Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

July 31, 2026

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

July 31, 2026

AI Won’t Make Bug Bounty Hunters Obsolete. It Makes Them Indispensable

July 31, 2026
Facebook X (Twitter) Instagram
Friday, July 31
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»AiTM Phishing Becomes Top Initial Access Threat to Law Firms
News

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

Team-CWDBy Team-CWDJuly 31, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Adversary-in-the-middle (AiTM) phishing has become the single most common way attackers break into law firms, overtaking conventional credential theft in a sector where multifactor authentication (MFA) is now widely deployed but routinely bypassed.

According to a new legal sector threat intelligence report from eSentire shared with Infosecurity, AiTM attacks accounted for 28.57% of all initial access events in the legal sector.

The company’s Threat Response Unit (TRU) also recorded a 20% year-over-year (YoY) increase in incidents targeting legal organizations.

Credential and identity-focused activity made up 56.3% of all threats to the sector, split between account compromise at 45% and direct credential phishing at 11%. eSentire framed this as a decisive move away from technical exploitation, with legal professionals rather than legal infrastructure now the primary attack surface.

MFA Deployed, MFA Bypassed

AiTM attacks proxy the authentication process, so a user who enters credentials correctly and completes an MFA challenge still hands the attacker a valid session cookie.

eSentire read the sector’s comparatively low rate of conventional credential theft, 16.96% against a cross-industry average of 26.01%, as evidence that MFA has been widely adopted at law firms and that attackers have adapted around it rather than abandoning the target.

A single phishing-as-a-service platform, Tycoon2FA, drove 52.3% of AiTM-related account compromises in the legal sector across 2025. That platform was disrupted in March 2026 by a Microsoft and Europol-led operation in which eSentire was a partner, though activity quickly returned to early 2026 levels.

Read more on AiTM phishing: Tycoon2FA Phishing Service Resumes Activity Post-Takedown

Deadline Pressure as an Attack Surface

ClickFix attacks reached 13.39% of legal incidents against an 8.77% cross-industry average. The lures present fake browser errors claiming a document viewer, e-filing system or court portal needs immediate attention.

eSentire characterized this as workflow exploitation rather than a technical one, targeting the instinct to clear a blocking error before a filing deadline. The technique primarily delivered NetSupportManager RAT, which alone accounted for 26.2% of all malware detections in the sector.

Microsoft Teams abuse reached 6.25% of initial access, close to double the 3.40% cross-industry figure. Infostealers made up 30.4% of malware observed, led by Lumma Stealer at 9.6%.

The sector recorded an 86% overall intrusion ratio, meaning that in 86% of observed incidents the attack progressed beyond initial access into active intrusion. Ransomware intrusion sat at 23%, which eSentire read as attackers favoring quiet data and account access over operational disruption.

eSentire urged firms to deploy phishing-resistant MFA such as FIDO2 keys and passkeys, adopt conditional access policies that evaluate device health and location and monitor identity platform logs for anomalous session activity. It noted that only 34% of law firms hold a formal incident response plan, citing American Bar Association figures.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
Team-CWD
  • Website

Related Posts

News

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

July 31, 2026
News

AWS Blames North Korean Group for npm Supply Chain Attacks

July 31, 2026
News

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

July 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Watch out for SVG files booby-trapped with malware

September 22, 2025

What it takes to fool facial recognition

March 14, 2026

Beware of Winter Olympics scams and other cyberthreats

February 2, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.