Independent consumer resource. Always free, no sign up.
Text size: Family alerts
The Scam Exposed
Share
Scam Alerts

Fake Insurance Ads That Steal Your Code While You Watch

· · Updated · 6 min read
Fake Insurance Ads That Steal Your Code While You Watch

You search for car insurance. An ad at the top of Google looks like the company you already use. You click it, sign in, and a code arrives on your phone as it always does. You type it in.

By the time you finish typing, someone else is already inside your account.

This is not the old kind of password theft where the criminal comes back later. Everything happens live, in the seconds while you are still sitting there, and the one-time code you were told would protect you is the part they need most.

How the attack works

The technique has a name in the security industry: adversary in the middle. The fake page is not a copy sitting on its own. It is a relay, passing everything you type straight to the real website in real time.

  1. You click a paid search ad that looks like your insurer, your bank, or a comparison site.
  2. You land on a page built to look identical to the real login. Same logo, same colours, same layout.
  3. You enter your username and password. The relay immediately submits them to the genuine site.
  4. The genuine site sends a one-time code to your phone, exactly as it should, because as far as it can tell you are logging in.
  5. The fake page asks for that code. You have just received a real code on your real phone, so it feels legitimate.
  6. The relay uses the code within seconds and captures the session. It is now logged in as you.

Nothing about your behaviour was careless. You received a real code from a real company and entered it into a page that looked correct.

This is not a small or rare problem

Security researchers at Sekoia have catalogued roughly a dozen commercial relay phishing platforms in active use, sold as ready-made services with names like Tycoon 2FA, EvilProxy, and Evilginx.

In April 2026, Microsoft observed a single campaign of this type compromise more than 35,000 users across 13,000 organisations in 26 countries in three days.

The FBI issued a public warning in May 2026 about a platform called Kali365, noting that it lowers the barrier of entry, giving less technical criminals access to AI-generated lures, automated templates, and live tracking dashboards.

That phrase matters. This used to require real skill. It is now a subscription.

Why the advertisement is the weak point

Most advice about phishing says to check the link before clicking. That advice assumes the link arrived in an email.

Here it arrives at the top of a search results page, in the position people trust most, on a site people trust completely. Criminals pay for those ad slots exactly as any business would.

You were not tricked into visiting a strange website. You searched for your own insurer and clicked the first result.

The habit that fixes this: never click the ads. Scroll past the sponsored results to the ordinary listings below, or better, type the address yourself or use a bookmark. On a phone the ads can fill the whole first screen, so scrolling matters more, not less.

Why your one-time code no longer protects you

This is the uncomfortable part, and it is worth being precise about.

Text message codes, authenticator app codes, and push notification approvals are all transparent to a relay. The attack does not break them. It waits for you to complete them correctly, then takes the result.

That does not make two step login pointless. It still blocks the overwhelming majority of ordinary account takeovers, and turning it off would be a serious mistake. It simply is not sufficient against this specific attack.

What actually stops it

One thing does, and the reason is structural rather than a matter of being careful.

Passkeys. A passkey is cryptographically tied to the genuine website's address. On a fake page, it does not appear and cannot be used. There is no code to relay, because there is no code.

The relay's whole design depends on you typing something it can pass along. A passkey gives it nothing to pass.

Google, Microsoft, Apple, Amazon, and PayPal all support passkeys now, and banks and insurers are adding them. When a site offers one, take it. Look for "Create a passkey" in security settings.

Our device settings guide covers how to set one up.

Four habits that reduce the risk today

  1. Bookmark the sites that hold your money. Bank, insurer, pension. Use the bookmark every time and you never meet a fake login page.
  2. Scroll past sponsored results. If you must search, use the ordinary listings underneath.
  3. Read the code message before you type it. The text usually says what it is authorising. If it mentions a login you did not expect, or a payment, stop.
  4. Turn on login alerts. Many providers can email you when a new device signs in. It will not prevent the attack, but it tells you within minutes rather than weeks.

Signs your account has been taken over

Because the criminal logs in as you, there is no broken password to alert you. Watch for:

  • An email saying your contact details or password were changed, when you did not change them
  • A sign-in alert from an unfamiliar location or device
  • Emails disappearing from your inbox, which happens when a rule is set to hide them
  • A claim, policy change, or payment you did not make

If it has already happened

  1. Sign out of all devices. Most services have this in security settings, sometimes called "Sign out everywhere". This kills the stolen session, which is the thing they actually hold.
  2. Change the password from a different device, and change it anywhere else you used the same one.
  3. Check for new rules or forwarding in your email settings. Attackers frequently add one to hide alerts from you.
  4. Call the company on a number you already have and tell them the account was compromised.
  5. Report it at reportfraud.ftc.gov, and at ic3.gov if money was taken.
  6. If personal data was exposed, start a recovery plan at IdentityTheft.gov.

Our page on the first 48 hours after a scam covers what to say when you call.

The short version

A one-time code proves a code reached your phone. It does not prove the page asking for it is real.

So stop meeting login pages through search ads. Use a bookmark, and use a passkey where you can. Those two habits remove the situation entirely, which is more reliable than trying to spot a page built specifically to be unspottable.

Check a website before you trust it

Look up any website or phone number here, free and in about ten seconds.

Sources

What Do You Think?

No one has commented yet. If this happened to you as well, say so below. Knowing that other people had the same call makes it far easier for the next person to trust their instincts.

Add Your Comment

Every comment is read by a person before it appears, so it will not show up straight away. Never post your phone number, address, or bank details here.

This one question keeps the automatic spam out.

You're Safe Here. Let's Fix This Now.

If you already sent money or shared information, act fast. Follow these steps in order.

1

Call Your Bank or Card Company Immediately

Use the number on the back of your card, not any number the caller gave you. Ask them to freeze the transaction or account.

2

Call the National Elder Fraud Hotline

Free help, 7 days a week.

Call 1-833-372-8311
3

Report It to the Government

File a free report at the Federal Trade Commission so they can investigate.

Go to reportfraud.ftc.gov