Blog

Security Alert: New Phishing Scam Targeting Insurance Professionals

Subject: Beware of Online Meeting Requests from Prospects.

We want to make you aware of an emerging phishing technique that is increasingly targeting insurance agencies and agents.

What We’re Seeing Cybercriminals are sending emails that appear to come from legitimate prospects interested in purchasing insurance. In some cases, the emails may even originate from trusted carrier lead-generation or prospecting platforms, making them appear genuine. The prospect typically asks to:

  • Discuss insurance options

  • Review coverage needs

  • Show a vehicle or property

  • Conduct a virtual consultation

  • Meet online before moving forward

The email then contains or leads to a meeting invitation or a link to join an online meeting.

The Threat

The meeting link itself is often the malicious payload. Clicking the link may:
  • Direct you to a credential harvesting site designed to steal your Microsoft 365 password

  • Download malware to your device

  • Redirect you to a fake login page

  • Compromise your email account or agency network

    Because the request appears legitimate and aligns with normal insurance business activities, these attacks can be difficult to identify.
Our Recommendation

Never join online meetings using a link provided by an unknown prospect.

Instead:
  • Verify the legitimacy of the individual first.If a virtual meeting is needed, the agent should create and send the meeting invitation using the agency’s approved meeting platform (Microsoft Teams, Zoom, etc.). Ask the prospect to join your meeting link, not the other way around.Be cautious of prospects who insist that you use their meeting platform or their link.If anything seems unusual, report the message to Computer Rescue before clicking.
Red Flags Be especially cautious when:
  • The prospect is in a hurry to meet.

  • The meeting link uses an unfamiliar service.

  • The sender refuses a phone call but pushes for an online meeting.

  • The email contains poor grammar or unusual wording.

  • The meeting link redirects through multiple websites.

  • The request seems legitimate but there is little other information about the prospect.

When in Doubt

    a legitimate prospect will have no issue joining a meeting that you schedule and host. If a prospect insists on using their own meeting link, treat the request with suspicion until it can be verified.Remember: The safest practice is simple: If you’re meeting with a prospect online, you should always originate the meeting invitation and send the meeting link yourself.
If you receive a suspicious email or would like assistance verifying a meeting request, please contact Computer Rescue before clicking any links.