Manav.id
Regulated ยท 17 min read

The client trust account is a target with a compliance obligation attached

Every other business that loses money to a forged payment instruction has a bad quarter. A law firm that loses client money from trust has a bad quarter, a bar complaint, and a duty to make the client whole. The instruction that moves the money arrives by email, and almost nobody is checking the thing that actually matters.

It is a Thursday afternoon and a closing is scheduled for Friday morning. The paralegal handling the file has a client who has been responsive all week, a purchase price sitting in the firm's trust account, and a payee whose details were confirmed ten days ago. At 4:40pm an email lands in the thread that has carried this matter since June. Same subject line. Same signature block. Same slightly clipped tone the client has used throughout.

The bank the seller uses has flagged the receiving account for a routine compliance review, the message says, and rather than delay the closing they have arranged an alternative account at a different institution. Revised instructions are attached on the seller's letterhead. The client apologises for the timing.

The paralegal does the right thing. She does not simply act on the attachment. She picks up the phone and calls the number in the email footer to confirm, gets the person she expects, hears a voice she has heard before, and receives an unremarkable confirmation. She notes the call in the file, which is exactly what her firm's procedure requires. On Friday morning the funds go out.

On Monday the seller's counsel calls to ask where the money is.

Nothing in that sequence was careless. The procedure was followed. The call was made. The file was noted. And the loss is total, because a wire is final, and because the number she called had been in the attacker's control since the mailbox was compromised in July.

Short answer. Law firms prevent trust account wire fraud by making the disbursement instruction itself unforgeable, rather than by judging the email that carried it. The release instruction is signed by the enrolled client or counsel of record on their own device, covering the matter, the payee, the account and the amount, and the accounting system refuses to disburse without a valid signature. A compromised mailbox can send a request. It cannot produce the signature.

Why is a trust account different from an ordinary business account?

Because the money is not the firm's, and the rules governing it are written in the language of duty rather than the language of risk management.

Under the American Bar Association's Model Rule 1.15 and the state trust accounting rules that follow it, a lawyer holding property of a client or third person must keep it separate from the lawyer's own property, must maintain complete records, and must deliver funds promptly to the person entitled to receive them. The obligation is not calibrated to the sophistication of the attack. It does not ask whether the lawyer was tricked cleverly. It is a duty of safekeeping, and duties of safekeeping tend to be assessed by asking whether the property is safe, which in this scenario it conspicuously is not.

Compare that to the same fraud in a corporate accounts payable department. A manufacturer that wires a payment to an impostor has lost its own money. It writes off the loss, files an insurance claim, tightens a process, and holds an uncomfortable meeting. The consequences are financial and they stop there. The people involved may keep their jobs.

A law firm in the same position has lost someone else's money from an account it holds in trust, which raises three separate problems at once. There is the loss, which in many jurisdictions the firm is expected to make good regardless of fault, and which for a closing or a settlement is routinely a seven figure sum against a partnership balance sheet that was never designed to absorb one. There is the regulatory exposure, because trust account irregularities attract disciplinary attention in a way that ordinary commercial losses do not. And there is the professional liability claim from a client who has just discovered that their house deposit or their settlement award is in an account in another country.

This is why the topic deserves separate treatment rather than being filed under business email compromise generally. The attack is the same. The blast radius is not.

The escrow agent has the same problem without the law degree

Title and escrow companies, paying agents, and the escrow arms of banks all sit in the identical position: holding other people's money, releasing it on instruction, and bearing a duty defined by the escrow agreement and by general fiduciary principles. An escrow agent who disburses on a forged instruction has, depending on the agreement and the jurisdiction, failed to perform. The escrow agreement almost always contains language about acting on instructions believed to be genuine, and the fight afterwards is about the word believed.

How does the attack actually run?

There are three recognisable settings, and they share one structural feature that makes them all work.

