Stop Payment-Redirection Fraud: A Checklist for Accountants and Law Firms

Payment-redirection fraud is simple and effective. An attacker gets into an email account, or convincingly impersonates one, watches for a payment or settlement, then sends new bank details at the right moment. Law firms, accountants, and anyone handling client funds are prime targets.

Prevent account takeover

  • Multi-factor authentication on every email account, including shared mailboxes.
  • Alerts for suspicious sign-ins and for new mailbox forwarding or inbox rules.
  • Staff trained to spot credential-phishing pages.

Make impersonation harder

  • Publish SPF, DKIM and DMARC records for your domain so others can’t easily spoof it.
  • Turn on impersonation and external-sender warnings in your email system.
  • Watch for lookalike domains registered close to yours.

Verify before you pay

  • Never act on changed bank details received by email alone.
  • Confirm changes by phone using a number from your records, not from the email.
  • Tell clients at the start of every engagement that you will never change bank details by email.
  • Require a second person to approve new or changed payees.

If it happens

Contact your bank immediately, since speed matters for recovering funds. Then secure the affected account, work out what the attacker could see, and report the incident to the NCSC. Consider whether you need to notify affected clients under the Privacy Act.

Want us to check your firm’s defences? Call 04 282 0045 or see how we help law firms.