Maria and three partners run a law firm in Everett focused on real estate, estate planning, and small business work. Real estate closings mean the firm regularly wires large sums out of its trust account to sellers, lenders, and title companies.
A colleague at another firm had just lost a closing payment to a spoofed email, and Maria asked us the question every firm like hers should ask: would we be covered?
What she asked for
An answer on whether the firm's lawyers professional liability policy would cover a misdirected wire from the trust account.
What the review found
Malpractice covers some of it, sometimes. The firm's lawyers professional liability policy would respond if a client sued the firm for negligence in handling the funds. But many policies limit or exclude claims involving the loss of trust account funds to fraud, and none cover the firm's own money. Coverage would depend on facts, and possibly a fight.
There was no cyber policy. A compromised mailbox at a law firm means privileged client information exposed, notification duties to affected clients, forensics, and possibly bar reporting obligations. None of that falls under malpractice.
The firm had no social engineering or funds transfer fraud coverage anywhere. That is the coverage designed for exactly this scenario.
The office package was out of date. Its business owners policy listed an old address and a property limit from before a renovation.
What we put in place
We added a cyber liability policy built for law firms: breach response, privacy liability, regulatory defense, business interruption, and a social engineering and funds transfer fraud endorsement with a limit sized to the firm's typical closing amounts, not a token sublimit.
We also added a small commercial crime policy covering computer fraud and funds transfer fraud, including third-party funds held in trust. Between the cyber and crime policies, the stolen wire scenario is now covered from two directions.
We reviewed the malpractice renewal to confirm how it treats trust account losses and kept its retroactive date. We updated the BOP's address and limits.
The carriers' applications required two controls the firm adopted: multi-factor authentication on all email accounts and a verbal confirmation, at a known phone number, before any wire goes out or any payment instruction changes.
Why it mattered
Two months later, a "seller" emailed revised wire instructions two days before a closing. The paralegal followed the new call-back rule, reached the real seller at the number in the file, and the fraud was stopped. If it had not been, the firm would now have coverage built for it rather than a malpractice policy arguing about exclusions.
If you run a law firm
- Ask your malpractice carrier exactly how it treats trust account fraud
- Buy cyber with a real funds transfer fraud limit, sized to your wires
- Consider a crime policy that covers third-party funds in your care
- Verify every payment instruction by phone at a number you already have
More on professional services firms. Get a free policy review before your next closing.