The closing

A real estate closing has a fixed date, multiple parties who mostly do not know each other, a large sum in motion, and an email thread that everyone treats as the system of record. The attacker compromises any one mailbox in that thread, which may be the buyer's personal account, the seller's agent, the mortgage broker, or the firm itself, and then waits. They do not act immediately. They read until they understand the timeline, the amounts, the personalities and the vocabulary. Then, close enough to the closing date that a delay would be painful, they send revised wiring instructions.

The FBI's Internet Crime Complaint Center recorded roughly 275 million dollars in reported real estate wire fraud losses across more than twelve thousand complaints in 2025, as compiled in industry reporting by CertifID from IC3 data. That figure is the closest measured neighbour to the problem in this post and it is worth reading carefully: it is reported losses only, from complaints actually filed, in one transaction category.

The settlement disbursement

A litigation matter resolves and the firm holds the settlement in trust pending distribution to the client, lienholders and counsel. The client, who may be an individual with no institutional security posture at all, emails updated banking details because they have changed banks, or moved, or because someone reading their mailbox says they have. The amount is large, the client is entitled to it, and the firm's instinct is to pay promptly, which is itself a professional obligation.

The deal escrow

An acquisition closes and the purchase price, or an indemnity holdback, sits with a paying agent pending release. The release instruction arrives from a compromised counsel mailbox during the final hours of a transaction where everyone is exhausted, several parties are in different time zones, and the cost of asking an obvious question is social rather than financial. Deal escrows are routinely eight figures.

The shared feature

In all three, the money is released on the strength of a message whose authenticity is judged by the channel it arrived through. The attacker does not need to break any cryptography, forge any signature, or defeat any control. They need to be inside a mailbox that the recipient already trusts, and then to write a plausible paragraph. That is the whole attack.

What do we actually know about the size of this?

Less than the vendors selling into it would like you to believe, and it is worth being straight about that.

Business email compromise as a whole accounted for roughly 3.05 billion dollars in reported United States losses across 24,768 complaints in 2025, according to the FBI's Internet Crime Complaint Center, with the overwhelming majority of that money moving by wire or ACH. Real estate wire fraud, as noted, is the best measured adjacent category.

There is no reliable separate national figure for law firm trust account losses. That is not an oversight in this article, it is a fact about the evidence base, and the reasons are instructive. Losses are frequently settled confidentially between a firm, its insurer and its client, because everyone involved has an interest in it not becoming a public matter. Disciplinary outcomes are published inconsistently across jurisdictions and often describe the accounting consequence rather than the attack. Insurers hold claims data that they do not publish. And the incentive on a firm that has just repaid a client is to say nothing at all.

So the honest position is this: the category is large enough that state bars and title underwriters have issued repeated guidance about it, and small enough in published data that anyone quoting a precise national total for trust account fraud should be asked where it came from. The per incident number is the one that matters for a firm's decision making, and the per incident number is the size of the largest disbursement you handle.

Why does the callback fail exactly when it matters most?

Verbal verification is the standard advice from every bar association, title underwriter and malpractice carrier that has written on this subject, and the advice is not wrong. It is simply weaker than its reputation, and it is weakest under precisely the conditions of a closing.

There are four distinct failure modes and they compound.

The number comes from the attacker. This is the most common and the most avoidable. If the phone number is taken from the email signature, the attachment, the website linked in the message, or anywhere else inside the attacker's reach, the callback is a conversation with the fraudster. The advice has always been to use an independently sourced number, from the engagement letter or an earlier record, and the advice is frequently not followed because the number in the footer is right there and the closing is tomorrow.

Caller identification proves nothing. Displayed numbers are trivially spoofable. Even where carrier level authentication is in place, it attests to how a call entered the network, not to who is speaking.

Voice is no longer evidence. This is the change that has broken the control conceptually rather than incrementally. Recognising a familiar voice was, for decades, a genuinely strong signal between people who had spoken before. Synthesis from a short sample has removed that. A paralegal who has spoken to a client six times and is confident she recognises them is now relying on a signal that can be manufactured.

The human factors are all wrong. The callback is performed by someone under time pressure, whose professional purpose is to complete the transaction rather than to obstruct it, often speaking to a party they have never met, about details they have no independent way to check, in a conversation where the socially expensive move is to express doubt. Ask any experienced paralegal how it feels to tell a client you cannot proceed because you are not sure they are who they say they are.

