Share

Here's how cyber criminals are targeting attorneys in scams to steal cash

accreditation
Hacker. (Duncan Alfreds, Fin24)
Hacker. (Duncan Alfreds, Fin24)

Attorneys are the latest targets facing attack by cyber criminals intent on stealing money.

According to research conducted by Stalker Hutchison Admiral (SHA) Specialist Underwriters, attorneys have proved to be vulnerable to spear phishing attacks.

In these scams, cyber crooks send a conveyancing attorney a fraudulent email purporting to be from a home seller.

"The approach is simple. The attorney firm is instructed by a client to register the sale of a property. Once the property is registered at the Deeds Office, the proceeds of the sale are due to the seller," Christopher Appanah, claims team leader for PI and liability at SHA, told Fin24.

"It is at this point that cyber criminals make their move. The attorney is sent a last-minute email alleging to be from the seller, requesting that the seller's banking details be amended. The proceeds of the sale are then diverted to the hacker's account."

Three contributing factors

This correlates with research by Mimecast, which found that 90% of all cyber attacks began with an email.

Appanah said that three factors made attorneys vulnerable to this kind of targeted attack.

"First of all, attorneys are not infallible. There is a perception that has been created that an attorney cannot falter in the performance of their professional duties. If this [were] the case, then there would be no need for professional indemnity insurance."

He also said that cyber attacks had evolved from simple schemes to sophisticated fraud, where crooks create content that closely mimics official websites and emails.

The differences may be extremely subtle, for example substituting a "1" for an "I", or a name like "Petersen" may be spelled "Pietersen" in an email. In a high-pressure environment, mistakes may be overlooked easily.

"Finally, there can be an increase in risk, where the attorneys themselves do not attend to the so-called non-professional tasks or administration-related tasks, which do not require the application of their particular professional judgment," said Appanah.

"These tasks may be assigned to staff who may not necessarily be aware [of] or alive to the potential risks that lurk within cyber interactions."

Appanah advised firms, especially those that deal with sensitive personal information, to be more proactive when clients requested detail changes.

"Some firms have adopted the rule that bank details can only be amended in person, rather than through emails or even telephonically. It may be wisest to incorporate a combination of innovative and proactive steps to mitigate some of these risks," said Appanah.

* SUBSCRIBE FOR FREE UPDATE: Get Fin24's top morning business news and opinions in your inbox.

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.00
+0.0%
Rand - Pound
23.70
-0.1%
Rand - Euro
20.30
-0.0%
Rand - Aus dollar
12.25
-0.1%
Rand - Yen
0.12
-0.0%
Platinum
948.30
-0.5%
Palladium
1,038.00
+0.3%
Gold
2,375.76
+0.6%
Silver
28.46
+0.8%
Brent Crude
87.29
-3.1%
Top 40
66,899
0.0%
All Share
72,995
0.0%
Resource 10
63,378
0.0%
Industrial 25
97,824
0.0%
Financial 15
15,384
0.0%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders