Email security
A Close Call With a Fake Wire Instruction
The money did not move. The email still had to be treated as an incident: mailbox, identity, authentication, and a written call-back.

- IndustryLaw firm
- WhereSF Valley
- Timeline1 week
- EngagementEmail security
Meet the client
A firm that almost sent a settlement to the wrong account
Firm name, staff names, matter captions, and the exact dollar amount are withheld at the client's request. The engagement type, method, and constraints are real.
A San Fernando Valley law firm almost sent a settlement wire after a lookalike email used a partner's display name. Staff called the partner on a known number first. The partner had not sent it. Secure Techies reviewed the mailboxes, closed identity gaps, set email authentication on a path to enforcement, and left a written call-back that is now a rule, not a suggestion.

Primary goals
What had to be true before we left
Prove the money path was closed
No wire, no new payee, no silent inbox rule still forwarding the next try. Contain first. Explain later.
See whether a mailbox was actually owned
Display-name spoof and account takeover look the same to the person holding the check. They are not the same job.
Leave a rule staff will follow on a Friday
A call-back on a number already in the file, not in the email. Written. Dual control on the wire itself.
The challenge
What made the afternoon dangerous
The firm did not lose money. They still had a live lookalike, a tenant they had never really audited, and a wire process that lived in people's heads.
- 01
The email used a name everyone trusted
Display name matched a partner. The domain was one character off if you stared. On a phone screen it looked like internal mail. Urgency did the rest: settlement, today, new account.
- 02
Nobody could say if the mailbox was owned
A spoof does not need your password. A takeover does. Until we looked at rules, forwarding, sign-in logs, and MFA, we had to assume both.
- 03
Authentication was half-finished
SPF and DKIM existed. DMARC was monitoring. Impersonation protection was the default policy, which is not the same as naming the partners attackers would impersonate.
- 04
The wire process was a habit, not a rule
The office manager did the right thing this time. There was no written requirement that the next person would.

How we worked
Contain, then harden, then write it down
We treated the afternoon as an incident even though the money stayed put. A close call is how you find out whether the next one would have landed.
- 01
Freeze the payment path
Confirm no wire left the bank. Hold any payee change. Tell staff: no payment or banking change from email until we say otherwise.
- 02
Read the mailboxes, not the story
Inbox rules, forwarding, delegates, recent sign-ins, MFA status on the partner and the people who can move money.
- 03
Close the easy doors
MFA on every privileged and finance mailbox. Kill leftover forwards. Start DMARC toward enforcement. Name the partners in anti-phishing impersonation.
- 04
Write the call-back
Out-of-band verification on a number already in the file. Dual control on the wire. A one-page note staff actually read.
What we examined
What we examined
A fake wire instruction is not only an email problem. It is identity, mail flow, and the habit at the desk.
Mailbox and mail-flow review
Rules, forwarding, send-as, and whether anything was quietly copying mail out of the firm.
Identity and MFA
Who held Global Admin, who could approve a wire, and whether a stolen password was enough.
Email authentication
SPF, DKIM, and DMARC as they actually were, not as last year's questionnaire claimed.
Impersonation controls
Anti-phishing policy: named users, owned domains, what happens when a lookalike arrives.
Wire process
Who can initiate, who can approve, which phone number counts, what gets written down.
Staff briefing
Fifteen minutes with the people who move money. The sample email. The rule. No slide deck.

The email looked like the partner. The phone call did not.

