CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
By [email protected] (The Hacker News)
AI Summary
CTM360 research documents a shift in insurance-sector phishing operations from credential harvesting to real-time account hijacking, where adversary-in-the-middle infrastructure intercepts sessions immediately upon victim login rather than storing credentials for later use. This technique bypasses SMS-based MFA and renders traditional credential-theft detection less effective, since account takeover occurs within seconds of the phishing interaction. Financial services security teams should evaluate phishing-resistant MFA (FIDO2/passkeys) and real-time session anomaly detection as mitigations.
Relevance score: 65.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →