Skip to content
Guide·Cybersecurity·3 min

Notaries and lawyers: professional secrecy put to the test by email

A notary's office handles funds and deeds, a law firm handles confidential cases. Both receive the same fraud attempts, on the same days.

The essentials in 30 seconds

Legal practices combine three things that attract attackers: confidential information, movements of funds, and time pressure that pushes people to act fast. The most cost-effective countermeasure is not technical: it is a rule of double-checking bank details through a channel other than email, applied without exception, including when the request comes from a partner.

Payment fraud is among the threats most often reported by French businesses to Cybermalveillance.gouv.fr (the French government's cyber assistance service), and notary offices are a favoured target for an obvious reason: the sums involved and the tight timetable for deeds.

The pattern is always the same. An apparently legitimate email announces a change of bank details, just before a payment. It arrives at the right moment because the attacker has already been reading the correspondence for several weeks.

The rule that costs least and protects most

Any change of bank details is checked by a phone call to a number known in advance, never the one given in the message.

  • The number comes from the file, not from the email signature.
  • The rule allows no exception, including when the request appears to come from a partner or a long-standing client.
  • It is written down, displayed, and known to everyone who might prepare a transfer.

Lock down email before anything else

A compromised mailbox almost always comes before the fraud. The attacker reads, learns the firm's vocabulary, spots the cases in progress, then steps in at the exact moment their request will look normal.

  1. Turn on multi-factor authentication for every mailbox, with no exception for partners.
  2. Check the existing automatic forwarding rules: a discreet copy to an external address is the most common sign of a compromise in progress.
  3. Disable legacy authentication protocols, which make it possible to bypass the second factor.
  4. Monitor sign-ins from unusual locations.

Confidentiality of communications and files

Professional secrecy does not stop at the office door. Three points deserve checking every year.

  • Remote access: who can connect to files from outside, and with what level of authentication.
  • Laptops: a stolen computer without disk encryption exposes every file it holds.
  • Providers: those who work on the system need a written framework, not permanent, untracked access.

What happens if everything is encrypted tomorrow morning

A firm without its files cannot work at all. So the question is not the backup but the recovery time, and that time must be known.

An offline or immutable copy, and a restore that has already been timed at least once, are the only two things that turn a three-week disaster into a two-day stoppage.

Frequently asked questions

How can a notary's office or law firm protect itself against payment fraud?
By requiring a phone check of any change of bank details, to a number taken from the file and not from the message received, with no exception possible. This organisational rule is more effective than any technical filter, because the fraud relies on trust and urgency, not on a software flaw.
How can I tell whether a mailbox has been compromised?
The most frequent signs are a new automatic forwarding rule to an external address, messages missing from the sent folder, and sign-ins from unusual locations. All three can be checked in the email administration console.
Is laptop encryption necessary?
Yes, as soon as a laptop holds client files and leaves the office. Without disk encryption, a lost or stolen computer gives access to all the documents stored on it, regardless of the session password.

Next step

Audit my firm's security

Sources

Published 31 August 2026 · Équipe Skill Group, Cybersécurité

Going further

Guide·Cybersecurity

Ransomware: what to do in the first hour

The decisions taken in the first sixty minutes largely determine how long the shutdown lasts. Here is the order of actions, and the three mistakes to avoid.

3 min·
Read the resource
Guide·Business continuity

Food industry: what really stops when IT goes down

On a production site, an IT failure does more than get in the way: it blocks shipping, traceability and sometimes the line itself. Here is how to prioritise.

3 min·
Read the resource