Lawyers occupy a uniquely attractive position for scammers. They handle significant sums of client money, they deal in sensitive information, they operate under professional obligations that can be exploited, and they work in a culture where responding quickly and efficiently to client demands is deeply ingrained. That combination makes attorneys prime targets, and the arrival of sophisticated artificial intelligence tools has dramatically raised the stakes. Scams that once required a human scammer with specific knowledge and language skills can now be generated, personalized, and deployed at scale in seconds. Every attorney and every law firm needs to understand what these schemes look like, how they operate, and what can be done to stop them.
The Fake Client Scam: A Classic That AI Has Supercharged
One of the oldest and most persistent scams targeting lawyers involves fabricated prospective clients, and AI has made it considerably more dangerous. The scheme typically works as follows: an attorney receives unsolicited email correspondence seeking legal representation, often from a business or individual claiming to be located overseas. The prospective client claims to be owed a significant sum of money from a company located in the same city or state as the attorney. Once the attorney agrees to represent the client, the fraudster sends a cashier’s check drawn on a U.S. bank, accompanied by a letter purportedly from the debtor stating that the check represents payment to satisfy the debt. The fraudster then instructs the attorney to deposit the check and wire the proceeds to the overseas client, minus a legal fee.
The check, of course, is counterfeit. The wire transfer is completed before the bank identifies the fraud, and the attorney is left holding the loss. What has changed in the AI era is how convincingly these initial solicitations are crafted. AI tools allow scammers to generate hyper-personalized phishing communications that reference real court cases, recent verdicts, and even ongoing negotiations to make fraudulent requests appear entirely legitimate. Several firms have reported falling victim to information leaks and unauthorized fund transfers after receiving solicitations that seemed indistinguishable from genuine client inquiries.
Business Email Compromise: When the Wire Instructions Change
Business email compromise, commonly called BEC, represents one of the most financially devastating categories of fraud targeting the legal profession. These scams typically involve a compromised email account — which can belong to the attorney, the client, or even the bank — and scammers monitor the account to uncover pending transactions such as a real estate purchase, a loan, or the settlement of a lawsuit. At the appropriate moment, when the parties are expecting a request for funds, the scammers send fraudulent wire instructions. The funds are immediately swept from the account.
In recent incidents, individuals impersonating attorneys have sent emails that appear to originate from legitimate law firms but are in fact transmitted from fraudulent domains that differ from the authentic firm domain by only one or two characters, such as substituting a lowercase letter for an uppercase letter or replacing one letter with a visually similar one. These subtle changes are frequently overlooked during fast-paced settlement negotiations.
The consequences can be severe and personal. In one documented case on the East Coast, hackers took control of an attorney’s email account during active litigation. When a settlement payment came due, the hackers used the compromised account to send fake wire instructions to opposing counsel, redirecting the settlement proceeds to a fraudulent account abroad. The court ultimately held the attorney responsible for failing to exercise ordinary care, and the firm absorbed the loss. A California case made the stakes even clearer: defense counsel wired a $475,000 settlement to a fraudulent account after receiving falsified wire instructions and, critically, attempting to verify them by calling the telephone number contained in the fraudulent email itself rather than an independently verified number. The courts held that the settlement obligation remained unsatisfied and that the firm was responsible for the loss.
AI-Powered Phishing: Personalized, Polished, and Nearly Undetectable
Traditional phishing emails were often identifiable by poor grammar, generic salutations, and unconvincing impersonation. AI has eliminated nearly all of those tells. AI bots now sift through social media profiles, professional biographies, and public legal databases to gather information about a target, then generate communications that impersonate someone known to the recipient, include relevant professional details, and read as fluently and professionally as any legitimate correspondence. These messages routinely bypass spam filters.
Scammers used AI to generate phishing attacks specifically tailored to law firms as early as 2023, and the trend has accelerated sharply since. The messages reference real matters, real parties, and real procedural history in ways that make recipients believe the communication is entirely legitimate.
Courts have also become a vector for this type of attack. Attorneys and law firms across the country have reported a phishing scam that uses email to deliver fake electronic filing notifications that appear to come from the federal judiciary’s CM/ECF system. These fake notices prompt recipients to reply immediately and then send a link to a malicious website disguised as a case document. An attorney who clicks the link while managing a busy docket may compromise their entire system before they realize anything is wrong.
Deepfake Audio and Video: When You Cannot Trust What You Hear
The most alarming development in fraud targeting lawyers involves deepfake technology — AI-generated audio and video that can impersonate real, known people with startling convincingness. Deepfakes use advanced AI algorithms to replace an individual’s image or voice in synthetic media, creating realistic fake audio and video that can deceive even people who know the target well.
The financial losses associated with these attacks have been staggering. In one widely cited case, an employee at a global engineering firm was deceived into wiring $25 million to fraudsters after participating in a video conference that featured deepfake versions of the company’s CFO and other executives. The employee believed they were participating in a legitimate call with their leadership team. In Hong Kong, an employee at a London-based firm was deceived by a digitally recreated version of the firm’s CFO in a video call, resulting in a loss of approximately $25.5 million.
