Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Phishing attacks on insurance companies evolve to real-time account hijacking

Phishing campaigns targeting insurance companies have evolved from credential harvesting to real-time account hijacking, using sophisticated phishing kits like "InsureOTP Kit" to intercept one-time passwords (OTPs) and bypass multi-factor authentication during a single live session. Attackers initiate these campaigns via spoofed Google ads leading to disposable phishing sites built on legitimate platforms, then authenticate in real-time against the victim's legitimate portal as the victim logs in. This shift transforms phishing into an active hijacking operation, requiring defenders to move beyond domain blocklisting to analyze attacker infrastructure and methodologies.
Read Full Article →

Phishing Phishing attacks on insurance companies evolve to real-time account hijacking July 27, 2026 Share By SC Staff (Adobe Stock) Phishing campaigns targeting financial institutions are evolving from credential harvesting for later use to real-time account hijacking, based on information published by The Hacker News. Recent investigations reveal a shift in phishing operations, particularly targeting the insurance sector, which has become an attractive target due to expanded online services for customers. Attackers are now synchronizing their activities with victims in real time, authenticating against legitimate insurance portals as victims unknowingly complete the login process within a single browsing session. This sophisticated approach often begins with sponsored Google advertisements, directing users to phishing websites that closely mimic genuine insurance providers. These sites replicate branding and user interfaces to reduce suspicion. The underlying infrastructure is disposable, frequently utilizing legitimate website builders and free hosting platforms. A key development is the "InsureOTP Kit," a phishing kit designed for live session management and real-time data collection, including the interception of one-time passwords (OTPs) to bypass multi-factor authentication. This evolution transforms phishing from a data collection exercise into an active account hijacking operation, requiring defenders to adopt a more comprehensive approach beyond identifying malicious domains to understanding attacker infrastructure, tooling, and operational methodologies. Source: The Hacker News SC Staff Related Ransomware Steam forums used for ClickFix cryptominer attacks SC Staff July 27, 2026 In a report by Bleeping Computer, threat actors are exploiting Steam discussion forums to distribute cryptominers through a social engineering tactic known as ClickFix. Threat Management UK issues alert over Russian zero-click email attacks SC Staff July 24, 2026 The UK's National Cyber Security Centre (NCSC) issued an alert regarding a new 'zero-click' threat campaign orchestrated by Russian state-backed hackers targeting organizations across critical sectors, according to a recent report by IT Pro. Threat Management Don’t break in, log in: How abuse of trust leads to system compromise Paul Wagenseil July 23, 2026 Today's attackers win not by defeating security controls, but by exploiting the trust we place in legitimate technologies. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article