Insurance Phishing Now Hijacks Accounts in Real Time via Google Ads
A new investigation from CTM360, published via The Hacker News, reveals that insurance-focused phishing operations have evolved beyond traditional credential harvesting into real-time account hijacking. Rather than collecting usernames and passwords for later use, attackers now synchronize their activity with victims in real time, authenticating against legitimate insurance portals as the victim unknowingly completes the login process. The entire attack unfolds within a single browsing session, dramatically reducing the window for detection and making stolen credentials immediately exploitable. This shift underscores why organizations must move beyond simply identifying malicious domains and instead analyze the operational infrastructure, techniques, and workflows behind modern phishing campaigns.
The campaign, documented in CTM360's InsureTrap report, spans multiple insurance providers across Saudi Arabia, Europe, the United States, and India. Threat actors reused the same phishing infrastructure across numerous insurance brands, adapting language, branding, and content to match local markets. Compromised insurance accounts proved especially valuable because they contain policy records, identity documents, payment methods, and extensive personal information (data that can fuel fraud well beyond the initial account takeover). Users can check whether their credentials or email addresses have already been exposed using hackmyip.com's email breach checker and verify password strength with the password checker tool.
The most notable technical finding involves the abuse of sponsored Google advertisements as the primary attack vector. Instead of relying on phishing emails or SMS lures, attackers purchased ads that surfaced when users searched for terms like "compare car insurance offers" or "cheapest third-party insurance." Clicking the ad redirected victims to phishing sites designed to closely mirror genuine insurance portals, capturing credentials and session data in real time. Because the phishing pages are hosted on lookalike domains, verifying site legitimacy before entering credentials is critical; users can confirm whether a domain's certificate is properly configured using the SSL/TLS checker. As digital insurance services continue to expand, this real-time hijacking model signals yet another escalation in phishing tradecraft, one that demands both consumer vigilance and stronger authentication controls across the insurance sector.