The fake wire instruction used the partner’s name, a settlement the office already knew about, and a new account number that needed to go out before close of business. It was a business email compromise attempt dressed as a routine wire fraud email.
The office manager called the partner on the cell number already in the directory. The partner was in a hearing. He had not sent anything. The wire stayed in the account.
That is when the law firm called Secure Techies. They wanted to know whether a mailbox was owned, whether the next email would look the same, and what to write down so the next person at the desk did the same call. This page is that afternoon and the week after. Client identifiers stay out. The method does not.
What the fake wire instruction almost did
The message was not clever in a cinematic way. It was ordinary. Display name matched a partner. The subject named a real matter. The body asked for a payee change because “the client updated their account.” On a laptop, if you hovered the From address, the domain was wrong by one character. On a phone, most people would not hover.
The FBI’s Internet Crime Complaint Center has been publishing the same pattern for years: attackers impersonate a trusted party and ask for a legitimate-looking transfer of funds (IC3 on business email compromise). Their 2024 update put adjusted BEC losses since 2013 in the tens of billions. That is a national series, not a quote for this office (IC3 PSA, September 2024). It is still the number partners have in their heads when they ask “could that have been us.”
It could have been. The only reason it was not is a phone call that was not required in writing.
CISA’s guidance on social engineering is blunt: verify unexpected requests out of band, not inside the same thread that asked you to hurry (CISA on phishing and social engineering). The office manager already knew that. The process did not.
What this engagement was, and was not
Secure Techies sells cybersecurity and Microsoft 365 operations. A close-call review is incident work plus a short harden. It is not a courtroom forensic package and it is not a claim that we “saved” a dollar figure the bank never sent.
We wrote the non-goals down.
Out of scope on purpose:
- A full penetration test
- Pretending a week of email work replaces daily monitoring
- Filing an IC3 complaint in the firm’s name
- Inventing a loss number for a wire that did not leave
In scope:
- Contain the payment path
- Mailbox and identity review
- Email authentication and impersonation controls
- A written call-back and dual control
- A staff briefing the people who move money actually attended
The American Bar Association’s cybersecurity work exists because competence now includes the technology that holds client funds and client mail. That is not a slogan. It is why a lookalike email is an ethics problem as well as an IT problem.
How we worked the afternoon
Hour one: contain
First question: did any money move. It had not. Second: was any payee file already edited. It was not. Third: tell the room, in one sentence, that no payment or banking change from email goes out until we finish the review.
We collected the message as it sat: headers, the lookalike domain, who it was sent to, who was cc’d. We did not need a novel. We needed evidence we could still see after someone hit delete.
The rest of the day: the mailboxes
A spoof and a takeover require different work. A spoof means the partner’s mailbox may be fine and the attacker never had a password. A takeover means inbox rules, forwards, and a quiet copy of everything the partner reads.
We assumed both until the tenant said otherwise.
What we opened:
- Inbox rules and automatic forwarding on the partner, the office manager, and accounting
- Delegates and send-as
- Recent sign-ins and MFA status
- Whether Global Admin was a shared password from a prior vendor
The mailboxes did not show a takeover. No hidden forward. No rule deleting sent items. Sign-ins matched the people in the room. That was good news. It was not a reason to skip the rest. The next email might not be a spoof.
Microsoft documents how multifactor authentication stops a stolen password from becoming a tenant problem (how Entra MFA works). MFA was on for most users and missing on a shared operations mailbox that sometimes initiated wires “so we are not stuck when someone is out.” That mailbox was the real finding, not the lookalike domain.
The week: harden and write
We did not rip tools for theater. We closed the doors this firm actually left open, then we wrote the habit down.
What the mailbox actually showed
The message was a lookalike. One-character domain. Partner display name. No malware, no link that mattered. That is why the spam folder did not save them. There was nothing for a simple filter to hate.
The partner mailbox was not owned. We still rotated the password and confirmed MFA, because “probably fine” is how leftover sessions survive an afternoon.
A shared mailbox could start a wire. It had no MFA. Two people knew the password. That is not a process. That is a hope.
Delegates were undocumented. A former assistant still had access to a partner calendar and mail. Offboarding had been a conversation, not a ticket.
None of this required a nation-state. It required an afternoon that treated a close call as a gift you do not waste.
Email authentication and impersonation
