Documented social engineering incidents targeting the legal services sector, sourced and fact-checked.
A federal grand jury in Columbia, South Carolina indicted 12 people on 12 counts (conspiracy, wire fraud, bank fraud, money laundering) for a nationwide BEC ring that monitored hacked/compromised business email accounts, spoofed emails from trusted insiders and vendors to redirect wire payments, and laundered more than $25 million through sham U.S. companies before sending proceeds overseas.
ConfirmedPosing as NatWest bank security, vishing criminals exploited a landline callback delay to convince Surrey solicitor Karen Mackie to wire £734,000 of client money to "safe" accounts, costing her nearly £512,000 unrecovered, her legal career, and ultimately her home and solvency.
ConfirmedeSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns: SEO-poisoned fake "agreement" downloads delivering GootLoader, and a compromised Notary Public website serving a fake Chrome update to deliver SocGholish.
ConfirmedGootLoader operators hijacked Google search rankings for legal-agreement phrases, luring law firm staff to fake forum "direct download" pages that delivered malicious JavaScript loaders, some of which escalated via Cobalt Strike into REvil ransomware attacks, a pattern CFC's Incident Response Team documented after seeing it hit multiple insured legal services firms.
ConfirmedAir Canada admitted in a sworn Ontario Superior Court affidavit that it hired private investigators who twice took trash from outside WestJet co-founder Mark Hill's home (a collection Hill's own affidavit says involved the investigators walking onto his driveway, a claim IPSA disputed) and had shredded documents digitally reconstructed by a Houston forensic firm, as part of its corporate-espionage suit against WestJet, a fight that ended in a CAD 15.5 million WestJet settlement and public apology.
ConfirmedAfter going quiet on March 31, 2025 following a researcher's disruption campaign, Gootloader returned on November 5, 2025 with a glyph-swapping WOFF2 web font to hide malicious filenames and a malformed ZIP archive that extracts a working JScript loader in Windows Explorer but a harmless decoy in 7-Zip, Python, or VirusTotal - spread across 100+ SEO-poisoned sites and thousands of keywords, feeding the Supper SOCKS5 backdoor and, via Storm-0494/Vanilla Tempest, ransomware deployment.