What does a one-time code actually prove? Most people would answer "that it's me" without stopping to think, and that answer is doing a great deal of work. Password stolen? Fine, they still need the code from your phone. But the code proves who you are. It says nothing at all about which website just received it.
What does a one-time code actually prove?
When a company texts you a 6-digit code, it is answering one question: is the person trying to sign in holding the phone that belongs to this account? Answering yes is genuinely useful. It stops someone in another country from using a password they bought in a leak.
But the code travels in one direction only. Your bank sends it to you. Nothing in the message checks where you type it next. Paste it into a page that isn't your bank, and the page now holds a live key to your account, minted seconds ago by the real company, with your full cooperation.
What is the fake page doing while you type?
The older version of phishing was patient: a fake login page harvested passwords, someone came back later and tried them. Two-factor authentication broke that model, because by the time the attacker showed up, they still needed a code they couldn't get.
So the model changed. The fake page stopped being a collection box and became a middleman, operated live.
Security firm CTM360 published a report on 22 July 2026 describing exactly this, in a campaign it calls InsureTrap, built on a previously undocumented phishing kit it named InsureOTP. In a contributed writeup published on The Hacker News on 25 July 2026, CTM360 describes the sequence: attackers synchronise their activity with the victim in real time, authenticating against the legitimate insurance portal while the victim is still on the fake one. The real insurer sends its one-time password to the customer, and the fake page immediately prompts the victim to enter that same code. Credential theft and account takeover happen inside a single browsing session.
Two details make it feel less like a hack and more like a job. First, there is a backend dashboard: CTM360 describes live session management with manual approval workflows, meaning a human is watching and deciding. Second, when authentication fails, that backend can request another code from the victim, and the page simply asks again. Stolen data is pushed out through Telegram bot APIs or servers the attackers control.
Independent coverage from SC Media reported the same core mechanism: live session management and real-time interception of one-time passwords to bypass multi-factor authentication.
One caveat worth stating plainly, because it changes how you should read all of this: the Hacker News piece is labelled as a contributed piece from a partner. It is CTM360's own research, not independent reporting, and CTM360's public report page is a gated summary. There are no published counts of domains, brands or victims anywhere in the accessible material, so this article doesn't give you any. The mechanism is what's documented, and the mechanism is the part that matters to you.
You didn't click a bad link. You clicked an ad.
This is the uncomfortable part. CTM360 says victims did not arrive via a phishing email or a scam text. They arrived through sponsored Google ads placed against completely normal searches: insurance quotes, renewals, price comparisons, things like "compare car insurance offers."
Think about what that removes. There is no suspicious sender to inspect. No urgent "your policy is suspended" message to distrust. No shortened link. You went looking for the thing, and the thing appeared at the top of the results, where useful results live.
The hosting helped too. CTM360 reports the fake sites sat on legitimate website builders and free hosting platforms, naming GitHub Pages, Netlify, Hostinger, Wix and Lovable. Those services are fast, they serve HTTPS by default, and they are used by millions of real businesses. So the padlock was there. The page loaded instantly. Nothing looked broken, because nothing was broken.
And the domain wasn't a clever lookalike
If you read a lot of phishing advice, you're primed to hunt for a near-miss spelling: the zero standing in for an O, the doubled letter. That's a real trick, and we've written about it at length.
It is not what happened here. CTM360 describes the campaign's domains as randomized, with little or no resemblance to the insurance brands being impersonated, precisely so campaigns could rotate quickly and slip past brand monitoring. So there was no letter to catch.
your-actual-insurer.comthe address you'd reach from your own bookmarkq7-quote-portal-4821.exampleillustration only, not an observed domain: nothing to misread, just nothing you recogniseThe warning sign in a campaign like this isn't a near-miss. It's unfamiliarity: an address you have never seen before, sitting under a brand name you have. Which is a much weaker feeling to act on, and that's the whole design.
