🟠 High | Source: The Hacker News
Phishing campaigns targeting insurance customers have evolved beyond simple credential harvesting into real-time account hijacking, where attackers intercept sessions as they happen rather than using stolen passwords later. This adversary-in-the-middle approach bypasses traditional defences such as password resets and basic MFA, making compromise immediate and harder to detect. The shift represents a significant escalation in sophistication for financially motivated phishing operations.
Security Architect’s Take: Review your identity protection controls to ensure MFA implementations use phishing-resistant methods such as FIDO2/passkeys rather than OTP or SMS, which are vulnerable to real-time relay attacks. Additionally, implement continuous session validation and anomalous login detection in your cloud identity platforms to catch hijacked sessions even after initial authentication succeeds.
Original advisory: CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking