home  /  security & threats  /  attacks on firms
security · ai for legal practice

AI-enabled attacks on firms.

Three of these are old attacks made cheap. One is genuinely new, and it arrives inside a document you have to read.

begin here

Where is your firm?

Start a conversation with the AI Adoption Concierge, already scoped to attacks on firms. Pick a starting point, or describe your situation directly.

AI Adoption Conciergeattacks on firms · orientation, not legal or ethics advice
Tell me whether the firm handles client funds and what your verification process looks like today. I'll help you work out where the exposure is. This isn't a security audit — for that you want a qualified assessor.

Law firms have been targeted deliberately rather than incidentally for years — a federal advisory issued to the legal sector in May 2025 said as much, attributing sustained targeting since 2023 to the sensitivity of legal data. What AI changed is the economics. Impersonation that once required skill and time now requires roughly ten seconds of a partner's recorded voice, which any CLE recording or podcast appearance supplies. Reconnaissance that once rationed spear-phishing to high-value targets now scales. And a genuinely new attack class arrived that has no pre-AI analogue: instructions concealed inside a document, invisible to a human reader, aimed at whatever AI processes it. Lawyers are professionally obliged to read documents written by their adversaries, which gives the profession an exposure no other has.

mechanisms

What is actually being aimed at firms.

In rough order of consequence rather than frequency.

Wire fraud on trust and closing funds

The attack with the largest single-event consequence. Federal reporting for 2025 showed real-estate wire-fraud losses rising sharply year over year, including matters where the fraudulent instruction impersonated the buyers' own attorneys.

Deepfake voice and video

The reference case involved a finance employee who already suspected the initiating email — and was convinced by a video call on which every other participant was synthetic.

Prompt injection in adversary documents

Text concealed in a filing or production, formatted to be invisible to a person, instructing any AI that reads it. Addressed by courts in two countries in 2026.

Vishing against reception and support staff

Callers impersonating internal IT. One reported campaign escalated to sending a person to the office posing as a technician.

Business email compromise

Often from a genuinely compromised counterparty mailbox, inside a real reply thread. No attachment, no link, nothing for a filter to catch.

Unsanctioned tool use

Not an attack, but the exposure that produces no alert at all — which is why it is the one firms discover last.

methodology

What the evidence shows — and what we examine.

The controls that actually work against these.

Out-of-band callback, alwaysTo a number from the firm's own records. The attack depends on you not making that call.
A hold period on instruction changesUrgency is the attack. Friction is the defence, and it costs nothing.
Render adversary documents before AI reads themPrinting is literally what exposed the concealed-text attack a court addressed in 2026.
Written authority to refuseStaff must know they will never be penalised for delaying a payment to verify. The reference case failed socially, not technically.
what's at stake

What is at risk.

For a firm holding client funds, the top of this list is existential rather than expensive.

client funds held in trust fiduciary and disciplinary exposure privileged and pre-announcement material the integrity of AI-assisted review client relationships and OCG compliance insurance sublimits far below a routine wire

Check the sublimit before you need it.

Social-engineering cover inside a cyber policy commonly sits at $100,000 or $250,000 — frequently far below a firm's largest routine trust wire. A US federal court held that two fraudulent transfers made a minute apart shared a single sublimit, leaving the insured recovering a fraction of the loss. This is a renewal conversation, not a claims conversation.

common questions

Attacks on firms — practical questions.

How much audio does someone need to clone a partner's voice?

Reporting through 2025 and 2026 has converged on roughly ten seconds of clean audio, using consumer tools costing a few dollars a month or nothing. For most firms that material is already public — a CLE recording, a podcast appearance, a conference panel, a firm marketing video, or a voicemail greeting. The practical implication is not to remove that material, which is unrealistic and commercially counterproductive. It is to stop treating voice recognition as authentication, and to build a verification protocol for funds movement that does not depend on recognising who is speaking.

What is prompt injection, in plain terms?

Instructions hidden inside content that an AI will later read as data. An AI model has no reliable way to distinguish "material I was asked to analyse" from "instructions I should follow," so text concealed in a document — white text on white, a three-point font, an off-screen block — can direct the model that processes it. Courts in the United States and Brazil addressed instances in 2026 where this was used in litigation filings. For firms the exposure is structural: discovery productions, opposing counsel's filings, counterparty contract drafts and unsolicited intake submissions are all adversary-authored content that a firm's AI is now asked to read.

Are we too small to be targeted individually?

That assumption no longer holds, and the reason is economic rather than reputational. Targeting used to be rationed by the attacker's time: researching a specific firm, its matters and its counterparties took effort that only paid off against large targets. Automated reconnaissance removed that constraint. Meanwhile the sector-specific reporting — federal advisories aimed at the legal industry, and threat research documenting campaigns running against dozens of legal and professional-services organisations in a single window — describes firms of all sizes. Smaller firms are also likelier to be running consumer AI tiers, which is a separate exposure.

What should we do about concealed text in documents we receive?

Sanitise on ingest, but do not simply strip it. Removing hidden characters before a document reaches a model is the protective step; preserving the original and flagging it to the case team is the other half, because concealed instructions in an adversary's production are potentially evidence of misconduct rather than a technical nuisance. A rendering step — converting to image and back, effectively what printing does — defeats most current concealment techniques. Some firms are also considering protective-order language requiring parties to certify that productions contain no non-displaying text intended to influence automated review. That is not yet standard practice.

related

Related specialization areas & resources.

Is your wire protocol written down?

Describe what happens today when payment instructions change. The Institute will help you close the gap.

AI adoption conciergeorientation · not legal or ethics advice
Tell me whether the firm handles client funds and what your verification process looks like today. I'll help you work out where the exposure is. This isn't a security audit — for that you want a qualified assessor.