# Real-Time Account Hijacking Emerges in Insurance Phishing Attacks

*Published July 27, 2026*
*Source: [https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html](https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html)*

## Executive Summary

Insurance phishing attacks have advanced from traditional credential theft to real-time account hijacking, with attackers synchronizing their actions with victims as they log into insurance portals. This method allows for immediate access to sensitive data, highlighting the need for deeper understanding of phishing infrastructures and operations.

## Article

Phishing attacks targeting the insurance industry have evolved significantly, moving from traditional credential theft to real-time account hijacking. Recent findings by CTM360 reveal that attackers are now synchronizing their actions with victims as they log into legitimate insurance portals. This strategy allows attackers to authenticate in real time, completing the attack within a single browsing session.

As insurance providers expand their digital services, offering everything from policy purchases to claims processing online, they inadvertently create lucrative opportunities for cybercriminals. Unlike banking scams that focus on financial transfers, compromised insurance accounts yield a wealth of personal and sensitive information, which can be used for extended fraudulent activities.

A coordinated phishing campaign was discovered targeting multiple insurance companies across several regions, with Saudi Arabia as a primary focus. Attackers employed sponsored Google ads to lure users searching for insurance services. These ads directed victims to phishing sites that mimicked genuine insurance providers with high levels of detail to avoid raising suspicion.

The infrastructure supporting these attacks is both sophisticated and disposable, utilizing legitimate website builders and free hosting platforms like GitHub Pages and Wix. This approach allows for rapid changes in domain usage, complicating efforts to track and stop these operations. The phishing campaigns are further enhanced by a specific phishing kit, dubbed the InsureOTP Kit, which manages live sessions and uses tools like Telegram Bot APIs for real-time data collection and session management.

The evolution of phishing into real-time hijacking highlights the need for a deeper understanding of these campaigns beyond mere identification of malicious domains. To effectively defend against these threats, security teams must analyze the broader infrastructure and operational techniques used by attackers.
