The Fake-Insurer Factory: Auto-Insurance Lead-Gen Smishing
The Fake-Insurer Factory: Auto-Insurance Lead-Gen Smishing
Since early 2026, one operator has flooded US phones with auto-insurance rate-drop texts that direct recipients to fabricated-brand quote pages built to harvest personal data. The savings hook rarely changes ("safe drivers can now get full coverage as low as $29/mo"), but the supposed insurer changes with every domain. Rather than impersonating a real carrier, the operator invents insurance brands, one for each burner domain, and assigns each one a dedicated toll-free number or leased 5-digit shortcode. Every brand fronts the same quote funnel, and every funnel has one purpose: collect a consumer's ZIP, vehicle, date of birth, and contact details, then sell that record to downstream lead buyers. We tracked more than 20 coined CTA domains and more than 50 sender identities operating continuously from at least February 2026 into mid-2026. Together, they pushed tens of thousands of scam text messages to US consumers.
Key Takeaways
- A single operator runs a one-brand-per-domain factory. Each burner domain has its own coined insurance name and the same quote funnel, allowing the network to scale without reusing a recognizable brand.
- Neither the brand nor the sender provides the durable fingerprint. Both rotate. The constant is the funnel grammar:
app.<brand>,start.<brand>,request.<brand>, andinfo.<brand>subdomains that host a byte-identical PII-harvest template. - The domains divide cleanly into three provisioning clusters based on registrar and mail stack, including a purpose-built batch registered on Cloudflare during a two-week window in December 2025.
- Delivery is SMS only, using six toll-free prefixes (833, 844, 855, 866, 877, 888) and a pool of leased shortcodes. The same CTA domain is often sent over both rails.
- The operator also runs a parallel template variant written to resemble ordinary marketing. This evasion tier carries the same lure but removes the signals that make the loud tier obvious.
- The kit crosses verticals. Auto is primary, while a Medicare arm and a life-insurance arm reuse the same funnel and delivery.
Background
Auto and health insurance are among the highest-value lead-generation verticals, backed by a large legitimate industry. Real insurance lead generation uses a ping-post auction: a landing page collects a partial consumer profile (ZIP, vehicle, age), "pings" it to a pool of buyers, and sends the complete record as a full "post" to the winning bidder. Leads may be sold as shared records to several buyers or as exclusive records to one, at anywhere from a few dollars to tens of dollars each in the auto and health verticals. This economic incentive helps explain why fabricated insurance brands and quote funnels remain a persistent smishing pretext. A scam operator only needs to mimic the funnel long enough to harvest the data, then monetize it through the same broker and exchange plumbing used by the legitimate market.
Two shifts moved this class of operator onto SMS. STIR/SHAKEN call authentication made anonymous voice spoofing harder, so the long-running "cheap car insurance" pitch moved to texting, where per-message identity attestation is weaker. Sender infrastructure is also cheap to acquire. US application-to-person (A2P) business texting uses toll-free numbers and leased 5-6 digit shortcodes. Both require carrier or registry vetting on paper, but operators can buy capacity in blocks through lightly-vetted resellers and aggregators. Toll-free numbers can be provisioned quickly and in bulk, and they still give consumers a residual cue of "official business." Shortcodes offer more throughput and an even stronger appearance of legitimacy. When carriers block a number or it becomes flooded with STOP replies, the operator discards it without disrupting the campaign.
The domains are equally disposable. Each brand needs a registrar and a way to receive mail without revealing an identity, and the operator's chosen stack leaves a fingerprint. PrivateEmail is Namecheap's hosted-mailbox product, and its mail records indicate a Namecheap-provisioned inbox. Cloudflare Email Routing is a free, forward-only service that receives mail at a brand address and sends it to a burner inbox at zero mailbox cost. This helps explain why batch-registered throwaway domains cluster on it. Domains-by-Proxy is GoDaddy's WHOIS-privacy arm, which masks the registrant's identity. None of these products is abusive by itself, and millions of legitimate sites use them. Together, however, they allow one operator to create dozens of look-alike domains cheaply and anonymously. Beyond .com, inexpensive alternative TLDs such as .co and .link can be registered immediately without extra vetting and used as rotation inventory when a primary domain burns.