We wrote a fuller teardown of this control in Call to verify, the number came from the fraud. The short version for this audience: keep doing callbacks, document them, source the number independently, and stop treating a completed callback as a verification. It is a deterrent against unsophisticated attempts and a record that you tried.

What about two person release?

Dual authorisation on trust disbursements is real and worthwhile, and it fails in a specific way that firms rarely consider. It was designed against internal misappropriation, where the threat model is one dishonest person, and it works well for that. Against a forged instruction it does not help, because both authorisers are looking at the same forged instruction and neither has any independent means of checking it. Two people agreeing that an email looks fine is one judgment, made twice. We covered the general form of this failure in Dual control is not dual when both approvers are behind the same phishing kit.

What is actually being authorized here?

This is the reframing that makes the problem tractable, and it is worth going slowly.

Firms tend to think of trust account security as an accounting discipline. Reconciliations, three way matching, segregated ledgers, records retention, the machinery that bar rules prescribe. All of that is necessary and none of it addresses this attack, because every one of those controls operates on a disbursement that has already been authorised. Reconciliation will tell you, accurately and promptly, that the money left. It will not tell you it should not have.

The authorisation event is the release instruction. That is the moment where a decision is made about whether a particular sum leaves the account and where it goes. Everything before it is preparation and everything after it is bookkeeping.

And that moment is currently represented by an email. Not by a signed document, not by a verified instruction, not by anything with cryptographic properties. By a message in a mailbox, evaluated by a human on the basis of plausibility.

Here is the analogy worth holding on to. Imagine a bank that kept immaculate records, reconciled to the penny every night, retained everything for seven years, and let anyone who could produce a convincing handwritten note withdraw from any account. The record keeping would be genuinely excellent. It would also be entirely beside the point, because the authorisation step in the middle is doing no work. That is the current state of trust disbursement at most firms: rigorous on both sides of a decision that rests on a plausible paragraph.

How does a signed release instruction work?

The control is to make the instruction itself something only the right human can produce, and to make the accounting system enforce it.

The client or counsel of record enrols a device once. When a disbursement is required, the instruction is not an email; it is a request the enrolled party signs on their own device, and what they sign is the specific detail of the disbursement rather than a general approval.

Here is what the signed payload contains, conceptually:

release_instruction = {
  "matter_id":      "2026-CLS-4471",
  "matter_name":    "Purchase, 14 Oakfield Road",
  "trust_account":  "IOLTA-***-8820",
  "payee_name":     "Marchmont Title Services LLC",
  "payee_account":  "****3391",
  "payee_routing":  "****0027",
  "amount":         "412750.00",
  "currency":       "USD",
  "not_valid_after":"2026-10-02T17:00:00Z"
}

digest = SHA-256(canonical_json(release_instruction))
signature = sign_on_enrolled_device(digest)   # WebAuthn assertion

Three properties of that block matter more than the syntax.

First, the signature covers the payee account and the amount. It is not an approval of a matter or a session or a login. If any digit of the receiving account changes, the digest changes, and the signature is invalid. There is no version of this where an attacker alters the destination of a signed instruction and it still verifies.

Second, the signature is produced on a device the enrolled party controls, using a private key that never leaves it. Compromising the client's mailbox gives an attacker the ability to send messages. It does not give them the device.

Third, the resulting receipt verifies offline. The escrow platform, the firm's accounting system, the malpractice carrier and, if it ever comes to it, a court, can each check the signature against a published key without calling anybody. That property matters enormously in a dispute, because the artifact does not depend on the firm's own logs of what the firm says happened.

