Phishing against insurance portals has moved from collecting credentials for later reuse to taking over the account while the victim is still logging in. The old response misses the point: once the attacker can relay the login and OTP in real time, the session is already lost before any offline review can help.
CTM360 says the InsureOTP kit does this by forwarding the victim’s username, password, and one-time code to the real site fast enough to finish authentication in the same browsing session. The campaign was seen across multiple insurance brands and regions, with the same infrastructure reused and localized for Saudi Arabia, Europe, the United States, and India.
That makes SMS- and app-based OTP flows a live interception point, not just a barrier against stolen passwords. The broader risk reaches any customer login that still treats a one-time code as proof that cannot be reused immediately.