Email Hijacking and Business Email Compromise: Why Law Firms Remain a Prime Target for Cyber Criminals
As cyber criminals become more sophisticated, email hijacking remains one of the most effective and financially damaging attacks facing law firms today. While the techniques used by attackers have evolved, the objective remains the same: gain access to a trusted email account, monitor communications, and exploit opportunities to steal money or sensitive information.
The threat is far from theoretical. According to the UK Government’s Cyber Security Breaches Survey, published in April 2026, 43% of UK businesses experienced a cyber security breach or attack in the previous 12 months. The survey also found that phishing remains the most common form of cyber attack, highlighting the continued effectiveness of email-based threats against organisations of all sizes.
For law firms, the consequences can be particularly severe. A successful email hijacking attack can expose confidential client information, disrupt transactions, trigger regulatory investigations and cause significant reputational damage. In some cases, firms may also face reporting obligations to the Information Commissioner’s Office (ICO), the Solicitors Regulation Authority (SRA), and affected clients.
How Do Cyber Criminals Benefit from Email Hijacking?
Unlike ransomware attacks that announce themselves immediately, email hijacking attacks are often patient and deliberately difficult to detect.
Once attackers gain access to an account, they may spend days, weeks or even months monitoring email conversations. Their goal is to identify financial transactions, client communications, conveyancing matters, settlement payments, or other opportunities where a trusted email account can be used to manipulate the flow of money.
In many cases, attackers use compromised accounts to conduct Business Email Compromise (BEC) attacks. By impersonating solicitors, clients, suppliers or colleagues, they can alter payment instructions, redirect funds, or persuade recipients to disclose confidential information.
The longer an attacker remains undetected, the more intelligence they can gather and the greater the potential damage. Even a short window of access to email can provide attackers with sufficient information to launch further attacks against your organisation or your clients.
Why Are Law Firms Such Attractive Targets?
Law firms face many of the same cyber risks as other organisations, but they also carry unique responsibilities and exposures.
Legal firms routinely handle:
- Client monies
- Property and conveyancing transactions
- Commercial acquisitions and mergers
- Litigation settlements
- Sensitive personal information
- Confidential corporate documentation
This combination of financial activity and high-value data makes the legal sector particularly attractive to cyber criminals. Whether targeting client funds, confidential legal communications or sensitive personal data, attackers recognise that a successful compromise can have significant financial and operational consequences for both firms and their clients.
Recent Examples from the Legal Sector
Recent incidents demonstrate the real-world consequences of weak email and identity security.
In 2025, the Information Commissioner’s Office (ICO) fined Liverpool-based law firm DPP Law £60,000 following a cyber attack that exposed highly sensitive client information. Investigators found that attackers had exploited an account that lacked multi-factor authentication (MFA), gaining access to systems containing confidential legal records. The breach reportedly resulted in more than 32GB of stolen data and was only discovered after the National Crime Agency alerted the firm.
The legal sector also felt the impact of the 2025 Legal Aid Agency cyber incident, which disrupted services and affected systems containing applicant information dating back many years. The incident highlighted the risks associated with legacy technology and the sensitivity of the data held throughout the legal ecosystem.
These incidents serve as a reminder that cyber security failures can result in financial losses, regulatory scrutiny, reputational damage, and a loss of client trust.
How Do Email Hijacking Attacks Work in 2026?
While weak passwords remain a problem, modern attackers have expanded their toolkit considerably.
Today, email accounts are commonly compromised through:
- Phishing emails designed to steal usernames and passwords. This now includes AI-generated phishing campaigns that create highly convincing and personalised messages
- Multi-factor authentication (MFA) fatigue attacks that pressure users into approving login requests
- Session hijacking techniques that steal authenticated browser sessions and bypass MFA protections
- Data breaches exposing credentials from third-party services
Once access is obtained, attackers frequently create hidden forwarding rules, divert emails to private folders, or silently monitor conversations from within the compromised mailbox. Their objective is to remain invisible while gathering intelligence and identifying opportunities for fraud.
What Could Happen if a Law Firm Is Compromised?
The impact extends far beyond stolen funds.
A successful email hijacking attack may expose privileged communications, personal data, commercial information and confidential case details. Firms may also face obligations to notify affected clients, report breaches to the ICO, and consider their regulatory responsibilities under SRA requirements.
Beyond regulatory implications, firms must also contend with potential reputational damage. Clients expect their legal advisors to safeguard highly sensitive information, and any loss of confidence can have long-term commercial consequences.
How Can Law Firms Protect Themselves?
No single security measure can eliminate the risk of email hijacking. Effective protection requires a layered approach that combines technology, processes and user awareness.
Law firms should ensure they:
- Enforce multi-factor authentication on all accounts
- Monitor mailbox forwarding rules and suspicious login activity
- Configure advanced security settings that are available in your email platform
- Enable mailbox auditing and security alerting
- Conduct regular phishing awareness training
- Monitor for compromised credentials on the dark web
- Ensure your email filtering configuration is set up to remove as much malicious and unwanted inbound email as possible
- Ensure you have defined Incident Response plans that include a suitable IR expert you can call upon.
Most importantly, cyber security should not be viewed solely as an IT responsibility. Every employee plays a role a role in protecting client data and maintaining the firm’s security posture.
Staying One Step Ahead
The most dangerous email hijacking attacks are often the ones that go unnoticed.
Modern attackers are patient, disciplined and increasingly supported by automation and artificial intelligence. For law firms handling sensitive information and significant financial transactions, robust security controls, continuous monitoring and well-informed users remain the most effective defence against a threat that continues to evolve.
Cyber security is no longer simply a technical issue. It is a business-critical risk that firms must actively manage to protect their clients, their reputation and their future.
Need Help Protecting Your Firm?
As a trusted cyber risk management partner to legal professionals, Mitigo works with law firms of all sizes to help identify cyber risks, strengthen resilience, and protect client data, finances and reputation.
From Cyber Essentials certification and cyber security assessments through to managed detection, incident response and staff awareness training, our team helps firms take a proactive approach to cyber security.
To discuss your firm’s cyber security requirements or arrange a no-obligation consultation, contact Mitigo today.
Email: info@mitigogroup.com
Phone: 0330 223 1869
Website: www.mitigogroup.com