The enforcement side is short:

def disburse(instruction, receipt):
    if not receipt:
        raise Blocked("no signed instruction on file")
    if not verify_ed25519(receipt.signature,
                          sha256(canonical_json(instruction)),
                          published_key):
        raise Blocked("signature does not match this instruction")
    if receipt.signer not in matter.authorised_parties:
        raise Blocked("signer is not counsel of record or client")
    if now() > instruction.not_valid_after:
        raise Blocked("instruction expired, re-sign required")
    return send_wire(instruction)

Note what the accounting system is doing. It is not evaluating whether the instruction seems reasonable. It is checking a fact. Either a signature over these exact details exists from an enrolled party on this matter, or the disbursement does not happen. There is no judgment call left in the money path, which is the entire objective, because the judgment call is the part that fails at 4:40pm on a Thursday.

The same attack, replayed

Return to the opening scene. The attacker still owns the mailbox. They still send the revised instructions. The paralegal still receives them, and may still make the call, and may still hear the same convincing voice.

But the accounting system will not release funds against an email. It requires a signed instruction naming the payee account, and the only party who can produce one is the client on the device they enrolled at engagement. The attacker can ask for a signature. They cannot generate one. If they persuade the client to sign, the client is signing a screen that displays the actual destination account, on their own phone, away from the email thread, which is a materially different act from replying yes to a message.

The wire does not leave. Not because anybody spotted the fraud, but because the fraud could not produce the thing the system required.

Where does enrolment happen?

The obvious objection to any scheme requiring enrolled parties is that legal matters involve people who are not enrolled and will not be. It is a fair objection and it has a straightforward answer for the party that matters most.

The engagement letter is the natural enrolment moment. It is the one point in a matter where the firm and the client are already exchanging formalities, where the client expects administrative steps, and where nothing is time critical. Adding a device enrolment to that process costs the client about thirty seconds and costs the firm one line in an existing workflow.

For transactional matters the equivalent moment is the signing of the transaction documents, where all the parties are already present and already executing formalities.

What you get from enrolling at engagement is that by the time a disbursement is contemplated, months later, under pressure, the control is already in place and nobody is scrambling to set something up on closing morning. The whole design fails if enrolment happens when the money is moving.

Which control resists which failure?

Here is the honest comparison across the four failure modes described above.

ControlAttacker supplied numberSpoofed caller IDCloned voiceClosing time pressure
Callback to number in the emailNoNoNoNo
Callback to independently sourced numberYesPartlyNoNo
Two person release, same instructionNoNoNoPartly
Waiting period before new payee usePartlyPartlyPartlyYes
Signed release instruction from enrolled partyYesYesYesYes

The waiting period row deserves a note, because it is the most underrated control in this table and it costs nothing. A rule that a newly added payee account cannot receive funds for a defined period defeats the entire class of attacks that depend on a last minute change, which is most of them. It is blunt, it is annoying, and it works. Any firm that reads this article and implements only the waiting period will have improved its position materially.

Honest limits

A signed release instruction is a narrow control and it is worth being precise about what it does not do.

It does not help with parties who are not enrolled. Multi party transactions involve opposing counsel, agents, lenders and unrepresented individuals. You can require signatures from your own client and your own authorised staff. You cannot unilaterally require them from the other side of a deal, and until enrolment is common the practical position is a mixed one where some instructions are signed and some are not.

It does not address paper. Some closings still run on paper, some jurisdictions require it, and a signed digital instruction has no bearing on a physical document handed across a table.

It does not stop a client who genuinely instructs a bad payment. If a client is defrauded elsewhere and sincerely directs funds to an attacker, they will sign, and the signature will be valid, because it was. This control establishes that the instruction came from the right human. It does not evaluate whether the human was right.

It does not prevent internal misappropriation by an enrolled person. A partner with signing authority who steals from trust will sign a valid instruction. Dual authorisation, reconciliation and bar oversight remain the controls for that threat, and this does not replace them.

Manav has not built legal platform connectors. The signing and receipt verification primitives are shipped and available through an API and an embeddable widget, and there is a working demonstration at the signing lab. Integrations with practice management and escrow platforms do not exist today, which means adopting this now means either an API integration by your platform vendor or a manual step alongside your existing process.

None of this is legal advice. Trust accounting obligations vary by jurisdiction, and whether any control satisfies your bar's rules is a question for your bar and your professional liability carrier, not for a technology article.

