Flagship insight
Trust account fraud in Australian law firms: how payment redirection works and the controls that reduce risk
Payment-redirection attacks exploit a normal business process: an email arrives, bank details change and a busy person acts. The strongest response is a payment process that assumes email alone is not proof.
Composite scenario
The email looks right because the attacker has studied the matter
This opening is a composite scenario based on the attack pattern described in Australian legal-sector and cyber guidance. It is not presented as a Tier 1 client incident.
A firm receives a message shortly before settlement saying that payment details have changed. The signature and tone look familiar. The message may come from a compromised mailbox or a convincing lookalike address. Under deadline pressure, the new details are accepted and the transfer is sent before anyone confirms the change through a separate channel.

Section 03
The Australian numbers
The Australian Signals Directorate reported that business email compromise represented 15 per cent of self-reported business cybercrime in its 2024-25 reporting, while a further 19 per cent involved email compromise without financial loss. Its business factsheet reported an average self-reported cybercrime cost of $56,600 for small businesses, up 14 per cent year on year.
The National Anti-Scam Centre reported $166.8 million in Australian payment-redirection scam losses during 2025, an increase of 9.3 per cent from the previous year. Those figures cover the wider economy, not law firms alone, but they show why payment verification deserves leadership attention.
Section 04
How the attack chain works
Access often begins with stolen credentials or a convincing impersonation. The attacker watches communication for a payment event, prepares a message that fits the context and changes the destination account at the point when time pressure is highest.
Australian legal-sector guidance treats rapid action as critical after a suspicious transfer. The firm needs a known escalation path to its bank and, for relevant property transactions, the appropriate conveyancing platform and professional advisers.
1. Access or impersonation
An attacker compromises an account or creates a message and address that appear legitimate.
2. Reconnaissance
Payment timing, parties, language and process are learned from available communication.
3. Changed instructions
New bank details arrive close to a deadline in a familiar-looking thread.
4. Transfer and delay
The payment is sent before the change is verified through a trusted second channel.
Section 05
Eight controls that reduce payment-redirection risk
No single control removes the risk. The aim is to break the attack chain at several points and make a bank-detail change impossible to approve on email evidence alone.
1. Verify every bank-detail change out of band
Call a known number already held on file. Do not use contact details supplied in the change message.
2. Require multi-factor authentication for email
Apply MFA consistently to business email and administrative access, with exceptions treated as visible risks.
3. Monitor forwarding and mailbox rules
Review unexpected forwarding, hidden rules and changes that can let an attacker observe or redirect communication.
4. Use a two-person payment process
Separate preparation and approval for high-value transfers and require both people to see the independent verification record.
5. Protect the firm's email domain
Configure domain authentication and monitor lookalike domains so obvious spoofing is harder and suspicious messages are easier to identify.
6. Train the roles attackers target
Use realistic examples for accounts, conveyancing and fee-earning staff, including what to do when a request arrives near a deadline.
7. Prepare and test the response path
Record who contacts the bank, platform, insurer, client, legal adviser and authorities, and make the plan easy to find under pressure.
8. Use authenticated channels for sensitive instructions
Where practical, move bank details and approvals out of ordinary email into a controlled, authenticated workflow.
Section 06
Where to start
Start with the payment workflow. Confirm that every bank-detail change is independently verified, every email account is covered by appropriate MFA and staff know the exact response path when something looks wrong.
Then test the controls. Evidence that a process works is more useful than a policy that has never been exercised.
Section 07
Questions for the next partners' meeting
These questions turn payment security into an owned business process. A weak or uncertain answer identifies where a short test or control improvement should begin.
Can email alone change bank details?
The answer should be no, with a separate trusted channel and a retained verification record required every time.
Who can prepare and approve a transfer?
Roles, limits and separation should be clear, including how urgent requests and absences are handled.
Who calls the bank first?
The contact path, authority and information needed for rapid escalation should be known before a transfer is questioned.
When was the process last tested?
A short exercise can show whether staff recognise the signal, find the right contact and preserve evidence under pressure.
Primary and professional guidance
Sources used for this article
Statistics and legal-sector guidance should be rechecked at each scheduled article review.
ASD Annual Cyber Threat Report 2024-25 business factsheet
Business email compromise and small-business cybercrime cost figures.
ExploreNational Anti-Scam Centre Targeting Scams report
Australian payment-redirection scam loss reporting.
ExploreAUSTRAC: exploitation of legal professionals
Legal-sector exposure around client funds, confidentiality and transactions.
ExploreLPLC Cyber Security Guide for Lawyers
Payment-verification and incident-response guidance for legal practice.
ExploreA quiet first step
Test the controls before a payment is at risk
Tier 1 can review the workflow, evidence and response path with the people who operate them.
Book a confidential call