The phantom client and the trust account: the fraud your cyber policy does not cover
There is a fraud designed specifically for law firms, and it works because of a duty rather than despite one. A lawyer must act on client instruction. The scheme supplies a client, a matter, a counterparty and a settlement — all of them the same person — and the firm's obligation does the rest.
Why doesn't cyber insurance cover a trust account loss?
Because many policies specifically exclude funds held in trust. State bars have warned about schemes where a fraudster plays both sides of a matter to move money through a firm's trust account, and the firm discovers at the claim that the one account it is strictly liable for is the one carved out.
- State bars issued renewed warnings in 2026 about phantom-client schemes moving money through attorney trust accounts.
- Many cyber policies exclude funds held in trust or escrow, so the loss is restored from partner capital rather than from insurance.
- The fraud has six decision points. Existing controls address two of them, and the two they address are not the ones that matter.
Part of Courts and fiduciary identity
How it presents
The matter arrives looking ordinary. A prospective client, often from another jurisdiction, needs help with a commercial dispute, a collection, or a settlement that is already substantially agreed. The engagement is straightforward, the fee is reasonable, and the work is genuinely light.
A settlement is reached quickly. Funds arrive into the firm's trust account — a cashier's cheque, a wire, sometimes both. The client instructs disbursement to a third party, net of the firm's fee.
The firm disburses. Days later the incoming instrument is dishonoured, or the wire is reversed as fraudulent, and the outgoing funds are gone. The firm has paid out its own money on the strength of an instruction from a person who does not exist.
Why the duty is the vulnerability
Under Model Rule 1.15 and its state analogues, a lawyer holds client property separately and must deliver funds the client is entitled to receive promptly. That obligation is not optional and it is not negotiable.
The scheme is engineered against it. Delay is characterised as a breach of duty. Scrutiny is characterised as distrust. And the instruction — the thing that triggers the disbursement — arrives by email from a relationship that was constructed entirely through email.
The six decision points
| # | Decision point | Existing control | Adequate? |
|---|---|---|---|
| 1 | Accept the engagement | Conflicts check, intake screening | Partially — screens conflicts, not fabrication |
| 2 | Verify the client's identity | ID collection at intake, sometimes | Weak — collected, rarely verified, never bound to later instructions |
| 3 | Accept incoming funds | Bank clearance policy | Partially — addresses instrument risk, not identity |
| 4 | Accept the disbursement instruction | Email from the client | None |
| 5 | Verify the payee details | Callback, sometimes | Weak — callback to a number from the same relationship |
| 6 | Release the funds | Partner authorisation | Partially — authorises the act, does not verify the instruction |
Points four and five carry the loss and have the weakest controls. Points one and three, where most firm effort goes, cannot stop a well-constructed scheme.
The insurance position, stated carefully
This varies by carrier and by endorsement and no firm should rely on a general statement, including this one. Read your own policy.
That said, a common structure in law firm cyber policies excludes funds held in a fiduciary capacity for others — trust and escrow funds — from social engineering and funds transfer fraud coverage. The reasoning from the carrier's side is coherent: those funds are not the firm's own money, and the exposure is enormous relative to the firm's revenue.
The consequence for the firm is that a loss at decision point four is restored from partner capital, with a bar complaint and a client protection fund claim alongside it.
The control that addresses point four
The instruction needs to come from a verified principal rather than from an email address. Concretely:
- At intake, the client enrols a credential. This is a one-time act that takes a minute and can be done remotely.
- Every disbursement instruction is presented to the client as a canonical statement rendering the full payee name, the full account and routing details, and the amount — unmasked.
- The client signs it with the enrolled credential.
- The firm verifies the signature before releasing. The callback disappears from the critical path, because there is nothing to call about.
A fabricated client can still enrol a credential. What they cannot do is produce a signature that the firm did not solicit against a specific rendered instruction — which means the scheme loses its ability to redirect an instruction after the fact, and the firm acquires a record of exactly what the client authorised.
On rendering account details unmasked
Masking account numbers in the confirmation screen is a habit imported from consumer banking interfaces. In this context it is harmful. A client confirming a payee whose account shows as four visible digits has confirmed almost nothing, and the digits an attacker alters are precisely the ones hidden.
What to do this week
- Read your cyber policy for a funds-held-in-trust exclusion. Do this before anything else; it changes the size of the problem.
- Map your last twelve months of trust disbursements against the six decision points.
- Identify how many disbursement instructions arrived solely by email.
- Pick the threshold above which you will require a signed instruction, using the value distribution rather than a round number.
Why the trust account is uniquely exposed
| Property | Effect |
|---|---|
| Strict professional liability | The firm is responsible regardless of fault |
| Fast disbursement expectation | Closings and settlements run to a clock |
| Frequently excluded from cyber cover | No risk transfer |
| Instructions arrive by email | Same weakness as every other payment channel |
Objections and honest limits
“Our professional indemnity policy responds.” Sometimes, partially, and with its own exclusions and deductible. The point is to read both policies against this specific scenario before it occurs rather than after.
“We verify all disbursement instructions.” If the verification channel came from the instruction, it verified the fraudster. And in a manufactured matter the ‘client’ confirms enthusiastically.
Hardening trust disbursement
- Read the trust fund exclusion in your cyber policy. Before the loss, and with your broker.
- Require a bound signature on every disbursement. From the responsible lawyer, over the rendered destination.
- Never disburse against uncleared funds. The manufactured matter depends on this.
- Verify the client through a channel established at intake. Not one supplied with the instruction.
Terms used here
- Client trust account
- An account holding client money, subject to strict professional rules and personal responsibility.
- Manufactured matter
- A fabricated engagement where the fraudster controls both sides, used to move funds through a firm.
- Social engineering exclusion
- Policy language removing cover for losses where the insured was induced to transfer voluntarily.
Frequently asked questions
Does this stop the fraud entirely? It closes the point where the loss occurs — an unverified disbursement instruction. It does not prevent a fabricated client from engaging the firm, which is decision point one and requires different controls.
Is the insurance exclusion universal? No. It is common and varies by carrier and endorsement. Read your own policy and ask your broker directly about funds held in a fiduciary capacity.
Will clients accept enrolment? Enrolment is a one-minute act at intake, at the moment the client is most motivated. Firms that have tried it report the friction is at the firm's end, not the client's.
What about long-standing clients we know personally? Those are the accounts where email compromise does the most damage, because familiarity suppresses scrutiny. Enrol them too.
Why are trust funds excluded from cyber cover? Insurers treat them as a distinct exposure with its own rules and severity, and many policies carve them out explicitly.
What makes a manufactured matter effective? The fraudster controls both sides, so every verification the firm attempts is answered enthusiastically by the fraudster.
What is the single most effective control? Never disbursing against uncleared funds. The scheme depends on the timing gap.
Where this fits in Manav
Manav binds the authorising person to the exact instruction, filing or declaration, and produces a receipt a court, an opposing party or a bar regulator can verify without access to the firm's systems.
Sources and further reading
- ABA Model Rules of Professional Conduct — Rule 1.15 safekeeping property
- ABA guidance on lawyer liability for wire transfer fraud.
- ABA Model Rule 1.15 — safekeeping property, and state analogues.
- FBI IC3 2025 Internet Crime Report