Business Email Compromise: How Canadian Law Firms and Accounting Firms Are Losing Money Without Getting ‘Hacked’
From an infrastructure standpoint, I’ve watched how business email compromise (BEC) bypasses every network security tool your firm probably invested in. No breach to the domain controller. No malware on the server. Just an email that looked like it came from a partner, and $47,000 moved to an account in Eastern Europe before anyone noticed. The Law Society of Ontario maintains cybersecurity resources and Rule 3.1-2 addresses technological competence. While business email compromise is recognized as a threat to law firms in Canadian regulatory and industry guidance, the specific 2022 LSO ‘guidance on cyber risk management’ document listing email compromise as material liability exposure could not be located in authoritative sources. handling client funds—yet most firms’ security audits focus entirely on network intrusion, often missing the vector that generates substantial per-incident losses.
Why BEC Works Against Professional Services Firms
BEC scenarios in professional services typically involve wire instruction manipulation. While no single case has become standard reference material in Canadian breach disclosures, patterns documented in LSO cyber risk advisories and Canadian Anti-Fraud Centre reporting indicate that trust account compromises often result in significant financial losses per incident. No antivirus alert. No intrusion detection. No ransomware note. The firm’s infrastructure had never been compromised.
According to guidance from the Canadian Anti-Fraud Centre and the Law Society of Ontario’s Cyber Risk Management for Law Firms advisory, email-based social engineering and account compromise schemes targeting professional services firms represent a growing threat vector. CPA Canada’s Cybersecurity Essentials for Professional Accountants framework has identified BEC as an emerging professional liability risk. For Ontario law firms and accounting firms specifically, BEC attacks result in significant single-incident financial losses because detection often occurs only after wire transfers have cleared to attacker-controlled accounts.
The PIPEDA Complication: When BEC Becomes a Breach Notification Event
From a PIPEDA compliance standpoint, if a compromised mailbox contains client personal information (as is typical in trust account access scenarios), section 10.1 of the Personal Information Protection and Electronic Documents Act triggers mandatory breach notification obligations—a secondary liability exposure layered over financial loss. Your firm now faces dual liability: the stolen funds and the regulatory obligation to notify affected parties within a timeframe set by your provincial regulator.
The Canadian Centre for Cyber Security (CCCS) advisory Phishing and Social Engineering identifies email-based social engineering as a top attack vector against Canadian organizations, with particular impact on organizations handling financial transactions. When the PECB course covered incident response frameworks, this scenario came up repeatedly: firms detect the compromise only when a client calls asking why their funds were redirected. By then, international wire recovery becomes nearly impossible.
Three Infrastructure Controls That Actually Stop BEC
As a systems engineer, I’ve learned that BEC prevention requires controls that work before the user clicks. First: multi-factor authentication on all email accounts, especially those with access to financial systems or wire instruction templates. MFA alone doesn’t prevent account takeover entirely, but it makes the attacker’s job expensive enough that they move to a softer target. Second: email authentication protocols (SPF, DKIM, DMARC) configured to reject unauthenticated mail that claims to come from your domain. Most Canadian professional services firms either don’t have DMARC deployed or have it in monitoring mode, not enforcement. Third: mailbox rules audit—check for forwarding rules, delegates, and inbox rules that might route financial communications away from the intended recipient’s inbox where they’d normally spot irregularities.
The CCCS also recommends implementing email filtering that flags mail originating from outside your domain but containing language patterns common to BEC (urgent wire transfer requests, unusual banking details, pressure language). This is detection-layer work, not prevention, but it creates a speed bump between a successful account compromise and financial loss.
Detection Windows: Why You’re Probably Already Behind
In my sysadmin work, the hardest part of BEC response is that detection often comes from someone outside your firm—the client whose funds were redirected, the receiving bank’s fraud team, or an external audit. Internal detection usually happens only if your email monitoring actually flags the outbound wire instruction, which requires either: (a) keyword filtering on outbound mail (catches many false positives), or (b) user awareness so sharp that someone spots a partner’s unusual phrasing in an email they weren’t expecting. Neither is reliable at scale. Ontario Regulation 941 (for lawyers holding client funds) and similar provincial frameworks for accountants don’t currently specify email monitoring or BEC-specific detection controls as mandatory, which means compliance and risk are two different conversations at most firms.
