A mid-size American law firm serving real estate transactional clients engaged LeakTrace after its outside cyber counsel flagged an unusual pattern of external reconnaissance against three of the firm's partners. The audit produced findings consistent with the reconnaissance phase of a closing-wire redirect operation. Remediation completed before any fraudulent instruction was issued.
Engagement origin
The firm's outside cyber counsel, an American Bar Association-member attorney specializing in law-firm cyber matters, forwarded the initial pattern observation to LeakTrace. The firm employs approximately sixty attorneys and staff across two offices in a single Eastern state, handles a steady real estate transactional book, and had recently increased its wire volume in the quarter preceding the engagement. The firm was not the target of a public incident. It was the subject of active preparatory reconnaissance.
Discovery scope
LeakTrace conducted a seventy-two-hour forensic engagement covering the firm's external surface. The scope included the firm's public web presence, the partners' individual email exposure patterns, the firm's DNS and mail infrastructure configuration, and public-record aggregation on the partners' personal identities. The firm's IT provider participated in one call to confirm scope boundaries but did not provide system access.
Findings summary
The findings clustered into three categories, each consistent with a specific stage of a business email compromise operation targeting real estate closings.
- Partner credential exposure. Two of the three partners under external reconnaissance had personal email addresses in breach databases actively monitored by threat actors. Both had passwords recovered. Both reused patterns consistent with their firm email login structure. This is the enumeration stage of the operation.
- Calendar reconnaissance surface. The firm's public case-tracking portal disclosed transaction milestones through link metadata that indexed into public search results. A threat actor could observe the firm's closing calendar without any authenticated access, allowing precise timing of a fraudulent wire instruction.
- Domain infrastructure. A visually confusable domain had been registered against the firm's primary domain approximately three weeks before the engagement began. Registration records were anonymized behind a privacy service. Mail exchange records had been provisioned. This is the pretexting infrastructure required to send a fraudulent wire instruction that appears to originate from the firm.
Client actions
The firm rotated the two exposed partner credentials, enforced multi-factor authentication across the partnership, and moved to a Federal Financial Institutions Examination Council-recommended authentication baseline. The case-tracking portal was reconfigured to require authenticated access to closing milestones. The look-alike domain was reported and taken down through the firm's counsel channel; the registrar cooperated within five business days. The firm implemented callback verification on every wire instruction above a stated threshold, memorialized in a written procedure signed by the managing partner.
Outcome
No fraudulent wire was issued. The firm's cyber counsel later cited the engagement as an example of the reconnaissance-to-execution timeline that legal risk-management guidance describes but rarely observes in real time. The firm engaged LeakTrace for continuous monitoring covering the partners' personal exposure surface, the firm's domain infrastructure, and the case-tracking portal.
Findings were drawn from public web indexing, breach database monitoring, DNS and certificate transparency logs, and registrar records. No internal systems were accessed. No purchased breach data was used. Coordination with the firm's cyber counsel was maintained throughout the engagement to ensure privileged communications were not disturbed.