< Back

Wire Fraud Prevention Is a Process, Not a Judgment Call

Post on August 11th, 2026

Wire fraud prevention depends less on spotting suspicious messages than on following a process that no email, phone call or urgent request can override.

Unfortunately losses due to financial crimes continue to grow. In 2025, the FBI’s Internet Crime Complaint Center received more than 1 million complaints, with reported losses totaling $20.877 billion; business email compromise alone accounted for more than $3.04 billion in reported losses. Law firms, due to handling large transactions, are attractive targets for cybercriminals and make up part of these statistics. 

For law firms, preventing these losses requires more than reminding employees to “be careful.” It requires a deliberate system for controlling who may transfer funds, how instructions are communicated and how every transaction is independently verified. This article explains the core controls firms should include in a wire-transfer control process and offers practical reminders for putting those controls into daily use.

  1. Limit Who Can Initiate and Approve a Transfer

A strong wire fraud prevention process begins by controlling access. Firms should designate the specific employees who are authorized to initiate wire transfers and prohibit all other employees from doing so. Limiting authority reduces the number of potential failure points and makes it easier to establish consistent procedures, training and accountability.

For larger or higher-risk transfers, consider separating initiation from approval. The person entering the transfer should not be the only person deciding whether the instructions have been properly verified. A second authorized employee can review the verification record and transaction details before funds are released.

The policy should cover every transfer, regardless of the amount, deadline, or apparent identity of the person making the request. An email that appears to come from a partner, longtime client or trusted business contact should not create an exception.

  1. Train Employees on Fraud Red Flags, Cybersecurity, and the Wire Transfer Policy

Everyone involved in handling funds should be trained on cybersecurity, fraud warning signs, and your firm’s wire transfer policy. New employees should receive training immediately at onboarding and existing employees should receive periodic refreshers. The policy should be updated when banking procedures, technology or fraud methods change.

Employees should examine messages for slight changes in email addresses, domains, names or account information. Spelling, grammar and punctuation errors can be warning signs, as can unusual phrasing, unexpected attachments or requests that depart from prior instructions. The FBI specifically advises recipients to review addresses, URLs and spelling carefully because criminals often use small variations to make a message appear authentic.

Those warning signs are useful, but they should not be the firm’s primary defense. A well-written message, especially as generative AI progresses, can still be fraudulent. The safer approach is to treat every set of wiring instructions—initial, modified or replacement—as unverified until the firm completes its required confirmation procedure.

Technology protocols can reduce the likelihood that a criminal gains access to the information needed to construct the fraud. Firms should:

  • Require multifactor authentication for email, banking, document-management, remote-access and other important systems
  • Use email security tools that filter phishing messages and suspicious attachments
  • Review accounts for unfamiliar forwarding or filtering rules
  • Exchange wiring instructions through an approved encrypted email system, secure client portal or secure fax process
  • Use long, unique passwords and an appropriately vetted password manager
  • Change credentials promptly when compromise is suspected or confirmed

Finally, the policy itself needs to be in use, not just on the shelf. Employees should understand who has authority and responsibility to approve a wire transfer, best practices to verify contact information (discussed below), and protocol to verify the details of the transfer.

reduce financial fraud in law firms with strong policy

  1. Establish Verified Contact Information Before Funds Are Involved

The firm should not assume that an instruction is legitimate because it came from a familiar email address, appeared in an existing thread or contained accurate details about the transaction. A compromised account allows a criminal to observe legitimate communications and produce a request that fits the surrounding conversation.

The firm should establish a “known and trusted” telephone number and contact information for every person or organization that may provide wiring instructions.

A known telephone number and other contact information should come from an independent source, such as:

  • Information confirmed during an in-person meeting
  • A number already maintained in an established client or vendor record
  • A reputable public directory or official organizational website
  • A separate communication with a person the firm already knows
  • Contact information independently confirmed during intake

Encryption and secure transmission are important, but they do not establish that the person controlling an account is authorized to give the instruction. Secure communication must therefore support—not replace—the firm’s independent verification procedure.

