Breaking
SecurityDeveloping Story

Law Firms Under Pressure From AiTM Attacks

New data from eSentire indicates that adversary-in-the-middle phishing has bypassed standard authentication protocols at law firms.

··1 month ago·2 min read
Woman working on laptop at office desk with city view.
Photo by Gorilla ROI Data Connector on Unsplash

Law firms are facing a significant shift in the threat landscape as attackers increasingly bypass multifactor authentication (MFA) to gain unauthorized access. While the legal sector has implemented widespread authentication measures, malicious actors have pivoted toward adversary-in-the-middle (AiTM) tactics to circumvent these defenses.

The Mechanics of Modern Phishing

AiTM attacks function by proxying the authentication process between the user and the target service. Even when a staff member correctly enters their credentials and completes an MFA challenge, the process unintentionally delivers a valid session cookie to the attacker. This technique effectively renders standard authentication checks insufficient for preventing initial account compromise.

Workflow Exploitation Tactics

Beyond standard credential theft, attackers are increasingly using workflow-based lures known as ClickFix. These schemes display fraudulent browser errors, masquerading as urgent notifications for court portals, e-filing systems, or document viewers. By mimicking the administrative pressures inherent in legal work, attackers exploit the professional necessity of clearing blocking errors before critical filing deadlines.

Metrics of Sector Vulnerability

  • AiTM phishing is responsible for 28.57% of all initial access events within the legal sector.
  • The Threat Response Unit (TRU) at eSentire documented a 20% year-over-year increase in incidents targeting legal organizations.
  • Credential and identity-focused activity accounts for 56.3% of all sector threats.
  • ClickFix attacks reached 13.39% of legal incidents, compared to an 8.77% cross-industry average.
  • Microsoft Teams abuse accounted for 6.25% of initial access, nearly double the 3.40% cross-industry figure.
  • The legal sector maintains an 86% overall intrusion ratio, with 23% of these incidents involving ransomware.

The Persistence of Malicious Platforms

A single phishing-as-a-service platform, Tycoon2FA, was responsible for 52.3% of AiTM-related account compromises in the legal sector throughout 2025. Although a report noted that a Microsoft and Europol-led operation disrupted the platform in March 2026, activity levels returned to their early 2026 state shortly thereafter. Furthermore, malware in the sector remains dominated by infostealers, with Lumma Stealer accounting for 9.6% of detections, often delivered through these sophisticated phishing lures.

Consequences for Legal Practice

This trend suggests that traditional password and standard MFA security postures are no longer sufficient to protect sensitive legal documentation. With only 34% of law firms maintaining a formal incident response plan, the high intrusion ratio indicates that many organizations may remain exposed to attackers who prioritize quiet data access over immediate disruption. Moving forward, the adoption of phishing-resistant hardware keys and strict conditional access policies may become a necessity for firms seeking to secure their identity platforms against these persistent session-hijacking techniques.

#aitm#phishing#legal sector#cybersecurity#mfa

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories