Engagements

Detecting credential-stuffing fraud via behavioral analytics and dark web intelligence

Silohouette on defocussed background
Client issue: A client received reports of unauthorized policy cancellations and missing claim payments, raising concerns about potential fraud within its online customer portal.
CRA approach: CRA professionals were engaged to investigate. The team analyzed behavioral data and server logs, using session recordings and risk-based flags to identify suspicious activity. The investigation revealed that many compromised accounts were accessed using credentials leaked on the dark web in a credential stuffing attack.
Client impact: CRA’s findings enabled the client to remediate affected accounts, mitigate further fraudulent activity, and secure additional vulnerable accounts. The team also delivered technical recommendations to enhance the portal’s future security defenses.

Key contacts