Fake Lawyer Scams: How to Verify a Law Firm Before You Send Money or Personal Information
Scammers borrow real law firms' names to collect fees and personal details. Here's how to check a firm yourself before you pay or share anything.
Brief No. 001 · September 30, 2026
Plain-English briefings on phishing, scams, passwords and account safety for households, nonprofits and small businesses. Each one tells you how to recognize a threat, prevent it, respond to it and recover from it.
Scammers borrow real law firms' names to collect fees and personal details. Here's how to check a firm yourself before you pay or share anything.
Headlines from Krebs on Security, the EFF's Deeplinks and The Hacker News. We link to their reporting and never copy it.
BRF-01 / Internet Safety
Most online trouble starts on a normal day: an update you put off, a download from the wrong site, a shared tablet nobody locked. This section covers the everyday habits that close those gaps for households, classrooms and small offices.
Read the internet safety briefingsBRF-02 / Phishing
Phishing is a message pretending to be someone you trust so you'll click, sign in or pay. It arrives by email, text, phone and QR code. The delivery changes. The trick doesn't.
Read the phishing briefingsBRF-03 / Online Scams
Every scam is a story with a deadline. Fake invoices, fake lawyers, fake tech support, fake refunds. We take the script apart so you can see the seams before the money moves.
Read the online scams briefingsBRF-04 / Password Security
The biggest password problem isn't weak passwords. It's reused ones. A password manager and a single good passphrase fix most of it in an evening.
Read the password security briefingsBRF-05 / Multi-Factor Authentication
Multi-factor authentication means a stolen password isn't enough on its own. It's the single setting we most want every reader to turn on, starting with email.
Read the multi-factor authentication briefingsBRF-06 / Account Protection
Your email account is the master key, because password resets for everything else land there. Protect it first and a takeover gets much harder.
Read the account protection briefingsYou don't need technical training to start. Most attacks on individuals and small organizations work by tricking people rather than breaking code, so the habits that matter most are spotting warning signs, using a password manager and turning on multi-factor authentication. Begin with the one account you'd hate to lose, usually your email, and secure that first.
The basics are free wherever you live. Built-in security settings on your accounts, official fraud-reporting services and plain-English guides like ours cost nothing. A paid password manager or formal staff training for a small business or nonprofit adds some cost, but most of the protection comes from free habits you set up once.