Skip to Content

AiTM Phishing: When Identity Becomes the Target

Attacks that bypass traditional MFA are moving identity to the center of the security budget, and there are practical ways to close that door.
July 31, 2026 by
AiTM Phishing: When Identity Becomes the Target

The attack has changed targets: now it wants to be you

A threat intelligence report released by Infosecurity Magazine indicates that AiTM (adversary-in-the-middle) phishing has become the leading initial access vector against law firms. According to the same report, identity-based attacks already account for 56% of all threats observed in the legal sector. The publicly available analysis further indicates that the technique is migrating to professional service providers in other segments.

What makes AiTM different from classic phishing is the mechanism. Instead of merely capturing a username and password, the attacker inserts an intermediary page that relays the authentication in real time and captures the session cookie, the temporary file that keeps the user logged in after verification. With that cookie in hand, the traditional second factor has already been satisfied and is not requested again. Additional reporting from Infosecurity Magazine shows that phishing campaigns have also been exploiting legitimate collaboration platforms as a delivery channel, which increases the credibility of the lure.

That leaves the question that matters to decision-makers: if your second factor can be bypassed without anyone noticing, what exactly is protecting the account of the person who signs contracts at your company?

Why this matters to any company, not just law firms

The legal sector makes headlines for a simple economic reason: firms concentrate contracts, merger and acquisition data, corporate information, and client secrets. A single compromised mailbox there is worth a great deal. But the attacker's reasoning is replicable. Accounting, retail, manufacturing, construction, and healthcare companies also store proposals, price lists, supplier banking details, and conversations that reveal who approves payments.

The central point is a change of target. The asset under attack is no longer the server but the identity. That shifts the budget conversation: protecting only the network perimeter accomplishes little when the door being used is a valid credential accessed from outside, with a legitimate session and no malware involved. For the internal IT leader, the 56% figure is an objective argument for revisiting the priority of the identity layer.

There is also a chain effect that often goes unnoticed. A compromised account at one company becomes a trusted sender for clients, suppliers, and partners. That is how variations such as the fake attorney or fake supplier scam are born, in which the message comes from the real address, with real history, requesting a change of banking details that seems plausible. There is no need to break into the finance department when you can write from the mailbox of someone the finance department trusts.

For IT entrepreneurs who serve client portfolios, the data has a direct commercial reading: reviewing the authentication posture of the entire client base before the first incident is cheaper, and far more comfortable, than reviewing it afterward.

The good news: this door has a known lock

The first move, and the one with the greatest impact per dollar invested, is to adopt phishing-resistant MFA. Standards such as FIDO2 and passkeys bind authentication cryptographically to the legitimate address of the service, so that an intermediary page simply cannot relay the credential. It is the difference between a second factor that confirms an action and a second factor that confirms the identity of the destination. SMS codes and push approvals are still better than a password alone, but they are precisely the scenario AiTM was designed to defeat.

The second move is conditional access policies, rules that only release the session when access comes from a known, managed, and compliant device. Tying the session to a trusted device strips the stolen cookie of its value: even if captured, it opens nothing on another machine. On top of that, 24/7 monitoring with anomalous login detection and automatic session revocation shortens the window between credential theft and the attempted fraud, which is where the loss actually occurs.

The next layer handles what comes after the initial access. EDR (Endpoint Detection and Response) prevents the intruder from establishing persistence on devices. Patch management closes the flaws used to escalate privileges. Immutable backup, the kind that cannot be altered or deleted within the retention period, combined with a tested continuity plan, ensures that an extortion attempt does not halt operations. And periodic user training keeps the team able to recognize the odd request before the click.

None of this requires a two-year project. It requires sequence: identity first, endpoint next, resilience always, with audit trails that meet clients' contractual requirements and privacy regulatory frameworks such as GDPR and LGPD.

Could your company detect a hijacked session before the loss?

That is the question that separates those who have security from those who merely have tools installed. The practical answer is quite attainable. An honest inventory of which accounts still depend on SMS or simple push, starting with partners, executives, finance, and IT, usually reveals in a few hours where the real exposure lies. From there, migrating that group to phishing-resistant MFA and applying conditional access with a trusted device already eliminates most of the value of a stolen cookie.

The rest is continuous, well-distributed operation: 24/7 monitoring that spots an improbable login and revokes the session without waiting for business hours, active EDR on endpoints, patch management on a defined cadence, immutable backups tested through restoration, recurring training, and structured remote support to respond quickly when something seems off. Companies with 5 to 5,000 employees run this set of practices every day, many with a lean team and the support of a managed IT model. AiTM is sophisticated, but it isn't invincible: it depends on one specific link, and that link has a mature, available replacement. Companies that make this switch in an organized way break out of the cycle of reacting to scares and begin operating with predictability.

Frequently asked questions

What is AiTM phishing and why does it bypass MFA?

AiTM (adversary-in-the-middle) phishing is a technique in which the attacker places an intermediary page between the user and the real service, relaying the authentication in real time. Because the legitimate login is completed, the attacker captures the session cookie, the file that keeps the user authenticated. With that cookie, the second factor has already been satisfied and isn't requested again, which allows access without a password or a code.

Are SMS or push MFA still worth it?

Yes, any second factor is better than a password alone and still blocks the majority of automated attacks. The issue is that SMS and simple push don't protect against session hijacking, because they don't verify whether the site requesting the authentication is the legitimate one. That's why the recommendation is to move to phishing-resistant MFA, with standards such as FIDO2 and passkeys, prioritizing the accounts of partners, executives, finance, and IT.

Which accounts should the authentication migration start with?

Priority should follow the value of what the account accesses and the decision-making power of the person using it. Partners, C-levels, finance, legal, and IT administrators concentrate contracts, payment approvals, and elevated privileges, making them the most lucrative targets. After that core group, the rollout to the rest of the organization can be done in waves, without interrupting operations.

If you want to map where your company still depends on vulnerable authentication, talk to our specialists in a Strategic IT Assessment, No Commitment.

AiTM Phishing: When Identity Becomes the Target
July 31, 2026
Share this post
Tags
Archive