Advertisement
SecurityDeveloping Story

Law Firms Face Rising AiTM Threat

Adversary-in-the-middle phishing has eclipsed standard credential theft as the primary initial access vector for legal sector organizations.

··1 hour ago·2 min read
Woman working on laptop at office desk with city view.
Photo by Gorilla ROI Data Connector on Unsplash
Advertisement

Law firms are experiencing a fundamental shift in how attackers breach their systems, moving away from technical exploitation and toward the manipulation of legal professionals. Recent data indicates that Adversary-in-the-middle (AiTM) phishing has become the leading method for unauthorized entry into these organizations, effectively rendering conventional multifactor authentication (MFA) inadequate against sophisticated session hijacking.

The Pivot to Identity Hijacking

The reliance on MFA across the legal sector has led adversaries to adapt their tactics. Rather than attempting to crack passwords or bypass security controls directly, attackers are now using AiTM techniques to proxy the entire authentication process. By doing so, they intercept not just login credentials, but the session cookies generated after a successful MFA challenge, granting them immediate, authorized access to protected systems.

This shift is evidenced by the sector's comparatively low rate of standard credential theft. While the legal industry reports a 16.96% rate for conventional credential theft, significantly lower than the cross-industry average of 26.01%, the increase in AiTM activity suggests that attackers are successfully navigating around existing authentication defenses rather than abandoning these high-value targets.

Tactical Exploitation of Workflows

Beyond traditional phishing, attackers are increasingly weaponizing the high-pressure environment inherent in legal work. Through ClickFix attacks, adversaries present fraudulent browser alerts that mimic legitimate document viewers, e-filing systems, or court portals. These lures exploit the professional necessity of resolving potential blocking errors ahead of strict filing deadlines.

  • AiTM attacks accounted for 28.57% of all initial access events in the legal sector.
  • The legal sector recorded a 20% year-over-year increase in incidents targeting legal organizations.
  • Credential and identity-focused activity represented 56.3% of all threats to the sector.
  • ClickFix attacks reached 13.39% of legal incidents, compared to an 8.77% cross-industry average.
  • A single platform, Tycoon2FA, was responsible for 52.3% of AiTM-related account compromises in early 2025.
  • The overall intrusion ratio in the legal sector reached 76%.

The Persistence of Active Intrusions

Once initial access is gained, the threat to legal firms rarely ends at the login page. The sector is seeing a high rate of progression from initial entry to active intrusion. Furthermore, while ransomware remains a concern with a 23% intrusion rate, observers note that attackers are increasingly prioritizing persistent access to sensitive data and accounts over immediate operational disruption.

The prevalence of infostealers, which accounted for 30.4% of observed malware, further complicates the security posture of these firms. As attackers continue to refine their evasion techniques, the legal sector remains a primary target for those seeking deep, stealthy access to confidential legal documentation and communication infrastructure.

Consequences for Legal Security

The transition toward AiTM and workflow-based exploitation suggests that static MFA is no longer a sufficient deterrent for sophisticated threat actors. For law firms, this implies an urgent need to transition toward phishing-resistant authentication methods, such as FIDO2 keys and passkeys, which are designed to withstand session hijacking attempts. The high rate of successful progression from initial access to active intrusion underscores the importance of proactive log monitoring and robust device health policies. Without a formal incident response plan, which currently exists in only 34% of law firms, these organizations remain uniquely vulnerable to prolonged, undetected access by persistent adversaries.

#aitm#phishing#legal sector#cybersecurity#mfa

Sources

Xploitwire Editorial Team

Xploitwire Newsroom

This article's narrative text was drafted by AI (Google Gemini) from the sources listed above, and passed through our automated fact-check gate before publication. It has not been individually reviewed by a human editor prior to going live. Our AI Policy →

← Back to all stories
Advertisement