Home / Jul 27, 2026 / Story
0
#5 The Hacker News general July 25, 2026 at 10:14 UTC

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

By [email protected] (The Hacker News)

AI Summary

CTM360 research documents a shift in insurance-sector phishing operations from credential harvesting to real-time account hijacking, where adversary-in-the-middle infrastructure intercepts sessions immediately upon victim login rather than storing credentials for later use. This technique bypasses SMS-based MFA and renders traditional credential-theft detection less effective, since account takeover occurs within seconds of the phishing interaction. Financial services security teams should evaluate phishing-resistant MFA (FIDO2/passkeys) and real-time session anomaly detection as mitigations.

Relevance score: 65.0/100

# More from July 27