HomeRisk ManagementsAiTM Phishing Emerges as Leading Initial Access Threat for Law Firms

AiTM Phishing Emerges as Leading Initial Access Threat for Law Firms

Published on

spot_img

Surge in AiTM Phishing Attacks Targeting Law Firms

Adversary-in-the-middle (AiTM) phishing has emerged as a formidable threat in the realm of cybersecurity, particularly within law firms, where it has overtaken conventional methods of credential theft. This trend has been underscored by a recent threat intelligence report from eSentire, which reveals alarming statistics regarding these types of attacks. Despite the widespread implementation of multifactor authentication (MFA) security measures, attackers have found ways to circumvent these defenses with increasing regularity.

The legal sector has witnessed a substantial increase in AiTM attacks, which accounted for 28.57% of all initial access events reported within this industry. The data shared with Infosecurity also indicates a 20% year-over-year increase in incidents specifically targeting legal organizations. This highlights a concerning trend that suggests that criminals are honing in on the unique vulnerabilities within the legal profession, escalating their efforts as they adapt to thwarting standard security measures.

Credential-focused threats constitute 56.3% of all reported incidents affecting the sector. This figure represents a significant shift, as it indicates that the primary target has moved away from technical exploits and toward human factors—the legal professionals themselves have become the favored entry point for cybercriminals. Within this realm, account compromises represent 45% of threats, while direct credential phishing stands at 11%. This trend sharply illustrates that legal practitioners find themselves on the front lines of cyber defenses, facing persistent and insidious threats.

Weakness in MFA Security

The mechanics of AiTM phishing attacks involve an innovative technique that undermines the authentication process. In this scenario, even if a user correctly enters their credentials and satisfies an MFA challenge, they inadvertently provide an attacker with a valid session cookie. eSentire’s analysis suggests that the comparatively lower rate of conventional credential theft in the legal sector—16.96%, significantly below the cross-industry average of 26.01%—points to the effective deployment of MFA measures across law firms. Yet, this has not deterred attackers, who have adapted their strategies to continue breaching defenses rather than moving away from their targets.

A crucial player in the landscape of AiTM phishing is the phishing-as-a-service platform known as Tycoon2FA, which was identified as the source of 52.3% of AiTM-related account compromises in the legal sector in 2025. Although Tycoon2FA was targeted in a major disruptive operation led by Microsoft and Europol in March 2026—wherein eSentire played a collaborative role—the platform’s activities quickly rebounded to early 2026 levels, evidencing the resilience of such cybercriminal enterprises.

Exploiting Legal Workflow Pressures

Alongside these alarming phishing tactics, another significant concern has emerged: ClickFix attacks. Reported incidents of ClickFix reached 13.39% within the legal sector, surpassing the cross-industry average of 8.77%. These attacks manipulate common workflow factors by presenting users with urgent, fake browser errors, claiming that essential documents or court portals require immediate attention. eSentire has termed this approach as a form of "workflow exploitation," targeting the natural instinct to rectify perceived errors before crucial filing deadlines. Notably, this technique often delivers NetSupportManager Remote Access Trojan (RAT), which emerged as a major threat, accounting for 26.2% of malware detections within the legal sector.

Additional sources of initial access include the abuse of Microsoft Teams, which reached 6.25% in the legal sector, nearly double the cross-industry figure of 3.40%. Within the malware spectrum, infostealers were responsible for 30.4% of observed threats, with Lumma Stealer dominating at 9.6%. The overall intrusion ratio across the sector stood at an alarming 86%, meaning that in a vast majority of instances, successful attacks progressed beyond the initial access phase, culminating in active intrusions.

Ransomware incidents accounted for 23% of the threats, and eSentire suggested that cybercriminals are increasingly favoring low-profile data and account access over high-impact operational disruption.

Recommendations for Legal Firms

In light of these developments, eSentire has strongly recommended that law firms consider deploying phishing-resistant MFA solutions, such as FIDO2 keys and passkeys. Additionally, they suggested the adoption of conditional access policies that evaluate the health and location of devices used to access sensitive information. Monitoring identity platform logs for unusual session activity is also critical to enhancing cybersecurity defenses.

Worryingly, the data highlighted that only 34% of law firms currently maintain a formal incident response plan, according to statistics from the American Bar Association. This alarming statistic underscores the urgent need for law firms to bolster their cybersecurity measures and enhance their preparedness in facing these evolving threats.

Source link

Latest articles

Keycloak Vulnerability Exposes Users’ Personal Data to Restricted Administrators

Security Flaw in Keycloak Exposes User Data A serious vulnerability in Keycloak has come to...

ISMG Editors: A New Front in the Naming Conflict

Also: The AI Spending Reality Check, Nvidia Takes on Closed...

Google Develops New Names for Threat Actors

Google Unveils New Threat Actor Naming Convention in Cybersecurity In an evolving landscape of cybersecurity,...

More like this

Keycloak Vulnerability Exposes Users’ Personal Data to Restricted Administrators

Security Flaw in Keycloak Exposes User Data A serious vulnerability in Keycloak has come to...

ISMG Editors: A New Front in the Naming Conflict

Also: The AI Spending Reality Check, Nvidia Takes on Closed...