Cybersecurity threats have long been framed as a digital problem; something managed at the firewall, the inbox, and the endpoint. That framing is no longer sufficient.
A shift is underway in how sophisticated threat actors target organizations. The most dangerous attacks today don’t begin with malware or zero-day exploits. They begin with a phone call.
Social engineering (the process of manipulating people rather than systems) has become the dominant entry point for data theft and fraud across high-value industries. Law firms and financial institutions are among the most actively targeted, and for the same reason: both hold extraordinarily sensitive information that can be monetized through extortion, fraud, or resale. Attackers know that the fastest way in is often through a trusting employee, not a technical vulnerability.
And when the phone isn’t enough, some are willing to walk through the front door.
The Threat Landscape: Two Converging Attack Vectors
Telephone-Based Social Engineering
Fake tech support scams have long targeted individuals, but the same playbook is now being run against organizations at scale. In a typical attack, an employee receives a call or message from someone claiming to be from internal IT, a software vendor, or a regulatory body. The urgency is manufactured. They’ll claim there was a security breach, a failed backup, or maybe a compliance issue, and the ask is always access.
Once access is granted, the attacker moves quickly. Files are exfiltrated, credentials harvested, and sensitive data copied before the employee realizes anything is wrong. In financial institutions, these calls may impersonate bank regulators, fraud prevention teams, or core system vendors. In law firms, they tend to impersonate IT staff or document management providers.
The FBI and FTC have both documented a sharp rise in these callback phishing schemes targeting professional services organizations. The social engineering is often sophisticated enough that even security-aware employees are deceived.
When the Phone Fails, They Show Up
Recent FBI advisories have confirmed an escalation that moves these attacks firmly into the physical world. When remote social engineering attempts fail, some threat actors do not move on, they show up in person.
Posing as IT support staff, attackers enter offices and approach employees directly, continuing the impersonation facade face-to-face. Once they have physical access to a device, they claim to need to “image” it or run diagnostics. What they are actually doing is copying sensitive files onto a USB drive to use as extortion leverage.
The FBI has flagged this tactic specifically for the legal sector, where it has been reported with enough frequency to warrant dedicated guidance. But the same logic applies to any organization where physical access to a workstation could yield high-value data, which describes virtually every financial institution and law firm in the country.
Why Law Firms and Financial Institutions Are Primary Targets
These two sectors share a profile that makes them disproportionately attractive to social engineers.
-
- Data density. Both hold concentrated stores of highly sensitive information: privileged legal communications, client financials, transaction records, litigation strategy, and account credentials. A single successful intrusion can yield leverage worth far more than the cost of the attack.
- Trust-dependent workflows. Both industries operate on relationships and assumed legitimacy. Employees are culturally conditioned to be responsive and helpful, especially to people who appear to be colleagues or vendors. Social engineers exploit this directly.
- Regulatory and reputational exposure. The threat of leaked data carries compounding consequences: regulatory penalties, professional liability, client attrition, and reputational damage that can be difficult to recover from. Attackers know this, and they price their extortion demands accordingly.
- Distributed access points. Large firms and institutions have many employees, offices, and vendors, all of which represent potential entry points. The attack surface is wide, and not every node is equally well-defended.
How These Attacks Typically Unfold
Stage 1 — Reconnaissance and Initial Contact
Attackers identify a target organization and research its personnel, vendors, and IT infrastructure often through LinkedIn, firm websites, and public filings. They then initiate contact via phone, SMS, or email, impersonating a known and trusted entity: an IT helpdesk, a software vendor, a regulator, or a financial system provider.
Stage 2 — The Social Engineering Play
The attacker manufactures urgency. A security alert, a failed compliance check, an unauthorized transaction. The employee is told they need to act immediately, and is guided toward granting remote access, providing credentials, or installing software. In financial institutions, callers may claim to be from fraud prevention and walk employees through “verification steps” that are actually credential harvesting.
Stage 3 — Escalation to Physical Access
If remote access cannot be obtained, some threat actors escalate to in-person contact. They arrive at the office, sustain the impersonation, and request physical access to a device. USB drives are the primary tool at this stage. They connect quickly and can copy targeted files in minutes.
What Organizations Should Do Now
The following measures are recommended by the FBI and align with best practices for both legal and financial institutions.
-
-
-
- Disable external USB ports on all devices that handle confidential data. This is the single most direct countermeasure against in-person intrusion. If a drive cannot connect, the physical attack fails.
- Establish strict visitor and vendor verification protocols. Any person claiming to be IT support, internal or external, should be verified via a callback to a known number before being granted access to any device or system. This applies to scheduled visits as much as unexpected ones.
- Train staff to recognize social engineering in every form: over the phone, via email, and in person. Employees should feel empowered to pause, verify, and escalate without fear of appearing uncooperative. Attackers rely on social pressure; removing that pressure neutralizes a key part of their toolkit.
- Require phishing-resistant multi-factor authentication (MFA) across all services, with particular attention to remote access, financial systems, and any platform holding sensitive client data.
- Restrict access to sensitive data from less-secure networks and apply the principle of least privilege. Employees should only have access to the data they need for their specific role.
- Establish a clear verification culture. In both law firms and financial institutions, there should be a well-understood, no-exception protocol for any request involving remote access, data transfer, or device access, regardless of how urgent or legitimate the request appears.
-
-
The Broader Implication
The convergence of telephone-based fraud and in-person intrusion tactics reflects a broader truth: when technical defenses improve, attackers move to the human layer. People are harder to patch than software.
For law firms and financial institutions, this means security is no longer a back-office IT concern. It is a firm-wide discipline that requires the same rigor applied to legal compliance or financial controls. Leadership must set the tone, protocols must be clear and enforced, and every employee, from the managing partner to the front desk, is part of the defense.
The threat is real, it is active, and it is showing up at the door.
If your organization has experienced a suspected social engineering incident or in-person intrusion attempt, report it to the FBI’s Internet Crime Complaint Center (IC3) at ic3.gov.
