Cyber threat to lawyers at all time high

Professional firms are increasingly at risk of high level cyber-attacks, according to leading experts in the field of law, finance and mortgage lending.
Prefer the Global Legal Post on Google

bluebay

Speaking at the Mortgage Tech UK conference this week, Georgina Squire, Partner at solicitors Rosling King, warned professionals of the dangers that cyber-attacks impose to professional firms such as lenders, valuers, brokers and solicitors and advised on what steps should be taken to prevent and mitigate the fall-out when falling victim to a such an attack. A joint report by GCHQ’s newly-opened National Cyber Security Centre and the National Crime Agency published earlier this year, warned that the cyber threat to UK business is at an all-time high.

Take proactive steps to manage risk

Georgina Squire said: ‘Given that 2016 was the year that law firm data security came to the fore, by means of high profile events such as the Panama Papers and the rise of Ransomware, it seems reasonable to suggest that the threat will impact professional services firms in much the same way as the wider economy…Over the last year, professional firms such as my own, have been urged to take proactive steps to manage the risk posed by cybercrime to protect both ourselves and our clients.’

Increase staff training

She also encouraged firms to increase staff training and awareness and to build in additional security and protections to try to limit the potential harm, adding: ‘We have legal and regulatory obligations like all other professionals involved in the mortgage industry. Our regulators are increasingly taking on more hands-on approach to data security and publishing regular guidance.’

Key concerns

It was pointed out that current threat areas for law firms and other professionals involved in mortgage origination are: cloud computing, email fraud/phishing, ransomware and identity fraud.Miss Squire said: ‘It is now getting to the stage where criminals are paying people to pose as tenants and rent a property using fake identities. One of the tenant’s changes their name by deed poll to match the true owner’s name, put the property on the market and sells it to a cash buyer. It is only when the buyer goes to register the change of ownership with HMLR that the true owner, the landlord, is alerted.’

'Friday Afternoon Fraud'

The second major type of cybercrime hitting professional firms acting in the mortgage industry, is what has commonly become called Friday Afternoon Fraud. ‘As solicitors, we see alerts from our regulator, the SRA, almost weekly now with stories of Friday Afternoon Fraud,’ said Miss Squire. To avoid this type of fraud, she urged lawyers to beware of changes in bank details mid-transaction and beware of requests to do so during a transaction.

Double check

Legal advisers are also being advised that when someone asks for money to be sent to a particular bank account, they should call back on a phone number to double check those bank account details over the phone and verify them as only the most sophisticated of fraudsters would be able to intercept that call and provide their own mobile phone number to verify the fraudulent bank details.

Extra layer of protection

FInally, lawyers are told they should ‘never ever’ send out our bank details in open emails but rather in in a password protected attachment with the password sent by separate email. ‘It may sound simple but it should act as an extra layer of protection and is something that is certainly worth doing,’ concluded Ms Squire.

Email your news and story ideas to: [email protected]

The Global Legal Post

© 2026 The Global Legal Post. All Rights Reserved

Top