The claims-payment unit of an insurance company received an email appearing to come from an aggrieved policyholder: the reference number of the approved claim file was correct, and it said "I've changed my IBAN, please pay to my new account." Because the reference number was correct, the team processed the request. But the real policyholder's email had been compromised weeks earlier; the attacker had silently watched the approved claims process and stepped in at the exact moment of payment. The claim compensation went not to the victim but to the attacker.
Insurance and finance are a first-class target for email attackers for three reasons: a direct flow of money (claim payments, loan disbursements, investment transfers), extraordinarily dense personal and financial data (policies, health, national ID, account details), and a heavy regulatory burden (banking/insurance regulators, KVKK, anti-money-laundering). When these three combine, a single email incident means both a large financial loss and a serious compliance breach. In this article we cover the sector's threat vectors and defense.
1. Why Are Insurance/Finance a First-Class Target?
- Direct money flow: Claim payments, loan disbursements, premium refunds, investment/fund transfers — money is this sector's product. For the attacker, the path "straight to the vault" without touching an intermediary.
- Dense sensitive data: Policy details, medical reports, national IDs, income documents, account statements. This data is both a target (ransom, identity theft) and the raw material for later attacks (convincing phishing).
- Heavy regulation: Banking/insurance supervision, data-protection obligations, anti-money-laundering reporting. A data breach or fraud produces serious administrative/legal consequences beyond the financial loss.
- Broad intermediary network: Agencies, brokers, adjusters, bank branches. Every intermediary is a surface where identity verification gets harder and a trust relationship.
2. The Four Threat Vectors We See in the Sector
2.1 Claim / Payment Redirection
The opening scenario. A policyholder, intermediary, or supplier (contracted service, hospital) is impersonated or compromised; at the moment of an approved payment, an "IBAN changed" request arrives with the genuine file reference. The attacker has often watched the process in advance and steps in at the exact moment of payment. The compensation/payment goes to the attacker, not the victim.
2.2 Leakage of Dense Personal/Financial Data
Policy, health, identity, and account data can leak out via targeted phishing, ATO, or the wrong recipient. This is a serious breach requiring notification under KVKK, and the leaked data becomes the raw material for later fraud. DLP on the outbound side is the direct antidote to this vector (see our DLP & KVKK article).
2.3 The Agency/Broker Chain and Account Takeover
Compromising an account in the broad agency/broker network opens the door to both customer data and the "internal" trust relationship with the company. Mail going from a compromised agency account to the company or the customer is the most trusted, and the hardest for a gateway to see (see our ATO article).
2.4 Regulator / Official-Authority Impersonation
Emails impersonating banking/insurance regulators, anti-money-laundering authorities, or official bodies, themed "urgent notice," "audit request," or "compliance document update." Because the regulatory burden is heavy, such "official and urgent" emails are met with a high compliance reflex; a malicious attachment or fake portal kicks in.
3. Field Note: The "Correct Reference Number" Trust
The clear pattern we see in the insurance/finance field: a correct file/policy/claim reference number acts, on its own, like a seal of trust. The team operates on the assumption "only the real counterpart could know this number" — but if the attacker has compromised the account or watched the process, they already know it. A second observation: the sector's heavy regulatory awareness is often focused not on the inbound threat but on compliance documents; so an organization saying "our data-protection file is complete" may have sensitive data flowing out of its email every day. A compliance document and a technical control are not the same thing.
4. Defense: Three Layers Worthy of Regulation
Process
For claims, loans, and any payment, an IBAN/account change — even if it contains the correct reference number — is not processed without confirmation via a call-back to a registered number. The critical nuance: the correctness of the reference number doesn't prove the correctness of the account; the two are verified separately. Dual authorization is added for high-value payments. These rules are written into the claims/payment procedure and audited regularly.
Technology
Check Point Harmony Email & Collaboration provides the following in insurance/finance scenarios:
- Look-alike and newly registered domain detection — flags policyholder, agency, supplier, and regulator impersonation.
- Correspondence-pattern learning — contextually flags the "IBAN changed" request at the moment of payment, even when the reference number is correct.
- Account-takeover protection and internal-traffic visibility — catches compromised agency/employee accounts early.
- DLP — blocks policy, health, identity, and account data from leaving policy-out in outbound traffic; logs for the KVKK burden of proof.
- Attachment analysis (sandboxing) and click-time URL protection on targeted phishing/regulator-impersonation emails.
People
Sector-specific simulations for claims, loan, operations, and compliance teams: a fake claim IBAN change (with a correct reference), regulator impersonation, a data-request lure. The rule to embed: "A correct reference number doesn't verify the account — money movement is always confirmed through a separate channel."
Frequently Asked Questions
Only the real counterpart could know the reference number — confirm anyway?
That assumption is exactly the source of the risk. If the attacker has compromised the account or watched the process, they already know the reference number. So the reference number verifies not identity but only the file; the correctness of the payment account must be confirmed through a separate channel.
Our data-protection/regulatory compliance documents are complete — isn't that enough?
A compliance document is necessary but doesn't replace a technical control. To say "we took measures," the measure must actually be working and recorded; if sensitive data is flowing out of email, the document doesn't close that gap. An observe scan clarifies the difference between a document and a working control.
We can't secure our agencies — what can we do?
You can't control the agency's security, but you can control your own payment process and internal-traffic visibility. Dual-channel confirmation protects you even if the agency's account is compromised; behavioral analysis catches what comes from a compromised agency account.
Can we measure what our current protection misses in these scenarios?
Yes. In a 14-day monitor-mode trial, we report what's missed — claim/payment redirection, agency impersonation, targeted phishing, and outbound data leakage included — without touching your existing protection.
What Should You Do Now?
If you work with money flows and dense personal data and are subject to heavy regulation, start with two questions: (1) "Would a fake IBAN-change request with a correct reference be caught by our process?" (2) "Do we know which sensitive data is flowing out of our email?"
- Free Field Audit + DLP Observe Scan: Your impersonability (DMARC), targeted-phishing surface, and outbound sensitive-data flow (in KVKK categories) — reported.
- 14-Day Check Point Trial (monitor mode): Missed threats in inbound and outbound traffic, reported.
About this article: The twelfth article of our Sector Series. Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level, holding Email, Endpoint & Browser, Mobile, and SASE Solution Specialization accreditations. The author, Kemal Özleyen, is a cybersecurity engineer certified as a Check Point Workspace Security Expert. Field scenarios are shared in anonymized form. This content is for general information; your organization's regulatory obligations should be assessed with the relevant expertise.