What to do this week

  1. Impose a payee waiting period. No newly added or newly changed payee account receives funds from trust for a defined period, with no exceptions granted by anyone below the managing partner. This is free, it is a policy change rather than a purchase, and it defeats the timing that most of these attacks depend on.
  2. Ban numbers sourced from the message. Write it down as a rule: verification numbers come from the engagement letter or the matter file, never from the email, the attachment, or a website linked in either. Audit five recent files to see whether this actually happened.
  3. Find your largest single disbursement of the last twelve months. That number, not a national statistic, is your exposure. Take it to your next partners' meeting.
  4. Add device enrolment to the engagement letter workflow. Even before any signing requirement exists, having clients enrolled means the option is available when you want it.
  5. Read your professional liability policy on social engineering. Specifically, whether funds transfer fraud is covered, at what sublimit, and whether coverage is conditioned on controls you may not have. Carriers have been narrowing here.
  6. Ask your practice management and escrow vendors one question. Can a disbursement be blocked in your system unless a cryptographic signature over the payee details is present? Their answer will tell you where they are.
  7. Run a tabletop on the scene at the top of this article. Walk your closing team through it and stop at each step to ask what would have caught it. The discomfort is the point.

Technical readers evaluating the mechanics will find the signing and offline verification model in the developer documentation.

Frequently asked questions

How do law firms prevent trust account wire fraud? By requiring the disbursement instruction to be signed by the enrolled client or counsel of record on their own device, covering the matter, payee account and amount, and configuring the accounting system to refuse unsigned instructions regardless of which mailbox they arrived from. Callbacks and reconciliation remain useful, but neither can establish that an email is genuine.

Is a lawyer liable for trust funds wired to a fraudster? That depends on the jurisdiction, the facts and the professional conduct rules that apply, and it is a question for your bar and your carrier. What can be said generally is that duties of safekeeping under rules modelled on ABA Model Rule 1.15 are demanding, and that many firms have concluded they must make clients whole irrespective of how sophisticated the deception was.

Does a callback to a known number solve this? It helps and it is not sufficient. A callback to an independently sourced number defeats attacks that rely on supplying their own contact details, which is a real improvement. It does not survive caller identification spoofing or voice synthesis, and it is performed under exactly the time pressure that degrades human judgment.

What is the difference between this and two person authorisation? Two person authorisation was designed against internal theft and works reasonably well for it. Against a forged instruction, both authorisers evaluate the same forged document with no independent means of checking it, so the control provides one judgment made twice rather than two independent judgments.

Can escrow agents use the same control? Yes, and the fit is arguably better, because escrow agents disburse on instruction as their core function and typically have a defined set of parties per transaction. The release endpoint in an escrow platform is the natural place to require a signature over the payee and amount.

What if the client does not have a smartphone? Then you need a documented alternative path, and that path should be slower and more heavily verified rather than simply exempted. Any control with an easy exception becomes the exception, and attackers will find it faster than your clients will.

Does a signed instruction have legal effect? A cryptographic signature is evidence about who authorised something and what they authorised. Whether it satisfies a particular legal or regulatory requirement is a separate question governed by the applicable law and rules, and should be confirmed with counsel and with your bar rather than assumed.

Sources

  1. FBI Internet Crime Complaint Center, 2025 Internet Crime Report, for business email compromise totals and complaint counts: ic3.gov annual reports
  2. CertifID, State of Wire Fraud reporting, compiling IC3 data on real estate wire fraud losses and complaint volumes: certifid.com
  3. American Bar Association, Model Rules of Professional Conduct, Rule 1.15 Safekeeping Property: americanbar.org model rules
  4. American Land Title Association, guidance and best practices for title and settlement companies on wire fraud: alta.org
  5. Uniform Commercial Code Article 4A, governing funds transfers and the allocation of loss on unauthorised payment orders: law.cornell.edu UCC 4A
  6. Federal Communications Commission materials on caller identification authentication and its limits: fcc.gov call authentication
Reconciliation tells you the money left. It has never once told you it should not have.