  1. Require Independent Verification and Document It

All changes to wiring instructions should be treated as potentially fraudulent until independently verified. The employee should confirm the recipient’s identity, financial institution, routing number, account number and purpose of the transaction.

Before initiating a wire, an authorized employee should call the person providing the instructions at the independently established telephone number. This requirement should apply to:

  • The initial setup of wiring instructions
  • A new recipient or financial institution
  • A change in account or routing information
  • A request to divide or accelerate a payment

The firm should document the verification in the client or transaction file, including:

  • The date and time of the call
  • The number called
  • How that number was independently verified
  • The name and role of the person reached
  • The information confirmed
  • The employee who completed the verification
  • Any required second-person approval

Documentation creates a record that the policy was followed and gives the approving employee enough information to conduct a meaningful review.

A checkbox stating “verified” is less useful than a brief record showing how verification occurred.

  1. Confirm Completion and Be Prepared for a Failed Transfer

The firm’s responsibility should not end when the bank accepts the transfer. After funds are sent, contact the intended recipient at the verified telephone number and confirm that the correct account received the money. Prompt confirmation may reveal a problem while there may be an opportunity to contact the financial institutions involved.

Firms should have a written incident response procedure if a transfer is misdirected or fraud is suspected. That procedure should include:

  1. Contact the sending financial institution immediately and request that the transfer be recalled or frozen.
  2. Ask the sending institution to contact the receiving financial institution.
  3. Report the incident promptly to the FBI’s Internet Crime Complaint Center.
  4. Notify the firm’s technology or incident response professionals.
  5. Preserve relevant emails, attachments, account information, message headers and transaction records.
  6. Notify the firm’s insurance carrier or agent in accordance with applicable policy requirements.
  7. Evaluate any obligations to notify affected clients, parties, regulators or law enforcement.

The FBI advises victims of business email compromise to contact both IC3 and the financial institution immediately.

Firms should also review their insurance regularly. Ensure that coverages provide for losses involving social engineering, fraudulent funds transfers, or business email compromise. Coverage terms, exclusions, sublimits and deductibles can differ. Firms should discuss their particular risks with an insurance professional and determine whether additional cyber coverage is appropriate.

Make the Process Stronger Than the Message

An effective wire fraud policy does not depend on an employee correctly deciding whether an email looks suspicious, rather it assumes that all transfers must follow a disciplined process. No deadline justifies bypassing the established process. A time-sensitive event may create pressure to act quickly, but the firm should not release funds until every required control has been completed.

The policy should give employees clear direction and authority to complete verification and to stop the process if something appears inconsistent. The procedure is most effective when following it is treated as an ordinary professional responsibility—not as an accusation that the client or requesting party is untrustworthy. When those controls are written, understood and consistently followed, a fraudulent message alone isn’t enough.

For firms with cyber breach response coverage from OBLIC, make sure that you utilize the new Breach Solutions Cyber Risk Management Resources that include extensive learning content, risk assessments, phishing simulations, and employee training. Contact Loss Prevention for login credentials.

For additional reading on this topic, see:

Stop Payment Fraud Before Money Moves (March 2026)

Wire Transaction Fraud: Impact on All Areas of Practice (December 2022)

With questions or for additional resources, contact your OBLIC Loss Prevention team. We’re here to help.

Gretchen K. Mote, Esq.
Director of Loss Prevention
Ohio Bar Liability Insurance Co.
Direct:  614.572.0620
gmote@oblic.com
Merisa K. Bowers, Esq.
Director of Marketing and
Loss Prevention Counsel
Ohio Bar Liability Insurance Co.
Direct:  614.859.2978
mbowers@oblic.com

This information is made available solely for loss prevention purposes, which may include claim prevention techniques designed to minimize the likelihood of incurring a claim for legal malpractice. This information does not establish, report, or create the standard of care for attorneys. The material is not a complete analysis of the topic and should not be construed as providing legal advice. Please conduct your own appropriate legal research in this area. If you have questions about this email’s content and are an OBLIC policyholder, please contact us using the information above.