The Law Society of Scotland has issued a warning about a sophisticated phishing campaign targeting the legal profession. Unlike traditional scam emails that impersonate solicitors, attackers are gaining direct access to genuine solicitor mailboxes and sending emails from legitimate accounts. This means the messages can appear completely authentic, including genuine email signatures and passing standard email security checks.
The emails often contain attachments or links disguised as statements of account, remittance advice or other routine legal correspondence. These links direct recipients to fake Microsoft sign-in pages designed to steal login credentials.
The risk extends far beyond credential theft. Once a mailbox is compromised, fraudsters can monitor live transactions and attempt convincing payment diversion frauds, potentially leading to the loss of substantial client funds.
The key message is simple: do not rely solely on an email appearing genuine. If you receive an unexpected email containing links, attachments or payment instructions, verify it independently by telephoning the sender using known contact details before taking any action. The same vigilance should apply whether you are a solicitor, client or professional contact.
Cybercrime continues to evolve, and this alert is a reminder that even trusted accounts can be compromised. A quick phone call can prevent a costly mistake.
🔗 Read the full Law Society of Scotland warning here:

/Passle/59994aefb00e801a0c1447be/SearchServiceImages/2026-08-22-08-51-34-832-6a896316c6717a6a80ea7ade.jpg)
/Passle/59994aefb00e801a0c1447be/SearchServiceImages/2026-08-22-08-35-38-772-6a895f5a78492b23f8e76e69.jpg)
/Passle/59994aefb00e801a0c1447be/SearchServiceImages/2026-07-24-09-51-58-648-6a6335be20291f5022b83109.jpg)