The challenge
A health insurer based in the East Coast was experiencing ongoing fraud related to registrations for their web-facing member portal. The client has millions of active users producing hundreds of millions of log entries daily, making it challenging to analyze the data and quickly diagnose the issue.
CRA approach:
CRA cybersecurity experts were engaged to perform a forensic investigation to determine how the fraudulent registration activity occurred and confirm that no internal data leaks existed. Our team conducted a thorough review of activity related to more than 100 million user registration log entries and associated data points, including plan type, location, email address, phone number, IP address, and user-agent, to identify distinct patterns tied to fraudulent activity.
We custom-built a scalable, complex anomaly identification model and applied it across the full data set, correlating data points across multiple source systems. Throughout the engagement, we maintained rigorous compliance with all legal and regulatory requirements under the continuous guidance of external legal counsel.
The impact
Our investigation identified hundreds of fraudulent accounts and determined that the fraudulent registration activity resulted from a vulnerability in the application code combined with weak user-authentication controls. We are conducting a technical review of the client’s portal application code to identify other potential code vulnerabilities and enhance security moving forward.
Our findings provided counsel with an evidence-based assessment of the incident, enabling them to advise the client on remediation and disclosure obligations.



