The record
Written from the 1 report below. Nothing here is unsourced.
- A new CTM360 report describes insurance phishing campaigns that have shifted from stealing credentials for later use to hijacking accounts in real time during the victim's own login session.
- Attackers relay victims' usernames, passwords, and one-time passwords to legitimate insurance portals as they are entered, defeating multi-factor authentication within a single session.
- The campaigns reportedly targeted multiple insurers across several regions, with Saudi Arabia the primary target and additional activity in Europe, the United States, and India.
- Sponsored Google ads advertising insurance quotes were the main delivery method, with phishing pages hosted on disposable platforms like GitHub Pages, Netlify, and Wix, making detection harder.
What to watch next
- Whether insurers and regulators respond to the report's finding that brand monitoring alone is no longer sufficient.
- Any action by Google or ad platforms on sponsored advertisements used as the initial attack vector.
- Further details from the full CTM360 report on the previously undocumented InsureOTP phishing kit.
Coverage1
1 report
English national1
All filed from India
Named Saudi Arabia · United States · India · CTM360 · GitHub Pages · Google · Hostinger · InsureOTP Kit · Lovable · Netlify · Telegram · Wix
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
