Insurance phishing gets faster: attackers now hijack accounts in real time
Researchers say fake insurance login pages are being run live, with criminals stepping in the moment a victim types their password.

Key points
- Phishing campaigns aimed at insurance customers have shifted from collecting passwords for later use to hijacking accounts the moment credentials are typed.
- The technique, documented by CTM360, uses live operator sessions and reverse-proxy pages that sit between the victim and the real insurance site.
- Attackers capture one-time codes and session cookies in real time, sidestepping the multi-factor login checks banks and insurers rely on.
- The behaviour overlaps with tradecraft seen in phishing-as-a-service kits tracked by several vendors, though CTM360 stops short of naming a specific crew.
- Ordinary customers should treat unexpected insurance emails and SMS renewal reminders with suspicion, especially any that push them to log in through a link.
Insurance customers are the latest target of a phishing shift that security analysts have been warning about for two years. The old model was patient. Criminals sent fake login pages, stored the passwords, and used them days or weeks later.
That delay is gone.
Researchers at CTM360, whose report was picked up by The Hacker News, say insurance-themed phishing sites are now being operated live. When a victim types their username and password into the fake page, a human or automated script on the other end feeds those details straight into the real insurance portal.
If the real site asks for a one-time code sent by text, the fake page asks the victim for the same code a second later. The attacker types it in before it expires.
How does the attack actually work?
The fake site acts as a middleman. In technical terms this is called a reverse-proxy phishing kit, meaning software that quietly passes every click and keystroke between the victim and the genuine website while copying everything down.
Because the victim is really logging into the real insurance account (just through a hostile middleman), the session looks legitimate. The attacker walks away with the session cookie, a small file the browser uses to prove you are still logged in, and can then browse the account as if they were the customer.
This defeats most standard multi-factor authentication, the extra step where a code is sent to your phone. The code is captured and used within seconds.
Why insurance customers?
Insurance accounts are quietly valuable. They hold bank details for premium payments, home addresses, vehicle registration numbers, medical notes, and identity documents uploaded during claims.
A hijacked policy can be altered to redirect a payout, or mined for the information needed to open credit elsewhere. CTM360 says the phishing lures often mimic renewal notices, claim updates, or premium refund messages.
What the tradecraft tells us
The TTPs (tools, techniques and procedures) described by CTM360 overlap with phishing-as-a-service platforms that vendors have tracked under names like EvilProxy, Tycoon 2FA and Greatness. These kits are rented out on criminal forums and lower the bar considerably: an operator does not need to build the infrastructure, only pay for it.
Attribution to any single group would be premature. The behaviour is now widespread enough that multiple unrelated crews use similar kits, and infrastructure overlap alone is not enough to tie a campaign to a named cluster with confidence.
What is clearer is intent. The move to real-time hijacking is deliberate. It gets around the security controls insurers rolled out over the past few years and shortens the window defenders have to react from days to seconds.
| Old phishing | Real-time phishing |
|---|---|
| Credentials stored, used later | Credentials used within seconds |
| Defeated by MFA prompts | Captures MFA codes live |
| Static fake login page | Reverse-proxy relays to real site |
| Detectable by password reset | Session cookie stolen, reset less effective |
What should customers do?
Treat any insurance email or SMS that pushes you to log in with suspicion, particularly ones warning of an expiring policy or offering a refund. Open the insurer's app or type the web address by hand instead of tapping the link.
If you think you clicked, ring the insurer directly, ask them to force a logout of all sessions, and change the password from a device you trust.



