SUNDAY, JULY 26, 2026|No. 8891
Cybersecurity · Phishing

SMS Phishing Attacks Surge 146% as Criminals Target Insurance Customers

A new wave of phishing attacks has driven SMS fraud up 146%, with hotels and insurance companies becoming primary targets.

Illustration of a smartphone displaying a phishing SMS with a fraudulent link.
Illustration of a smartphone displaying a phishing SMS with a fraudulent link.
1 sources
Pipeline ingest
3 reads
Positive / Neutral / Negative
1 countries
Related coverage

Phishing Wave: SMS Fraud Jumps 146%, Insurers in the Crosshairs

IT security researchers and consumer advocates are raising the alarm. A new generation of highly specialized phishing attacks is specifically targeting travelers and insurance customers. Criminals are using real-time account takeovers and manipulation of IT infrastructures to obtain credit card data and personal information.

Compromised Hotel Accounts: When the Fraudster Knows Your Booking Data

A particularly insidious scam currently affects users of booking platforms such as Booking.com. Criminals gain access to official hotel operator accounts through phishing. With these authentic credentials, they obtain real booking data – names, stay periods, hotel names.

Shortly before the planned arrival, the attackers contact travelers via WhatsApp or email. Since they provide correct booking details, the communication appears extremely credible. In a documented case from Bautzen, an attacker posed as a hotel employee and threatened cancellation unless a supposed payment was confirmed via a sent link. The link leads to fake payment pages with the sole goal of stealing credit card data.

The Saxony Consumer Advice Center and the industry association HORESCA advise caution. Travelers should not click on any links in unsolicited payment requests but should contact the hotel directly via official channels or check the booking in the app.

"InsureOTP Kit": Real-Time Takeover of Insurance Accounts

Alongside the travel wave, security analysts at CTM360 are observing increased activity against insurance companies. The focus is on the so-called "InsureOTP Kit" – a software that enables attackers to take over customer accounts in real time.

The attack often begins with sponsored search ads that redirect victims to manipulated pages. While the user enters their data, the perpetrators intercept one-time passwords (OTP) and simultaneously access the account. The main targets of these campaigns are Europe, Saudi Arabia, the USA, and India. The infrastructure behind the attacks uses legitimate hosting platforms such as GitHub Pages, Netlify, and Wix – this significantly hinders detection by security software.

Manipulated Hotel Wi-Fi: Fake Microsoft Pages in the Crosshairs

But the attackers go even further. Analyses by ReliaQuest show a campaign running since June 2026, in which criminals manipulate DNS settings of Wi-Fi gateways in hotels. Anyone logging into the hotel Wi-Fi is redirected to fake Microsoft 365 login pages.

The goal is to steal access credentials from financial services, healthcare, and energy sectors. The attackers sometimes misuse device code authentication to bypass multi-factor authentication (MFA).

The Numbers Speak a Clear Language

The threat landscape is real and growing rapidly. According to data from BioCatch, SMS fraud increased by 146 percent in the first half of 2026. Microsoft alone recorded 7.6 billion email phishing attempts in the second quarter.

An international success was achieved by authorities such as the BKA and the FBI: They dismantled the "Kratos" phishing platform, which was used to control around 15,000 campaigns per month in 35 countries.

Given the professional threat situation, regulatory authorities like the ECB are demanding concrete action plans from banks by October. Experts advise companies and private individuals to use VPN services with full tunnel routing and encrypted DNS – as protection against infrastructure manipulations.

PAN's pipeline reviewed approximately 1 open sources for this article. No human editor reviewed this article before publication.

Related Reads

Show on timeline →