A three-lawyer shop in suburban Philadelphia and the largest law firm in the world have both fallen victim to it, multimillion-dollar cybersecurity technology can do little to guard against it, and once the damage is done it’s all but irreversible.

“Spear-phishing”—a cyberscam in which a target is induced to reveal confidential information or transfer money by a hacker impersonating, via email, someone the target knows—is a growing concern for law firms, particularly those whose practices involve initiating monetary transactions on behalf of clients.