Home / Blog / Legal services

Social engineering against lawyers: how one action can expose attorney–client privileged information

11 min read Legal services
Social engineering against lawyers: how one action can expose attorney–client privileged information
There are many ways to gain access to a lawyer’s confidential information, and doing so does not always require finding a technical vulnerability in a smartphone or server. Attackers may choose an easier route — psychological manipulation: persuading the user to open a file, follow a link, disclose a verification code or enter a password on a fake page.
Social engineering is built on precisely these principles. Its primary purpose is to obtain information through emotional engagement by exploiting curiosity, trust or a desire to help. Such attacks pose a particular risk to lawyers because compromising a single account may expose client correspondence, criminal case materials, procedural documents and other information protected by attorney–client privilege.

Emotion versus logic: how social engineering works

Social engineering is a set of methods attackers use to persuade victims to disclose confidential information or take particular actions in order to extract personal or banking data or gain unauthorised access to a computer to install malware. The mechanism is fairly simple: the victim is induced to act emotionally and hand over valuable information themselves. Psychological pressure can persuade a person to visit a fake website, reveal a password, grant access to applications or permit remote control of a computer.
Most such traps combine three elements: manipulation, deception and influence, which makes this approach highly effective. A company may deploy modern firewalls, encryption, multi-factor authentication and intrusion detection systems. Yet some of these controls can be bypassed with a single click if a user voluntarily supplies credentials or runs a malicious file.
Statistics from actual incidents confirm the scale of the problem. According to the Verizon 2025 Data Breach Investigations Report, a human element was involved in 60% of the breaches examined. This category includes the use of stolen credentials, social actions, user errors and interaction with malicious software.
Although not every cyberattack uses social engineering, the human element plays a substantial role in modern attacks.

How fear, urgency and a credible pretext work

Social engineering is much more effective when a person does not have enough time to assess a situation objectively. Attackers’ main weapon is emotion: fear, anxiety, interest, fatigue, a sense of responsibility or guilt. This is why we tend to react immediately to an account-blocking notice, an urgent document or an alert about an attempted account breach. Emotion makes us click a link before we stop to think and verify.
A second common sign is urgency. Messages such as “confirm within ten minutes”, “open the document urgently” or “send the code immediately” create artificial time pressure and suggest that the matter must be resolved at once. The third essential element is credibility. This is especially important in targeted attacks, where an attacker researches the lawyer before making contact: their website, social media, publications, professional relationships, court cases and other publicly available information. The resulting phishing message no longer looks like ordinary spam.
Incoming call from an unknown number on a lawyer’s desk
Vishing often begins with an urgent call supposedly from a bank, support service or law-enforcement officer

Mass and targeted attacks

Mass social engineering targets large numbers of potential victims. An attacker sends thousands of identical emails or SMS messages, creates a fake website or launches automated calls. Success requires only a small percentage of the enormous recipient pool to take the bait.
Targeted attacks pose a much greater threat to legal practice. They are directed at a specific person: the attacker may know a client’s surname, a court case number, the name of a company the lawyer represents or even the name of a colleague.
For example, a lawyer may receive an email purportedly from a court inviting them to download a procedural document, or a message from a client asking them to review a file urgently. The client’s account may already have been compromised, so knowledge of case details does not in itself confirm the sender’s identity.

The difference between phishing, vishing and smishing — and how they work

Phishing

A phishing attack is delivered by email: the victim receives a link to a fake login page or a malicious attachment. A distinct and particularly dangerous form is spear phishing — personalised phishing prepared for a specific lawyer with a clearly defined objective.

Vishing

Fraudsters use voice calls for vishing attacks. The caller may pose as a “bank representative”, “security service”, “technical support”, “law-enforcement officer” or another person whose pretext fits the situation perfectly, seeking to panic the user into disclosing a password or an SMS code.

Smishing

Smishing has long since expanded beyond ordinary SMS. Such messages now arrive through Viber, Telegram or WhatsApp. Fraudsters send a link to a fake bank, delivery-service or tax-authority page. Their objective is to make the victim follow the link and enter their details.

