In part one of Law Cover Cyber Podcast series, post Julian Morrow talks to Law Cover Chief Legal Officer, Elissa Baxter, about how cyber fraud has evolved over the last few years, and what law practices can do to protect themselves and their clients. Welcome to Mr. Donair. I'm Julian Morrow, and today we are talking about the never-relaxing topic of cyber-assisted fraud.
I'm very pleased to say that we're joined by Elissa Baxter, the Chief Legal Officer at Law Cover. Welcome, Elissa. Thank you. Pleasure to be here.
Now, Elissa, when did Law Cover first get a claim from a law practice for loss of client funds due to a cyber crime? So I think our first claim came through in about 2017, and we were a little surprised that we were really dealing with fraud and that we were then having to cover client funds that were lost out of a law practice's trust account. 2017, in some ways, seems like a long time ago, but in cyber crime, it's an age ago. What sort of issues were you dealing with in the early days in the cyber area, and how's it changed since then?
The very first claims were really quite rudimentary, so it was just an email that had come into the law practice looking like it came in from a client's email address, but that email address had been slightly changed. So this is your classic email fraud scam? Indeed, except it wasn't very sophisticated, it was really obvious that it wasn't a legit email. It came into the law practice and said, can you please send the money through to this bank?
And the lawyer did it, and afterwards it became clear that they sent it to the wrong place. We started getting our messaging out around then that lawyers need to be a little bit more careful checking that the bank account details sent in an email were legitimate, and we really started wrapping up our messaging around that, and we also put in place a group cyber policy for the benefit of all of our insurance. Since then, lawyers have become a lot better. We actually saw claims drop off quite dramatically in that first couple of years, and we thought, job done, we solved the problem.
You finally? Yeah. The criminals had to move to an easier target, because lawyers knew what they were doing by then and were checking bank account details before they paid money out, and so then the criminals started targeting the clients and sending the fraudulent emails to the clients, and the clients who were less sophisticated would send the money, thinking it was going to the law practice, actually, after a fraud system bank account. So we've had to keep evolving our messages, and it's changed quite a lot.
Now there's quite a few clients who are quite savvy. They do check bank account details, and now we're seeing an evolution where the criminals are kind of staying one step ahead of that, and fraudulently confirming bank account details with the client or with the law practice and still fooling them into paying their money away. And that comes to the broader question of what steps and law firms take to protect their clients' funds from being stolen, but how have the steps that you need to take changed? Yeah, so in the olden days, when I first started practice, almost everything was done over the phone or by letter, and letters took a long time to get there, so you would always do things over the telephone.
We evolved into relying on email. It's easy. We're all comfortable with it. You can send an email, someone can get back to you when they're ready, and it's taken a while to educate people that email isn't really secure.
And to get across the message when anything's got to do with money, you can't really rely on email. We've now got that message across. I think that you need to assume always that an email is going to be intercepted or might have already been intercepted. So people are now picking up the telephone.
But what we're also doing is having to get the message out that talking on the telephone sometimes isn't enough. Do you know enough about your client to know that it's your client you're talking to on the telephone? And also, you might need to warn your client that this could be an issue in the future. People often put a warning in the footer of their email that says, side of scan, is it problem?
And so you need to check bank account details and tell their clients that. Some people put in their retainer letters. Some people put in their retainer letters. This is the law firm's trust account details.
We will never change these details by email. So there are a few steps that you can take. I'm going to say probably best practice would be make sure you meet your client. Make sure you meet your client in person, hand them a letter that has in it, in hard copy, very old school, bank account details, a telephone number that they can call to check, and say we're never going to change those bank account details by email.
That way, you know for sure that this person has got the information that they need, and then the criminals aren't going to be able to get around that by some kind of scan that they might come up with. And criminals have been coming up with these pretty extensive scans. We've seen emails come in saying, I can't check the bank account details over the phone. I have an ear infection.
Or I'm just about to go overseas and get on a plane, just text me, and I will confirm the bank account details by text. So people have been trying to get around the person speaking on the phone. But most recently we started to see the criminals themselves taking the step of saying, I know you want to check bank account details, so I'm just calling into the office, and I'm going to confirm the bank account details with you preemptively. And that is very tricky if you're not speaking to the person who's met the client before.
Most of our staff, the receptionist and the secretaries, I want to be helpful, and they want to do their job, and they want to help clients, and so if the client calls in, they're not going to ask too many questions, they're just going to try and do the right thing. They know they should check bank account details, and so when the client's called in, they go, oh, thank you for doing this, this is fantastic. They believe they're being helpful, they believe they're doing their job, and they're not quite being suspicious enough to say, how do I know this is Julian Morrow that I'm speaking to? How do I know that you're not someone else?
