Payment redirection fraud happens when a scammer convinces someone to pay money into the wrong bank account, usually with an email that appears to come from a client, another firm or a supplier. Law firms are a natural target because they move large sums for settlements, estates and trust distributions.
A few simple procedures stop most attempts. This article explains how the scam works and what your firm can put in place.
How payment redirection fraud works
Most attempts follow the same pattern:
- A scammer gets into an email account, either your firm’s, your client’s or the other party’s, often through a phishing email that collects a password
- They read the email history quietly and learn when a payment is due
- Close to settlement or payment, they send an email with “updated” bank details, either from the real account or from an address that looks almost the same
- Some follow up with a phone call to make the request seem genuine
The Law Society Journal described a case where a finance manager acted on changed bank details received through a compromised email account, after the scammer followed up by phone pretending to be the client. The practice suffered a significant loss and had to restore the shortfall in its trust account.
The call-back check

The most effective control is a procedure rather than a piece of software. Before acting on any new or changed bank details, someone calls the client or recipient on a phone number you already hold, not the number in the email, and confirms the details out loud.
To make it work in practice:
- Write it down as a firm rule, so no one has to decide in the moment whether it applies
- Record who made the call, when, and which number they used
- Apply it to every change, including requests that seem to come from a partner or a long-standing client
- Tell clients at engagement that your bank details will never change by email, and that they should call you if they receive an email saying otherwise
The Law Society of NSW now lists independent verification of bank details, using trusted methods rather than email alone, as a baseline expectation for trust account management.
Make email harder to take over
Most redirection scams start with a compromised mailbox. These controls make that much harder:
- Multi-factor authentication on every Microsoft 365 account, so a stolen password alone is not enough
- Email filtering that catches phishing links and look-alike domains
- SPF, DKIM and DMARC records on your domain, so scammers find it harder to send email that appears to come from your firm
- Alerts when a mailbox creates forwarding rules, which scammers often use to hide replies from the real owner
Train the people who handle payments

Staff who process payments should know what a redirection attempt looks like and feel comfortable slowing down. Short phishing simulations and regular reminders work better than one long session a year.
The warning signs include urgency, a change of bank details close to settlement, an email address that is slightly different, and a request to keep the change quiet.
Add approval steps for large payments
Two-person approval for trust payments above a set amount gives a second chance to spot a problem. Most banking platforms can enforce this, so it does not rely on anyone remembering.
What to do if a payment has gone to the wrong account
Act straight away, because the sooner the bank knows, the better the chance of recovering the money.
- Call your bank and ask them to contact the receiving bank to recall the payment.
- Lock the affected email account and change its password, then check for forwarding rules and unfamiliar sign-ins.
- Call your IT provider to work out how the scammer got in and what else they accessed.
- Report it through ReportCyber and check your reporting obligations to the Law Society if trust money is involved.
- Tell the affected client and your professional indemnity insurer.
How Digitek helps
Digitek IT sets up multi-factor authentication, email filtering and DMARC for law firms, runs phishing training and simulations, and helps you put a call-back check in place before any change to bank details.
If something does go wrong, we help secure the affected accounts, work out what was accessed and restore data where needed.
Find out more about our IT support for law firms and cyber security services, or call 02 4504 8643.






