Flagship insight

Trust account fraud in Australian law firms: how payment redirection works and the controls that reduce risk

Payment-redirection attacks exploit a normal business process: an email arrives, bank details change and a busy person acts. The strongest response is a payment process that assumes email alone is not proof.

Scroll to explore
02Composite scenario

Composite scenario

The email looks right because the attacker has studied the matter

This opening is a composite scenario based on the attack pattern described in Australian legal-sector and cyber guidance. It is not presented as a Tier 1 client incident.

A firm receives a message shortly before settlement saying that payment details have changed. The signature and tone look familiar. The message may come from a compromised mailbox or a convincing lookalike address. Under deadline pressure, the new details are accepted and the transfer is sent before anyone confirms the change through a separate channel.

Two rows of documents on a night table, one row diverted before the end.
03Tier 1

Section 03

The Australian numbers

The Australian Signals Directorate reported that business email compromise represented 15 per cent of self-reported business cybercrime in its 2024-25 reporting, while a further 19 per cent involved email compromise without financial loss. Its business factsheet reported an average self-reported cybercrime cost of $56,600 for small businesses, up 14 per cent year on year.

The National Anti-Scam Centre reported $166.8 million in Australian payment-redirection scam losses during 2025, an increase of 9.3 per cent from the previous year. Those figures cover the wider economy, not law firms alone, but they show why payment verification deserves leadership attention.

04Tier 1

Section 04

How the attack chain works

Access often begins with stolen credentials or a convincing impersonation. The attacker watches communication for a payment event, prepares a message that fits the context and changes the destination account at the point when time pressure is highest.

Australian legal-sector guidance treats rapid action as critical after a suspicious transfer. The firm needs a known escalation path to its bank and, for relevant property transactions, the appropriate conveyancing platform and professional advisers.

1. Access or impersonation

An attacker compromises an account or creates a message and address that appear legitimate.

2. Reconnaissance

Payment timing, parties, language and process are learned from available communication.

3. Changed instructions

New bank details arrive close to a deadline in a familiar-looking thread.

4. Transfer and delay

The payment is sent before the change is verified through a trusted second channel.

05Tier 1

Section 05

Eight controls that reduce payment-redirection risk

No single control removes the risk. The aim is to break the attack chain at several points and make a bank-detail change impossible to approve on email evidence alone.

1. Verify every bank-detail change out of band

Call a known number already held on file. Do not use contact details supplied in the change message.

2. Require multi-factor authentication for email

Apply MFA consistently to business email and administrative access, with exceptions treated as visible risks.

3. Monitor forwarding and mailbox rules

Review unexpected forwarding, hidden rules and changes that can let an attacker observe or redirect communication.

4. Use a two-person payment process

Separate preparation and approval for high-value transfers and require both people to see the independent verification record.

5. Protect the firm's email domain

Configure domain authentication and monitor lookalike domains so obvious spoofing is harder and suspicious messages are easier to identify.

6. Train the roles attackers target

Use realistic examples for accounts, conveyancing and fee-earning staff, including what to do when a request arrives near a deadline.

7. Prepare and test the response path

Record who contacts the bank, platform, insurer, client, legal adviser and authorities, and make the plan easy to find under pressure.

8. Use authenticated channels for sensitive instructions

Where practical, move bank details and approvals out of ordinary email into a controlled, authenticated workflow.

06Tier 1

Section 06

Where to start

Start with the payment workflow. Confirm that every bank-detail change is independently verified, every email account is covered by appropriate MFA and staff know the exact response path when something looks wrong.

Then test the controls. Evidence that a process works is more useful than a policy that has never been exercised.

07Tier 1

Section 07

Questions for the next partners' meeting

These questions turn payment security into an owned business process. A weak or uncertain answer identifies where a short test or control improvement should begin.

Can email alone change bank details?

The answer should be no, with a separate trusted channel and a retained verification record required every time.

Who can prepare and approve a transfer?

Roles, limits and separation should be clear, including how urgent requests and absences are handled.

Who calls the bank first?

The contact path, authority and information needed for rapid escalation should be known before a transfer is questioned.

When was the process last tested?

A short exercise can show whether staff recognise the signal, find the right contact and preserve evidence under pressure.

08Primary and professional guidance

A quiet first step

Test the controls before a payment is at risk

Tier 1 can review the workflow, evidence and response path with the people who operate them.

Book a confidential call