The main legal exposure is the Telephone Consumer Protection Act (TCPA): unsolicited marketing texts sent without prior express written consent carry $500 to $1,500 in statutory damages per message. Regulators have also acted against the surrounding ecosystem. The FCC moved to close the "lead-generator loophole," in which a single consent is distributed to hundreds of sellers, and the FTC brought a combined $145M action against insurance lead generators (Assurance IQ and Media Alpha) for deceptive practices. Consumer-security reporting from outlets including Malwarebytes and TNS documents the same pattern used by this operator: unsolicited texts from unknown numbers without a real company name, premiums that are too good to be true, and a quote form that progresses from basic vehicle information to financial and identity details.
Discovery and Infrastructure
We first found the network through a seed pair of toll-free phones and shortcodes connected to a handful of coined insurance domains. Expanding from the shared quote-funnel template and sender pools exposed the rest of the infrastructure. The common element was never the brand name, which is deliberately unique to each domain, but the funnel behind it. Every coined brand resolves to the same app.<brand> or start.<brand> quote page and uses identical harvest copy.
One phone anchored the attribution. A single toll-free number rotated among three separate coined brands (maplecoverage[.]com, autopolicyplus[.]com, and roadelo[.]com), showing that domains presented as distinct "insurers" draw from a common operating pool. The shortcodes followed the same pattern, with several used for more than one brand. From there, the domain set divided by registrar and mail provider into three provisioning generations, all of which share the template.
| Indicator | Role | Notes |
|---|---|---|
maplecoverage[.]com |
CTA funnel | Cluster A anchor, Namecheap/PrivateEmail, reg 2024-11-04 |
autopolicyplus[.]com |
CTA funnel | Cluster A, Namecheap/PrivateEmail, reg 2024-03-12 |
easyroadpolicy[.]com |
CTA funnel | Namecheap reg 2024-12-19 with Cloudflare mail, an A-to-B bridge |
medicarepolicyplus[.]co |
CTA funnel | Cluster B anchor, Medicare vertical, reg 2022-10-24 |
bitticksinsurance[.]com |
CTA funnel | Cluster B, Cloudflare Dec-2025 batch; typosquat of a legitimate regional agency |
autoinsurer-quote[.]co |
CTA funnel | Cluster C anchor, GoDaddy/Domains-by-Proxy, reg 2025-05-15 |
autopolicy2026[.]com |
CTA funnel | Cluster C, GoDaddy, reg 2026-04-07, year-stamped burner |
switchinsure[.]link |
CTA switch-link | Cloudflare, .link rotation, routed via a conversational-texting platform |
app.maplecoverage[.]com |
Quote funnel | Uniform harvest subdomain |
request.easyroadpolicy[.]com |
Quote funnel | Uniform harvest subdomain |
How It Works
A target receives an unsolicited text from a toll-free number or a 5-digit shortcode. The message opens with a savings claim and first-name personalization taken from a purchased list. It names the coined brand in both the message and the link and cites a specific low premium ($27 to $40 a month). The operator creates urgency with phrases such as "rates drop at month-end" or "lock in before rates reset this weekend." Some messages use the brand's acronym as a prefix (AIQ:, LIQ:, Maple:) to identify the funnel. A conversational variant opens with a persona ("Abby here, can I compare rates for you?") and tries to begin a back-and-forth exchange on a texting platform. TCPA opt-out language is frequently absent.
The link opens the brand's quote funnel on an app. or start. subdomain. The page presents itself as a neutral rate-comparison site, using generic promises of "top-rated quotes," "A.M. Best ratings," and "trusted partner coverage." It then takes the visitor through an escalating form: ZIP first, followed by vehicle, date of birth, and full contact details. The harvested record is the product. It enters the same ping-post resale pipeline used by legitimate lead generation, so the operator does not need a real carrier or policy at the other end. The Medicare and life arms change the pretext to eligibility, "new benefits," or age-banded life premiums, but use the same funnel and delivery.
Sample Lures
All samples are SMS. Recipient identifiers are redacted; CTA domains are defanged. Attacker-side content only.
Auto rate-drop lure (shortcode delivery):
[recipient name], safe drivers can now get rates as low as 30/mo!
MapleCoverage has verified lower rates in your area.
Get your free quote: hxxps://maplecoverage[.]com
Retirement-targeted variant with brand acronym prefix (shortcode delivery):
AIQ: Driving less in retirement? Don't overpay for coverage.
