Several BC law firms have recently fallen victim to cybercrimes.
At one firm, the criminal spoofed a lawyer’s email address and sent a fraudulent invoice to his assistant for payment. The assistant asked the lawyer for a file number to process the invoice. They discovered the invoice and email were fraudulent, made no payment, and thought they were in the clear. However, on the same day, the hacker tried again and accessed the assistant’s email. The hacker caused 1,850 emails to be sent to about 850 people from the assistant’s account. The message asked recipients to click on a link. Several people emailed the assistant to check its legitimacy. The hacker intercepted those emails, and emailed them back saying that it was and that they should click on the link.
At another firm, an in-house bookkeeper’s email was compromised. The hacker sent an email to the firm’s bank and requested that funds be sent to another bank. It was fortunate that in this case the bank contacted the firm personally to confirm the transfer to the different bank account and the firm was able to stop the transfer.
At a third firm, a lawyer received an email that he thought was from their storage provider stating that the firm’s disc space was full and including a log-in link. The email, link and log-in page were convincing, but fraudulent.
As always, be vigilant by remembering:
Talk to your IT professional about our top five recommendations to avoid cyber risk:
Coalition’s policy is claims-made and applies to data (privacy) breaches, network security failures and common cybercrime risks – funds transfer fraud, social engineering fraud and cyber extortion. You have access to an industry-leading 24/7 incident response and claims team, so report all incidents immediately to Coalition, Inc. even if you think your incident was a “near miss.” Their security team can ensure you have no remaining risk.
Further information, including links to pre-recorded webinars, details on coverage, risk management and FAQs, is available here. If you have questions about LIF’s new cyber program, email Shelley Braun at sbraun@lif.ca.
For the latest updates from LIF, follow us on Twitter @Lifbc.