Law firm wire fraud is the theft that lands at the exact moment a firm disburses money it is holding for someone else: a spoofed email changes the payoff instructions on a settlement, a paralegal wires the funds in good faith, and the money settles into an account no one verified. Because the firm authorized the transfer, the loss usually falls on the firm and its malpractice carrier rather than on the bank, and the funds are typically gone before anyone notices. The federal numbers make the exposure concrete: business email compromise took $3.046 billion in 2025, with 86 percent of that money moving by wire or ACH1. In August 2025, investigators managed to hold $449,000 tied to a single attorney-impersonation wire1, a rare recovery in a category where most transfers settle and disappear. This guide covers who actually absorbs the loss when settlement funds are wired to a fraudster, how the diversion reaches a trust account in the first place, the verification standard a malpractice carrier will respect, and what that verification really adds to a disbursement timeline. One honest note up front: no firm can screen away every spoofed email, because the fraudulent instructions arrive looking exactly like the client’s. What a firm controls completely is whether a payoff leaves for an account nobody confirmed.
Where the loss lands when settlement funds are wired to a fraudster
When a firm wires settlement or trust funds on fraudulent instructions, the loss usually falls on the firm, not the bank. A bank that executes the customer’s authorized payment order is generally protected under the loss-allocation scheme of UCC Article 4A, and the firm is the party that authorized the transfer. So the firm absorbs the loss and turns to its malpractice carrier, and whether the carrier pays turns on a single question: was the firm’s verification of the payment instruction reasonable? The American Bar Association’s own analysis frames lawyer liability for wire transfer fraud2 around exactly that reasonableness standard rather than around whether a scam occurred.
That framing has a practical consequence most firms miss: the defensible position is not "we were deceived," which every victim can say, but "here is the verification we performed before we released, and here is the record of it." A firm holding client money in trust owes a fiduciary duty over its disbursement, and a settlement payout is a high-value, one-time transfer with no recurring baseline to compare against, which is precisely the profile fraud selects for. The exposure is not hypothetical across the economy: the Association for Financial Professionals found that 76 percent of organizations experienced attempted or actual payments fraud in 2025, with wire transfers implicated in a quarter of cases3.
[A note on jurisdiction: trust-account and IOLTA rules, and the Article 4A allocation of loss, vary by state, and this section describes the general framework rather than the law of any single jurisdiction. Confirm how your state’s rules and your bar’s trust-accounting requirements apply with counsel licensed where you practice.]
How the diversion reaches a trust account
The diversion almost always rides in on a compromised or spoofed email thread. An attacker watches a matter approach disbursement, from a breached inbox at the firm, at opposing counsel, or at the client, then sends payoff or wire instructions that match the deal’s language, timing, and dollar figure. The paralegal or disbursing attorney keys them in because they look exactly like the client’s, and nothing on the screen distinguishes an authentic instruction from a forged one. The FBI’s data shows where the money goes once released: business email compromise moved 86 percent of its $3.046 billion in 2025 losses by wire or ACH1, the two rails a settlement disbursement uses.
The reason this defeats ordinary caution is that the instruction is authorized from the firm’s point of view. There is no malware to catch and no obviously suspicious login; there is a real, expected payment going out on a real matter, to instructions that arrived in a thread the firm was already having. The entry points are worth naming because each one is verifiable before release, not after.
- A breached inbox inside the firm, so the fraudulent instruction comes from a real internal thread.
- A compromised account at opposing counsel or the client, whose instructions the firm has every reason to trust.
- A lookalike domain that swaps one character, so a fast reader sees the expected sender name.
- An intercepted email thread where the attacker replies inline with new banking details near the disbursement date.
- Timing pegged to closing or settlement, when a large one-time transfer is expected and speed is prized.
A verification standard a malpractice carrier will respect
A defensible verification standard checks three things before any settlement leaves the trust account: the payee is who the matter says it is, the receiving account actually belongs to that payee, and a named person at the firm approved the release. The rule that ties them together is out-of-band confirmation: verify any new or changed payment instruction through a phone number or contact the firm already had on file for the client, never the number or reply address in the email that carried the new instruction. That single discipline defeats the entire spoofed-thread mechanism, because the attacker controls the email but not the client’s known phone line.
This is not just prudence; it is increasingly the baseline regulators expect. Nacha’s fraud-monitoring rules, whose second phase took effect on June 19, 2026 for all non-consumer ACH originators4, now expect businesses that originate ACH credits, which includes law firms disbursing client funds, to screen for payments induced under false pretenses. A settlement wired to an impostor on forged instructions is the textbook case. The move that makes verification durable rather than occasional is the same one that protects public-fund and fiduciary payments at any organization that holds money for others: build the check into the release path, so it fires before the money moves rather than depending on whoever is disbursing that afternoon to remember.
- Match the payee: the party being paid is the party the matter and the settlement documents name.
- Match the account: the receiving account belongs to that payee, confirmed out of band through a contact the firm already had, not the one in the instruction.
- Hold the change: the first payment to a new payee or to changed banking details waits until verification is complete.
- Prove the approver: a named person is on record approving this payee and amount, so the decision is auditable later.
What pre-settlement verification adds to a disbursement timeline
For a payee the firm has already verified, verification adds nothing to the timeline: the release goes straight through, because the account and approver are already on record. The cost lands only where it should, on a new payee or a changed account, which waits until someone confirms it through an independent channel. In practice that is minutes on a first disbursement or a mid-matter banking change, not a standing tax on every wire the firm sends. The objection that verification will slow closings assumes every payment is a fresh unknown; almost none are.
You might also be wondering whether a client can pressure the firm to skip the step near a deadline. This is where a structural gate matters more than a policy, because the pressure is real and the disbursing attorney is human. When the hold is built into the release path rather than left to discretion, the answer to "can we just send it, the client is waiting" is that a changed account is not eligible for release until it is verified, the same rule for every matter. That is the pattern every sector in the payment fraud league table converges on: pre-settlement payment verification that fires before release, not fraud scoring that flags a pattern after the money is gone. The same spoofed-instruction mechanic drives voice-cloned wire requests, and the same out-of-band check answers both.
The attestation record that defends the firm later
Every control above works, and every one of them fails the same way: under deadline pressure, on the afternoon a settlement has to go out, when checking is optional. The durable version is structural. Before a disbursement is released, the payee is verified against the party entitled to the payment, a new payee or a changed account is held until confirmed out of band, and a named approver is on record, so the firm’s file contains not just the claim that it verified but the evidence of it.
This is where RankShield Financial fits for settlement and trust-account disbursements. It is a verification and attestation layer in the authorization path, not a bank, an escrow agent, or a factor, and it never takes custody of funds; the firm’s bank and rails still move the money. It holds a disbursement when the payee does not match a verified record, requires proof that an authorized person approved the release, and seals a signed, tamper-evident record of who verified what and when, the artifact a malpractice carrier, a bar auditor, or a client can independently verify later rather than take on faith. The honest boundary: verification does not vet the underlying matter, opine on your trust-accounting duties, or replace pre-settlement payment verification disciplines your bar already requires; it makes the unsafe release impossible to do casually and produces evidence of who approved what. If your firm disburses settlement funds and wants that gate, you can see how it works or request access. This article is for general information and is not legal advice; consult a licensed attorney in your jurisdiction about your firm’s trust-account and verification obligations.