Sponsored content
Every day in my role working with businesses across Australia at ANZ, I see how cybercriminals are refining their tactics to target organisations that manage sensitive financial transactions and client funds.
Among these businesses are law firms, custodians of trust accounts, responsible for holding and transferring money on behalf of their clients, often under significant time pressure and strict regulatory obligations. That combination of trust, urgency and responsibility has made legal practices an increasingly attractive target for cyber criminals.
One of the fastest growing threats we are seeing is bank impersonation scams, and the impact on trust account holders, including law firms, can be severe.
A bank impersonation scam occurs when a cybercriminal contacts a business pretending to be from their bank. They typically claim to be calling from the bank’s fraud or security team and may raise concerns about an alleged account compromise, suspicious transaction or online banking outage. The goal is to create urgency and prompt immediate action.
These approaches are becoming increasingly convincing. Calls may appear to come from a legitimate bank phone number. Messages can arrive in the same text thread as genuine bank communications. Emails may closely replicate official bank branding and language.
For legal practitioners managing settlements, court deadlines and client expectations, the pressure to act quickly can be overwhelming.
The consequences of responding without verification can be devastating, not only in financial terms, but also through reputational damage, regulatory scrutiny and the loss of client trust.
Why trust account holders including law firms are being targeted
We are seeing a clear pattern emerge across businesses that operate trust accounts, including law firms, conveyancers and real estate agencies.
These businesses often deal with large, timesensitive transactions and client funds, making them particularly appealing to cybercriminals. For law firms, the stakes are even higher, given the professional and ethical obligations associated with managing trust money.
Industry bodies are already warning members about the rise in impersonation scams. At ANZ, we are seeing a corresponding increase in attempted and successful impersonation attempts involving trust accounts held by legal practices.
What makes bank impersonation scams particularly dangerous is the psychological manipulation involved. Scammers exploit authority and fear, posing as bank staff and insisting urgent action is required to protect funds. In some cases, businesses are instructed to transfer money, open new accounts or provide access to devices, all under the guise of security.
It is important to be absolutely clear – these are never actions a bank will ask you to take.
What ANZ will never ask a law firm to do
ANZ encourages all customers, particularly those operating trust accounts, to be highly cautious of any unsolicited contact claiming to be from the bank. ANZ will never ask you to:
- Share sensitive information such as onetime passcodes, PINs or card details
- Transfer trust or operating funds to another account to protect them
- Open a new account at the request of a caller, text or email
- Provide remote access to your computer or device
- Download software as part of a fraud investigation
If something feels urgent, unusual or inconsistent with your established processes, pause. That hesitation can prevent a serious incident.
Pause. Verify. Protect.
Given the volume of calls, emails and messages legal practices manage every day, it is easy to respond instinctively. Scammers rely on this.
If your firm receives an unsolicited call, message or email claiming to be from your bank:
- Hang up the call
- Close the message or email
- Contact your bank using known and trusted contact details, such as the phone number on the back of your card or official online banking channels.
Taking control of the interaction immediately removes the scammer’s advantage.
It is equally important that law firms warn clients about fraudulent emails that appear to come from the firm itself, advising that trust account details have changed. These messages are often timed around settlements or other urgent payment milestones.
To reduce this risk, firms should clearly advise clients that trust account details will not change and encourage them to save the firm’s trust account details in their internet banking platform. Clients should be instructed that if they receive unexpected instructions to change account details, they should pause the payment immediately and verify the request by contacting the firm using trusted contact details already on file.
Reinforcing this guidance through engagement letters and settlement communications helps normalise verification and reduces the risk of funds being misdirected.
Culture matters as much as controls
Strong cyber security is not built through technology alone. Like any highperforming organisation, resilience is created through consistent, disciplined habits.
For law firms, this means creating a culture where staff feel empowered to slow transactions down, question unusual requests and escalate concerns, regardless of urgency or seniority.
We have seen how this works in practice. In one instance, a law firm staff member received a call from someone impersonating ANZ and was told the firm’s trust account had been compromised and funds needed to be urgently moved to a new account. Because the firm had implemented an appropriate makerchecker process, the change was questioned and verified using trusted ANZ contact details. The call was confirmed as fraudulent and no funds were transferred.
This type of outcome is only possible when processes are supported by a culture that encourages staff to pause and verify, even under pressure.
Practical steps include:
- Regular scam awareness training, particularly for new and junior staff
- Clear, documented procedures for verifying payment requests or changes to banking details
- Dual authorisation for trust account transactions, especially under pressure
- Defined escalation pathways when something does not feel right
Cyber Security Awareness Month each October is a helpful reminder, but for trust account holders vigilance must be ongoing.
If the worst happens
If your firm suspects it has been targeted by a bank impersonation scam, or believes financial information has been shared or funds transferred, contact ANZ immediately. Our Customer Protection Team is available 24 hours a day, seven days a week to assist.
Firms are also encouraged to report incidents to:
- Scamwatch, operated by the Australian Government
- The Australian Cyber Security Centre
Reporting incidents helps protect not only your firm, but the broader legal profession.
Protecting client trust
Law firms are built on trust. Trust from clients, regulators and the community. Cybercriminals understand this and are actively seeking to exploit it.
By strengthening verification practices, embedding awareness across teams and clearly educating clients about how legitimate trust account payments work, law firms can continue to operate trust accounts confidently and securely. Protecting client funds is not simply a compliance requirement. It is fundamental to protecting the profession itself.
