Back Lawsociety.Uk Email hijacking and business email compromise: why law firms remain a prime target for ...
As cyber criminals become more sophisticated, email hijacking remains one of the most effective and financially damaging attacks facing law firms today.
While the techniques used by attackers have evolved, the objective remains the same: gain access to a trusted email account, monitor communications and exploit opportunities to steal money or sensitive information.
The threat is far from theoretical. According to the UK Government's Cyber Security Breaches Survey, published in April 2026, 43% of UK businesses experienced a cyber security breach or attack in the 12 months. The survey also found that phishing remains the most common form of cyber attack, highlighting the continued effectiveness of email-based threats against organisations of all sizes.
For law firms, the consequences can be particularly severe. A successful email hijacking attack can expose confidential client information, disrupt transactions, trigger regulatory investigations and cause significant reputational damage. In some cases, firms may also face reporting obligations to the Information Commissioner's Office (ICO), the Solicitors Regulation Authority (SRA) and affected clients.
How do cyber criminals benefit from email hijacking?
Unlike ransomware attacks that announce themselves immediately, email hijacking attacks are often patient and deliberately difficult to detect.
Once attackers gain access to an account, they may spend days, weeks or even months monitoring email conversations. Their goal is to identify financial transactions, client communications, conveyancing matters, settlement payments, or other opportunities where a trusted email account can be used to manipulate the flow of money.
In many cases, attackers use compromised accounts to conduct Business Email Compromise (BEC) attacks. By impersonating solicitors, clients, suppliers or colleagues, they can alter payment instructions, redirect funds, or persuade recipients to disclose confidential information.
The longer an attacker remains undetected, the more intelligence they can gather and the greater the potential damage. Even a short window of access to email can provide attackers with sufficient information to launch further attacks against your organisation or your clients.
Why are law firms such attractive targets?
Law firms face many of the same cyber risks as other organisations, but they also carry unique responsibilities and exposures.
Your firm routinely handles:
property and conveyancing transactions
commercial acquisitions and mergers
litigation settlements
sensitive personal information
confidential corporate documentation
This combination of financial activity and high-value data makes the legal sector particularly attractive to cyber criminals. Whether targeting client funds, confidential legal communications or sensitive personal data, attackers recognise that a successful compromise can have significant financial and operational consequences.
Recent examples from the legal sector
Recent incidents demonstrate the real-world consequences of weak email and identity security.
In 2025, the Information Commissioner's Office (ICO) fined Liverpool-based law firm DPP Law £60,000 following a cyber attack that exposed highly sensitive client information. Investigators found that attackers had exploited an account that lacked multi-factor authentication (MFA), gaining access to systems containing confidential legal records. The breach reportedly resulted in more than 32GB of stolen data and was only discovered after the National Crime Agency alerted the firm.
The legal sector also felt the impact of the 2025 Legal Aid Agency cyber incident, which disrupted services and affected systems containing applicant information dating back many years. The incident highlighted the risks associated with legacy technology and the sensitivity of the data held throughout the legal ecosystem.
These incidents serve as a reminder that cyber security failures can result in financial losses, regulatory scrutiny, reputational damage and a loss of client trust.
How do email hijacking attacks work?
While weak passwords remain a problem, modern attackers have expanded their toolkit considerably.
Today, email accounts are commonly compromised through:
phishing emails designed to steal usernames and passwords. This now includes AI-generated phishing campaigns that create highly convincing and personalised messages
multi-factor authentication (MFA) fatigue attacks that pressure users into approving login requests
session hijacking techniques that steal authenticated browser sessions and bypass MFA protections
data breaches exposing credentials from third-party services
Once access is obtained, attackers frequently create hidden forwarding rules, divert emails to private folders, or silently monitor conversations from within the compromised mailbox. Their objective is to remain invisible while gathering intelligence and identifying opportunities for fraud.
What could happen if a law firm is compromised?
The impact extends far beyond stolen funds.
A successful email hijacking attack may expose privileged communications, personal data, commercial information and confidential case details. You may also face obligations to notify affected clients, report breaches to the ICO and consider your regulatory responsibilities under SRA requirements.
Beyond regulatory implications, you must also contend with potential reputational damage. Clients expect their legal advisors to safeguard highly sensitive information, and any loss of confidence can have long-term commercial consequences.
How can law firms protect themselves?
No single security measure can eliminate the risk of email hijacking. Effective protection requires a layered approach that combines technology, processes and user awareness.
You should ensure that your firm:
enforces multi-factor authentication on all accounts
monitors mailbox forwarding rules and suspicious login activity
configures advanced security settings that are available in your email platform
enables mailbox auditing and security alerting
conducts regular phishing awareness training
monitors for compromised credentials on the dark web
ensures your email filtering configuration is set up to remove as much malicious and unwanted inbound email as possible
ensures you have defined incident response (IR) plans that include a suitable IR expert you can call upon
Most importantly, cyber security should not be viewed solely as an IT responsibility. Every employee plays a role in protecting client data and maintaining your firm's security posture.
Staying one step ahead
The most dangerous email hijacking attacks are often the ones that go unnoticed.
Modern attackers are patient, disciplined and increasingly supported by automation and artificial intelligence.
For law firms handling sensitive information and significant financial transactions, robust security controls, continuous monitoring and well-informed users remain the most effective defence against a threat that continues to evolve.
Cyber security is a business-critical risk that firms must actively manage to protect your clients, your reputation and your future.
Cyber security support for Law Society members
As a trusted cyber risk management partner to legal professionals, Mitigo works with law firms of all sizes to help identify cyber risks, strengthen resilience, and protect client data, finances and reputation.
From Cyber Essentials certification and cyber security assessments through to managed detection, incident response and staff awareness training, the Mitigo team can help your firm take a proactive approach to cyber security.
Members of the Law Society of England and Wales can benefit from 10% off a range of Mitigo cyber security services.
To your firm's cyber security requirements or arrange a no-obligation consultation, Mitigo today.
Email: [email protected]
Website:
Mitigo provides cybersecurity and cyber risk management services to the legal sector.
This article is written by Mitigo as a hosted feature on the Law Society website. Views expressed are Mitigo’s.
This article is provided for general information only. It is not intended to amount to advice on which you should rely. You should obtain professional or specialist advice before taking, or refraining from, any action on the basis of the content in this article. See our website legal notice .
Deepfakes and the legal sector
Five challenges facing the legal sector in 2026
Five key takeaways from the 2025 national risk assessment
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
