Cybersecurity alert

Alert: targeted phishing wave against legal firms (May 2026)

A fraudulent email campaign impersonating court registries and bailiffs is currently targeting law firms and notarial practices. Our recommendations.

Warning: active campaign

Our teams have observed, since late April 2026, a surge in fraudulent emails impersonating court registries, bailiffs, and RPVA platforms, specifically targeting French law firms and notarial practices.

The typical scenario:

  • Email mimicking the official formatting of a court registry
  • PDF attachment containing a malicious macro
  • Or a link to a fake portal requesting RPVA credentials

Immediate recommendations:

  1. Raise awareness amongst your staff: no authentication is ever carried out via a link in an email
  2. Check the actual sender address (not just the display name)
  3. Enable MFA on all critical accounts if not already done
  4. Report and delete without clicking

If in doubt, our teams can provide a free rapid analysis. Contact us.

Warning signs to look out for

  • senders impersonating a court registry, a colleague, the RPVA, or a regular supplier;
  • fake case notifications or procedural alerts, with an attachment or link to "consult urgently";
  • addresses that are close but incorrect (domain altered by one character), an urgent tone, an unusual request for a bank transfer or credentials.

The 5 key reflexes

  1. Check the sender: the actual address, not just the display name.
  2. Do not click if in doubt — type the official address yourself.
  3. Enable MFA on your email and sensitive tools.
  4. Report any suspicious message to your service provider and, if necessary, on signal-spam.fr.
  5. Inform the firm: a swift internal alert prevents a colleague from falling into the same trap.

If in doubt or in the event of an incident, contact us: we can help assess the threat and respond accordingly.

Targeted phishing against legal firms (May 2026)