Law Firm Falls Victim to Scam, Sued by Bank

If this headline doesn’t catch your attention, I’m not sure what will. Here is Sharon Nelson’s latest post on Ride the Lightning:

“It continues to amaze me how law firms fall for phishing scams, sometimes believing that they might have a potential client and sometimes, as here, clicking where they shouldn’t click. The latest law firm is Wallace & Pittman PLLC in North Carolina who reportedly got scammed to the tune of over $300,000.00. And it only went downhill from there.

The scam started with a batch of e-mails in May supposedly from an industry group saying that a transaction hadn’t cleared properly. These e-mails directed readers to click on a link to resolve the problem. Apparently, someone at the law firm did, which allowed hackers to install a keylogger on at least one law firm computer.

After figuring out the law firm’s online banking passwords, the hackers directed their bank, Park Sterling, to send a $336,600.01 transfer through JPMorgan Chase & Co. to a “Konstantin Pomogalove” in Moscow, according to a legal document filed by the law firm. As soon as the law firm received a confirmation of the transaction, it called the bank to cancel it, but it was too late. The bank initially refunded the stolen funds to the law firm’s account.

Later, the bank demanded the funds be returned. State and federal law does not compel banks to restore funds lost through fraudulent activity for commercial customers so long as the bank has reasonable security in effect.

But before the bank could debit the fund, the law firm obtained a restraining order against the bank, removed its funds and closed the account, igniting a lawsuit by the bank.

Park Sterling argues in court papers that Wallace & Pittman did not use an extra layer of security that would require two people to authorize wire transactions and that the request looked legitimate. It also said its customer agreement with the firm places the burden of loss on the customer.

Though the firm uses wire transfers regularly for real estate transactions, this was the first to go outside the country which the firm argues should have raised suspicion enough to put a hold on the transactions. Unsurprisingly, the firm questions the security practices of the bank.

Trial is scheduled for the fall.

There are conflicting cases on whether banks can be held liable, though most have found that they can be, putting a higher burden on information security for banks. My initial take, without having all the facts, is that a bank which suddenly received a high-figure transfer out of the country from a firm which has never done that before should sure as heck have flagged the transaction as potential fraud. And Wallace & Pittman needs to institute two-person authorizations and do some serious employee training!”

Learn how to avoid falling victim to such scams by attending “Protecting Your Firm and Your Clients from Fraud, Scams, and Financial Loss” on May 16 at the OSB Center. Registration open now – visit the PLF Web site > Upcoming Seminars.

3 thoughts on “Law Firm Falls Victim to Scam, Sued by Bank

  1. Reblogged this on Shawn R. Bradley, CFE; M.S. —— Fraud Blogging and commented:
    A North Carolina Law firm fell victim to over $300,000 scam and was then sued by their bank, JP Morgan Chase!! No effective internal controls over proper procedures authorizing a wire transfer and the lack of the bank not “knowing” its customer, combined for a terrible mix of mayhem. It is imperative for the company and its bank to have a heck of a decent relationship. Is JP Morgan Chase too big and only concerned about their bottom line and not yours?!

  2. Pingback: North Carolina Law Firm Falls Victim To A Scam of Over $300k and Gets Sued By Its Own Bank, JP Morgan Chase | Shawn R. Bradley, CFE; M.S. ------ Fraud Blogging

  3. Pingback: A Look at the Year Past – Tips You May Have Missed | Oregon Law Practice Management

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s