Florida Law Firms Are Under Attack: What Solo and Small Practices Need to Know About Email Compromise

ArisGate Security Team

•
July 31, 2026
ARISGATE SECURITY BRIEF · PHISHING & SOCIAL ENGINEERING
The money is usually gone before anyone notices.
Business email compromise is the most common attack on Florida firms right now, and it depends on one habit you can break today.

Business email compromise remains the most common attack vector against Florida firms. A criminal gains access to an attorney's email, often through phishing or a weak password, watches quietly to learn how money moves through the firm, then sends a fraudulent wire instruction or impersonates the attorney to staff. By the time anyone notices, the money is rarely recoverable.

Why this goes beyond money

This isn't only a financial problem. Florida Bar Rule 4-1.6 requires reasonable efforts to prevent unauthorized disclosure of client information, and weeks of a hacker reading privileged communications is a confidentiality breach regardless of whether money changed hands. Recommendation 25-1 pushes firms toward documented safeguards, and Florida's FIPA law requires breach notification within 30 days, with real enforcement risk for missing that window.

What to do this week

  1. Enable multi factor authentication on every email, case management, and cloud storage account.
  2. Verify any change to wire instructions by phone using a number you already have on file, never one from the email.
  3. Train staff quarterly, not once.

How ArisGate helps

ArisGate builds security programs around these exact Florida Bar obligations. Schedule a free security audit today.

Schedule a Call