Just asking that extra question. You can see how easily that could be just a little crack in the system because different firms have, people coming and going, someone might be sick, they might be a tampon, and it's actually really hard to maintain that level of client business service, but also be cautious and check identities, because I suppose what you're saying is that in the old days, we used to be able to trust that a verbal confirmation of some sort was most probably going to be okay, but now impersonation is really rich in terms of verifying bank account details and all that. Absolutely, and the firms that are most at risk for this kind of thing are firms that have between two and five partners. So you've got two and five partners, you've got a couple of staff, you've got some admin staffs and supports, you might have 10 or 15 people in the office, enough people that they can be miscommunication.
We aren't seeing as much business email compromise or fraud in one partner practices or sole practitioners, most of them know their clients. So if a client calls in, they'll go, that doesn't sound like Julian's voice, I'm not certain about this, I'm just going to hang up and call back the number that I know. That's where I think we can fall down is where the person who might have the relationship with the client isn't the person taking the phone call. We're going to walk that fine line, right, between being rude, you don't want to be rude to your client, but being a little bit suspicious because you need to be careful.
And it used to be the case that if you heard a voice that you knew, you could trust that that was the person that you were talking to. The technology clearly now exists for artificial intelligence to generate something that sounds like another person's voice. Is that something you've actually seen coming through to cyber assisted fraud claims at law cover or is it something that maybe is on the horizon? I think it's something that's on the horizon.
So we haven't seen that happen in the context of claims against solicitors. But I had heard in the insurance context of one very large fraud that happened in the US and it wasn't just artificial intelligence or generating a voice, it was actually generating an image. So it was like a team's call where the CEO was on the screen giving instructions to someone who was in another country, but they knew enough, they had interacted enough with the CEO to know what they look like and gave those instructions and the money was paid away. So I have heard about happening.
I think you need to have a fair bit of source material. So like your voice, probably someone, what'd be able to sample? They could take it off the risk on their podcast. But for most people, there won't be enough out there in the public domain for that necessarily to be a risk right away.
But what I think it can do is, for example, mask accents. So you might be getting a fraudster from another country who is making a telephone call and in real time, their voice might be being translated to an Australian accent, which might make you more comfortable with accepting bag of card details being verified. There are just so many levels of things you need to be aware of. But really from what you're saying, there's a mix of technical tools that you need, but then also the human element, as you so often the case in scams, it's the human element which is the critical one.
And that means training is important as well. Training not only your staff, it's incredibly important to train your staff, not just your legal staff, your support staff especially because often it's the support staff who are going to be making these phone calls and checking bank account details, but also training your clients. Getting your clients understanding that they can't necessarily trust everything that is sent in an email, if there's an email that says, we've changed our trust account details, the very first thing you think is that must be a scam because that's where we're seeing most of these scams happen. Any email that talks about money, be suspicious about it.
So train all your staff and train your clients, especially to be aware of this kind of thing. And also, I think we all need to train ourselves to just stop for an extra second and ask the question, does this look right? Because what we're often seeing with cyber scams is people get things right time and time and time again, and it's the Friday afternoon, it's the week before Christmas, it's in between Christmas and New Year, it's over Easter, that's where people are just kind of flicking off the last email before they're going to go on holiday, that's when the mistakes happen. People get off a plane, they're jet lag, they look at an email, they click on it.
That's where mistakes happen because people aren't being vigilant all the time. I know it's hard, it's a council of perfection, we can't all be perfect all the time, but just stop for a second and ask the question, does this seem suspicious? I'm supposed to all assume that every human is going to have a lapse at some point, so systems need to not be vulnerable to a lapse by one human in the jane. Yes, that's exactly right.
I mean, humans are going to be the weakest point in any system because every human can make a mistake. So we do need those back up systems around us, but doing double checks, asking me extra question, it might seem rude, but calling the client twice, calling the client on two different numbers, whatever it is that's going to make sure that you've actually got the right information, maybe making a test payment. So if you've got the client on a teams meeting, you're confident it really is the client, you know them, you've got them there, you know who they are, get them to send you a dollar, see if you can see it. Okay, that's come through to the right place, so now you can send your $100,000 or $500,000.
Sounds very wise. Of course, sometimes things are going to go wrong. And thankfully, that's where all law cover members can take at least some consolation in the fact that law cover does have a cyber risk insurance policy. Could you tell us about it, Alissa, and what its key benefits are for members?
Back in 2017, when we saw that first claim coming in, we knew this was going to be a problem. And part of what we do with our risk management education is to tell people the ways in which claims have been against solicitors. You kind of scare them a little bit, but we then try and give them the tools that they can do something about it. We knew cyber was going to be a problem, and so we purchased a group policy.
Now, it's not actually a law cover policy. Law cover's actually the insured in that policy. We bought the policy for the benefit of all of our insured members. So none of those people have to make an application and they don't have to pay any kind of premium.
We bought it on their behalf. It's a relatively low level of cover. It's like $50,000, but it's like a basic level of cover. It covers everyone, though.