Auto Insurer Quote has found lower rates for your vehicle.
Review now: hxxps://autoinsurer-quote[.]co
Medicare-arm lure (toll-free delivery):
[recipient name], you can access new benefits today, including no copay visits.
MedicarePolicyPlus has confirmed eligibility for your zip.
See your options: hxxps://medicarepolicyplus[.]co
Life-insurance-arm lure with age-band targeting (toll-free delivery):
LIQ: Life policies for persons born in 1958 are actually cheaper now.
LifeInsurerQuotes has a rate locked for you.
Check it: hxxps://lifeinsurerquotes[.]co
Technical Analysis
One-Brand-Per-Domain Factory
The operator's setup reverses the usual impersonation model. Rather than reuse one spoofed carrier across its infrastructure, it gives each domain an invented insurer and places the recognizable element at the subdomain layer. Every coined brand uses the same funnel grammar (app.<brand>, start.<brand>, request.<brand>, info.<brand>) and hosts a byte-identical harvest template. The recurring boilerplate offers to compare "top-rated auto insurance quotes with unbiased reviews, A.M. Best ratings, and trusted partner coverage." The same kit supports several verticals: auto is primary, medicarepolicyplus[.]co is the Medicare arm, and the lifeinsurerquotes brands make up the life arm. Because the brand is disposable while the funnel remains constant, brand-name blocking has little value, while the funnel shape persists.
Registration Cohorts
Three provisioning stacks divide cleanly by registrar and mail fingerprint. The separation also provides a rough timeline.
| Domain | Registrar | Created | Cluster |
|---|---|---|---|
mightypolicy[.]com |
Namecheap | 2022-05-04 | A (aged) |
medicarepolicyplus[.]co |
Namecheap | 2022-10-24 | B anchor (aged) |
insuredautorates[.]com |
Tucows | 2023-08-31 | Other (aged) |
enlivenix[.]com |
Name.com | 2024-02-26 | Other |
autopolicyplus[.]com |
Namecheap | 2024-03-12 | A |
revpolicy[.]com |
Namecheap | 2024-09-23 | A |
maplecoverage[.]com |
Namecheap | 2024-11-04 | A anchor |
easyroadpolicy[.]com |
Namecheap | 2024-12-19 | A-to-B bridge |
lifeinsurerquotes[.]co |
GoDaddy | 2024-12-27 | C |
autoinsurer-quote[.]co |
GoDaddy | 2025-05-15 | C anchor |
greenlightpolicy[.]com |
Namecheap | 2025-05-15 | A |
switchinsure[.]link |
Cloudflare | 2025-07-02 | Other (.link) |
insuremedy[.]com |
Cloudflare | 2025-10-03 | B (early Cloudflare) |
lifeinsurerquotessms[.]com |
GoDaddy | 2025-10-20 | C |
sminsures[.]com |
Cloudflare | 2025-12-06 | B (Dec batch) |
bitticksinsurance[.]com |
Cloudflare | 2025-12-06 | B (Dec batch) |
wikicarinsurance[.]com |
Cloudflare | 2025-12-10 | B (Dec batch) |
pminsure[.]com |
Cloudflare | 2025-12-10 | B (Dec batch) |
ariseinsure[.]com |
Cloudflare | 2025-12-19 | B (Dec batch) |
autopolicy2026[.]com |
GoDaddy | 2026-04-07 | C (year-stamped) |
Cluster A uses Namecheap plus PrivateEmail and contains the aged .com anchors. Cluster B moves to free Cloudflare email routing and consists largely of a purpose-built batch registered over roughly two weeks in December 2025. That set contains interchangeable insurance-named burners created through one registrar with the same mail-privacy stack. This batch is the network's strongest infrastructure signal: coordinated registration on the same stack within a narrow window is textbook staging of burner inventory before a blast. Cluster C uses GoDaddy plus Domains-by-Proxy and shows that the operator continued creating domains into 2026, including a year-stamped burner (autopolicy2026[.]com). The aged 2022-2024 holdings matter for another reason. Older creation dates blunt naive domain-age heuristics, and first-seen activity trails registration by months, indicating that some domains were bought aged or held in reserve before activation.
