Business Email Compromise: Wire Fraud Built From Your Own Org Chart
It knows the managing partner’s name, who controls payments, and what you’re closing this week — because you published all of it.
A generic phishing email is easy to spot: wrong name, odd greeting, obvious tell. A spear-phishing email is different, because it knows things. It knows the managing partner's name. It knows who the office manager reports to. It knows you're in the middle of a real estate closing. It arrives looking exactly like an internal request, from exactly the right person, at exactly the right moment.
None of that knowledge was stolen. It was assembled — mostly from your website and your team's LinkedIn profiles. And its payoff has a name every firm learns eventually: business email compromise, the wire-fraud engine.
Your public footprint is an org chart
Firms publish most of the raw material voluntarily. Attorney bio pages give names, roles, practice areas, and direct contacts. LinkedIn fills in reporting lines, tenure, who's new (and therefore unsure of the norms), and who just left (and whose absence can be exploited).
Stitch it together and an attacker has a working model of your firm: who has authority, who handles money, who's junior enough to comply with an unusual request from someone senior.
What business email compromise looks like
The classic patterns:
- The wire request. A message that appears to come from a partner, to the person who controls trust or operating funds, about a real-seeming transaction, with new payment instructions. Urgency, authority, plausibility — all sourced from public information. This is law firm wire fraud in its most common form.
- The credential lure. A message referencing a real matter or a real internal system, pushing the target to "log in" on a page that harvests the password (which then feeds everything in Chapter 2 and Chapter 5).
- The new-hire play. The person announced on LinkedIn last week doesn't yet know that the managing partner never asks for gift cards or same-day wires. They were selected precisely because they don't know.
A fictional firm's genuinely public artifacts. Collect each one and watch what it builds.
What actually fixes law firm wire fraud
1. Train the humans on the specific attack. Not generic "watch for phishing." The specific rule: any request to move money or change payment details gets verified through a second, known channel — a phone call to a number you already have — no matter who it appears to come from.
2. Make verification a policy, not a judgment call. The junior person should never have to decide whether it's okay to question the managing partner. The policy decides for them: payment changes are always verified, full stop. That removes the authority pressure the attack depends on.
3. Lock the email path. SPF, DKIM, and DMARC (same records as Chapter 3) make it materially harder to spoof your domain, and make lookalike sends easier to catch.
4. Audit your public footprint deliberately. You can't (and shouldn't) go invisible — findability is the point of a firm's website. But you can decide what's published: whether bios list direct dials, how much organizational detail is public, whether "new hire" announcements need to name the exact role that controls payments.
5. Run a phishing simulation. A safe, internal test tells you where you actually stand better than any assumption — and normalizes the idea that these messages are expected, not shameful to report.
Your firm's BEC / spear-phishing checklist
