Find notable cyber news and cases, enriched with sources, timelines, and signals.

Insurance provider Google Ads real-time OTP phishing campaign

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The insurance-focused phishing campaign now uses Google Ads, lookalike domains, and real-time OTP relaying to hijack sessions before victims notice. The operation spans Saudi Arabia, Europe, the United States, and India, broadening exposure across multiple insurers. Instead of delayed credential theft, attackers can complete login and take over accounts during the same browsing session. That raises the risk of immediate access to customer data, policy records, and payment information.

Related Happenings

Infostealer malware operation targeting online store users

Malware Activity
H score32 First: 21.05.2026 00:36 Last: 21.05.2026 00:36 Sources 1

About this happening: A malware operation using infostealer tools infected users’ devices between 2024 and 2025, stealing browser sessions and account credentials that enabled account theft...

W3LL Microsoft 365 adversary-in-the-middle phishing campaign

Campaign
H score39 First: 13.04.2026 21:55 Last: 13.04.2026 21:55 Sources 1

About this happening: The W3LL phishing operation turned into a high-volume Microsoft 365 credential-theft campaign, exposing more than 17,000 victims worldwide to BEC risk. The kit use...

TikTok for Business phishing campaign using Turnstile and reverse proxy

Campaign
H score31 First: 26.03.2026 16:09 Last: 26.03.2026 16:09 Sources 1

About this happening: A phishing campaign is targeting TikTok for Business accounts and uses Cloudflare Turnstile to block automated analysis before exposing a reverse-proxy credential-...

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon2FA has shifted from a subscription-based PhaaS and AitM credential harvester into a more resilient campaign that now uses device-code phishing against Mic...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

1Campaign-DuppyMeister ecosystem shift changes threat-actor operations

Threat Actor Meta
H score22 First: 24.02.2026 23:45 Last: 24.02.2026 23:45 Sources 1

About this happening: 1Campaign is a long-running cloaking service that helps operators keep malicious Google Ads online while evading researcher scrutiny and automated inspection. The...

Timeline

  1. 25.07.2026 13:14 2 articles · 2h ago

    Insurance phishing operation uses Google Ads and real-time OTP relaying

    Initial Disclosure

    CTM360 identified a coordinated phishing operation targeting multiple insurance providers across Saudi Arabia, Europe, the United States, and India that used Google Ads, lookalike insurance portals, and disposable cloud hosting to lure victims into live login flows. The campaign synchronized attacker activity with victims in real time, relayed one-time passwords before they expired, and used the previously undocumented InsureOTP Kit to manage sessions, monitor victims, and complete authenticated access during the same browsing session.

    Show sources