Identity

AiTM phishing overtakes credential theft as top threat to law firms

Trustmark National Bank and Greenbank, N.A. have dropped their claims related to the class-action lawsuit filed recently against the retail giant and the security firm.

Adversary-in-the-middle (AiTM) phishing has become the most common method for attackers to gain initial access to law firms, surpassing traditional credential theft. This shift occurs even as multifactor authentication (MFA) is widely adopted within the legal sector, yet frequently bypassed by sophisticated attack techniques, as reported by Infosecurity Magazine.

A new report from eSentire reveals that AiTM attacks accounted for 28.57% of all initial access events in the legal sector, with a 20% year-over-year increase in incidents targeting these organizations. While credential and identity-focused threats remain significant at 56.3%, the nature of attacks has evolved. AiTM attacks work by proxying the authentication process, allowing attackers to steal valid session cookies even after a user completes an MFA challenge. The Tycoon2FA phishing-as-a-service platform was a major driver of these compromises.

Additionally, ClickFix attacks, which exploit workflow pressures and fake error messages, have surged in the legal sector, often delivering NetSupportManager RAT. Microsoft Teams abuse and infostealers like Lumma Stealer are also prevalent. With an 86% overall intrusion ratio, attackers are prioritizing data and account access over operational disruption, favoring quiet infiltration. eSentire recommends phishing-resistant MFA, conditional access policies, and robust log monitoring, noting that only 34% of law firms have a formal incident response plan.

Source: Infosecurity Magazine

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds