VYPR
researchPublished Jul 25, 2026· 1 source

Insurance Phishing Evolves to Real-Time Account Hijacking, CTM360 Reports

CTM360 research reveals a shift in insurance phishing attacks towards real-time account hijacking, bypassing MFA and enabling immediate fraudulent activity.

Phishing campaigns, long a staple of cybercriminal operations, are undergoing a significant transformation, moving beyond simple credential harvesting to sophisticated, real-time account hijacking. New research from CTM360 highlights how threat actors are increasingly targeting the insurance sector, leveraging evolved techniques to compromise user accounts instantaneously.

Traditionally, phishing attacks involved tricking victims into submitting login credentials to fake websites, with attackers harvesting this information for later exploitation. However, this model is rapidly becoming obsolete. The latest wave of insurance-focused phishing operations demonstrates a synchronized approach where attackers actively authenticate to legitimate insurance portals in real-time as victims unknowingly complete the login process. This entire malicious interaction can unfold within a single browsing session, drastically reducing the window for detection.

The insurance industry has become a prime target due to the wealth of sensitive personal and financial data stored within customer accounts. Beyond policy details and payment methods, compromised insurance accounts often contain identity documents and other personally identifiable information that can be exploited for a wide range of fraudulent activities, extending far beyond simple financial theft.

Attackers are demonstrating remarkable operational efficiency by reusing the same infrastructure across multiple insurance providers and regions. A coordinated campaign identified by CTM360 targeted numerous insurance brands globally, adapting its language, branding, and content to suit local markets, with Saudi Arabia appearing as a primary focus, alongside activity observed in Europe, the United States, and India.

A notable trend in these campaigns is the heavy reliance on sponsored Google advertisements as the initial attack vector. Instead of traditional phishing emails or SMS messages, threat actors purchase ads that appear prominently in search results for insurance-related queries, such as "Compare car insurance offers" or "Cheapest third-party insurance." These ads lead unsuspecting users to meticulously crafted phishing websites designed to mimic genuine insurance providers.

The infrastructure supporting these operations is equally dynamic and evasive. Operators frequently utilize legitimate website builders and free hosting platforms like GitHub Pages, Netlify, and Wix, employing randomized domains that bear little resemblance to the targeted brands. This disposable infrastructure allows campaigns to rotate rapidly, making conventional brand-monitoring efforts less effective.

The core innovation lies in the real-time account hijacking mechanism. Phishing portals are no longer static data collection pages; they actively engage with victims during the authentication process. When a legitimate insurance provider sends a one-time password (OTP) or other multi-factor authentication challenge, the phishing page prompts the victim to enter the code, relaying it to the genuine portal before it expires. This allows attackers to bypass MFA and establish authenticated sessions in real time.

CTM360 has identified a new, purpose-built phishing kit dubbed the "InsureOTP Kit." This kit provides live session management, real-time data collection, backend administration, and multiple data exfiltration methods, underscoring the professionalization and sophistication of these evolving insurance phishing schemes.

Synthesized by Vypr AI