TechNewsReel
Live

CTM360 Uncovers 'InsureTrap' Campaign Hijacking Insurance Accounts in Real Time

A new phishing kit relays stolen credentials and OTPs instantly, bypassing multi-factor authentication before victims realize their sessions are compromised.

TechNewsReel Newsroom · July 26, 2026

Cybersecurity firm CTM360 has identified an evolution in phishing tactics targeting the insurance sector, shifting from traditional credential harvesting to real-time account hijacking.

The campaign, dubbed 'InsureTrap', deploys fake insurance portals that deceive policyholders and corporate users. Rather than storing stolen credentials for later use, attackers authenticate as victims within the same session using a specialized tool called the InsureOTP Kit.

How the Attack Works

The InsureOTP Kit functions as a real-time relay system. When a victim enters login credentials and a one-time password (OTP) on a fraudulent portal, the kit instantly forwards both to the legitimate insurance platform. This allows attackers to establish an authenticated session before the victim's own login attempt completes.

This is an Adversary-in-the-Middle (AiTM) attack engineered to circumvent multi-factor authentication. By capturing and relaying OTPs during the active authentication flow, the attacker becomes the legitimate user in the eyes of the target system.

Why Traditional MFA Falls Short

This evolution renders conventional MFA methods—particularly SMS and email-based OTPs—insufficient for protection. Since hijacking occurs in real time, victims receive their authentication codes normally and may not suspect compromise until fraudulent activity appears on their accounts.

This creates a narrow detection window. Attackers can gain full account access before the victim realizes the session has been intercepted, enabling immediate fraudulent claims processing, policy modifications, or theft of sensitive personal and financial data.

Broader Implications

Historically, phishing against financial and insurance institutions focused on harvesting credentials for asynchronous use. The rise of MFA forced attackers to develop more sophisticated techniques that capture session tokens or OTPs as they are entered.

InsureTrap demonstrates that credential-based authentication, even with OTP layers, cannot fully protect against determined adversaries with real-time relay capabilities. Security teams should add controls such as device fingerprinting, behavioral analytics, and phishing-resistant authentication methods like FIDO2 security keys.

CTM360's research underscores an arms race: as defenders deploy stronger authentication, attackers engineer workarounds that exploit the gap between user expectation and technical reality. For insurance carriers and their customers, the message is clear—MFA alone is no longer a silver bullet.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.