Law Letter Hub Articles
Cyber Claim Update
31 March 2025
The current article is published in my capacity as the Claims Manager for the Professional Indemnity Insurance Scheme. The purpose of the article is to provide readers with an overview of the current cyber fraud claims that I have managed on behalf of the Scheme, their common characteristics, the cover provided by the policy of insurance and when the policy will respond to a cyber claim. I have further outlined a number of practical steps that can be taken by Law Firms to promote awareness and prevent the cyber fraud claims.
Cyber criminals continue to target legal professionals due to the significant high value transactional work that they undertake, the nature of the information they manage, combined with potential weaknesses in their cyber security defences.
As the Claims Manager for the Professional Indemnity Insurance Scheme for the Law Society of Tasmania, we are not immune from cyber fraud claims and I have managed several similar claims. These breaches target specific practice areas and emphasise the financial impact of cyber attacks. The claims underscore the need for strong cybersecurity measures and heightened awareness among staff and clients.
This article will highlight the common features of the current cyber fraud claims and the current cover provided by the policy of insurance.
Time of Year
The cyber fraud claims managed by the Scheme do have a theme with respect to the time of the year. The claims traditionally tend to arise toward the end of the year as lawyers head toward Christmas. In my experience lawyers tend to have added work pressure and deadlines and this may be an additional factor in these claims.
Target Practice areas for Cyber Claims and Common Features
The key practice areas that are the subject of cyber fraud claims are generally the transactional practice areas of conveyancing and probate. Currently, the more significant claims have arisen in the probate setting.
The cyber fraud claims share common characteristics. They involve cyber hackers accessing the IT systems of a legal practice. Once access is gained, the hackers establish several “rules”. These rules enable them to identify specific phrases related to money, estates, and distributions.
Most claims indicate that hackers accessed IT systems through phishing.
Once the hackers have gained access to the system, they then wait to identify an estate that is pending distribution or may require the payment of invoices.
After identifying the relevant estates, the hackers send emails that appear to be from a senior partner or an external lawyer. These emails authorise the release of funds as distributions from the estate or instruct the probate clerk to pay an attached invoice (fraudulent) on behalf of the estate.
Several current claims failed to verify fraudulent payment instructions by phone or direct follow-up with the author of the instruction. The payments were made based solely on the fraudulent email instructions.
Language used in the Emails by the Hackers
Hackers are now becoming more proficient in the drafting of fraudulent emails that are sent requesting the release of funds or authorising the payment of invoices. Cyber hackers often review previous emails sent to ensure that the language style is consistent to ensure that the recipient does not become suspicious with the request.
Delay in Detection
A common feature of the cyber fraud claims is that there is often a delay in detection. The problem with a delay in detection is that the substantial funds transferred from the impacted client/estate may be held by the bank for a period of time and that crucial time period is missed. The funds are then often transferred to an offshore account, making recovery by the banks impossible.
The Cover Provided by the Policy
The relevant insuring clause contained within the current policy of insurance is clause 2(b), which provides:
On the terms and conditions herein contained the Insurer agrees to indemnify the Insured up to an amount not exceeding the Limit of Indemnity for any amount paid by the Insured (the claim) to reinstate a deficiency in any trust account where the deficiency is caused by the fraud or dishonesty of a third party if:
[i] the Insured was not knowingly concerned in or a party to the fraud or dishonesty;
[ii] the Insured failed to exercise reasonable care and skill to take steps to prevent the deficiency from occurring;
[iii] the deficiency was first discovered by the Insured and first notified to the Insurer during the Period of Insurance; and[iv] the deficiency did not result from a default within the meaning of s.350 of the Legal Profession Act 2007.
For the relevant Clause 2(b) of the policy to be triggered, there is a requirement for the insured to reinstate the deficiency in the trust account and this can require legal firms to have readily available a large amount of money to address that deficiency.
It must further be established on notification, by the insured that no member of staff was a party to the fraud or dishonesty and that there was a failure to take steps to prevent the deficiency from occurring. The insurers will require evidence from the insured to support the claim and this can often be a time intensive exercise.
There is also an onerous requirement to provide evidence of the breach including the requirement of IT system reports and this can be a time consuming and expensive process.
Clause 2(b)[iv] – no default within the meaning of s. 350 of the Legal Profession Act 2007 (Act). Section 350 is a definitional provision in Part 3.5 of the Act, and it defines the word “default” for the purposes of that Part as follows: default, in relation to a law practice, means –
(a) a failure of the practice to pay or deliver trust money or trust property that was received by the practice in the course of legal practice by the practice, where the failure arises from an act or omission of an associate that involves dishonesty; or
(b) a fraudulent dealing with trust property that was received by the practice in the course of legal practice by the practice, where the fraudulent dealing arises from or is constituted by an act or omission of an associate that involves dishonesty; [Emphasis added]
Prevention
Law firms can implement several measures to mitigate cyber claims:
- Don’t accept email requests on face value. The email asking you to re-direct or transfer money might look genuine, but it could have been sent by a hacker.
- Call the sender personally to check authenticity. Use a number you know, not one suggested in the email. Ask for the account number, write it down, then compare with the email. Verify the veracity of any invoices, check all of the details on the invoices including if the supplier actually exists and look for anomalies including VAT instead of GST.
- Make a file note that you made the call and confirmed the payment instructions, so you can prove it in the event any of your actions are called in to question,
- Warn your client they might also be targeted with fake emails from you and not to act on email payment directions without calling to check. Make sure that you provide your client with sufficient information on the risks. Consider the use of a standardised pamphlet and put the warning in your engagement letters.
- Double check the transfer. Always have a second person in the transfer to make sure that the transfer is legitimate and that you have not missed any vital clues that the request may be from a hacker.
Fleur Dewhurst
Lawyer
Professional Indemnity Insurance Scheme-Claims Manager
Law Society-Tasmania
Author: Fleur Dewhurst
Lawyer : Professional Indemnity Insurance Scheme-Claims Manager
Law Society-Tasmania



