SRA scam alerts: verifying client instructions
Fourteen SRA alerts in four days expose a practical question for law firms: can a client check who issued an instruction without trusting the message itself?
The Solicitors Regulation Authority published 14 scam alerts dated 22–25 September 2026. Our count of its alert index includes warnings about messaging profiles, websites and correspondence. It measures published warnings, not losses, victims or a change in the underlying rate of fraud.
Two alerts make the practical problem clear. On 25 September, the SRA described a WhatsApp profile using a genuine solicitor’s name and Cross Border Legal Limited Solicitors’ details to seek payments for purported immigration services. The genuine firm denied any connection. Read the SRA’s Cross Border Legal alert.
On 23 September, it described a WhatsApp message and telephone call misusing Ward & Rider Ltd’s name. The message used the genuine firm’s logo and a picture ID. The firm and named solicitor confirmed they were unconnected to the communications. Read the SRA’s Ward & Rider alert.
A real firm and a genuine instruction are different questions
For a client, recognising a name answers very little about the particular request in front of them. The name may belong to a real firm while the person asking for money has no authority to act for it.
The SRA advises checking suspicious correspondence by contacting the genuine firm through reliable, established means. Its verification advice appears in the alert. Our analysis is that firms should make that route understandable before a client needs it. “Contact us if unsure” leaves a gap if the client uses the telephone number supplied in the suspect message.
This is a useful test of what we call formal communication: an exchange in which the participants, their authority, the content, its delivery and the retained record can be established. That is our editorial definition, not a claim that a particular channel creates legal validity.
Run one instruction through five checks
Use a fictional request to change payment details. Give a colleague who has not written the procedure the same welcome material a client receives. Keep the exercise separate from live payments. Ask them to work through the following checks.
- Participant: how do they establish which firm and person they are dealing with? Start with information obtained independently of the test message.
- Authority: who at the firm can confirm this particular change? A receptionist’s confirmation that someone works there is different from approval of payment details.
- Content: what exactly is being confirmed? Record the specific instruction and its version, rather than an ambiguous “all checked”.
- Delivery: can the client reach the verification route, receive a clear answer and understand whether the original request remains on hold?
- Record: could another authorised colleague establish later who checked what, with whom, when and with what result?
These checks are our proposed exercise. They are not a finding about the controls of any firm named in the alerts.
Measure whether the client can finish the check
Record where the tester first looked, how many handoffs were needed and whether the final answer resolved the precise request. Note any point where they had to guess. A short written procedure is only useful if the intended reader can follow it.
Repeat the exercise with a different person after changing the instructions. Do not treat a quick completion as success if the tester confirmed the wrong detail, or a slower completion as failure if it exposed a genuine ambiguity.
The concrete decision for a managing partner is who owns this verification route from beginning to end. Assign that person responsibility for the client instructions, the staff response and the retained confirmation. The relevant benchmark is whether an unfamiliar client can obtain an attributable answer without relying on the suspicious request.
The next step is preserving that answer so a colleague can retrieve it. We examine a separate decision-record retrieval exercise in our report on the FCA’s planned supervisory handover.
We counted each distinct SRA alert URL dated 22–25 September 2026 once, using the index accessed on 29 September. The daily totals were 1, 5, 6 and 2. The linked register below makes the count reproducible. We examined the Cross Border Legal and Ward & Rider alerts for the examples in the article. No estimate of fraud incidence, victim numbers or losses was attempted. The five-check exercise is original editorial analysis; we have not tested the named firms’ procedures.
Alert register: 22–25 September 2026
- 25 September 2026 — Cross Border Legal: WhatsApp impersonation
- 25 September 2026 — Irwin Mitchell: impersonating correspondence
- 24 September 2026 — Andrew Hamilton: name misused in emails
- 24 September 2026 — Hausfeld: name and details misused
- 24 September 2026 — Samuel Ross, Elizabeth Murphy and Hamilton Law: correspondence
- 24 September 2026 — Cyber Law Solution: purported law firm
- 24 September 2026 — Al-Taawon Law: purported law firm
- 24 September 2026 — Clarke Willmott: false tenancy-change letter
- 23 September 2026 — Longfords: details misused in a letter
- 23 September 2026 — Hilton Law: impersonating website
- 23 September 2026 — Ward & Rider: WhatsApp message and call
- 23 September 2026 — Atlee Chung: impersonating website
- 23 September 2026 — Mark Shillito: name misused in an email
- 22 September 2026 — Linklaters: impersonating correspondence