So the order changes
All of the above collapses into one practical rule. The domain has to be checked before the code, not after. Once the code is typed, there is nothing left to verify.
- Never start a login from an ad or a search result when money or an account is involved. Type the company's address yourself, or use a bookmark you made when you weren't in a hurry. This one habit removes the entire attack.
- Read the address bar before you type your password, not after. Look at the part immediately before the final
.comor.co.uk. If you don't recognise it, stop there. - Treat a code request as a checkpoint. Before you enter it, ask: did I start this login, on a site I arrived at deliberately? If a page asks for a second code after the first "didn't work," treat that as a loud signal, not a glitch.
- Check the domain when it's unfamiliar. Copy it out of the address bar and look up what's publicly known about it, or paste it into IP Tracker and read the signals.
- If you already gave a code away, act as though the account is compromised: change the password from the real site, sign out all sessions, and check whether the email address, phone number or payout details on the account were changed.
Where IP Tracker fits
IP Tracker is a free Chrome extension. Paste a domain or a full email address into the popup and it surfaces what's publicly known about that address, in plain English. The free tier is 50 checks a day, with no account and no tracking; only the value you paste is looked up.
For an unfamiliar domain like the ones in this campaign, the useful signals are:
- Google Safe Browsing. Whether Google's list of reported dangerous sites has flagged that address for social engineering or malware. This is the strongest single signal when it fires.
- Security-vendor reputation. How many vendors on VirusTotal currently flag the domain, and its reputation score.
- How old the domain is. WHOIS registration date. A domain registered days ago, wearing an established brand's name, is worth pausing over. IP Tracker shows this as a supporting clue, never as a verdict by itself.
- Who's behind the address. The resolved IP, its owner and hosting network, plus community abuse reports on that IP.
What it gives you is a few seconds of outside information at the moment you'd otherwise be guessing. That's it, and it's deliberately that.
What can't it do?
Being straight about this matters more than sounding reassuring, so here are the limits that apply to precisely this kind of campaign:
- Lookalike detection would find nothing here. IP Tracker's lookalike check compares an address against a list of widely impersonated brands, looking for swapped characters and near-miss spellings. Against a randomized string that resembles no brand at all, it correctly returns nothing. On this campaign, the lookalike feature is not the one doing the work, and it would not have named the site as a fake.
- "Unknown" is the most common answer for a brand-new domain. A site registered this week often has no reputation data at all. IP Tracker deliberately does not treat that silence as reassurance, and neither should you. An unknown domain asking for your password is a reason to slow down, not to relax.
- Blocklists lag reality. Safe Browsing is strong on reported sites, but a fresh domain rotated in this morning may not be listed yet. Campaigns that rotate addresses quickly are built specifically to exploit that gap.
- Legitimate hosting is not a signal it can convert. A page on a well-known website builder inherits that platform's clean reputation. HTTPS and a fast-loading, professional-looking page tell you nothing about who wrote it.
- It cannot intervene. IP Tracker is something you consult, not something that stands between you and a page. It does not block sites, does not watch your browsing, and does not act on its own.
The uncomfortable takeaway from CTM360's research isn't that two-factor authentication failed. It's that it was never designed to answer the question we've been asking it to answer. It confirms you. Only you can confirm the site.
To summarize:
- ✓ A one-time code proves who you are, not where you are.
- ✓ Real-time phishing pages relay your code into the genuine login while you're still on their page.
- ✓ These sites reached people through sponsored search ads, on ordinary hosting, with valid HTTPS.
- ✓ The domains were random strings, not lookalikes, so the tell was unfamiliarity.
- ✓ Check the domain before the code. Afterwards there's nothing left to check.
Your code is yours. Nobody legitimate is ever waiting on the other end for it. 😎
Sources
- InsureTrap: fake insurance phishing and account hijacking, CTM360 report summary, July 22, 2026.
- CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking, The Hacker News (contributed partner piece), July 25, 2026.
- Phishing attacks on insurance companies evolve to real-time account hijacking, SC Media brief.