Sector
Intelligence for law firms
Law firms hold concentrated, high-value client information and are trusted implicitly in payment instructions. That combination makes them a standing target.
Start a pilotThe attack that matters is rarely technical. It is a domain registered to look like yours, an email that arrives at the right moment in a conveyancing chain, or a partner’s digital footprint assembled into a convincing approach. The firm’s own systems may never be touched.
We monitor for those threats, and we produce findings in a form your risk partner, your COLP and — where it goes that far — a court can use. Every report is sourced, dated and explicit about its limits, because output that cannot withstand scrutiny is worse than none in this sector.
- Client-facing impersonation
- Lookalike domains and cloned sites used to intercept payments or harvest client credentials.
- Partner targeting
- Senior figures profiled from public sources and approached with convincing pretexts.
- Credential exposure
- Staff credentials surfacing in breach corpora, often via unrelated third-party services.
- Matter-driven exposure
- Contentious instructions attracting hostile attention to the firm itself.
01 Representative matter
Matter A — Europe
A lookalike domain targeting the firm’s own clients
A phishing campaign was identified running through a domain built to impersonate the firm. Mayfield evidenced the infrastructure and supported the takedown with the registrar.
02 Capabilities
What we usually run.
Engaged individually or as a standing retainer, scoped to the exposure rather than sold as a package.
- Brand & Domain Protection Impersonation detection and takedown support
- Dark & Deep Web Monitoring Threat detection across closed sources
- Digital Forensics Evidence recovery and incident analysis
- Asset Tracing Locating assets through open sources
- Due Diligence & Background Checks Enhanced screening of people and companies
- Digital Footprint & OSINT Investigations What the internet already knows
03 Common questions
Can your reports be used in proceedings?
They are written to that standard — sourced, dated, with method stated and limits made explicit. Admissibility is a matter for the court and for you as instructing solicitors, and we work alongside counsel from the outset where that is the intended use.
Do you work on instruction from the firm or the client?
Either. Where we are instructed by a firm on behalf of its client, we are used to working within privilege and to the firm’s own conflict and confidentiality requirements.
How do you handle confidentiality?
Engagements are confidential by default. We are UK-registered, Cyber Essentials Plus certified and insured, and we will sign your engagement terms rather than insisting on our own.
Tell us what you would want watched. We will scope a pilot on it, in writing, before anything is agreed.