Manav.id
Compliance · 5 min read

The phantom client and the trust account: the fraud your cyber policy does not cover

The phantom client and the trust account: the fraud your cyber policy does not cover

There is a fraud designed specifically for law firms, and it works because of a duty rather than despite one. A lawyer must act on client instruction. The scheme supplies a client, a matter, a counterparty and a settlement — all of them the same person — and the firm's obligation does the rest.

Why doesn't cyber insurance cover a trust account loss?

Because many policies specifically exclude funds held in trust. State bars have warned about schemes where a fraudster plays both sides of a matter to move money through a firm's trust account, and the firm discovers at the claim that the one account it is strictly liable for is the one carved out.

Key takeaways
  • State bars issued renewed warnings in 2026 about phantom-client schemes moving money through attorney trust accounts.
  • Many cyber policies exclude funds held in trust or escrow, so the loss is restored from partner capital rather than from insurance.
  • The fraud has six decision points. Existing controls address two of them, and the two they address are not the ones that matter.

How it presents

Fraudster plays both sidesclient and counterpartymanufactured matterFunds arrive in trustapparently clearedDisbursement instructedbefore the funds settleLoss falls on the firmcyber policy excludes trust funds
Every step is a normal engagement. The exclusion is discovered at the end.

The matter arrives looking ordinary. A prospective client, often from another jurisdiction, needs help with a commercial dispute, a collection, or a settlement that is already substantially agreed. The engagement is straightforward, the fee is reasonable, and the work is genuinely light.

A settlement is reached quickly. Funds arrive into the firm's trust account — a cashier's cheque, a wire, sometimes both. The client instructs disbursement to a third party, net of the firm's fee.

The firm disburses. Days later the incoming instrument is dishonoured, or the wire is reversed as fraudulent, and the outgoing funds are gone. The firm has paid out its own money on the strength of an instruction from a person who does not exist.

Why the duty is the vulnerability

Under Model Rule 1.15 and its state analogues, a lawyer holds client property separately and must deliver funds the client is entitled to receive promptly. That obligation is not optional and it is not negotiable.

The scheme is engineered against it. Delay is characterised as a breach of duty. Scrutiny is characterised as distrust. And the instruction — the thing that triggers the disbursement — arrives by email from a relationship that was constructed entirely through email.

The six decision points

Where the fraud can be interrupted, and what currently addresses each.
#Decision pointExisting controlAdequate?
1Accept the engagementConflicts check, intake screeningPartially — screens conflicts, not fabrication
2Verify the client's identityID collection at intake, sometimesWeak — collected, rarely verified, never bound to later instructions
3Accept incoming fundsBank clearance policyPartially — addresses instrument risk, not identity
4Accept the disbursement instructionEmail from the clientNone
5Verify the payee detailsCallback, sometimesWeak — callback to a number from the same relationship
6Release the fundsPartner authorisationPartially — authorises the act, does not verify the instruction

Points four and five carry the loss and have the weakest controls. Points one and three, where most firm effort goes, cannot stop a well-constructed scheme.

The insurance position, stated carefully

This varies by carrier and by endorsement and no firm should rely on a general statement, including this one. Read your own policy.

That said, a common structure in law firm cyber policies excludes funds held in a fiduciary capacity for others — trust and escrow funds — from social engineering and funds transfer fraud coverage. The reasoning from the carrier's side is coherent: those funds are not the firm's own money, and the exposure is enormous relative to the firm's revenue.

The consequence for the firm is that a loss at decision point four is restored from partner capital, with a bar complaint and a client protection fund claim alongside it.

The control that addresses point four

The instruction needs to come from a verified principal rather than from an email address. Concretely:

  1. At intake, the client enrols a credential. This is a one-time act that takes a minute and can be done remotely.
  2. Every disbursement instruction is presented to the client as a canonical statement rendering the full payee name, the full account and routing details, and the amount — unmasked.
  3. The client signs it with the enrolled credential.
  4. The firm verifies the signature before releasing. The callback disappears from the critical path, because there is nothing to call about.

A fabricated client can still enrol a credential. What they cannot do is produce a signature that the firm did not solicit against a specific rendered instruction — which means the scheme loses its ability to redirect an instruction after the fact, and the firm acquires a record of exactly what the client authorised.

On rendering account details unmasked

Masking account numbers in the confirmation screen is a habit imported from consumer banking interfaces. In this context it is harmful. A client confirming a payee whose account shows as four visible digits has confirmed almost nothing, and the digits an attacker alters are precisely the ones hidden.

What to do this week

  1. Read your cyber policy for a funds-held-in-trust exclusion. Do this before anything else; it changes the size of the problem.
  2. Map your last twelve months of trust disbursements against the six decision points.
  3. Identify how many disbursement instructions arrived solely by email.
  4. Pick the threshold above which you will require a signed instruction, using the value distribution rather than a round number.

Why the trust account is uniquely exposed

Three properties that compound
PropertyEffect
Strict professional liabilityThe firm is responsible regardless of fault
Fast disbursement expectationClosings and settlements run to a clock
Frequently excluded from cyber coverNo risk transfer
Instructions arrive by emailSame weakness as every other payment channel

Objections and honest limits

“Our professional indemnity policy responds.” Sometimes, partially, and with its own exclusions and deductible. The point is to read both policies against this specific scenario before it occurs rather than after.

“We verify all disbursement instructions.” If the verification channel came from the instruction, it verified the fraudster. And in a manufactured matter the ‘client’ confirms enthusiastically.

Hardening trust disbursement

  1. Read the trust fund exclusion in your cyber policy. Before the loss, and with your broker.
  2. Require a bound signature on every disbursement. From the responsible lawyer, over the rendered destination.
  3. Never disburse against uncleared funds. The manufactured matter depends on this.
  4. Verify the client through a channel established at intake. Not one supplied with the instruction.

Terms used here

Client trust account
An account holding client money, subject to strict professional rules and personal responsibility.
Manufactured matter
A fabricated engagement where the fraudster controls both sides, used to move funds through a firm.
Social engineering exclusion
Policy language removing cover for losses where the insured was induced to transfer voluntarily.

Frequently asked questions

Does this stop the fraud entirely? It closes the point where the loss occurs — an unverified disbursement instruction. It does not prevent a fabricated client from engaging the firm, which is decision point one and requires different controls.

Is the insurance exclusion universal? No. It is common and varies by carrier and endorsement. Read your own policy and ask your broker directly about funds held in a fiduciary capacity.

Will clients accept enrolment? Enrolment is a one-minute act at intake, at the moment the client is most motivated. Firms that have tried it report the friction is at the firm's end, not the client's.

What about long-standing clients we know personally? Those are the accounts where email compromise does the most damage, because familiarity suppresses scrutiny. Enrol them too.

Why are trust funds excluded from cyber cover? Insurers treat them as a distinct exposure with its own rules and severity, and many policies carve them out explicitly.

What makes a manufactured matter effective? The fraudster controls both sides, so every verification the firm attempts is answered enthusiastically by the fraudster.

What is the single most effective control? Never disbursing against uncleared funds. The scheme depends on the timing gap.

Where this fits in Manav

Manav binds the authorising person to the exact instruction, filing or declaration, and produces a receipt a court, an opposing party or a bar regulator can verify without access to the firm's systems.

See legal receipts →

Sources and further reading