The scams that reach a law firm are the ones your insurer already catalogues
Wire redirection, changed banking details and lookalike senders, practised safely by your staff before the real one lands in an inbox.
A law firm is a particular kind of target: often small enough to have no IT department, and trusted enough to hold other people's money. Your insurer's fraud library tells the same story in a dozen costumes, a payment lands in trust, a convincing client presses to have it disbursed, and the wire is the last anyone sees of the funds.
That story almost always starts with a message somebody believed: a lookalike client, a supplier whose banking details changed, a document waiting for a signature. Training the people who read those messages is the control that works before the money moves, and the only one that does.
The evidence, and where it comes from
Every figure below links to the source it came from. We have quoted what each number counts, because a percentage without its denominator is not evidence, it is decoration.
reported lost to business email compromise in 2025, across 24,768 complaints to the FBI's Internet Crime Complaint Center, the second-costliest crime type in the report. This is the changed-instructions, wire-the-funds scam, and a firm that wires settlement or closing money is precisely the shape it hunts.[1]
lost to fraud by Canadians in 2025 as reported to the Canadian Anti-Fraud Centre, with reported losses since 2022 past $2.4 billion. The same release says only 5 to 10 per cent of frauds are reported, so read these figures as a floor.[2]
is why firms are targeted, in your own insurer's words. LAWPRO's fraud warnings describe scams built on a payment arriving in trust and the lawyer being pressed to disburse it, with real estate practice among the most exposed. It publishes patterns rather than claim counts, so we quote the pattern and do not invent a number.[3]
of technological competence sits in the Model Code. Its commentary says a lawyer “should develop an understanding of, and ability to use, technology relevant to the nature and area of the lawyer's practice and responsibilities”, and should understand its benefits and risks, in the same breath as the duty to protect confidential information. Law societies adopt it province by province.[4]
None of these figures counts law firms specifically. The FBI and CAFC numbers count reported fraud across whole economies, and LAWPRO publishes case patterns rather than totals. Law-firm breach percentages do circulate in vendor marketing; we could not verify one against a primary source we could link you to, so none appears here.
Does my law society require security awareness training?
No, and we will not pretend otherwise. What exists is a duty of technological competence in the Model Code's commentary, confidentiality obligations that apply however a breach happens, and your law society's own cyber guidance. Ontario's, for example, maintains a cybersecurity resource hub with training tutorials. In practice, the party asking about staff training is usually your insurer.
- A certificate per person, naming them and the course, dated the day they finished.
- A serial on every certificate that anyone can verify on our site without an account.
- A record for every person on your roster, including who has not finished, because a report that lists only the people who passed is not evidence of a programme.
- An export you can attach to a renewal form as a document, rather than a screenshot of a dashboard.
Whether your insurer treats this as satisfying a training question on a renewal is their decision, not ours: a certificate evidences that a named person completed named training, and nothing beyond that. The fastest path is to put one line to your broker: “ongoing security awareness training for all staff, with dated per-person completion records and verifiable certificates”. If that is what they want, this produces it, and you will know before you spend anything.
How practice here maps to the frauds that reach a firm
The insurer's catalogue, forged safely
Changed banking details, urgent wire confirmations, documents waiting for a signature and lookalike senior partners are all shapes our generator produces, and your staff practise on them inside the product. Nothing is ever sent to a real inbox. That is a stance, not a missing feature.
Client files stay out of it
Training your staff needs their names and work email addresses, and nothing else. No client data, no matter files, no connection to your document system.
Certificates with a verifiable serial
Completion issues a certificate carrying a serial anyone can check on our site without an account, so the evidence stands up on its own.
A few minutes a week, not an annual module
Practice keeps running through the year, and the scam types somebody keeps missing come back around until they stop missing them.
What your people will practise, explained free
These are the same scams this page is about, written for the person who has to spot one on a Tuesday morning. No account needed to read them.
What is true in every sector
of breaches involved the human element, up from 60% the year before, across more than 22,000 confirmed breaches in 145 countries.[5]
of breaches began with vulnerability exploitation, which this year overtook credential abuse (down to 13%) as the single most common way in. People are involved in most breaches, but they are not the most common entry point, and we are not going to tell you otherwise.[5]
of breaches came through social engineering, the third most common pattern. In simulations, the median click rate for voice and text lures runs 40% higher than for email.[5]
And the uncomfortable part, which we would rather you heard from us
One of the largest field studies of phishing training ever published followed roughly 19,500 staff at a large health system through ten simulated campaigns over eight months. It did not flatter the industry we are in.
was the entire effect of embedded phishing training on the likelihood of clicking a phishing link. Having recently completed annual mandatory security training showed no significant relationship with falling for phishing at all.[6]
of the people who landed on the training page spent a minute or less on it, and about a third closed it immediately. That is a finding about attention, not about people being careless.[6]
We read that as the strongest argument for how BadgerQuest is built, not against it. What the study measured is the industry standard: an annual module, an ambush simulation, and a training page served to somebody who has just been told they failed. Nobody reads that page. Training that gets skimmed for forty seconds is not a smaller dose of training that works, it is a different thing entirely.
So the daily round is two minutes and it is a game, because that is the version people voluntarily finish. We do not send simulated phishing to real inboxes, because being ambushed by your own IT department is what produces the closed tab. Nobody is shamed for a wrong call, and what we train is the judgement to tell the two apart rather than a reflex to flag everything. Topics somebody keeps missing come back around instead of being marked complete.
The study's authors also recommend refocusing on technical countermeasures, specifically two-factor authentication and password managers that only fill on the correct domain. They are right, and those will stop more attacks than any training will. Do them first. We will say the same on a sales call. Training is for the part those controls do not cover, and it should be honest about being exactly that.
Sources
Read them yourself. That is the entire habit we are trying to teach, and it would be a strange thing for us to ask of your staff and not of ourselves.
- FBI Internet Crime Complaint Center (IC3). 2025 IC3 Annual Report Published 2026. 1,008,597 complaints and US$20.877 billion in reported losses for 2025. Figures count complaints the public filed with IC3, so they are self-reported, United States centred, and a floor rather than a total. Figures quoted here were read from the report PDF.
- Competition Bureau Canada. Fraud Prevention Month to bring hidden crime into the spotlight News release, 6 March 2026. Loss figures are Canadian Anti-Fraud Centre data, and the release itself carries the caveat that only 5 to 10 per cent of frauds are reported.
- LAWPRO (practicePRO). Current scams, cons, and swindles Ontario lawyers' professional liability insurer, last updated 26 June 2026. Case-pattern warnings rather than statistics: LAWPRO publishes no claim counts, which is why no number is quoted from it here.
- Federation of Law Societies of Canada. Model Code of Professional Conduct, commentary to rule 3.1-2 (competence) Commentary [4A] and [4B], quoted from the Federation's own published code; read 13 August 2026. Law societies adopt the Model Code province by province, so check your own society's code for the wording in force where you practise.
- Verizon Business. 2026 Data Breach Investigations Report, Executive Summary 19th edition, published May 2026. More than 31,000 security incidents, of which more than 22,000 were confirmed data breaches, across organisations in 145 countries. Figures quoted here are from the executive summary PDF.
- Ho et al., University of Chicago, UC San Diego and UC San Diego Health. Understanding the Efficacy of Phishing Training in Practice 46th IEEE Symposium on Security and Privacy, May 2025. Roughly 19,500 staff at UC San Diego Health, ten simulated campaigns over eight months. Findings summarised by UC San Diego Today, 17 September 2025.
See what the evidence looks like
Free for individuals, forever. Teams are $4 CAD per person per month, month to month, no minimum, cancel whenever you like.