AiTM Phishing Now #1 Break-In Method for Law Firms

Infosecurity Magazine · High sophistication
Last updated July 31, 2026

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because it can bypass MFA by stealing valid session cookies. The report highlights deadline-driven lures (fake document/court portal errors) and abuse of Microsoft Teams as growing entry points, with many incidents progressing into deeper intrusion.

How the attack worked

Threat intelligence covering the legal sector found that adversary-in-the-middle (AiTM) phishing has become the most common way attackers gain initial access to law firms, responsible for 28.57% of initial access events. Instead of simply stealing a password, AiTM pages proxy the real authentication flow. A user enters credentials and completes an MFA prompt as normal, but the attacker sits in the middle of that exchange and captures the resulting session cookie, gaining access without ever needing to defeat MFA directly.

A second common pattern used fake browser or portal errors, often called ClickFix-style lures, where a message claims a document viewer, e-filing system, or court portal needs urgent attention. These errors were elevated in legal incidents (13.39%) compared to cross-industry rates (8.77%), and the technique primarily delivered a remote access trojan when victims followed the on-screen 'fix' steps.

Why it succeeded

These attacks succeeded by exploiting two things at once: technical trust in MFA and human urgency. Because the login flow looks legitimate and MFA is genuinely completed, users have little reason to suspect anything is wrong. Layered on top of that, deadline pressure specific to legal work, such as court filings, made staff more likely to act quickly on an unexpected error rather than pause to verify it. Microsoft Teams abuse was also noted as a growing entry point, appearing in 6.25% of cases, nearly double the cross-industry figure.

What to watch for

  • Login pages reached via unexpected or unsolicited links, even if they request MFA normally
  • Sudden 'urgent' error messages while accessing document viewers, e-filing systems, or court portals
  • Prompts urging users to run a fix, script, or download to clear a blocking error
  • Session activity that continues even when the user did not initiate a new login
  • Any single phishing-as-a-service pattern driving a large share of compromises, since one platform was linked to over half of AiTM-related compromises in the sector

Building resistance

Because 86% of observed incidents progressed beyond initial access into active intrusion, with ransomware intrusion at 23%, stopping AiTM phishing at the entry point matters. Recommended defenses include deploying phishing-resistant MFA such as FIDO2 keys and passkeys, adopting conditional access policies that evaluate device health and location, and monitoring identity platform logs for anomalous session activity. Staff should also be trained to verify document portal or court filing issues through a known bookmark or official channel rather than following in-page prompts, especially under deadline pressure.

Key findings

  • AiTM phishing was the most common initial access method in the legal sector, accounting for 28.57% of initial access events.
  • Attackers bypass MFA by proxying logins and capturing a valid session cookie even when users complete MFA successfully.
  • A phishing-as-a-service platform (Tycoon2FA) was attributed as driving 52.3% of AiTM-related account compromises in the legal sector across 2025.
  • ‘ClickFix’ lures used fake browser/document portal errors and were elevated in legal incidents (13.39%) versus cross-industry (8.77%).
  • Microsoft Teams abuse was a noted initial access vector (6.25%) and near double the cross-industry figure (3.40%).
  • In 86% of observed incidents, activity progressed beyond initial access into active intrusion; ransomware intrusion was 23%.

Who’s being targeted

  • Commonly targeted roles: Attorneys, Paralegals, Legal assistants / executive assistants, IT / Identity & Access Management, Security operations.
  • Affected industries: Legal services (law firms), Professional services.
  • Attack channels: website, email.
  • Impersonated: Document viewer, e-filing system, or court portal support page (appears as a legitimate workflow error), Legitimate identity provider sign-in (lookalike page used by an adversary-in-the-middle service).

Red flags to watch for

  • Unexpected ‘urgent’ error message that appears while accessing legal documents/portals
  • Pressure to act quickly due to filing deadlines
  • A ‘fix’ workflow that asks the user to run or install something to proceed
  • Login page reached via an unexpected link
  • MFA prompt appears but the sign-in experience feels unusual (extra prompts/redirects)
  • Session continues even if the user did not initiate a login
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is AiTM phishing and why does it bypass MFA?

AiTM (adversary-in-the-middle) phishing proxies the real login process, so even when a user enters correct credentials and completes an MFA challenge, the attacker captures a valid session cookie and can access the account without needing the password or MFA code again.

Why are law firms specifically targeted with these attacks?

A legal-sector threat intel report found AiTM phishing was the most common initial access method in the legal sector, accounting for 28.57% of initial access events, often using deadline-driven lures tied to court filings and document portals.

What is Tycoon2FA and how does it relate to this attack?

Tycoon2FA is a phishing-as-a-service platform that was attributed as driving 52.3% of AiTM-related account compromises in the legal sector across 2025.

What happens after attackers gain initial access this way?

In 86% of observed incidents, activity progressed beyond initial access into active intrusion, and ransomware intrusion occurred in 23% of cases.

Read the video transcript

In law firms right now, the number one break‑in method isn’t malware, it’s AiTM phishing that steals your session even after MFA. Here’s the trick: you click an email link, land on a perfect-looking login, enter your password, even approve MFA, and an AiTM service like Tycoon2FA quietly grabs your session cookie and walks into your account as you. Or you’re racing a filing deadline, and a fake court portal or document viewer throws a ‘ClickFix’ error, “you must install this to view the filing”, which quietly drops NetSupportManager RAT while you think you’re just clearing a blocker. Your move: if a login or portal error pops up from a link, email, Teams, wherever, don’t trust it. Close it, then go to your own bookmark or type the official site yourself and sign in there.

Similar attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

Vishing Lures, Fake Identities, and Repo-Trap Attacks

This recap describes multiple real-world social-engineering-driven attacks, including vishing calls that push employees to spoofed login pages and a supply-chain trick where cloning/opening a GitHub repo in developer tools triggers malware. It also highlights an unusual case where an AI model…

August 10, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Teams Phishing Rises After Tycoon2FA Takedown

Teams Phishing Rises After Tycoon2FA Takedown

Microsoft reported that phishing tied to the Tycoon2FA phishing-as-a-service platform dropped sharply after a disruption, pushing attackers to change tactics rather than stop. The report highlights real campaigns that shifted toward Microsoft Teams-based social engineering, highly automated BEC…

July 24, 2026
Fake Teams “Update” Led to $630K Crypto Theft

Fake Teams “Update” Led to $630K Crypto Theft

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft Teams call link. After the call “had no working audio,” the victim approved what looked like a Teams update, which installed a malicious…

July 21, 2026
Fake Screenshot ZIP Led to DigiCert Cert Theft

Fake Screenshot ZIP Led to DigiCert Cert Theft

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization…

July 17, 2026