TESTIMONIALS

“Received the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.”

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Commercial

Fraud round-up

by Mark Rowe

Fraudsters are targeting much bigger payouts, according to the trade body the Association of British Insurers (ABI). While the number of detected fraudulent claims reported to the association by its members fell slightly to 93,900 cases, down 2.7pc on 2024, the value of fraudulent activity continued to rise sharply. The average value of a fraudulent claim reached £14,300 last year – the second-highest level on record, just below the peak of £14,600 recorded in 2022.

Motor insurance remained the area where insurers identified the highest claims fraud, accounting for 55pc of all detected cases. With 51,900 fraudulent motor claims worth £625 million uncovered during the year, the figures point to fewer but more costly cases, reflecting a shift towards higher severity fraud. Property insurance showed a similar year-on-year pattern. The number of detected fraudulent claims fell by 6.2pc to 17,700, while their total value rose by 3.4pc to £201 million – bringing the average value to a record high of £11,400. Travel recorded the sharpest increase in volume. Detected cases rose 85pc to 4,500, while value increased 16pc to £8.6 million.

Types

As for the types of fraud scammers attempted to commit, exaggerated loss remains the most common, with 26,900 cases identified. This is when someone deliberately attempts to increase the cost of a claim beyond its true value.  Contrived incident and loss fraud saw the largest increase, rising by 30pc to around 5,600 cases. In these scams, fraudsters deliberately creating or staging incidents, losses or circumstances in order to make a claim.

Insurers also prevented fraudulent insurance applications worth £1.8 billion last year. Application fraud occurs when information is deliberately misrepresented or withheld in order to obtain insurance cover or reduce premiums. The total number of detected application fraud cases increased significantly, rising by 24pc year-on-year.

Mark Allen, head of Fraud and Financial Crime at the ABI, said: “As emerging technologies such as AI become more widely available, fraudsters will continue to look for new ways to exploit them. Insurance fraud pushes up costs for everyone, making it more important than ever that as an industry, we continue to work together to detect, prevent and deter fraud across all lines. Anyone considering committing insurance fraud should be under no illusion – it’s a serious crime with serious consequences, including a criminal conviction and imprisonment.”

On average, more than 250 fraudulent insurance claims are detected each day, added Temporary Detective Chief Inspector Simon Klust, Head of the Insurance Fraud Enforcement Department (IFED) at the City of London Police. He said this is unfortunately likely to be just the tip of the iceberg. “It is therefore important for collaboration across law enforcement and industry to further deepen to help with taking further steps to increase detection of insurance fraud, fight fraud and bring offenders to justice.”

Online protection

The police reporting line Report Fraud has launched an awareness campaign, urging the public to protect their online accounts from hackers by switching to passkeys and securing accounts. Hacking, in the context of online accounts, refers to criminals gaining unauthorised access someone’s email, social media, or other online account to commit further fraudulent activity such as impersonating the account owner to defraud family and friends by asking for money or offering fake tickets. One of the most common themes identified from reports is compromised accounts being used to impersonate family members and friends.

Chief Supt Amanda Wolf, Head of Report Fraud Operations, said: “For most people, being hacked isn’t just a cyber issue, it’s personal. It can leave victims locked out of important accounts, worried about what information has been accessed, and concerned that criminals may use their identity to target others. What starts with one compromised account can quickly impact family, friends and colleagues as fraudsters exploit trusted relationships to commit further fraud.

“The good news is that there are simple steps people can take to protect themselves. Switching to passkeys and enabling two-step verification adds a strong extra layer of security and makes it much harder for criminals to gain access to your accounts.”

Comment

Nic Sarginson, principal product manager at the authentication product company Yubico, said: “Passwords and legacy authentication methods like SMS-based one-time passwords (OTPs) are insufficient to stay secure from these increasingly sophisticated attacks which rely on human judgement or susceptible tools to phishing attacks. However, they are unfortunately still being used widely: 81 percent of hacking-related breaches stem from weak or reused passwords. Their widespread use directly fuels the 400 percent rise in sums stolen from hacked email and social media accounts highlighted by Report Fraud.

“It’s welcome to see the City of London Police joining the UK Government in endorsing passkeys – with both citing them as the recommended method for enhanced security – helping cement their place as the future of secure, phishing-resistant authentication. Rather than requiring a user to remember a password – which can easily be forgotten, stolen or phished – a passkey links a public and secure private cryptographic key pair to authenticate. In its most secure form, a hardware-backed passkey is stored on a local device like a physical hardware security key instead of in the cloud, proving intent of authentication by requiring a user’s physical touch of the key registered to the account. This adds a vital extra layer of security over synced passkeys stored in cloud accounts, as hardware-bound keys cannot be remotely extracted, synced across unauthorised devices or accessed even if a user’s cloud account is compromised.”