Domain Generation
The naming scheme combines a templated insurance-token vocabulary with invented head-words. Recurring suffixes include (-coverage, -policy, -insure, -insures, -insurance), while recurring prefixes include (policy-, auto-, life-). These are attached to coined stems (maple, roadelo, enlivenix, and similar). Three variants are particularly relevant to detection engineers. A year-stamped burner (autopolicy2026[.]com) indicates disposable, time-boxed inventory. A typo-sibling of a real insurer (bitticksinsurance[.]com, an added "s" on a legitimate regional agency's domain) is the only case in which the operator draws on real-brand equity instead of inventing a name. Cheap-TLD rotation also moves the same funnel onto .co and .link twins when a .com burns.
Cross-Cluster Pivots
Three registrar stacks would usually point to three actors. In this case, they resolve to one. The byte-identical harvest template connects the clusters, as does the uniform app./start./request./info. funnel grammar used across every brand. A shared sender pool also links them: the pivot toll-free number and reused shortcodes span brands and clusters, and the same CTA domain is delivered through both toll-free and shortcode rails. The typosquat, Medicare spin-off, and life spin-off all use the same kit rather than separate ones. This points to a single operator working across successive infrastructure generations, not a kit sold to independent affiliates.
Escalation Over Time
The provisioning path runs from A to B to C. The earliest activity relies on Namecheap and PrivateEmail with aged .com brands. It then shifts to zero-cost Cloudflare email routing at scale with the December 2025 batch, followed by GoDaddy and Domains-by-Proxy with same-day apex twins and year-stamped burners through mid-2026. Over time, the inventory becomes cheaper, faster to create, more anonymous, and more disposable. The operator also maintains a parallel evasion-tier template variant written to resemble ordinary marketing instead of an overt promotion.
Detection Observations
The most useful signals distinguish this traffic from legitimate insurance marketing at the ecosystem level rather than within a single message. Pivots across domains and senders therefore provide the clearest view.
- The funnel grammar is the most persistent pivot. A coined insurance brand using an
app.<brand>orstart.<brand>subdomain to serve a generic "compare top-rated quotes / A.M. Best" template, without a real carrier behind it, remains constant across the operator's infrastructure. - The December 2025 Cloudflare registration cohort provides a clear cluster: multiple insurance-named domains created through one registrar within days of one another and using the same mail-privacy stack. Legitimate agencies do not provision infrastructure this way.
- The lure template remains consistent across brands. It uses a specific low premium anchor ($27 to $40 a month), a rate-savings claim, manufactured month-end or weekend urgency, first-name personalization, and frequently no opt-out language. Brand acronym prefixes (
AIQ:,LIQ:,Maple:) also recur. - Sender behavior provides another signal. Dedicated toll-free numbers and leased shortcodes carry one or two coined insurance domains each, deliver the same CTA through both rails, and rotate quickly. This differs from the stable, branded sender identity of a real carrier.
- The operator maintains a parallel version of the same lure written to appear neutral rather than openly promotional. Defenders should expect this quieter tier to use the identical funnel and should focus on the funnel and infrastructure signals above, not message tone alone.
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The lists below are a representative subset of the verified-malicious set.
