Law Firms Under Pressure From AiTM Attacks
New data from eSentire indicates that adversary-in-the-middle phishing has bypassed standard authentication protocols at law firms.
Law firms are facing a significant shift in the threat landscape as attackers increasingly bypass multifactor authentication (MFA) to gain unauthorized access. While the legal sector has implemented widespread authentication measures, malicious actors have pivoted toward adversary-in-the-middle (AiTM) tactics to circumvent these defenses.
The Mechanics of Modern Phishing
AiTM attacks function by proxying the authentication process between the user and the target service. Even when a staff member correctly enters their credentials and completes an MFA challenge, the process unintentionally delivers a valid session cookie to the attacker. This technique effectively renders standard authentication checks insufficient for preventing initial account compromise.
Workflow Exploitation Tactics
Beyond standard credential theft, attackers are increasingly using workflow-based lures known as ClickFix. These schemes display fraudulent browser errors, masquerading as urgent notifications for court portals, e-filing systems, or document viewers. By mimicking the administrative pressures inherent in legal work, attackers exploit the professional necessity of clearing blocking errors before critical filing deadlines.
Metrics of Sector Vulnerability
- AiTM phishing is responsible for 28.57% of all initial access events within the legal sector.
- The Threat Response Unit (TRU) at eSentire documented a 20% year-over-year increase in incidents targeting legal organizations.
- Credential and identity-focused activity accounts for 56.3% of all sector threats.
- ClickFix attacks reached 13.39% of legal incidents, compared to an 8.77% cross-industry average.
- Microsoft Teams abuse accounted for 6.25% of initial access, nearly double the 3.40% cross-industry figure.
- The legal sector maintains an 86% overall intrusion ratio, with 23% of these incidents involving ransomware.
The Persistence of Malicious Platforms
A single phishing-as-a-service platform, Tycoon2FA, was responsible for 52.3% of AiTM-related account compromises in the legal sector throughout 2025. Although a report noted that a Microsoft and Europol-led operation disrupted the platform in March 2026, activity levels returned to their early 2026 state shortly thereafter. Furthermore, malware in the sector remains dominated by infostealers, with Lumma Stealer accounting for 9.6% of detections, often delivered through these sophisticated phishing lures.
Consequences for Legal Practice
This trend suggests that traditional password and standard MFA security postures are no longer sufficient to protect sensitive legal documentation. With only 34% of law firms maintaining a formal incident response plan, the high intrusion ratio indicates that many organizations may remain exposed to attackers who prioritize quiet data access over immediate disruption. Moving forward, the adoption of phishing-resistant hardware keys and strict conditional access policies may become a necessity for firms seeking to secure their identity platforms against these persistent session-hijacking techniques.
Sources
- Infosecurity Magazine Original source
Continue Reading
Acronis Backup Plugin Flaw Exploited
Acronis has disclosed CVE-2026-87886, a high-severity Linux privilege-escalation flaw in its cPanel and Plesk backup plugins, citing limited in-the-wild attacks.
Boards Want Proof Controls Work Now
A CISO argues that point-in-time audits no longer satisfy boards, regulators, and customers who want live proof that security controls are functioning.
LiteSpeed Enterprise Flaw Risks Root on Shared Hosts
cPanel warns a LiteSpeed Web Server Enterprise bug could let one hosting account gain root on shared servers, with no CVE assigned.