top of page

The Friday Afternoon That Cost a LawFirm Everything It Hadn't Backed Up

  • Writer: Ricky Mosel
    Ricky Mosel
  • Jul 1
  • 3 min read
A breach is rarely sophisticated. More often it is the slow accumulation of small, unwatched gaps — and the difference between having security and being secure is exactly where the damage lives

It started with an invoice.


A mid-size litigation firm — forty attorneys, a tri-state presence, the kind of practice that had spent thirty years building a reputation. On a Thursday afternoon, someone in accounts payable received an email from a vendor they'd worked with for years. Same logo. Same sign-off. A routine request to update the banking details on file for the next payment.


She updated them. Why wouldn't she? The email came from the right address — or what looked like the right address.


By the following Tuesday, $180,000 had moved to an account that no longer existed. But that wasn't the real damage. The fraudulent email had been the easy part. To send something that convincing, the attackers had already been inside the firm's email system for six weeks — reading correspondence, learning the vendor relationships, studying how people wrote, waiting for the right moment.


How did they get in? A paralegal who'd left the firm four months earlier still had an active account. No one had disabled it. The password had been exposed in an unrelated data breach, and the firm had no multi-factor authentication on email. The door hadn't been forced. It had simply been left unlocked, with the key under the mat, for anyone who thought to check.


They had antivirus. They had a firewall. By every measure they'd been told to care about, they were "protected."

Here's what makes this story worth telling: nobody at the firm was careless. They had an IT vendor who responded when something broke. The problem was never a missing tool. It was the absence of anyone whose job it was to watch the things that don't announce themselves.


The gap between having security and being secure

This is the part most businesses get wrong, and it's not their fault — they've been sold tools and told that tools are the answer.


Antivirus is a tool. A firewall is a tool. They're necessary. But they are not a security posture, and the difference between those two things is exactly where this firm lost $180,000 and a great deal more in client trust.


A security posture is the discipline underneath the tools. It's the process that disables a departed employee's access the day they leave. It's the multi-factor authentication that makes a stolen password useless. It's someone actually monitoring for the unusual login from an unfamiliar location at 3 a.m. It's the regular review that asks, simply, what has changed, and what have we stopped watching?


The firm had every tool. What they lacked was anyone whose job it was to maintain the posture those tools were supposed to support. And that gap is invisible — right up until the moment it isn't.


What would have caught this

None of what failed that week required sophisticated defense. It required attention.


A proper off-boarding process would have closed the former employee's account automatically. Multi-factor authentication — a single afternoon to deploy — would have stopped the stolen credentials cold. Continuous monitoring would have flagged six weeks of suspicious access long before the fraudulent invoice ever went out. And a simple verbal-verification policy for any change to payment details would have turned a $180,000 loss into a thirty-second phone call.


This is what we do at Circle Square. Not sell you another tool to add to the pile, but build and maintain the security posture that makes the tools you already have actually work — offboarding discipline, identity protection, active monitoring, and the governance that keeps it all current as your business changes. For firms in legal, healthcare, and financial services, where a breach is also a compliance event, that posture isn't a luxury. It's the cost of staying in business.


The conversation worth having before the Friday afternoon

The firms that avoid this story have one thing in common: they had the conversation before the incident, not after.


If you're not certain whether your business has security or simply has tools — that uncertainty is the answer, and it's worth resolving now. We offer a confidential security assessment that surfaces exactly the kind of gaps that cost that firm everything. No obligation, no alarmism. Just an honest picture of where you actually stand.


The door may already be unlocked. Let's find out before someone else does.



 
 
 

Comments


bottom of page