A new report from CTM360 reveals a concerning evolution in phishing attacks targeting the insurance sector. Rather than simply stealing usernames and passwords, cybercriminals are now using real-time account hijacking techniques to bypass traditional security measures and take control of customer accounts during active login sessions.
According to the research, attackers employ advanced phishing kits capable of capturing login credentials, session cookies, and even Multi-Factor Authentication (MFA) tokens in real time. This enables them to hijack authenticated sessions without requiring victims to log in again, significantly increasing the success rate of account takeover attacks.
The report highlights that insurance companies are becoming attractive targets due to the sensitive personal, financial, and healthcare information they manage. Stolen accounts can be exploited to access policy details, process fraudulent claims, or steal customer data.
Recommended Security Measures
Organizations can reduce the risk of account hijacking by:
Deploying phishing-resistant MFA, such as FIDO2 security keys or passkeys.
Implementing real-time session monitoring and anomaly detection.
Using risk-based authentication for suspicious login attempts.
Training employees and customers to identify phishing websites.
Regularly reviewing and revoking suspicious user sessions.
Why It Matters
The shift from credential theft to real-time session hijacking shows that attackers are adapting faster than traditional security controls. Organizations must strengthen identity protection and continuously monitor user sessions to defend against increasingly sophisticated phishing campaigns.
Conclusion
CTM360's findings demonstrate that phishing is no longer limited to stealing passwords—it now enables attackers to seize active user sessions almost instantly. As identity-based attacks continue to evolve, businesses should prioritize phishing-resistant authentication, continuous monitoring, and user awareness to stay ahead of modern cyber threats.