Threat Intel

The Phishing Playbook Targeting Law Firms in 2026

Adversaries have moved past generic invoice scams. The current wave uses court-filing impersonation, MFA fatigue, and AI-cloned partner voices.

Attorney Armor Security Team May 28, 2026 6 min read
The Phishing Playbook Targeting Law Firms in 2026

The new lure: court filings

The dominant phishing pattern hitting AmLaw 200 inboxes this quarter impersonates PACER and state e-filing systems. The emails are timed to filing deadlines and include a real case caption scraped from the public docket.

MFA fatigue is back

Push-notification spam now arrives at 2-4 AM local time, often paired with a "helpdesk" call. Number matching helps. FIDO2 keys eliminate the attack entirely.

Voice cloning hits the partner channel

Three minutes of a recorded CLE talk is enough to clone a managing partner's voice well enough to authorize a wire from an associate. The defense is procedural, not technical: a callback policy that no senior partner is allowed to override.

What works

  • Hardware-bound passkeys for everyone with wire authority.
  • Out-of-band confirmation for any payment instruction change.
  • Quarterly red-team phishing with realistic legal pretexts — not the generic "Microsoft password expired" template.

Free Assessment

See what an attacker sees.

Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.

Start the assessment

Continue reading