Our Practice Advice Service answers a question around identifying a potential cyber attack
I am acting on the sale of a property which is due to complete tomorrow. My client has emailed me today informing me of a change of bank account details for the net sale proceeds to be sent. My client’s engagement letter specifically states that we will not accept an unverified change of bank details. In view of this, how should I proceed?
The first thing to consider is whether this email is genuinely from your client as there is a risk that this is a cybersecurity attack. This is commonly referred to as a ‘Friday afternoon fraud’. Fraudsters intercepting emails via insertion of malware between solicitors and their clients are the most common type of attacks.
The Law Society’s guidance on How to identify a cyber attack sets out how to recognise Friday afternoon fraud in point 2.
You should check communications are genuine if:
- you receive unusual instructions that appear to have come from your client
- you receive instructions that change at short notice, for example you’re sent new bank details
- your client’s bank contacts you to report a security breach and asks for their account details.
It’s vital to ascertain that the email was sent from your client. To do this you should telephone the client from their contact number given at the beginning of the transaction and not contact them from the email address in question. You should also remind your client that email changes are unacceptable as per the terms of your client engagement letter.
Make sure you take time to verify the client’s details and check the bank details obtained either face to face or from original documents already held on file. As a precautionary measure, you may also wish to make a ‘test’ payment of £1 on completion to ensure this is received by your client before transferring the whole net sale proceeds.
If it transpires the email is fraudulent, you will need to consider your reporting obligations to the relevant authorities.
For further information on, please see the Law Society’s guidance on How to identify a cyber attack and Chapter A25 of the Law Society’s Conveyancing Handbook (32nd edition) which is available for purchase from Law Society’s online bookshop.
While every effort has been made to ensure the accuracy of the information in this article, it does not constitute legal advice and cannot be relied upon as such. The Law Society does not accept any responsibility for liabilities arising as a result of reliance upon the information given.
This article is compiled by the Law Society’s Practice Advice Service. Comments relating to the questions should be sent to practiceadvice@lawsociety.org.uk














