How a Single Phishing Email Nearly Cost a Canadian Law Firm Everything
It Started at 6:47 PM on a Friday
The call came in at exactly 6:47 PM on a Friday in October, 2025. A senior partner at a regional Canadian law firm with 100+ employees, three offices could not access the shared client files drive. Within 15 minutes, six more staff were reporting the same. By 7:30 PM, the firm’s managing partner had confirmed: this was a ransomware attack.
By the time the NeoCipher Consulting incident response team was engaged, files across four shared drives were actively encrypting.
The Attack Vector: AI-Enhanced Phishing
Forensic analysis conducted over the 72 hours following containment confirmed the initial access occurred five days before the detonation event. A junior paralegal received an email that appeared, in every detail, to be from a senior partner. The sender display name was accurate. The email domain used a homoglyph substitution invisible at a glance. The subject line referenced a matter she was actively working on. The attached document, described as an NDA draft, executed a macro payload on opening.
The payload installed a remote access tool and sat dormant for four days conducting reconnaissance, mapping the network, and identifying the highest-value shared drives before triggering the encryption routine.
The Response: Hour by Hour
Hour 1: NeoCipher Consulting’s IR team engaged remotely. Network topology confirmed. Affected segments isolated.
Hour 2: Forensic preservation of affected systems initiated. Email logs obtained and analyzed. Initial access vector identified.
Hour 3: Backup provider contacted. Integrity of most recent clean backup confirmed at 11:58 PM Tuesday, four days prior.
Hours 4–8: Malware behavior analysis. Network traffic logs reviewed for data exfiltration indicators. No evidence of outbound data movement confirmed.
Hours 8–18: Clean backup restoration initiated across priority systems. System integrity verification. Controlled re-connection to network.
Hour 18: Full operations restored. The firm opened normally Monday morning.
The Cost
Total direct cost of the incident: approximately $92,000 CAD, comprising IR consulting fees, overtime IT labor, and temporary licensing costs. Had client data been confirmed exfiltrated, the regulatory exposure under PIPEDA, mandatory Law Society notification, client-by-client disclosure, and litigation risk could conservatively have reached $2 million to $4 million CAD before reputational damage.
What We Implemented Post-Incident
Over the four weeks following recovery, NeoCipher Consulting implemented:
- MFA enforced across all 100+ accounts, including shared and admin accounts,
- AI-powered email filtering with sandbox detonation for all attachments,
- Network segmentation isolating file server infrastructure from user workstations,
- Privileged access management; no user account with local admin rights,
- Offline, immutable backup copy verified weekly,
- Tailored incident response plan tested via tabletop exercise within 30 days,
- Security awareness training delivered in-person across all three offices.
Key Lessons
Speed of containment is the primary determinant of breach cost.
- AI-generated phishing now routinely bypasses legacy email security filters. The gap between initial access and detonation is getting longer; meaning attackers are in your environment before you know it. An untested backup is a false comfort. Verify integrity before you need it. Without an incident response plan, every decision in the first hours is reactive and costly.
Does your organization have a tested incident response plan? Contact NeoCipher Consulting — we offer IR readiness assessments for organizations of all sizes.