I think the primary benefit of it is it gives you emergency assistance. So if you think you might have had a cyber breach, if you think you might have had hackers in your system, you can just call up a number and get forensic people in straight away to check your system and make sure everything's okay. That's, I think, the primary benefit of the policy, but it has a few other benefits. It has a couple of other kinds of cover.
So with client funds are stolen or paid away, that will be covered under the law cover, professional indemnity policy. If the insured firm's own money is paid out of the office account, that will be covered under the cyber group policy. Preaches of privacy, you might have to notify the privacy commissioner. You might need to notify clients.
Those kinds of expenses are going to be covered. If your system is shut down because of a ransom wear attack and your system then needs to be rebuilt, the rebuilding costs are covered under that policy. And actually the ransom itself. Now, what we hope to do is never pay a ransom.
But if your system is shut down and there is no available backup, every now and again, it becomes necessary to pay a ransom. Sometimes they're very small in order to get the system unlocked. Solicitors in particular find that very difficult if they have a trust account and they don't have access to their trust account details. They can't function.
So that's the whole business that's stopped. Business interruption is also covered under the policy. So whatever loss of business you've had for that day when the office was shut down, that will also be covered under the policy. So that's cyber group policy, only has a $50,000 limit, but it can be accessed in a number of different ways.
I've got to say, Alyssa, over the years, when we've been talking on risk on here, I have noticed a bit of a trend amongst insurers. They do seem to say that you should get in touch with your insurer if you're concerned about an incident pretty quickly. Would that happen to apply to the cyber-risk insurance policy as well? Absolutely.
In fact, that is probably the main thing that people should do. The reason is if you've got a cyber incident, money's been paid away. If it's been paid to an Australian bank account, that bank, if you can't take them quickly enough, can put a stop on the money. Now, often the money's gone overseas, almost straightaway, but they do have ways of cloring it back.
The quicker the bank knows, the better the chances are of cloring that money back. So we will say to people who do call us on our hotline, we'll get the forensics team in and make sure that there's nothing else happening in your system, call the bank straightaway, see if you can get a stop put on the money. It's good to call the police and tell them it's been a crime. There's so much cyber crime that's happening.
Unfortunately, the police are not actively investigating a lot of those matters. Nevertheless, you still need to call the police as a whole bunch of people that you need to call. If you call us first, we can start that process. We've got a whole checklist of things that we can tell you to do that are going to help you in that circumstance.
You mentioned that in the early days, there was a bit of a spike, but then things tended to ease off a little bit. Is the cyber risk insurance policy an active area of claims? Like, is this something that a lot of members are experiencing? So it's not our biggest area of claim, like any stretch of the imagination.
Certainly not on the professional identity policy. But we're seeing enough claims coming in that you can really start to see trends. And what we are seeing on the group cyber policy, that is the emergency response policy, quite a few claims come in where there's no loss of funds, no loss of client funds. And what's often happened in those cases is that the solicitable call us up and say, I think I might have been hacked.
And the reason they know they might have been hacked is that a client has received an email saying, we've changed our bank account data. The client was educated enough to pick up the phone and call the law firm and say, got this email and that seemed weird to me. And they said, no, no, that wasn't us. We didn't send that email.
They realized there's a problem. They get the forensics team in. It gets sorted out. And all they've really done is fix a problem and there's been no loss.
And we start to see quite a few of those now, which gives us heart that actually the policy is working, that the education message is getting out there. But we also recently did a survey of our insurers and ask them, how many of you have cyber cover? And more than half said they didn't. We were like, yes, you do.
You've got it with us. You've got it with us. You already have it with us. So I really want to get across the message to people that they already have cyber cover.
It's free. It's automatic. You don't have to apply for it. We bought it for your benefit.
So don't feel afraid to use it. And just understand a little bit about what it covers because it's a benefit that you get when you ensure with us for your professional indemnity. And don't feel that the threshold for taking advantage of that benefit is a financial loss. No, no, all that you need to have is a cyber breach.
Actually, all you need to have is a suspected cyber breach. So it's actually just a suspecting that you've had a cyber breach that allows you to access that policy. If you are in that nervous situation where you think they might have been a breach, how do you best get in touch with Law Cover? We're talking about a step, software dressed on below, sent popped in the post or something.
What is there an easier one? Terri Pige, maybe. So there is a hotline that you can call. Well, a hotline sounds like a much more efficient way to get in touch.
What is the hotline number, Elissa? So the hotline number is 1-800-427-322, which is 1-800-4-britched. Let's staff 24-7. Fantastic.
Elissa, thanks very much for joining us on risk on air. So, that's a good question. Law Cover's Group Cyber Insurance is underwritten by Tokyo Marine Keon, and is subject to the full terms and conditions of the policy wording. To view the policy wording and additional cyber tools, go to lawcover.com.au and type Cyber Risk Insurance.
Thanks for listening to Risk On Air by Law Cover. Join us for the next episode on current risks and legal practice to stay up to date.