You receive an email from your law firm. The invoice looks legitimate. The matter reference matches your current transaction. The email signature has all the right details. But the bank account details have changed, and there's a polite note explaining they've switched banks. You pay the invoice.

Except it wasn't your law firm. And that $47,000 just went to a criminal in another country.

This scenario plays out across Australian businesses every week. Scammers impersonate law firms because lawyers handle large transactions, communicate about sensitive matters, and their clients expect urgent requests. If you're wondering how to train staff on phishing emails, law firm impersonation scams deserve special attention because they're designed to bypass your team's normal suspicions.

Why Scammers Love Pretending to Be Lawyers

Law firms make ideal targets for impersonation. They regularly send invoices for thousands (or hundreds of thousands) of dollars. Their communications often involve time-sensitive matters where delays cost money. And because legal matters are confidential, staff may hesitate to question requests or verify details with colleagues.

Criminals research their targets carefully. They might know you're buying a property, settling a dispute, or completing a business acquisition. This information can come from public records, social media, or even compromised email accounts at either your business or the law firm itself.

Armed with this knowledge, they craft emails that reference real matters, use correct terminology, and arrive at exactly the right time in your transaction.

The Warning Signs Your Team Needs to Recognise

Phishing training for employees Australia-wide needs to cover these specific red flags for legal impersonation scams:

Changed Bank Account Details

This is the most common tactic. A legitimate law firm will almost never change their bank details mid-transaction. If you receive an email (or text, or WhatsApp message) advising new payment details, treat it as suspicious until proven otherwise.

Real law firms typically provide bank details on formal letterhead or invoices, not in the body of an email. Any request to change where you send money should trigger an immediate phone call to a number you already have on file, not one provided in the suspicious email.

Unusual Email Addresses

Check the sender's email address carefully. Scammers use addresses that look similar but aren't quite right:

  • smithjones-lawyers.com instead of smithjoneslawyers.com
  • smithjoneslawyers.co instead of smithjoneslawyers.com.au
  • [email protected] when your actual firm uses smithjoneslawyers.com.au

Also check the reply-to address. Scammers sometimes send from a legitimate-looking address but set replies to go somewhere different. Your email client might show the display name "Smith Jones Lawyers" while the actual address is something completely different.

Missing Attachments or Vague References

Some scammers deliberately send emails without the invoice attached. When you reply asking for it, you've now started a conversation. They've built a small amount of rapport, and the actual scam email with fake payment details arrives in an ongoing thread that feels legitimate.

Be suspicious of any email that mentions an invoice or document but doesn't include it, especially if the tone suggests you should already know what they're talking about.

Pressure and Urgency

Phrases like "settlement is tomorrow" or "court deadline approaching" create panic. Scammers know that high-pressure tactics bypass careful thinking. Your staff need to understand that genuine urgency is exactly when verification matters most, not least.

Threats of Legal Action

Emails threatening lawsuits, debt collection, or court action unless you respond immediately are a classic phishing tactic. Real lawyers don't typically threaten legal action via email to people who aren't already aware of a dispute.

How to Train Staff on Phishing Emails From Fake Law Firms

General security awareness helps, but simulated phishing attacks that specifically mimic law firm communications give your team practical experience. We've seen that employees who experience realistic simulations can become better at spotting real attacks, although the practical benefits are often most significant when the training is interactive and part of a wider approach to security.

Your training should cover:

Verification procedures: Every staff member who handles payments needs to know that bank detail changes require phone verification. Not a phone call to the number in the suspicious email. A call to a number from your existing records, a business card, or the firm's website (which you visit directly, not via any link in the email).

Escalation without embarrassment: Staff should feel comfortable flagging suspicious emails without worrying they'll look paranoid. The cost of one successful scam far exceeds the minor inconvenience of verifying legitimate requests.

Email header inspection: Show your team how to check the actual sender address, not just the display name. Most email programs let you hover over or click on the sender to reveal the true address.

Building Verification Into Your Payment Processes

Training alone isn't enough. You need processes that make it hard to pay the wrong people even if someone does fall for a scam.

Consider requiring two people to approve any payment over a certain threshold, or any payment to new or changed bank details. Maintain a verified contact list for regular suppliers and professional services, with phone numbers confirmed independently of any email communication.

Some businesses implement a mandatory 24-hour delay on payments to new bank accounts. This creates a cooling-off period where the urgency tactics have time to wear off and someone might notice something wrong.

What To Do If You Receive a Suspicious Email

Don't reply to it. Don't click any links. Don't open attachments.

Contact your actual law firm using contact details you already have. Ask them directly whether they sent the communication. If they didn't, they'll want to know about it so they can warn other clients.

Report the scam to the ACSC's ReportCyber service. If you've already paid money, contact your bank immediately. Sometimes payments can be stopped or reversed if you act quickly enough.

Making Training Stick Without Wasting Time

The challenge for most small businesses is finding time for security training when everyone's already busy. Lengthy annual presentations don't work. People forget the content within weeks, and the training becomes a box-ticking exercise rather than genuine skill-building.

Short, regular simulations work better. When an employee clicks on a simulated phishing email, they get immediate feedback about what they missed. This keeps training engaging rather than tedious, and the lessons stick because they're tied to a concrete experience.

Automated systems can handle this without you needing to manage anything. Employees receive realistic test emails, including ones that mimic law firms and other professional services. Those who fall for them get training. Those who don't get progressively harder tests. You get reports showing who needs extra attention.

Test Your Own Instincts

Before you train your staff, test yourself. Sign up for a free trial with Phishing Training Australia and send yourself a simulated phishing email. See whether you spot the warning signs, or whether you'd have clicked.

It takes about two minutes to set up, and you'll get a much better sense of what your team is up against. The scammers impersonating your lawyer are getting better at their craft every day. Your defences need to keep pace.