02 8987 4501  ·  0406 340 856
Google Reviews
Legal Services

Trust account fraud is targeting law firms, and the losses are climbing fast.

Published 2 August 2026

This isn't ransomware. Nothing gets locked or encrypted. A firm's own trust account payment gets quietly redirected through a compromised or convincingly faked email thread, and by the time anyone notices, the money's already gone.

Why IT Service Centre
Since 2004Two decades supporting Sydney businesses
2-hour responseDuring business hours, sooner for urgent issues
One partnerSupport, security, networks and cloud, together

What's actually happening

Business email compromise, often shortened to BEC, cost Australian businesses more than $150 million in 2024 alone, a jump of around two-thirds on the year before. The average loss reported per incident to the Australian Signals Directorate's cyber centre was close to $100,000. Industry reporting on the legal sector specifically has flagged conveyancing and law firms as frequent targets, precisely because they routinely instruct large payments by email.

The mechanics are almost boring in how simple they are. An attacker gains access to, or convincingly imitates, an email thread involving a solicitor, a client or a bank. At the right moment, usually right before a settlement or a large trust account transfer, they send new bank details, styled to look exactly like a legitimate update. If nobody double-checks by phone, the payment goes straight to the attacker's account instead.

Why this hits law firms particularly hard

Unlike a ransomware attack, there's no negotiation and no decryption key to recover. Once a trust account payment clears, it's gone, and the firm is often the one left explaining to a client what happened to their money. Legal bodies including the ACT Law Society have issued direct warnings to member firms about exactly this pattern, which suggests it isn't a rare edge case but a live, ongoing risk.

Professional services more broadly, including legal and accounting practices, have ranked among the most targeted industries globally for two years running, according to insurance industry reporting. The combination of high-value transactions and email-based workflows makes law firms a specifically attractive target for this kind of fraud, more so than for most other small businesses.

What actually reduces this risk

The single most effective habit is also the simplest: never change bank details based on an email alone. Any change to payment instructions gets confirmed by phone, using a number you already had on file, not one supplied in the email itself. Beyond that, multi-factor authentication on every email account makes it much harder for an attacker to get inside a real mailbox in the first place, and staff who know this specific scam pattern are far less likely to be caught by it under pressure.

None of this is complicated. It's a habit, not a piece of software, and it's the difference between a client's settlement funds arriving safely and a very difficult phone call.

Handling trust account payments?

Let's check your email security setup.

A short review covers MFA, account monitoring and the process your team follows when payment details change.

Start a conversation