Woman standing outside server room with laptop

Spotlight on fraud and cybercrime...it's not just AML

We are often told by COLPs that the risk of fraud and cybercrime keeps them awake at night, for some even more so than AML risks.

It’s hard to keep up with the fast-developing range of fraud and cyberattacks, even more so with the emergence of AI.

Fraud can of course be internal, as in the case of a Liverpool law firm fined by the SRA this month after allowing its COFA to steal £157,000 of client and office money over a 7-year period. The SRA identified lack of appropriate systems and procedures in place governing payments from client account, allowing COFA (the accounts manager) to transfer these sums to her own and her son’s accounts without the knowledge of the firm’s Principal and COLP.

Last month the SRA issued a scam alert, warning law firms to police their identity against fraudsters trying to convince members of the public that they are from a real law firm. The SRA dealt with 83 scam alerts in the last quarter, including phone calls and emails pretending to be from law firms, copied firm websites, and inheritance scams.

In February this year, the SDT fined a solicitor £26,000 including costs for failing to spot ‘Friday afternoon fraud’ in a residential conveyancing sale. The fraudsters intercepted emails between the highly experienced conveyancer and her client. The day before completion the solicitor received an email, apparently from her client (though from a slightly different email address) asking her to send the sale proceeds to a different bank account. Despite saying they would need the client to confirm the changed account details by phone, the solicitor accepted reconfirmation of the new account details in a second email and sent the money to that account on the next working day. The firm only became aware of the fraud two weeks later, when the bank raised concerns about the recipient account, and the client (who had not complained or alerted the firm) confirmed they had not received the funds.

The SRA’s major concern was the solicitor’s breach of duty to protect client money and assets. As an experienced conveyancer, they should have recognised a last minute change of instructions as a red flag. The SDT agreed that the solicitor should have taken steps to investigate further and prevent fraud; in particular the solicitor should have insisted on additional verification of the changes ‘given the critical importance of such steps to counter fraud and attempted criminality’.

How can law firms avoid becoming a victim of fraud and cybercrime?

  1. Ensure you have robust policies and procedures in place to ensure the compliance officers and managers have visibility and control of the practice.
  2. Effective supervision and open communication are essential.
  3. Train your team on the firm’s policies and procedures – ensure they understand what is expected of them and how to comply
  4. Make sure everyone in your firm knows how to report breaches or suspicions and feels comfortable doing so
  5. One of the best defences against cybercrime is to train your team to spot a potentially fraudulent email or phone call. It’s essential to train all your staff, as it’s not just solicitors that are targeted: support staff may also be on the receiving end of fraudulent emails or phone calls and are the first line of defence.
Picture of Anne Austin

Anne Austin

Director