They don’t hack, they borrow: How fraudsters target credit unions
Enhance identity verification by requiring multi‑factor authentication and real‑time KBA checks to prevent loan fraud.
Enhance identity verification by requiring multi‑factor authentication and real‑time KBA checks; monitor for stolen identity data.
Summary
Threat actors are using a structured fraud method that exploits identity verification processes in small and mid‑size credit unions. The attack does not rely on software vulnerabilities but on stolen personal data, knowledge‑based authentication (KBA) answers, and financial histories. The method involves acquiring full identity details, assessing credit profiles, preparing KBA answers, and submitting loan applications that pass KBA and standard checks. Credit unions are targeted because they rely on traditional identity verification, lack advanced behavioral fraud detection, and prioritize customer accessibility. The fraud workflow includes identity acquisition, credit profile assessment, KBA readiness, loan application submission, approval, and fund movement. Attackers source stolen identities and KBA answers from dark web forums and underground markets before contacting the institution. The process can lead to significant financial losses, with projected auto‑lending fraud reaching $9.2 billion in 2025.
The article highlights that fraudsters can bypass verification by pre‑collecting KBA answers and that the attack does not exploit software. It emphasizes the need for stronger identity verification, multi‑factor authentication, and real‑time KBA checks. The method demonstrates how fraud can be hidden within normal financial behavior, making detection difficult.
Financial institutions should enhance their identity verification procedures and monitor for stolen identity data to mitigate this organized fraud campaign.
Key changes
- Fraudsters use stolen identities and KBA answers to pass verification in small/mid credit unions
- Attack targets traditional identity verification methods lacking advanced fraud detection
- Workflow: identity acquisition, credit profile assessment, KBA readiness, loan application, approval, fund movement
- Stolen data sourced from dark web forums and underground markets before contacting institutions
- Process does not exploit software vulnerabilities, only design flaws
- Fraud can bypass verification by pre‑collecting KBA answers
- Projected auto‑lending fraud could reach $9.2 billion in 2025
- Detection is difficult because fraud mirrors normal financial behavior