The Phishing Playbook Targeting Law Firms in 2026
Adversaries have moved past generic invoice scams. The current wave uses court-filing impersonation, MFA fatigue, and AI-cloned partner voices.

The new lure: court filings
The dominant phishing pattern hitting AmLaw 200 inboxes this quarter impersonates PACER and state e-filing systems. The emails are timed to filing deadlines and include a real case caption scraped from the public docket.
MFA fatigue is back
Push-notification spam now arrives at 2-4 AM local time, often paired with a "helpdesk" call. Number matching helps. FIDO2 keys eliminate the attack entirely.
Voice cloning hits the partner channel
Three minutes of a recorded CLE talk is enough to clone a managing partner's voice well enough to authorize a wire from an associate. The defense is procedural, not technical: a callback policy that no senior partner is allowed to override.
What works
- Hardware-bound passkeys for everyone with wire authority.
- Out-of-band confirmation for any payment instruction change.
- Quarterly red-team phishing with realistic legal pretexts — not the generic "Microsoft password expired" template.
Free Assessment
See what an attacker sees.
Run a no-obligation external attack-surface scan on your firm's domain in under two minutes.
Start the assessment


