Logbook

Phishing Protection Professional Services

September 8, 2026 · 4 min read

Ask a law firm, an accounting practice, or a medical clinic why they’d be a target for a cyberattack, and you’ll often hear some version of “we’re too small to be worth the effort.” The data says the opposite. Professional services firms aren’t an occasional target that happens to get caught up in broader attacks — several recent industry reports now identify them as the preferred one.

The reason isn’t complicated. These businesses hold exactly what attackers want — sensitive client data, direct access to money movement, and a trusted identity that people don’t think twice about clicking on — usually without the security team a bank or a large enterprise would have watching over it.

Professional Services Aren’t a Side Target Anymore

In the second quarter of 2025, professional services — legal, accounting, and consulting firms — became the most heavily hit sector for ransomware attacks, according to ransomware-response firm Coveware, accounting for close to a fifth of all attacks tracked that quarter. Phishing remains the way most of those attacks get started: IBM’s 2025 Cost of a Data Breach Report found phishing responsible for 16% of successful breaches, a figure Verizon’s Data Breach Investigations Report corroborates independently.

What’s changed is who inside these firms gets targeted, and how convincing the attempt looks by the time it lands.

What Each Type of Firm Is Actually Seeing

Law firms are dealing with a phishing technique called adversary-in-the-middle, or AiTM, which became the leading way attackers gained initial access to law firm systems through 2025 and into 2026. Unlike a traditional fake login page that just steals a password, AiTM sits between the employee and the real login page in real time, intercepting the session after multi-factor authentication has already succeeded — which is why MFA alone, while still essential, isn’t a complete answer anymore. Separately, a threat group tracked as UNC3753 has been targeting professional and legal services firms with phone-based social engineering: calling and posing as IT support, then convincing someone to share their screen or install remote-access software. And when a fraudulent wire transfer does get through, courts have increasingly held firms liable even as the “victim,” specifically when basic out-of-band verification of payment instructions wasn’t in place.

Accounting and CPA firms are seeing a more targeted style of attack. One 2026 industry analysis found that of tens of millions of phishing emails tracked across a year, more than a quarter were aimed specifically at “VIP” accounts — managing partners, senior CPAs, and anyone else with broad access to client financial systems, rather than a scattershot blast to the whole firm. The same research found the share of phishing emails written to look like genuine, long-form client correspondence rose noticeably year over year, which tracks with what most security researchers now expect: AI-assisted phishing that reads like a real email from a real client, not the broken-English scam most training still pictures.

Healthcare providers and clinics may be the clearest example of a wrong assumption becoming dangerous. For years, healthcare breach headlines were a hospital story — big health systems, huge patient counts. That’s flipped. U.S. federal breach-reporting data from 2025 shows small and mid-sized practices now account for more than 60% of reported healthcare data breaches, not large hospital systems. Phishing remains the single most common way in, and the stakes go beyond data: healthcare is also the most expensive sector for breach costs of any industry, and disrupted patient care — not just a locked file — is an increasingly common consequence when a clinic’s systems go down.

Why “Don’t Click Suspicious Links” Isn’t Useful Advice Anymore

Most security awareness training that’s still in use was built around spotting obvious tells — bad grammar, a sender address that’s clearly wrong, urgent language that feels off. That advice assumed the fake was easy to spot. AI-written phishing that mimics a real client’s tone, AiTM attacks that get past MFA after the fact, and phone calls that sound exactly like a legitimate IT help desk don’t give employees those tells to work with.

That doesn’t mean training doesn’t work — it means training built for 2020’s phishing emails doesn’t hold up against 2026’s. What actually helps is ongoing, realistic simulation that evolves as these tactics do, identity monitoring that catches a hijacked session rather than relying on the login attempt alone to look suspicious, and a simple policy that no wire or payment detail changes without a phone call to a known number, not a reply to the email that requested it.

If you want the fuller picture on how session hijacking and account compromise actually get caught, that’s exactly what identity threat detection is built to do once a login makes it past the inbox. And ongoing training that actually moves the needle, rather than an annual video, is covered in more depth on the security awareness training page.

See Your Cyber Risk

Ready to remove cybersecurity as a business risk?

Every business carries cyber risk. The question is how much you are willing to carry.

Pricing → See Your Risk Score →