Management Assistance Program
Your Out-of-Office Autoreply Might Be Helping Scammers
By Julie Bays, OBA Management Assistance Program Director
Summer is in full swing, and many lawyers and law firm staff are taking well-deserved time away from the office. Before you set your out-of-office autoreply and head out the door, take a quick look at what that message actually says.
Out-of-office replies are useful. They help clients, courts, opposing counsel and colleagues understand when to expect a response. But when the message includes too much detail, it can also give scammers information they can use to target your firm.
For lawyers, this is more than a general cybersecurity concern. A well-crafted scam can put client confidential information, client trust funds, settlement funds, filing deadlines and law firm operations at risk. Reducing that risk is part of running a competent, well-managed law practice.
How Scammers Use Out-of-Office Replies
Social engineers love vacation season. When a scammer targets a law firm, they may start by sending a harmless-looking email to a guessable address, such as a lawyer’s direct email, a public-facing firm address, or an address listed on the firm website. The goal may be nothing more than triggering an automatic reply.
Consider this out-of-office message:
“I am out of the office on vacation in Mexico through July 18 with limited cell service. For urgent matters, please contact my paralegal Sarah
at extension 102.”
That message may feel helpful, but it gives a scammer several useful pieces of information:
- The lawyer is unavailable and may be difficult to reach.
- The lawyer’s absence has a specific end date.
- The lawyer may have limited ability to verify calls or emails.
- The scammer now has a believable excuse for why the lawyer supposedly cannot talk by phone.
With that information, a scammer can send a targeted message that appears to come from the lawyer:
“Sarah, I’m still traveling and cannot get a call through. I need you to process the wire for the Miller closing before 3:00 p.m. Please confirm by email when it is done.”
Because the out-of-office message already said the lawyer was traveling with limited cell service, the request may seem more believable. That is exactly how social engineering works. The scammer uses true details to make a false request feel legitimate.
Safer Out-of-Office Practices
Lawyers and law firm staff do not need to eliminate out-of-office replies entirely. But they should be written with care.
Keep the external message general.
People outside the firm usually do not need to know where you are, why you are gone, or whether you have limited cell service. A safer message might say:
“Thank you for your email. I am away from the office and may be delayed in responding. For immediate assistance, please contact our main office at [phone number] or [general office email].”
Use different internal and external replies.
Microsoft 365 and Google Workspace allow users to set different automatic replies for people inside the organization and outside the organization. Specific coverage details may be appropriate for internal staff, but the public-facing message should stay general.
Avoid naming staff members who handle money.
Do not tell the outside world which assistant, paralegal, bookkeeper or associate handles wire transfers, escrow matters, settlement checks or trust account activity. Direct external senders to a general office number or general email address instead.
Do not advertise that you cannot verify requests.
Avoid phrases such as “limited cell service,” “unable to take calls,” or “I will not be checking messages.” Those details can give a scammer a ready-made explanation for why an urgent request must be handled by email only.
Have a separate verification process for financial requests.
No wire transfer, trust account disbursement, change in payment instructions, or urgent financial transaction should be approved based only on an email. Law firms should have a clear process requiring independent verification through a known phone number or other trusted method.
A good rule of thumb: give clients and colleagues enough information to set expectations, but do not give scammers the script for an attack.
Further Reading: Cyber Wardens, “How your out-of-office email can be used in cyber-attacks.”