Mayfield Intelligence Operations Start a pilot

Sector

Intelligence for law firms

Law firms hold concentrated, high-value client information and are trusted implicitly in payment instructions. That combination makes them a standing target.

Start a pilot

The attack that matters is rarely technical. It is a domain registered to look like yours, an email that arrives at the right moment in a conveyancing chain, or a partner’s digital footprint assembled into a convincing approach. The firm’s own systems may never be touched.

We monitor for those threats, and we produce findings in a form your risk partner, your COLP and — where it goes that far — a court can use. Every report is sourced, dated and explicit about its limits, because output that cannot withstand scrutiny is worse than none in this sector.

01
Client-facing impersonation
Lookalike domains and cloned sites used to intercept payments or harvest client credentials.
02
Partner targeting
Senior figures profiled from public sources and approached with convincing pretexts.
03
Credential exposure
Staff credentials surfacing in breach corpora, often via unrelated third-party services.
04
Matter-driven exposure
Contentious instructions attracting hostile attention to the firm itself.

01 Representative matter

72h Detection to takedown

Matter A — Europe

A lookalike domain targeting the firm’s own clients

A phishing campaign was identified running through a domain built to impersonate the firm. Mayfield evidenced the infrastructure and supported the takedown with the registrar.

  • Brand & Domain Protection
  • Strategic OSINT

03 Common questions

Can your reports be used in proceedings?

They are written to that standard — sourced, dated, with method stated and limits made explicit. Admissibility is a matter for the court and for you as instructing solicitors, and we work alongside counsel from the outset where that is the intended use.

Do you work on instruction from the firm or the client?

Either. Where we are instructed by a firm on behalf of its client, we are used to working within privilege and to the firm’s own conflict and confidentiality requirements.

How do you handle confidentiality?

Engagements are confidential by default. We are UK-registered, Cyber Essentials Plus certified and insured, and we will sign your engagement terms rather than insisting on our own.

Tell us what you would want watched. We will scope a pilot on it, in writing, before anything is agreed.