CTM360 says phishing aimed at the insurance sector is no longer following the older pattern of simply collecting usernames and passwords for later use. Its research points to a shift toward real-time account hijacking, where attackers move quickly once a victim interacts with a fake login flow.

For years, phishing campaigns targeting financial institutions relied on a familiar method: trick a user into entering credentials, store that information, and wait for a later moment to abuse the account. The new trend described by CTM360 suggests that this approach is changing, with attackers seeking to take control much faster while the victim is still engaged.

That evolution matters because it turns insurance phishing from a delayed fraud risk into a live account takeover threat. Instead of treating stolen credentials as something to exploit later, threat actors appear to be designing campaigns around immediate access, making detection and response more difficult for both insurers and customers.

The report highlights a broader change in cybercrime tactics affecting financial services. As phishing becomes more dynamic and time-sensitive, insurance companies face added pressure to strengthen login security, monitor suspicious sessions, and prepare for attacks that unfold in real time rather than after the fact.