Bogus Law Firms: How Fraudsters Exploit Closed Practices

Originally published 1 February 2014. Updated 8 October 2026.

Bogus law firms can exploit the names, addresses and professional identities of genuine practices, including firms that have closed. The original version of this article highlighted that risk following publication of a list of 136 closed firms.

For COLPs, COFAs and practice managers, the concern extends beyond recognising a suspicious email. Firms need procedures for checking who they are dealing with, verifying payment instructions and responding when their own identity is misused.

The warning reported in 2014

The original article described fraudulent inheritance emails that misused the identity of a solicitor and a recently closed practice. The correspondence referred to an unclaimed inheritance from a previously unknown relative and used the former firm’s genuine address.

According to the account recorded at the time, the genuine solicitor and former practice had no involvement in the emails.

The important distinction was between genuine professional details and fraudulent correspondence. A real name or address did not establish that the person sending the message was entitled to use it.

The reference to 136 firms belongs to that historical report. It is not a current count of closed practices, and inclusion in a closure list should not be treated as evidence of fraud or misconduct.

Closed firms remain vulnerable to impersonation

The risk has continued. On 6 May 2026, the SRA published an alert about correspondence misusing the identity of Azhar & Co, a genuine firm that had ceased trading in December 2009.

The letter purported to come from a solicitor in connection with a visa application. The SRA stated that the named sender was not authorised or regulated by it.

This example shows why an old firm’s name can remain useful to a fraudster long after the practice has closed. Read the SRA alert concerning misuse of a closed firm’s identity for the details.

A genuine SRA number does not authenticate a message

Check the SRA Solicitors Register when verifying an SRA-regulated firm or solicitor. Confirm the relevant entity, office and current regulatory information.

That check does not, by itself, authenticate an email, letter or payment instruction. Fraudsters can copy information from genuine records.

Where correspondence is unexpected or inconsistent, verify it through reliable contact details obtained independently. Avoid using only the telephone number or link supplied in the message being checked.

The SRA’s warning notice on bogus law firms and identity theft explains the risks and relevant indicators.

Watch for changes that require further checks

Staff should escalate inconsistencies such as:

  • An email address that differs subtly from an established address.
  • A previously unknown office or unexplained change of contact details.
  • A payment request that does not fit the matter or the firm’s usual process.
  • Bank details that differ from previously verified instructions.
  • Pressure to bypass checks because payment is said to be urgent.
  • Correspondence about a transaction the genuine firm does not recognise.

A discrepancy is a reason to investigate. Record how it was resolved before relying on the communication.

Verify bank details through a separate channel

The SRA’s information security case studies describe fraudsters intercepting correspondence and substituting payment instructions. Some examples involved accounts bearing names similar to those of genuine firms.

Build independent verification into the payment process. A request to change bank details should prompt a check through an established contact route, with a record of who completed the check and what was confirmed.

Explain the process to clients at the start of the retainer so that an unexpected payment message is less likely to catch them unprepared. The SRA’s warning notice advises firms not to send changes of bank account details to clients by email.

See the SRA’s information security and cybercrime case studies for examples suitable for staff discussions.

Monitor misuse of your own firm’s identity

Include periodic checks of the firm’s published details in your fraud prevention arrangements. Investigate enquiries about unfamiliar matters, unexpected references to new offices or reports of communications that nobody within the practice recognises.

Give staff a clear route for reporting those incidents. Preserve the relevant correspondence and establish whether the problem affects a single communication, a website, an account or a wider group of clients.

Record material incidents, the response and any changes to controls. Our article on maintaining a living and breathing risk register explains why the register should respond to events within the practice.

Respond promptly when fraud is suspected

If a payment may have been diverted, contact the relevant bank immediately and preserve the available evidence. Escalate the incident to the appropriate senior person and obtain technical support where systems may have been compromised.

The SRA advises firms whose identities are being misused to contact it and their insurers, and to inform the police where there is evidence of a crime. Consider whether urgent legal action or other reporting is needed in the particular circumstances.

Review the incident across the firm’s operations. Accounts staff, fee-earners, IT providers and management may each hold part of the information needed to understand what happened.

Our earlier discussion of integrating risk management and SRA compliance explains the value of coordinating those responsibilities.

Keep fraud awareness practical

Use realistic examples to test whether staff recognise suspicious correspondence, know how to verify it and understand when to pause a payment. Review the process after incidents and near misses.

For the wider approach to identifying and addressing learning needs, see our guide to continuing competence for solicitors and COLPs.

Check current SRA scam alerts

Use published alerts alongside independent verification when investigating suspicious correspondence or possible misuse of a firm’s identity. The absence of an alert does not establish that a communication is genuine.

View SRA Scam Alerts

Response

  1. […] related article on bogus law firms and misuse of closed practices’ identities explains why closure and impersonation risks can […]

Leave a Reply

Discover more from Colp & Cofa

Subscribe now to keep reading and get access to the full archive.

Continue reading