Defeating Direct Deposit Phishing Attacks
Privacy, Cyber & AI Decoded Alert | 1 min read
Apr 16, 2019
Risk Management Question
What steps can lawyers and law firms take to guard against phishing attacks that try to re-route direct deposit paychecks to a scammer's bank account?
The Issue
Lawyers are not the only marks of scammers; administrative and support staff have become targets, too. This new phishing scam usually takes the form of sending a legitimate looking email to an unsuspecting human resource employee, purporting to be from another company employee or supervisor, with instructions to change bank account and routing information for direct deposit paychecks. The email is written convincingly and professionally, and warns that the sender is going into a meeting or is otherwise unavailable, thus dodging verbal confirmation of the new routing information. After the human resource employee implements the instructions, the employee's paycheck is sent to the wrong bank account, causing financial harm to both the employee and the firm.
Risk Management Solution
Take the following steps to help defeat direct deposit phishing attacks:
- Compare the sender's email address to the sender's known company email address.
- Implement policies requiring all direct deposit instructions to be confirmed verbally and/or in-person with the affected employee.
- To avoid rushed changes, and if permitted by law, set a deadline of at least one week prior to the next paycheck for employees to ask for direct deposit changes.
- Don't act on instructions sent from an employee's personal email account.
- Discuss with your IT Department additional options that may be implemented to spot and prevent phishing attacks.
The best defense is a good offense. Educate your employees on a regular basis about how to spot and prevent new phishing techniques and remind them to be careful out there.
Related People
Related Capabilities
Featured Insights

Event
Apr 23, 2026
Driving Ahead: Insights from Industry Leaders Auto Finance Seminar

Consumer Crossroads: Where Financial Services and Litigation Intersect
Mar 13, 2026
DOJ Settlement with Car Retailer Highlights SCRA Repossession Risks

Privacy, Cyber & AI Decoded Alert
Mar 11, 2026
Compliance Considerations for GDPR Consent in Biotech Clinical Research

Press Release
Mar 4, 2026
Marcia Mueller Named the 2026 Mentorship Award Winner by YWCA Northwestern Illinois

Press Release
Mar 3, 2026
Hinshaw Announces New Administrative Leadership Appointments

In The News
Feb 27, 2026
Hinshaw Partners Examine Implications for Nursing Homes of New Illinois Aid-in-Dying Law

In The News
Feb 24, 2026
Lucy Wang Authors Law360 “Expert Analysis” on Why Attorney Civility Means More in 2026

Press Release
Feb 13, 2026
Hinshaw Team Wins Appeal in Criminal Indictment of Waukegan City Clerk Janet Kilkelly

Press Release
Feb 10, 2026
Hinshaw Trial Team Secures $0 Defense Verdict in $15 Million Auto Accident Trial

Press Release
Feb 5, 2026
Hinshaw Legal Team Secures Directed Verdict in Florida Equine Fraud Case

Press Release
Feb 4, 2026
Hinshaw Celebrates 17 Consecutive Years of Being Named an Equality 100 Award Winner

![[Video] New Regulatory Priorities Under Mayor Mamdani’s NYC Department of Consumer and Worker Protection](/a/web/oHiTWa7kRy3Ht1brq6k4BT/bkMx39/new-york-city-skyline.jpg)
