactly why the legal sector has become one of the industries attackers target most persistently, and why a single successful phishing email at a law firm can trigger consequences far beyond the immediate financial loss.

This guide covers how common phishing attacks against law firms actually are, why the sector is such an attractive target, a real incident that illustrates the pattern, and what firms can do to reduce the risk.

In Short: Law firms are targeted heavily because they combine highly sensitive, high-value data with historically under-resourced security programs. Nearly 40 percent of law firms reported a breach in the past year, and more than half of those breaches exposed client data.

How Common Are Phishing Attacks on Law Firms

The scale of the problem is significant and growing. According to DeepStrike’s compilation of law firm breach statistics , drawing on an American Bar Association survey, roughly one in three law firms has experienced at least one breach, with about 39 percent reporting a breach within the past year alone. Among firms that were breached, more than half saw client data exposed. The same analysis cites FBI Internet Crime Complaint Center data showing over 193,000 phishing complaints reported in a single recent year, alongside business email compromise losses reaching 2.8 billion dollars across all sectors.

Separately, other industry research has put average law firm breach costs above 5 million dollars per incident, reflecting not just direct remediation costs but the cascading legal, regulatory, and reputational consequences unique to firms handling privileged information.

Why Law Firms Are Such an Attractive Target

A few structural factors make law firms a disproportionately attractive target compared to many other industries of similar size.

They concentrate extremely high-value information in one place. Merger and acquisition details, litigation strategy, trust account access, and privileged client communications are all things attackers can monetize directly or use for further extortion.

Attorney-client privilege raises the stakes of any breach. A breach at a law firm does not just expose data. It can compromise privilege itself, creating legal exposure for both the firm and its clients that a typical corporate data breach does not carry.

Security investment has historically lagged the value of what firms protect. According to Bristol Law Society’s analysis of legal sector cyberattacks , nearly 75 percent of breaches in the sector involve human action, whether accidental or deliberate, and only around a quarter of firms surveyed believed they were well prepared to respond to an incident.

The billable-hour culture creates natural urgency attackers exploit. Attorneys and staff operate under constant deadline pressure, which is exactly the emotional state phishing and pretexting attempts are designed to exploit.

Wire transfers are routine, not exceptional. Real estate closings, settlement payments, and trust account transfers make law firms a natural target for business email compromise schemes specifically built around redirecting a wire transfer.

A Real Example: The Utah State Bar Impersonation

Law firms are not just targeted through generic phishing. Attackers increasingly impersonate the exact institutions the legal profession trusts most. In June 2025, a threat actor reportedly spoofed emails appearing to come from the Utah State Bar’s own communications director, urging hundreds of attorneys and law firms to “update credentials” through what appeared to be an official bar communication. The emails led to fake login pages designed to harvest passwords and other sensitive information, exploiting the built-in trust attorneys place in communications from their state bar.

This pattern illustrates a broader trend worth understanding: attackers increasingly research and impersonate the specific institutions and relationships a target actually trusts, rather than relying on generic corporate impersonation. A law firm employee who would never fall for a generic phishing email may respond very differently to something appearing to come from their state bar association, a familiar opposing counsel, or a longtime client.

What This Means for Firms of Every Size

Smaller and mid-sized firms are not protected by their size. If anything, they are often more exposed, since they are less likely to have dedicated security staff while still handling the same category of sensitive client information as larger practices. A few practical implications follow:

Wire transfer requests need mandatory out-of-band verification, regardless of how legitimate the request appears or who it claims to come from, given how frequently business email compromise targets exactly this workflow at law firms.

Institutional impersonation deserves specific attention in training, not just generic phishing awareness, since attackers are increasingly spoofing bar associations, courts, and other trusted legal institutions rather than generic corporate brands.

Document-sharing platforms need scrutiny. Attackers have specifically targeted the SharePoint and OneDrive workflows common in legal document exchange, since a convincing fake document-sharing notification blends naturally into a lawyer’s daily routine.

Cyber insurance coverage needs a careful review. Legal professional liability policies frequently do not adequately cover cyber losses, leaving a gap firms may not discover until after an incident. Our guide on phishing simulation and cyber insurance covers how documented testing data increasingly factors into underwriting decisions.

Building a Realistic Testing Program

Given how frequently attackers impersonate institutions specific to the legal profession, generic phishing templates alone are unlikely to reflect the real risk a firm faces. Running a phishing test for employees using scenarios tailored to legal-specific pretexts, a fake bar communication, a spoofed opposing counsel email, a fraudulent wire instruction, gives a far more accurate picture of readiness than a generic corporate template. Partners, associates, and paralegals handling trust accounts or client communications directly are natural candidates for the kind of targeted testing covered in our guide on whaling attacks and why executives need different phishing training , since the same concentration-of-authority risk applies to senior partners and trust account signatories.

Tracking results over successive campaigns through an employee phishing risk score also helps firms identify whether risk concentrates in specific practice groups or roles, information that is far more actionable than a single firm-wide click rate. Employees who recognize a generic phishing lure but fall for a spoofed bar association email should also review our guide on how to spot a fake login page in 10 seconds , since many of these institutional-impersonation attempts end in exactly this kind of credential-harvesting page.

Final Thoughts

Law firms sit at an uncomfortable intersection: they hold some of the most sensitive, high-value information any organization handles, while historically investing less in security than the value of that data would suggest. Attackers have noticed. As impersonation tactics grow more specific to the institutions and relationships the legal profession actually trusts, generic phishing awareness is no longer enough. Firms that test against realistic, legal-specific scenarios, and treat wire transfer verification as non-negotiable, are in a meaningfully stronger position than those relying on awareness training built for a different industry entirely.

FAQ

Why are law firms targeted by phishing attacks so often?

Law firms concentrate highly sensitive, high-value information, including privileged client communications, financial transaction details, and personal records, while historically investing less in security relative to other industries handling comparable data, making them an attractive and often under-defended target.

How common are data breaches at law firms?

Recent industry research indicates that roughly one in three law firms has experienced at least one breach, with close to 40 percent reporting a breach within the past year, and more than half of breached firms losing client data.

What makes law firms different from other phishing targets?

Attackers increasingly impersonate institutions specific to the legal profession, such as bar associations, courts, or opposing counsel, rather than relying on generic corporate impersonation, since these institutional relationships carry inherent trust that generic brand impersonation does not.

Are small and mid-sized law firms at lower risk than large firms?

Not necessarily. Smaller firms often handle similarly sensitive client information while having fewer dedicated security resources, which can leave them more exposed rather than less, despite their smaller size.

What is the biggest phishing-related risk specific to law firms?

Business email compromise targeting wire transfers, particularly around real estate closings, settlements, and trust account transfers, represents one of the most financially damaging risks specific to the legal sector, since these transactions are routine and time-sensitive by nature.

Content Reviewed By

Mohammed Nawaz Sajjad, Sr. Security Analyst at PhishCare
Mohammed Nawaz Sajjad
Sr. Security Analyst at CyberSapiens | Phishing Simulation | Ethical Hacker | Bug Hunter | Red Team

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking.

He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.

View LinkedIn Profile

Generic phishing training was not built for the specific ways attackers target law firms. See how realistic, legal-specific phishing simulation works with a free PhishCare demo account, no credit card required.