I Sent a Fake Phishing Email to a Law Firm — The Results Shocked Me
Geek Heros War Stories
The Experiment
When a new client — a 30-person law firm specializing in family law and estate planning — came on board, they were confident about their security posture. "Our people are smart," the managing partner told me. "They're lawyers. They're not going to fall for some Nigerian prince email."
I nodded politely and suggested we find out. We proposed a baseline phishing simulation — a controlled test where we send realistic (but harmless) phishing emails to the entire firm and measure who clicks, who enters credentials, and who reports the email as suspicious.
The managing partner agreed, with one condition: "Don't make it too hard. I don't want to embarrass anyone."
We made it moderately realistic. Not an amateur-hour "URGENT: Click here to claim your inheritance" email. But not a nation-state-level spear phishing campaign either. Something in the middle — the kind of phishing email that actually lands in inboxes every day.
The Phishing Email
We crafted an email that appeared to come from Clio — the firm's practice management software. The email used Clio's branding, color scheme, and typical email formatting. The subject line read: "Action Required: Verify Your Account to Avoid Service Interruption."
The body of the email explained that Clio was "performing a security upgrade" and required all users to verify their login credentials by clicking a link. The link led to a replica of the Clio login page — hosted on a domain we controlled, with a URL that was close to Clio's real domain but slightly different (the kind of difference that most people don't notice).
The email was sent at 9:15 AM on a Tuesday — peak email-checking time. We tracked three metrics: who opened the email, who clicked the link, and who entered credentials on the fake login page.
The Results
After 24 hours, we compiled the data. The managing partner was not prepared for what we showed him.
Email opened: 87% of recipients (26 out of 30 staff)
Clicked the phishing link: 73% (22 out of 30)
Entered credentials on fake login page: 45% (13 out of 30, including 4 attorneys and the office manager)
Reported the email as suspicious: 3% (1 person — a junior paralegal who had previously worked at a financial services firm with mandatory security training)
Let that sink in. Nearly half the firm — including four attorneys who are ethically obligated to protect client data — typed their real usernames and passwords into a fake website. If this had been a real attack, the attackers would have had valid credentials for 13 accounts within hours.
What This Means for Client Data
Under ABA Model Rule 1.6, attorneys have an obligation to make "reasonable efforts" to prevent unauthorized access to client information. A firm where 45% of staff will hand over their credentials to a moderately convincing phishing email is not making reasonable efforts. Period.
Consider what an attacker could do with 13 valid login credentials:
Access every client file in the practice management system. Family law cases contain deeply personal information — financial records, custody evaluations, mental health records, allegations of domestic violence. Estate planning files contain Social Security numbers, financial account details, and complete asset inventories.
Read and send email as the compromised users. An attacker could send emails to clients from an attorney's real email address, requesting wire transfers, Social Security numbers, or other sensitive information. The client would have no reason to suspect the email wasn't legitimate.
Move laterally through the firm's network. With valid credentials, especially an office manager's credentials, attackers can access shared drives, financial systems, and administrative tools. From there, they can deploy ransomware, exfiltrate data, or establish persistent access.
The Fix: From 73% to Under 5%
After sharing the results (in a firm-wide meeting that was, by the managing partner's own admission, "humbling"), we implemented a comprehensive security awareness program:
Month 1: Baseline training. Every staff member completed a 45-minute interactive training module covering how phishing works, how to identify suspicious emails, and what to do when they receive one. The training used real-world examples from the legal industry, not generic corporate scenarios.
Month 2: First follow-up simulation. We sent a second phishing email — this time impersonating Microsoft 365 with a "your password expires today" message. Click rate dropped to 41%. Credential submission dropped to 18%. Progress, but not enough.
Month 3: Targeted training. Staff who clicked in the second simulation received additional one-on-one coaching. We walked them through exactly how the phishing email differed from a legitimate Microsoft email, what red flags to look for, and how to verify suspicious messages through a second channel.
Months 4-6: Monthly simulations with increasing sophistication. Each month, we varied the phishing technique — an invoice from a "vendor," a shared document notification, a fake voicemail transcription. Click rates continued to drop: 28%, 15%, 8%.
Month 6 result: Click rate was 4.2%. Credential submission was 0%. Report rate (staff correctly identifying and reporting the phishing email) was 67%.
The transformation took six months of consistent, ongoing training. Not a one-time lunch-and-learn. Not a checkbox compliance exercise. Real, regular, measured training with accountability.
The Cost of Not Training
Let's put numbers to it. The security awareness training program cost the firm approximately $150 per user per year — about $4,500 total. The average cost of a successful phishing attack on a law firm? According to industry data, somewhere between $200,000 and $2,000,000 depending on the scope of the compromise.
The one junior paralegal who correctly identified and reported our test phishing email had received security awareness training at her previous employer. That training — which probably cost her previous firm $150 — would have been the only thing standing between this firm and a catastrophic breach if our test had been real.
What You Should Do Right Now
If your firm isn't conducting regular phishing simulations and security awareness training, you are exposed. Here's the minimum:
1. Run a baseline phishing simulation. You need to know where you stand. The results will almost certainly be worse than you expect.
2. Implement monthly or quarterly training. Not annual. Not "when we get around to it." Regular, measured training with tracked completion.
3. Send monthly phishing simulations. Vary the techniques, track the metrics, and follow up with staff who click.
4. Create a reporting mechanism. Staff should know exactly what to do when they receive a suspicious email — and they should be praised, not penalized, for reporting false positives.
5. Deploy MFA on everything. Even if someone falls for a phishing email and enters their credentials, MFA prevents the attacker from using those credentials to log in.
Want to know your firm's phishing click rate? [Get a free site audit](#assessment) — we'll include a complimentary baseline phishing simulation so you can see exactly where you stand.
Get Your Free Site Audit
Find out where your firm stands on security, compliance, and IT performance — at no cost.