HackFirstAidLaw Firms
HomePlaybooksServicesRegulationsAboutContact
← Playbooks · Email & identity

New-matter intake / conflicts-check phishing

The intake inbox is the least-locked-down mailbox in the firm — and it's where credential theft starts.

Credential theft aimed at the intake inbox, then bulk exfiltration of client PII and matter data. Underappreciated because intake is often the least-locked-down mailbox in the firm.

The first hour

What to do, in order.

  1. 01

    Reset the intake account and require MFA.

  2. 02

    Review forwarding rules and recent search activity in the mailbox.

  3. 03

    Identify what intake data was accessible during the compromise window (name, contact, opposing party, matter type, dollar exposure).

  4. 04

    Notify prospective and current clients whose intake data was in scope.

Key decisions

The questions you'll be asked.

Does Rule 1.18 apply to prospective clients?
Yes. Prospective-client information (Rule 1.18(b)) carries the same safeguarding duty as current-client information under 1.6(c).

Regulatory & ethical hooks

What the rules say.

  • ABA Model Rules 1.6, 1.18
  • State data-breach notification laws

Cited for orientation, not as legal advice. Your firm's ethics counsel and LPL carrier should be consulted on every specific incident.

Related playbooks

  • Email & identity

    Business email compromise — impersonation

  • Email & identity

    Client portal / e-signature account takeover

HackFirstAid for Law Firms

The first hour after an incident decides whether your firm keeps the client's money, the client's secrets, and the client's trust. We walk firms through it in plain language.

Advisory, training, and incident response — not legal advice. Reading this site creates no attorney-client relationship.

The site

  • Home
  • Playbooks
  • Services
  • Regulations
  • About
  • Contact

Family

  • hackfirstaid.com
    Free for your household
  • business.hackfirstaid.com
  • municipal.hackfirstaid.com
  • education.hackfirstaid.com
  • medical.hackfirstaid.com
    HIPAA Business Associate overlay
  • boards.hackfirstaid.com
  • leadership.hackfirstaid.com
  • it.hackfirstaid.com
© 2026 HackFirstAid. All rights reserved.Scope of Use·lawfirm.hackfirstaid.com