You may think that phishing attempts are easy to spot and you couldn’t be fooled, but not all phishing attempts are created equal. Meet the spear phishing campaign.

Spear phishing occurs when fraudsters target a specific person, organization, or group using information they have gathered in advance. Unlike generic phishing attempts, these scams are personalized and more difficult to detect.

An especially devious version of a spear phishing campaign is currently targeting Indigenous communities. LAWPRO has received at least two reports related to this spear phishing campaign.

In one report, fraudsters first compromised a lawyer’s email account without the lawyer realizing it. They then used the account to correspond with an Indigenous organization that was preparing to transfer funds to the lawyer’s Indigenous client. To keep the lawyer from seeing the messages, the fraudsters redirected outgoing and incoming emails to a hidden folder. Believing the emails were legitimate, the organization sent the funds to the fraudsters’ account instead of to the client.

In another report, the lawyer received banking instructions that appeared to come from their Indigenous client. Without independently confirming those instructions with the client, the lawyer forwarded them to the organization responsible for transferring funds to the client. Relying on those instructions, the organization sent the funds to the fraudster instead.

Unfortunately, given its effectiveness, we expect to see more variations of this fraud.

Immediate steps to take if you suspect you have been comprised by a phishing campaign:

  • Contact your financial institution as soon as possible and request the funds be frozen in transit
  • Secure compromised email and bank accounts by changing passwords, enabling multi-factor authentication, and signing out of all active sessions
  • Report the incident to LAWPRO
  • Notify affected clients and third parties so they can take steps to protect themselves
  • Preserve evidence, including emails, systems logs, and banking records

General risk management steps:

  • Exchange banking information at the outset of the file. Independently verify any later changes to banking or payment instructions using a trusted phone number or another known contact method
  • Use multi-factor authentication on all email and bank accounts
  • Monitor email forwarding rules and mailbox settings for unauthorized changes
  • Treat urgent payment requests and last-minute banking changes as fraud indicators
  • Educate clients about the risks of email compromise and payment redirection fraud

The PracticePRO team ([email protected]) is always available to answer questions and provide support if you have questions about fraud or other risk management and claims prevention related matters.

Categories: Fraud Prevention