< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-25T15:44:21+05:30

CTM360 Research Details Evolution of Insurance Phishing into Real-Time Account Hijacking

CTM360 research reveals that insurance phishing has evolved into real-time account hijacking, with attackers using Google Ads as a delivery vector and sophisticated phishing kits like InsureOTP to enable live session management and OTP interception. The study highlights the shift from credential harvesting to immediate account compromise through synchronized authentication processes.

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.

That model is changing.

Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting

Read original article

*** END OF TRANSMISSION ***