HackFirstAidLaw Firms
HomePlaybooksServicesRegulationsAboutContact
← Playbooks · Email & identity

Client portal / e-signature account takeover

Stolen client credentials on the firm portal or DocuSign. The attacker may now be the client, for purposes of redirecting a disbursement.

Stolen client credentials on the firm portal or an e-signature platform (DocuSign-class). The attacker views or alters documents, or impersonates the client to redirect a disbursement.

The first hour

What to do, in order.

  1. 01

    Lock the affected portal accounts; force MFA re-enrollment.

  2. 02

    Audit recent document views, downloads, and signature events on the affected accounts.

  3. 03

    Call the client on a known number to verify recent requests — especially any payment or wire change.

  4. 04

    Hold any disbursement, refund, or instruction received through the portal in the last 30 days pending verification.

Key decisions

The questions you'll be asked.

Was a disbursement made on the attacker's instruction?
Go to the trust-account wire-fraud playbook immediately. Recall windows close fast.

Regulatory & ethical hooks

What the rules say.

  • ABA Model Rule 1.6(c)
  • State data-breach notification laws

Cited for orientation, not as legal advice. Your firm's ethics counsel and LPL carrier should be consulted on every specific incident.

Related playbooks

  • Money

    Trust-account / IOLTA wire fraud

  • Email & identity

    Business email compromise — impersonation

HackFirstAid for Law Firms

The first hour after an incident decides whether your firm keeps the client's money, the client's secrets, and the client's trust. We walk firms through it in plain language.

Advisory, training, and incident response — not legal advice. Reading this site creates no attorney-client relationship.

The site

  • Home
  • Playbooks
  • Services
  • Regulations
  • About
  • Contact

Family

  • hackfirstaid.com
    Free for your household
  • business.hackfirstaid.com
  • municipal.hackfirstaid.com
  • education.hackfirstaid.com
  • medical.hackfirstaid.com
    HIPAA Business Associate overlay
  • boards.hackfirstaid.com
  • leadership.hackfirstaid.com
  • it.hackfirstaid.com
© 2026 HackFirstAid. All rights reserved.Scope of Use·lawfirm.hackfirstaid.com