Cyber-criminals:
It's not just your money they're after!

It is not just your money that criminals want. To them, information is gold. 

Legal practices that handle confidential and commercially sensitive information are prime targets for cybercriminals. Law firms are particularly attractive targets for ransomware actors, phishing attacks, and business email compromises due to the nature of their operations, including time-sensitive transactions and complex client interactions. Smaller firms, who depend on external ICT services, can face more risks due to limited resources and vulnerabilities like out-of-date antivirus software and devices, or untrained staff.

A recent National Cyber Security Centre (NCSC) report states that cyberattacks have affected 75% of law firms. The trend is escalating, with the number of leading law firms experiencing attacks rising in the most recent financial year. The SRA has highlighted the financial impact of these attacks, with over £4 million stolen in 23 out of 30 targeted cases. The disruption caused by these attacks leads to significant financial and reputational losses for the firms and potentially irrecoverable loss of client trust.

Cybercrime awareness and prevention advice is consistent across the sector. As well as cyber security essentials such as strong firewalls, antivirus software and encrypting devices, the human element is just as important. Law firms must focus on their staff and raise awareness of identifying fraudulent e-mails, suspicious links, and attachments, using strong passwords, and managers only granting access to sensitive information on a “need to know” basis. Education is always the best defence against any criminal risk.

Picture of Paul Stratton

Paul Stratton

The Fraud Nerd
November 2023