Domains
| Value | Role | Notes |
|---|---|---|
maplecoverage[.]com |
CTA funnel | Cluster A anchor |
easyroadpolicy[.]com |
CTA funnel | A-to-B bridge |
autopolicyplus[.]com |
CTA funnel | Cluster A |
roadelo[.]com |
CTA funnel | Cluster A |
greenlightpolicy[.]com |
CTA funnel | Cluster A |
medicarepolicyplus[.]co |
CTA funnel | Cluster B anchor, Medicare arm |
bitticksinsurance[.]com |
CTA funnel | Cluster B, typosquat |
wikicarinsurance[.]com |
CTA funnel | Cluster B (Dec-2025 batch) |
pminsure[.]com |
CTA funnel | Cluster B (Dec-2025 batch) |
insuremedy[.]com |
CTA funnel | Cluster B |
autoinsurer-quote[.]co |
CTA funnel | Cluster C anchor |
lifeinsurerquotes[.]co |
CTA funnel | Cluster C, life arm |
lifeinsurerquotessms[.]com |
CTA funnel | Cluster C |
autopolicy2026[.]com |
CTA funnel | Cluster C, year-stamped |
switchinsure[.]link |
CTA switch-link | .link rotation |
| ... (representative subset; more than 20 verified-malicious operator CTA domains) |
Hosts
| Value | Role | Notes |
|---|---|---|
app.maplecoverage[.]com |
Quote funnel | PII harvest |
info.maplecoverage[.]com |
Quote funnel | Secondary |
app.easyroadpolicy[.]com |
Quote funnel | PII harvest |
request.easyroadpolicy[.]com |
Quote funnel | PII harvest |
yv.enlivenix[.]com |
Quote funnel | Coined-stem brand |
Shortcodes
| Value | Role | Notes |
|---|---|---|
24068 |
Sender | Highest-volume shortcode |
87408 |
Sender | Auto arm |
95349 |
Sender | Auto arm |
32842 |
Sender | Multi-brand |
96478 |
Sender | Evasion-tier delivery |
43029 |
Sender | Auto arm |
73056 |
Sender | Auto arm |
21931 |
Sender | Multi-brand |
27192 |
Sender | Multi-brand |
21736 |
Sender | Auto arm |
79293 |
Sender | Auto arm |
86109 |
Sender | Auto arm |
83031 |
Sender | Evasion-tier delivery |
75326 |
Sender | Auto arm |
Sender Phone Numbers
| Value | Role | Notes |
|---|---|---|
+1-833-413-1248 |
Sender | Pivot number across maple / autopolicyplus / roadelo |
+1-833-892-7968 |
Sender | Medicare arm |
+1-866-796-8207 |
Sender | autopolicyplus / roadelo |
+1-855-588-1909 |
Sender | Life arm |
+1-833-738-5889 |
Sender | maplecoverage |
+1-833-738-5890 |
Sender | maplecoverage |
+1-833-738-5891 |
Sender | maplecoverage |
+1-833-570-9174 |
Sender | roadelo |
+1-844-586-4430 |
Sender | Toll-free 844 block |
+1-833-658-4605 |
Sender | Evasion-tier delivery |
+1-888-485-0166 |
Sender | enlivenix |
+1-888-676-3235 |
Sender | Toll-free 888 block |
| ... (representative subset; dozens of verified-malicious toll-free sender numbers) |
Sender IDs
| Value | Role | Notes |
|---|---|---|
+8335709174 |
Sender | Carrier-normalization artifact (missing leading 1) of the 833 pool |
+8337220401 |
Sender | Carrier-normalization artifact of the 833 pool |
+8337220409 |
Sender | Carrier-normalization artifact of the 833 pool |
+8667968207 |
Sender | Carrier-normalization artifact of the 866 pool |
MITRE Fight Fraud Framework Mapping
This maps to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3) at https://ctid.mitre.org/fraud. F3 reuses ATT&CK technique IDs (T####) where one exists and mints fraud-specific IDs (F1### techniques, FA000# fraud-only tactics).
| Tactic | Technique | ID |
|---|---|---|
| Resource Development | Acquire Infrastructure: Domains (batch and rotation) | T1583.001 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Resource Development | Impersonate Official (typosquat of a real agency) | F1032 |
| Initial Access | Phishing: Smishing (rate-drop SMS lure) | T1660 |
| Reconnaissance | Phishing for Information (quote-funnel PII capture) | T1598 |
| Positioning | Gather Customer Information (structured profile harvest) | F1029 |
| Monetization | Lead resale of harvested PII (tactic-level) | FA0002 |
| Stealth | Domain and brand rotation, year-stamped burners, evasion-tier template variant | TA0005 |
Two mappings sit at tactic level by necessity: F3's Monetization tactic covers financial cash-out techniques and has no dedicated "sell harvested PII" node, and there is no fast-flux or rotation technique node, so domain churn maps to Stealth plus repeated infrastructure acquisition.
Conclusion
This network shows that the operator does not need a recognizable brand. By creating a disposable insurer for each domain and placing the same quote funnel behind every one, the operator avoids brand-based blocking and pushes defenders toward the funnel grammar, registration cohorts, and sender pools that remain constant while the names change. The pattern is likely to continue: newly coined brands on cheap TLDs, batch-registered burners prepared before blasts, quieter evasion-tier variants running alongside the loud sends, and the same kit redirected to whichever insurance vertical is in season.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.