Real-Time Insurance Phishing / Account Hijacking Campaign (CTM360)
First seen Jul 27, 2026 · Updated Jul 27, 2026
CTM360 researchers identified a shift in insurance-sector phishing campaigns from traditional credential harvesting to real-time account hijacking, where stolen credentials and session tokens are used immediately to take over accounts before victims can react. This evolution suggests attackers are increasingly leveraging automated relay infrastructure or adversary-in-the-middle (AiTM) techniques to bypass MFA and act on stolen sessions within seconds of capture.
Technical Analysis
The campaign moves away from static credential-harvesting phishing pages toward live proxy-based kits that relay victim input to legitimate insurance portals in real time, capturing session cookies and MFA tokens as they are generated (an AiTM pattern similar to Evilginx-style reverse-proxy phishing). This allows attackers to hijack authenticated sessions instantly rather than waiting to reuse static credentials later, significantly shortening the attack window defenders have to detect and respond. No specific CVEs are referenced; the technique targets business logic and authentication flow weaknesses rather than software vulnerabilities. If insurance-sector organizations use AI agents or LLM-based automation for underwriting, claims processing, or customer service that authenticate via hijacked sessions or API keys, stolen session tokens could grant attackers direct access to agent-integrated systems and any connected data pipelines, making this agent-relevant for orgs with automated financial/insurance workflows.
Affected Systems
Insurance company customer/agent portals, web-based authentication systems using session cookies and MFA, employees and customers of insurance and financial institutions using standard browser-based login flows
Indicators of Compromise
- No specific hashes, IPs, or domains disclosed in available reporting; indicators likely include newly registered lookalike insurance-branded domains, reverse-proxy phishing kit traffic patterns, and anomalous session token reuse from unfamiliar IP/geolocation shortly after legitimate login events
Remediation Steps
- 1
Deploy FIDO2/WebAuthn phishing-resistant MFA
Replace OTP/push-based MFA with hardware-backed authentication that cannot be relayed through AiTM proxies.
- 2
Monitor for session anomalies
Implement real-time detection for session token reuse from new devices, IPs, or geolocations immediately after login.
- 3
Shorten session token lifetimes
Reduce token validity windows and enforce re-authentication for sensitive account actions.
- 4
Domain and brand monitoring
Continuously scan for lookalike/typosquatted domains impersonating the insurance brand to enable rapid takedown.
- 5
User awareness training
Educate customers and staff on real-time phishing risks and verify login prompts occur only on official domains.
- 6
Audit API and agent credentials
For organizations using AI agents or automated workflows tied to insurance portals, rotate API keys and review access logs for anomalous automated activity following any suspected credential compromise.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.