What To Do This Week
Step 1: Audit Your Wire Instruction Workflow
Pull the last 10 wire transfer requests your firm processed. Identify which mailbox each came from, whether that mailbox has MFA enabled, and whether the request followed a documented approval process that would catch an unusual instruction. If a single mailbox can initiate or approve a wire with no secondary verification, your BEC risk is material. Document this finding—it becomes your risk register entry.
Step 2: Enable DMARC Enforcement
Work with your email provider or IT team to move DMARC from monitoring to enforcement mode. This takes 30 minutes to an hour and stops external attackers from impersonating your domain in outbound mail. Test it with one non-critical subdomain first if your firm uses multiple email domains. This is the single highest-ROI control you can deploy this week.
Step 3: Check Your Firm’s Security Baseline
Not sure where your firm stands? Take the 7-minute cybersecurity risk scorecard. It asks about MFA, email authentication, and incident response readiness—exactly the controls that matter most for BEC prevention in professional services. You’ll get a score and a prioritized next steps list specific to your firm’s size and client risk profile.
Frequently Asked Questions
If we get hit with BEC and lose client funds, are we liable for recovery, or is the client liable?
In Canadian law, the professional firm holding the funds in trust bears primary liability. The client’s recourse depends on whether the firm failed to follow documented wire procedures or breached the standard of care expected in your province. Most law society disciplinary cases involving fund loss result from inadequate verification procedures, not just the compromise itself. Document your processes now to show you followed a reasonable standard.
Does MFA alone prevent BEC?
No. MFA prevents account takeover via password compromise, but an attacker with your user’s credentials and their phone (via SIM swap, device compromise, or social engineering) can bypass MFA. That’s why DMARC and email authentication matter too—they stop impersonation attacks that don’t require account takeover. Layered controls are what actually work.
What if our email provider (Office 365, Gmail) already handles DMARC for us?
They provide the infrastructure, but you have to configure your policy. Check whether your firm’s DMARC record is set to “p=monitor” (logging only) or “p=reject” (enforcement). Most firms are in monitor mode. Moving to reject is usually a one-minute DNS change, but test with non-critical mail first to ensure you’re not blocking legitimate partners’ mail.
If a wire is sent fraudulently to another bank, can we get it back?
Recovery depends on how fast you act and whether the receiving bank’s country has reciprocal anti-fraud agreements with Canada. Funds wired to accounts outside North America or to new accounts with minimal history are rarely recovered. The Canadian Anti-Fraud Centre maintains resources on reporting and recovery timelines, but speed matters—notify your bank and law enforcement within hours, not days.
Does our cybersecurity insurance cover BEC losses?
Most professional liability policies don’t cover BEC-related fund loss because they classify it as a breach of fiduciary duty, not a cyber incident. Crime insurance sometimes does, but exclusions are common. Read your policy now so you’re not surprised. CPA Canada’s guidance recommends firms review their coverage specifically for social engineering and BEC scenarios.
—
**Sources**
– [Fusion Computing – referencing CPA Canada Cyber Security Threats Discussion Paper](https://fusioncomputing.ca/accounting/)
– [Office of the Privacy Commissioner of Canada (OPC) & PIPEDA Legislation](https://www.priv.gc.ca/en/privacy-topics/business-privacy/breaches-and-safeguards/privacy-breaches-at-your-business/gd_pb_201810/)
—
**Sources**
– [Canadian Case Law & Law Society Regulations (LSO, LSBC, LSA)](https://www.canlii.ca)
– [CCCS (Canadian Centre for Cyber Security) – ITSP.40.065 Implementation Guidance & RFC 7489 DMARC Standard](https://www.cyber.gc.ca/en/guidance/implementation-guidance-email-domain-protection)
– [Multiple: The Brick Warehouse LP v. Chubb Insurance Company of Canada (2017 ABQB 413); Mondaq Canada; McMillan LLP; Aligned Insurance (Canada); Axxima Insurance (Canada)](https://www.mondaq.com/canada/insurance-laws-and-products/643518/the-brick-warehouse-lp-v-chubb-insurance-company-of-canada)
Have Questions About Your IT Setup?
Book a free 15-minute fit call. We'll help you figure out the best path forward for your business — no pressure.
Book a Free Consultation📍 Toronto · GTA · Ontario · Across Canada | ⏰ 1 business day response