How to Guard Against Impersonation Phishing Attacks
Privacy, Cyber & AI Decoded Alert | 1 min read
Feb 12, 2019
Risk Management Question
What is an impersonation attack and what steps should you take to protect yourself and your firm?
The Issue
An impersonation attack is a type of phishing scheme where a hacker creates an email that appears to come from someone at your firm, usually a person in a leadership role such as a managing partner or a practice group leader. Many firms implement an email gateway which automatically flags emails that originate from outside the firm. In response, hackers will send an email from a personal, non-firm email account, like: managingpartnerprivate@gmail.com. While the email address is clearly suspicious, many hackers use an e-mail header that associates an attorney with the particular email address, such as: John Smith (managingpartnerprivate@gmail.com).
Risk Management Solution
You should be highly suspicious of any email that purports to come from the personal email account of an employee of your firm—especially someone senior. Take the following steps when handling such an email:
- Do not respond to the email without confirming the email is actually from the purported sender and not from a fraudster. Try using the telephone, but don't call the phone number in the email, because you could be calling the hacker.
- Similarly, don't try to confirm the identity of the sender by hitting the reply button, because you could be communicating with the hacker. Instead, find another way to communicate, such as the person's official firm email address.
- Never click on a link or an attachment in an email from someone you don't know. You should also never click on any link or attachment you were not expecting to receive—even if it's from a known sender—because it may be from a hacker impersonating the person you know.
By implementing security precautions, you can avoid big and expensive problems. Remember, think before you click.
Related Capabilities
Featured Insights

Hinshaw Alert
Apr 17, 2026
Q&A: How to Submit Your IEEPA Refund Claim as CAPE Portal Launches April 20, 2026

Webinar
Apr 29, 2026
When a Cyber Breach Hits: Cybersecurity, Privacy, and Compliance

Event
Apr 23, 2026
Driving Ahead: Insights from Industry Leaders Auto Finance Seminar

Press Release
Apr 17, 2026
André Sesler Elected to the Board of Trustees of the University of Florida Law Center Association

In The News
Apr 14, 2026
Bloomberg Law Recaps Panels Presented at Hinshaw's 25th Anniversary LMRM Conference

In The News
Apr 14, 2026
Michael Dowell Discusses the Uncertain Impact of Growing Medicare Advantage Scrutiny

Privacy, Cyber & AI Decoded Alert
Apr 9, 2026
6 Key Takeaways From the IAPP 2026 Global Summit for Privacy Compliance Professionals

In The News
Apr 9, 2026
Megan Lopp Mathias Discusses Future of DEI Employment Initiatives

Consumer Crossroads: Where Financial Services and Litigation Intersect
Apr 8, 2026
After Arbitration, Does a District Court Have Jurisdiction to Confirm or Vacate an FAA Award?





