Skip to main content
Threat IntelligenceEmerging Threats

AiTM Phishing Overtakes Credential Theft as Top Law Firm Threat

Modern law firm reception area with laptop and smartphone on desk.

28.57% — that proportion of initial access events in the legal sector was caused by adversary-in-the-middle (AiTM) phishing, according to a new eSentire threat intelligence report shared with Infosecurity.

AiTM phishing has overtaken conventional credential theft

eSentire’s Threat Response Unit (TRU) found AiTM attacks to be the single most common method attackers use to break into law firms, overtaking conventional credential theft in a sector where multifactor authentication (MFA) is now widely deployed but routinely bypassed. The company reported that AiTM attacks accounted for 28.57% of all initial access events in the legal sector.

eSentire read the sector’s comparatively low rate of conventional credential theft — 16.96% versus a cross-industry average of 26.01% — as evidence that law firms have widely deployed MFA and that attackers have adapted by proxying authentication sessions rather than abandoning targets that present the additional barrier of MFA.

Credential and identity-focused activity dominates the threat mix

Credential and identity-focused activity composed 56.3% of all threats to the legal sector, split between account compromise at 45% and direct credential phishing at 11%. TRU also recorded a 20% year-over-year increase in incidents targeting legal organizations. eSentire characterised this shift as a move away from technical exploitation toward attacks that make legal professionals the primary attack surface.

Tools and tactics: Tycoon2FA, ClickFix, NetSupportManager and Lumma

eSentire’s reporting names specific platforms, lures and malware that drove much of the sector’s activity in the period covered:

  • One phishing-as-a-service platform, Tycoon2FA, was responsible for 52.3% of AiTM-related account compromises in the legal sector across 2025. That platform was disrupted in March 2026 by a Microsoft- and Europol-led operation in which eSentire was a partner, but activity quickly returned to early 2026 levels.
  • ClickFix attacks — lures that present fake browser errors claiming a document viewer, e-filing system or court portal needs immediate attention — accounted for 13.39% of legal incidents, above an 8.77% cross-industry average. eSentire described this as workflow exploitation, targeting the instinct to clear a blocking error before a filing deadline.
  • NetSupportManager RAT was the primary payload delivered by ClickFix-style lures and accounted for 26.2% of all malware detections in the sector.
  • Microsoft Teams abuse represented 6.25% of initial access in the sector, nearly double the cross-industry figure of 3.40%.
  • Infostealers comprised 30.4% of malware observed, led by Lumma Stealer at 9.6%.

Operational impact: high intrusion rate, preference for quiet access over disruption

The legal sector recorded an 86% overall intrusion ratio — in 86% of observed incidents the attack progressed beyond initial access into active intrusion. Ransomware intrusion accounted for 23% of intrusions, a figure eSentire interpreted as attackers favouring quiet data and account access over noisy operational disruption.

What this means for law firm security teams, firm leadership, and regulators

  • Law firm security teams: eSentire urged deployment of phishing-resistant MFA such as FIDO2 keys and passkeys, adoption of conditional access policies that evaluate device health and location, and monitoring of identity platform logs for anomalous session activity. These are the concrete mitigations the report highlights to address AiTM and identity-focused threats.
  • Firm leadership and general counsels: the report’s citation of American Bar Association figures that only 34% of law firms hold a formal incident response plan underscores a governance gap — firms face a rising volume of incidents (20% YoY increase) while many lack formal IR preparations.
  • Policymakers and regulators: the rapid return of AiTM activity to pre-disruption levels after the March 2026 takedown of Tycoon2FA signals resilience among illicit services and suggests disruption operations alone may not yield sustained relief without parallel adoption of stronger authentication and access controls at target organizations.

eSentire’s findings create a clear through-line: attackers have shifted to session-proxying and workflow-focused lures that defeat widely deployed MFA and exploit legal workflows under deadline pressure. The brief but specific remedies the company recommends — phishing-resistant MFA, conditional access, and log monitoring — line up directly against the techniques observed. Whether law firms accelerate adoption of those controls, and whether that will move intrusion rates away from the 86% observed, remains the central practical question raised by the report.

Original report: https://www.infosecurity-magazine.com/news/aitm-phishing-top-entry-point-law/