AiTM Phishing Now #1 Break-In Method for Law Firms

Infosecurity Magazine · High sophistication
Last updated July 31, 2026

A legal-sector threat intel report says adversary-in-the-middle (AiTM) phishing is now the most common way attackers gain initial access to law firms, because it can bypass MFA by stealing valid session cookies. The report highlights deadline-driven lures (fake document/court portal errors) and abuse of Microsoft Teams as growing entry points, with many incidents progressing into deeper intrusion.

How the attack worked

Threat intelligence covering the legal sector found that adversary-in-the-middle (AiTM) phishing has become the most common way attackers gain initial access to law firms, responsible for 28.57% of initial access events. Instead of simply stealing a password, AiTM pages proxy the real authentication flow. A user enters credentials and completes an MFA prompt as normal, but the attacker sits in the middle of that exchange and captures the resulting session cookie, gaining access without ever needing to defeat MFA directly.

A second common pattern used fake browser or portal errors, often called ClickFix-style lures, where a message claims a document viewer, e-filing system, or court portal needs urgent attention. These errors were elevated in legal incidents (13.39%) compared to cross-industry rates (8.77%), and the technique primarily delivered a remote access trojan when victims followed the on-screen 'fix' steps.

Why it succeeded

These attacks succeeded by exploiting two things at once: technical trust in MFA and human urgency. Because the login flow looks legitimate and MFA is genuinely completed, users have little reason to suspect anything is wrong. Layered on top of that, deadline pressure specific to legal work, such as court filings, made staff more likely to act quickly on an unexpected error rather than pause to verify it. Microsoft Teams abuse was also noted as a growing entry point, appearing in 6.25% of cases, nearly double the cross-industry figure.

What to watch for

  • Login pages reached via unexpected or unsolicited links, even if they request MFA normally
  • Sudden 'urgent' error messages while accessing document viewers, e-filing systems, or court portals
  • Prompts urging users to run a fix, script, or download to clear a blocking error
  • Session activity that continues even when the user did not initiate a new login
  • Any single phishing-as-a-service pattern driving a large share of compromises, since one platform was linked to over half of AiTM-related compromises in the sector

Building resistance

Because 86% of observed incidents progressed beyond initial access into active intrusion, with ransomware intrusion at 23%, stopping AiTM phishing at the entry point matters. Recommended defenses include deploying phishing-resistant MFA such as FIDO2 keys and passkeys, adopting conditional access policies that evaluate device health and location, and monitoring identity platform logs for anomalous session activity. Staff should also be trained to verify document portal or court filing issues through a known bookmark or official channel rather than following in-page prompts, especially under deadline pressure.

Key findings

  • AiTM phishing was the most common initial access method in the legal sector, accounting for 28.57% of initial access events.
  • Attackers bypass MFA by proxying logins and capturing a valid session cookie even when users complete MFA successfully.
  • A phishing-as-a-service platform (Tycoon2FA) was attributed as driving 52.3% of AiTM-related account compromises in the legal sector across 2025.
  • ‘ClickFix’ lures used fake browser/document portal errors and were elevated in legal incidents (13.39%) versus cross-industry (8.77%).
  • Microsoft Teams abuse was a noted initial access vector (6.25%) and near double the cross-industry figure (3.40%).
  • In 86% of observed incidents, activity progressed beyond initial access into active intrusion; ransomware intrusion was 23%.

Who’s being targeted

  • Commonly targeted roles: Attorneys, Paralegals, Legal assistants / executive assistants, IT / Identity & Access Management, Security operations.
  • Affected industries: Legal services (law firms), Professional services.
  • Attack channels: website, email.
  • Impersonated: Document viewer, e-filing system, or court portal support page (appears as a legitimate workflow error), Legitimate identity provider sign-in (lookalike page used by an adversary-in-the-middle service).

Red flags to watch for

  • Unexpected ‘urgent’ error message that appears while accessing legal documents/portals
  • Pressure to act quickly due to filing deadlines
  • A ‘fix’ workflow that asks the user to run or install something to proceed
  • Login page reached via an unexpected link
  • MFA prompt appears but the sign-in experience feels unusual (extra prompts/redirects)
  • Session continues even if the user did not initiate a login
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is AiTM phishing and why does it bypass MFA?

AiTM (adversary-in-the-middle) phishing proxies the real login process, so even when a user enters correct credentials and completes an MFA challenge, the attacker captures a valid session cookie and can access the account without needing the password or MFA code again.

Why are law firms specifically targeted with these attacks?

A legal-sector threat intel report found AiTM phishing was the most common initial access method in the legal sector, accounting for 28.57% of initial access events, often using deadline-driven lures tied to court filings and document portals.

What is Tycoon2FA and how does it relate to this attack?

Tycoon2FA is a phishing-as-a-service platform that was attributed as driving 52.3% of AiTM-related account compromises in the legal sector across 2025.

What happens after attackers gain initial access this way?

In 86% of observed incidents, activity progressed beyond initial access into active intrusion, and ransomware intrusion occurred in 23% of cases.

Read the video transcript

In law firms right now, the number one break‑in method isn’t malware, it’s AiTM phishing that steals your session even after MFA. Here’s the trick: you click an email link, land on a perfect-looking login, enter your password, even approve MFA, and an AiTM service like Tycoon2FA quietly grabs your session cookie and walks into your account as you. Or you’re racing a filing deadline, and a fake court portal or document viewer throws a ‘ClickFix’ error, “you must install this to view the filing”, which quietly drops NetSupportManager RAT while you think you’re just clearing a blocker. Your move: if a login or portal error pops up from a link, email, Teams, wherever, don’t trust it. Close it, then go to your own bookmark or type the official site yourself and sign in there.

Similar attacks