Client issue: A client received reports of unauthorized policy cancellations and missing claim payments, raising concerns about potential fraud within its online customer portal.
CRA approach: CRA professionals were engaged to investigate. The team analyzed behavioral data and server logs, using session recordings and risk-based flags to identify suspicious activity. The investigation revealed that many compromised accounts were accessed using credentials leaked on the dark web in a credential stuffing attack.
Client impact: CRA’s findings enabled the client to remediate affected accounts, mitigate further fraudulent activity, and secure additional vulnerable accounts. The team also delivered technical recommendations to enhance the portal’s future security defenses.