SPF and DKIM were present. DMARC was p=none. Microsoft is explicit that the set is incomplete until DMARC is actually enforcing, after you have watched the reports (set up DMARC in Microsoft 365). Monitor-only is better than nothing. It is also what a questionnaire calls “we have DMARC” when you do not.
We moved them onto a short reporting window, then toward quarantine for failures, with a named owner for the reports. We did not flip enforcement the same afternoon as the scare. A bad cut breaks legitimate mail and teaches the firm to ignore the next change.
Anti-phishing policy was the tenant default. Defaults do not name the three partners an attacker would impersonate. Microsoft’s anti-phishing policies are built to do exactly that: spoof intelligence for everyone, impersonation protection when you tell the product who matters (anti-phishing policies in Microsoft 365). We named the partners, the controller, and the owned domain.
DMARC will not stop a lookalike domain. Impersonation protection might flag it. The call-back stops the wire either way. Stack the three. Do not pick a favorite.
If you want the longer hygiene list this week sat on, our Microsoft 365 security checklist and phishing guide are the same controls in blog form. MFA is the identity half.
The process that stops the next one
Tools narrow the funnel. The desk stops the payment.
The written rule we left is short enough to tape inside a drawer:
- Any new payee, any changed account, any “send today” wire from email is unverified until a human on a known number says it is real.
- The number comes from the directory or a prior trusted signature, never from the email that asked.
- Two people: one initiates, one approves. “The partner is in court” is not an exception. It is a reason to wait.
- If you cannot reach them, the wire waits. A delayed settlement is cheaper than a second wire you cannot get back.
We ran a fifteen-minute briefing with the people who actually move money. We showed the sample. We did not do an hour of slides. Security awareness training still belongs on the calendar. The briefing was for this incident.
The help desk number went on the same page. If the next email arrives at 4:50 p.m. and the partner’s cell goes to voicemail, they call us instead of deciding alone.
What changed in the following weeks
The incident does not “secure” a firm. Closing the items does.
By the end of the week: MFA on the shared mailbox, leftover delegate gone, DMARC reports arriving, impersonation names in the policy, call-back posted where accounting can see it. The managing partner asked us to stay on for managed cybersecurity rather than treat the afternoon as a one-off. That follow-on is a separate engagement. This page is the close call.
What they had that they did not have that morning:
- A clear answer: spoof, not takeover, with the evidence
- MFA on every mailbox that can touch a wire
- A path to DMARC enforcement with an owner
- A rule the next new hire can follow
What they still did not have, and should not claim:
- A guarantee the next lookalike never arrives
- A certification
- A substitute for the phone call
What a buyer should copy
Treat a close call as an incident. If you only say “good catch” and go back to work, you will meet the next email with the same luck.
Assume takeover until the tenant says otherwise. Rules and forwards are how a quiet compromise keeps paying.
Finish DMARC. p=none is a start. It is not a control you can brag about.
Name the humans attackers will impersonate. Defaults do not know your partners.
Write the call-back. The person who did the right thing this time will not be at the desk forever.
Planning for a close call of your own
If an email just asked you to change a payee, stop the wire and call a number you already trust. Then call us. If nothing has happened yet and you want the tenant reviewed first, bring Global Admin, the people who move money, and the last wire that felt rushed.
Secure Techies works from Canoga Park with firms across Los Angeles and Southern California. Schedule a consultation if you want the same kind of contain-and-harden this client used.
For a different kind of project record, see switching IT providers without a weekend outage or the Microsoft 365 email migration.
The outcome
What the firm had a week later
- Confirmation the lookalike was a display-name / lookalike-domain message, not a partner mailbox takeover. We still treated it as if it could have been both.
- MFA on every privileged account and every mailbox that can start or approve a payment.
- No leftover inbox forwards. Delegates listed and owned.
- DMARC moved from monitor-only toward enforcement after a clean reporting window.
- Partners and the controller named in anti-phishing impersonation protection.
- A one-page call-back rule: known number, two people, no exceptions for 'the partner is in court.'
- No invented dollar figure for money that never left the account.
Technologies and frameworks
Related services
Work that sits next to this project
More projects
Other case studies
Questions
Frequently asked questions
Did the firm lose money?
Was this a mailbox takeover or a spoof?
What is a call-back, exactly?
Does DMARC stop business email compromise?
Should we report a close call to IC3?
Is this only a law firm problem?
Had a close call, or do not want one?
Secure Techies reviews Microsoft 365, email authentication, and the wire process for Southern California firms. Start with a conversation in Canoga Park.
Switching IT Providers Without a Weekend Outage
IT Risk Assessment for a Financial Services Firm