VYPR
advisoryPublished Jul 30, 2026· Updated Jul 31, 2026· 1 source

AiTM Phishing Surges as Top Threat to Law Firms, Bypassing MFA

Adversary-in-the-Middle (AiTM) phishing has become the primary initial access vector for cyberattacks targeting law firms, accounting for 56% of threats and demonstrating a sophisticated bypass of multi-factor authentication.

Adversary-in-the-Middle (AiTM) phishing has rapidly ascended to become the dominant method for attackers to infiltrate law firms, surpassing traditional credential theft techniques. This shift is particularly notable in a sector where multi-factor authentication (MFA) is now widely implemented, yet attackers have adapted to circumvent it.

A report from eSentire's Threat Response Unit (TRU) indicates that AiTM attacks were responsible for 28.57% of all initial access events within the legal sector. Overall, credential and identity-focused threats constituted 56.3% of all attacks against legal organizations, with account compromise making up 45% and direct credential phishing at 11%. This trend signifies a strategic pivot by threat actors, focusing on exploiting human vulnerabilities and identity systems rather than solely targeting technical infrastructure.

The AiTM technique involves proxying the authentication process. Attackers intercept user credentials and, crucially, valid session tokens in real-time. This allows them to bypass MFA defenses, as a user who successfully authenticates and completes an MFA challenge inadvertently hands over an active session cookie to the attacker.

Evidence of MFA's widespread adoption in law firms is seen in the sector's comparatively lower rate of conventional credential theft (16.96%) compared to the cross-industry average of 26.01%. This suggests that rather than abandoning the lucrative legal sector, attackers have evolved their tactics to overcome existing security measures.

Notably, the phishing-as-a-service platform Tycoon2FA was a significant driver of AiTM-related account compromises in the legal sector throughout 2025, accounting for 52.3% of such incidents. Although a Microsoft and Europol-led operation disrupted the platform in March 2026, activity quickly resumed to pre-takedown levels, highlighting the resilience of these attack services.

Beyond AiTM, workflow exploitation tactics like ClickFix attacks also showed a notable presence, reaching 13.39% of legal incidents compared to an 8.77% cross-industry average. These attacks leverage fake browser errors, often related to document viewers or e-filing systems, to prompt urgent user action, particularly effective when targeting professionals facing imminent deadlines. These attacks frequently delivered NetSupportManager RAT, which was the most prevalent malware detected in the sector.

Microsoft Teams abuse also saw an increase, representing 6.25% of initial access, nearly double the cross-industry figure. Lumma Stealer was the leading infostealer observed, making up 9.6% of all malware detections. The legal sector experienced an 86% overall intrusion ratio, indicating that most attacks progressed beyond initial access. Ransomware intrusions stood at 23%, suggesting attackers are prioritizing data exfiltration and account access over disruptive encryption.

To counter these evolving threats, eSentire recommends law firms implement phishing-resistant MFA solutions like FIDO2 keys and passkeys, enforce conditional access policies based on device health and location, and enhance monitoring of identity platform logs for anomalous activity. The report also highlights a concerning statistic from the American Bar Association, indicating that only 34% of law firms possess a formal incident response plan, leaving them potentially ill-prepared for sophisticated cyberattacks.

Synthesized by Vypr AI