Lawyers should be especially cautious about podcasts, videos, and social media content that includes long, uninterrupted speech samples, because these recordings provide the raw material scammers need to clone a voice convincingly and use it to impersonate the attorney in calls to clients, colleagues, or financial institutions. A managing partner whose voice appears in a firm’s promotional video or a CLE presentation has, without knowing it, provided a potential fraud tool.
Fake Court Filings and AI Hallucinations: A Threat from Within
Not every AI-related threat to lawyers comes from outside the firm. Some of the most consequential dangers arise when attorneys themselves use AI tools without adequate verification of the output. A California attorney was fined $10,000 for filing a state court appeal in which 21 of 23 case quotations were fabricated by ChatGPT. The fine represented the largest issued over AI fabrications by a California court, and the opinion was described as blistering in its criticism of the attorney’s failure to verify the citations.
This is not an isolated incident. A tracker of cases in which lawyers have cited nonexistent legal authority due to AI use has identified more than 600 such cases nationwide, with more than 52 in California alone, and experts expect the number to increase as AI innovation outpaces attorney education about the technology’s limitations. A 2024 analysis by Stanford University’s RegLab found that some forms of generative AI produce hallucinations in one out of three queries.
While this category of risk involves an attorney’s own use of AI rather than a third-party scam, the consequences — sanctions, malpractice exposure, damage to professional reputation, and harm to clients — are every bit as serious. Experts warn that detecting fabricated citations in legal filings is likely to become harder as AI models grow in size and sophistication, and that many attorneys still do not know that AI generates false information or believe that legal technology platforms can eliminate all hallucinations.
IP Impersonation Scams: Fake Trademark Attorneys
Intellectual property practitioners and their clients face a distinct category of AI-enhanced fraud. A scam circulating among business owners involves emails impersonating intellectual property attorneys and containing false information about trademark matters, offering unsolicited trademark assistance. These emails typically create urgency by suggesting that the recipient’s trademark is at risk, that a conflicting application has been filed, or that a renewal deadline is imminent. The goal is to collect fees, personal information, or both from business owners who have no way of knowing that the attorney being impersonated is not the actual sender.
AI enables these attacks to be crafted in fluent, professional language that mirrors the tone and format of legitimate IP communications, complete with realistic attorney names, bar numbers, and firm branding harvested from public bar directories and firm websites.
Ransomware: Holding Confidential Files Hostage
Law firms have become high-value ransomware targets precisely because of what they store. Ransomware involves hackers demanding payment by threatening to release sensitive data, and it remains one of the most favored cyberattack methods against legal professionals. Email phishing remains the entry point for the vast majority of these attacks. A single employee clicking a malicious link can encrypt an entire firm’s files and expose client data, privileged communications, and financial records.
AI has accelerated ransomware deployment by making the initial phishing emails that deliver ransomware payloads far more convincing. What was once a numbers game — send enough generic emails and hope someone clicks — has become a precision operation in which the email arriving in an attorney’s inbox can reference their specific practice area, their current clients, and their recent court filings, making it far more likely to be opened without suspicion.
The Professional Liability Dimension
What makes fraud targeting lawyers different from fraud targeting most other professionals is the layer of professional responsibility that sits on top of every incident. Attorneys carry duties of competence, diligence, communication, and safeguarding of client property. Many jurisdictions now interpret technological competence to include understanding common cyber threats and implementing reasonable protective measures. Failure to implement reasonable verification safeguards may expose firms to malpractice claims that losses were preventable through industry-standard controls.
When a client’s settlement funds disappear into a fraudulent account, the client’s loss does not simply end there. The attorney may face a malpractice claim, a bar complaint, a trust account violation, and reputational damage, all flowing from a single email that bypassed an insufficient verification process. Business email compromise schemes targeting law firms are not isolated incidents — they reflect a coordinated and evolving threat landscape, and law firms should treat wire transfer verification protocols with the same rigor applied to conflict checks, trust accounting, and confidentiality safeguards.
How Lawyers Can Protect Themselves
The first and most reliable defense against wire fraud is independent verification. Any change to previously provided wire instructions should be treated as a red flag, and attorneys should verify the change by contacting the requesting party directly using a phone number obtained independently from their existing records — never from the email requesting the change. This single protocol, applied consistently, would prevent a significant proportion of the wire fraud losses that law firms currently absorb.
For AI-generated phishing and deepfake threats, a firm-wide culture of healthy skepticism provides the essential foundation. Establishing pre-agreed code words or phrases with known contacts, requiring a second layer of verification before any significant financial action, and training staff to recognize the pressure tactics — urgency, secrecy, and demands for immediate action — that accompany nearly all fraud attempts can significantly reduce a firm’s vulnerability.
For AI-assisted legal work, the only responsible approach is rigorous verification of every citation and legal reference that an AI tool produces. Courts have made clear that an attorney’s duty to personally verify legal citations does not transfer to the AI tool that generated them, and that reliance on AI output without independent confirmation is not a defense against sanctions.
Finally, firms should consult with their malpractice insurance providers to understand what fraud-related losses their policies cover, and should ensure that their cybersecurity infrastructure — email authentication protocols, multi-factor authentication, and endpoint protection — reflects the current threat environment rather than the one that existed five years ago. The scammers targeting lawyers are not standing still, and neither should the profession’s defenses.