Baiting, pharming, fake Wi-Fi and deepfakes

Baiting exploits curiosity or the desire to obtain something for free. The best-known scenario is a “lost” USB drive left in an office or car park. As soon as someone plugs it into a computer, the device silently launches malware.
Pharming redirects a user to a fraudulent resource that resembles the genuine one. A person may believe they are entering a password on a legitimate website while actually handing it to an attacker.
Fake Wi-Fi access points and deepfakes add further risks. Artificial intelligence enables fraudsters to imitate voices, photographs and videos within minutes. If a voice message in a messenger sounds exactly like a client or partner, that is no longer sufficient reason to take it at face value. See also safer client communication in messengers and mobile-network risks to attorney–client privilege.

How lawyers are attacked

A lawyer receives an email purportedly from a court. Nothing in the message appears suspicious: it gives a real case number, the client’s surname and notice of an urgent hearing. A link is provided to review the materials. The page imitates a familiar court service and asks the lawyer to sign in through their email account. The lawyer enters a username, password and verification code — and falls into the trap. The computer was never hacked: the user handed over the keys to the system.
Once an attacker gains access to the email account, they may read client correspondence, locate cloud storage, obtain documents or use the mailbox for a subsequent attack carried out in the lawyer’s name. Social engineering therefore creates a risk not only for the lawyer: a compromised account becomes a tool for attacking clients, colleagues and employees of the law firm.

Attorney–client privilege and digital access

Article 22 of Ukraine’s Law “On the Bar and Practice of Law” defines attorney–client privilege broadly. It covers any information about a client, the matters on which the client sought advice, the content of consultations and explanations, documents prepared by the lawyer, information stored on electronic media and other information obtained in the course of legal practice. The Law also expressly requires lawyers, law offices and attorneys’ associations to maintain conditions that prevent third parties from accessing or disclosing attorney–client privileged information.
In the digital environment, this requirement has a very practical meaning. If client materials are held in email, a messenger, cloud storage or on a lawyer’s laptop, protecting access to those systems effectively becomes part of safeguarding attorney–client privilege. See also lawyer–client confidentiality: how to prevent information leaks.
Article 23 of the same Law establishes guarantees for legal practice, including a prohibition on interference with private communications between a lawyer and client. The existence of a legal prohibition, however, does not eliminate the technical possibility that a third party may obtain information unlawfully.

What to change in everyday practice

To avoid becoming a victim of social engineering, check not only the wording of a message but also its source. If a bank, client, colleague, court or other person unexpectedly asks you to take an action involving access to information, a payment, a password or software installation, confirm the request through a trusted communication channel.
Call or message the person using a number you already knew, not contact details provided in the suspicious message. For any important service, it is better to enter the address manually in the browser or use a saved bookmark and avoid following links received in messages.
Hardware security key and authenticator app on a lawyer’s desk
Multi-factor authentication using a hardware key or authenticator app reduces phishing risk
Enable multi-factor authentication for every important account. Where possible, use authenticator apps or hardware security keys rather than SMS.
Never connect a found or unfamiliar USB drive to a work computer. Double-check every unexpected email attachment, even if it appears to have come from a colleague or acquaintance. Remember that the amount of professional information available on public social media matters. Public details about clients, current cases, locations, employees and internal working arrangements can be used to construct a convincing pretext.
The more you disclose about yourself on social media, the easier it is for fraudsters to create a trap that may later catch a colleague or partner. Urgency deserves its own rule. If an unknown person creates artificial time pressure while asking you to open a file, follow a link, provide a code or change security settings, that combination should trigger additional verification.

The human element is central to the security system

Social engineering demonstrates that a lawyer’s cybersecurity does not end with antivirus software, a complex password or a modern smartphone. An attacker may not target technical safeguards at all. It is easier to persuade the lawyer to grant the required access voluntarily. The ability to verify the other person’s identity, a website domain, the origin of a document and the reason for an urgent request can therefore protect attorney–client privilege as effectively as the most expensive antivirus product.
For a lawyer, these actions are directly connected with professional practice. A single compromised password may expose information not about one person but about dozens of clients. Resistance to social engineering should therefore be treated as one element of establishing an appropriate system for safeguarding attorney–client privilege.

Social engineering and attorney–client privilege

Do you suspect phishing, a compromised email account or a leak of client materials?

Contact ProDefence — we will assess the risks, help review accounts and digital communication channels, and establish practical safeguards for attorney–client privilege without making unsupported guarantees.

Request a consultation

Confidential. We will never ask for a seed phrase or private keys.