Insurance phishing has shifted to real-time account takeover: CTM360 study

Colleagues, I’d like to draw attention to a critical shift in cybersecurity: insurance phishing no longer simply steals logins and passwords — it now takes over accounts in real time.
A CTM360 study found campaigns delivered via Google ads, leading to fake insurance portals and using disposable infrastructure on GitHub Pages, Netlify and other platforms.
Notably, the InsureOTP Kit supports live sessions, OTP handling, admin panels and Telegram bots, enabling attackers to bypass MFA while the code is still valid.
Why it matters: defence must cover not only fake domains, but the entire attack chain — ads, infrastructure, session behaviour and OTP.
Is your team ready for attacks like this?
#cybersecurity #phishing #CTI #MFA


Latest comments
No comments yet.