Stolen IDs and Account Takeovers are Hurting Claims Teams. 3 Ways to Stop Rising Claims Fraud

A few months back, we wrote about the four stages of claims fraud and how carriers are using ForMotiv for predicting, identifying, and stopping fraud before it is even submitted. 

This spurred a lot of interest in questions, so allow us to expand. 

A common occurrence we see looks something like this:

  1. A bad actor obtains a stolen policy number and PII information for a legitimate policyholder at a carrier.
  2. The bad actor successfully registers for an online account.
  3. They then log into the portal and change banking and payment information.
  4. Dependent on the product, the bad actor files a claim digitally or through an offline channel (paper or phone).
  5. Bad actor collects payment.

Here are three ways we’re helping Claims and SIU teams fight back. 

1. Stop account takeover fraud at the front door

This is the stage getting the most attention from carriers right now, and for good reason. “Account takeover” is a catch-all title that can mean a few different things. Sometimes it’s a fraud ring running lists of stolen credentials against a portal, testing hundreds of logins in minutes, with no mouse movement, no scrolling, just superhuman speed and rapid-fire attempts across accounts. 

Sometimes it’s more targeted: someone with a stolen policy number and enough PII to register or log in as a real policyholder. Once they warm up the account, they start laying the groundwork for their eventual claim – changing bank/payment info, changing contact info, updating policy information, etc. 

Either way, the behavior gives it away before the fraud does. Real policyholders hesitate on identity verification questions, they type at human speed, they pause before answering things they’re not 100% sure of. A stolen-credential login doesn’t do any of that. It moves too fast, it fills fields too cleanly, and the device or session fingerprint usually doesn’t match the history on the account at all. 

Those are things a rules engine built around claim amounts or zip codes will never catch, because the fraud hasn’t happened yet. It’s still just a login. And the longer we work with in the Claims and SIU space, who initially were only focused on or cared about claims once they were filed, the more they are shifting focus to stopping fraud that is still in the “premeditated” stage. 

2. Stop it mid-claim

Once someone completes their account takeover fraud and is inside your app, the pattern from our original piece still holds: file the claim, then update the banking and personal information before anyone has a chance to look twice. But we’re seeing more variation on this stage than we expected.

Third-party fraud is one type in which the person filing isn’t actually the policyholder at all. It could be a contractor, a “helper,” someone who talked their way into the account. The tell here is usually familiarity that doesn’t line up with a first-time user, someone who navigates the portal like they’ve done this before, or a device and IP address with no history tied to the real policyholder. 

Synthetic identity fraud is another, where a fabricated identity binds a policy and then files a loss almost immediately after inception. That one’s sneaky because the fraud started at quote, not at claim, and the tell shows up as form-filling that’s too fast and too clean for someone recalling their own real information from memory. Genuine people misremember things. Fabricated ones don’t.

In every version, the behavioral signature is recognizable. Editing payment fields in the same session as filing, copy-pasted routing numbers instead of typed ones, and none of the back-and-forth research behavior a real claimant shows when they’re dealing with something that actually matters to them. These are just a few examples, but you get the point. 

3. Stop it after payout

Unfortunately, not every fraudulent claim gets caught before the check clears. Sometimes the tell doesn’t show up until later, a rescission gets pursued, a lawsuit lands on someone’s desk, a regulator asks for records going back two years on a policy nobody’s thought about since it paid out. The question at that point isn’t how fast the fraud can be flagged anymore. It’s whether anyone can go back and actually piece together what happened.

That’s really a different problem than the first two, and it needs a different kind of answer. If the behavior across every session, registration, application, policy changes, the claim itself, was captured and kept from the start, an investigator isn’t starting from scratch months later. They’re pulling up an actual record of how someone behaved on the account the whole way through, not guessing at intent from a stack of documents after the fact. ForMotiv is working closely with Claims and SIU teams on this exact use case – stitching together the behavioral timeline to help them build their fraud case.

This one tends to get overlooked because it doesn’t feel as urgent as stopping a bad login or freezing a claim in progress. But it’s often where the money actually gets recovered, or where a fraudulent payout gets challenged successfully instead of quietly written off.

Where this leaves carriers

The nice thing about account takeover fraud is that none of these three stages require waiting for a claim to look suspicious on paper. The registration was suspicious. The session where banking info changed was suspicious. The account checking its balance forty times in a day was suspicious. ForMotiv’s behavioral intelligence layer sits across all three moments, inside your existing policy admin and claims systems, flagging malicious intent to claims and SIU teams in real time instead of after the money’s already gone.

Claims fraud keeps evolving, and rules-based detection keeps playing catch-up. The behavior underneath it, though, doesn’t change nearly as much and that’s the part worth watching.

Why Use ForMotiv Data?

Simple Integration

Easy, light-weight Javascript integration. Zero performance degradation.

Glass-Box Approach

5,000+ behavioral data points captured in each application. Accessible in real-time or batch file.

1st Party Behavioral Data

Granular, curated 1st-party data easily combined with your existing data sets

Intuitive Data Features

Capture dozens of intuitive behaviors like Hesitation, Error Rate Collections, Cognitive Loads, and more

Totally Safe & Secure

Zero PII Captured. GDPR, CCPA & PIPEDA Compliant