The ‘spoofing’ of email addresses in this way is common and many business have been affected by this type of spam.
The administrator of your mail server can safely blacklist any email from this specific mailbox email@example.com. They may also be interested to note that we support Sender Policy Framework (SPF) as a method of ensuring that emails from @kennedyslaw.com genuinely originated from our mail server. This is a valuable method for securing legitimate email traffic between organisations. If you have received an email from firstname.lastname@example.org since 10 January 2017, then your mail server is not currently configured to support SPF.
The Solicitors Regulation Authority has included a warning about this email scam on the SRA website. Their page includes information on reporting fraud.