Manav.id
Fraud · 13 min read

The claimant sounded exactly like the policyholder

A voice on an insurer's service line can change a beneficiary, redirect a payout, or surrender a policy. Cloning that voice now costs less than the call. The control that survives is not a better detector, it is moving the authorisation off the call entirely.

A representative at a life insurer takes a call on a Thursday afternoon. The caller is calm, slightly impatient in the way of someone doing paperwork they have been putting off, and wants to update the beneficiary on a policy taken out eleven years ago. They know the policy number. They know the date of birth, the issue date, the approximate face amount, the name of the town where the policy was written, and the last four digits of the account the premiums come from.

The representative runs the script. Every answer is right. The voice matches the voiceprint on file, because the carrier enrolled this policyholder in voice authentication three years ago and the match score is comfortably above threshold. The change is keyed, a confirmation letter is generated to the address on record, and the call ends in under nine minutes, which is a good number.

The address on record was changed six weeks earlier, on a different call.

Nobody finds out for two years, when the policyholder dies and a family discovers that the death benefit is payable to somebody they have never heard of. By then the representative has taken perhaps eleven thousand more calls, the recording is past its retention window at some carriers, and the person who is out of pocket is a beneficiary who had no relationship with the insurer and no opportunity to notice.

Insurers cannot stop voice deepfake fraud by detecting the voice. The durable control is to stop authorising changes on the call: keep the contact centre for conversation and service, and require the policyholder's signature from an enrolled device for beneficiary changes, payout bank details, address changes, surrenders and loans. A cloned voice can pass any interrogation. It cannot produce a signature from a device it does not hold.

We have written about the general contact centre problem in the piece on why your call centre cannot hear a deepfake. This post is the insurance specific case, because insurance is where the consequences are largest, the discovery is slowest, and the industry has invested most heavily in exactly the control that is now failing.

Why is an insurer's contact centre different from any other call centre?

In most industries the call centre is a service channel attached to an account. Someone impersonating a customer can cause real harm, but the harm is bounded by what the account holds and is usually noticed within a billing cycle.

An insurer's service line is three things at once, and the third is the problem.

It is a service channel, handling questions about coverage, premiums and claims status. It is a claims intake channel, where a loss is first reported. And it is the policy servicing channel, where the terms of a contract worth six or seven figures can be altered by an instruction given verbally by someone the representative has never met and will never meet.

That third function is unusual. Very few other consumer relationships allow a phone call to change who receives a large sum of money at an unspecified future date. It exists because it has always existed, because policyholders reasonably expect to manage their own policies, and because the alternative used to be paper forms with wet signatures, which were slow and which nobody wants to return to.

The changes that actually matter

Most calls to an insurer are harmless in the relevant sense. Someone asks what their premium is, or when a claim will be paid, or what their policy covers. An impersonator learning those things is a privacy problem rather than a financial one.

A small set of changes is different, and they divide into two kinds. Some move money directly: payout bank details, surrender, policy loan. Others are enabling changes that move no money themselves but make the next fraud possible: address, phone number, email address. The enabling changes are the ones insurers under weight, because on their own they look administrative.

And then there is beneficiary designation, which sits in a category of its own.

What makes a beneficiary change close to a perfect fraud?

Consider the properties of this one instruction, because they combine in a way that appears almost nowhere else in financial services.

It is irreversible once acted upon. When the claim is paid to the recorded beneficiary, the money is gone. Recovery means litigation against a recipient who may be untraceable, and the litigants are a grieving family rather than an institution with a recovery function.

Discovery is measured in years. A fraudulent wire is discovered when the account is reconciled. A fraudulent beneficiary change is discovered at death, which may be a decade later. No fraud analytics model gets useful feedback on a decision it made in 2026 and learns about in 2034.

The victim is not the customer. The person harmed is a beneficiary who has no login, no relationship with the carrier, and no way to monitor anything. Every fraud control an insurer builds around customer notification is aimed at a party who, in this scenario, is not the one being defrauded.

Nobody is watching. Life policies are the definition of a dormant relationship. Years pass without contact, which is precisely the condition we described in the post on dormant account takeover: the safest thing to steal is something nobody is looking at.

Put those four together and you have a fraud with a large payout, no immediate detection, a victim who cannot detect it, and a feedback loop too slow to learn from. It is remarkable that it is authorised by a phone call.

Why does knowledge based authentication fail here?

The representative in the opening scene did nothing wrong. They followed a documented procedure and the caller passed it. The procedure is the problem.

Knowledge based authentication asks the caller to prove identity by producing facts about the policyholder. It worked when those facts were genuinely private. They are no longer private in any meaningful sense: dates of birth, address histories, family names, employment history and policy details have been exposed in bulk through two decades of breaches, and are assembled and sold as a routine commodity.

So the control now verifies that the caller did research. That is not nothing, since it excludes the laziest attacker, but it is a long way from verifying a policyholder, and it costs several minutes of handling time on every legitimate call to achieve it. Insurers are paying a real price for a control that a motivated attacker treats as a homework assignment.

There is a second failure that is specific to this industry. Some of the questions insurers ask are drawn from the policy record itself, and an attacker who has already made one successful enabling change now holds a piece of the answer key. Each successful call makes the next one easier.

What about the voice biometrics we already bought?

This deserves a direct and fair answer, because insurers have spent significantly on voice authentication and the people who bought it were not foolish.

Voiceprint authentication was a genuine improvement. It removed a minute or more of interrogation from millions of calls, it improved customer experience measurably, and it raised the cost of casual impersonation from nothing to something. As a replacement for asking a grieving relative for their mother's maiden name, it was better on every axis anyone was measuring at the time.

What changed is not the quality of the product. What changed is the cost of defeating it. Synthetic voice generation went from a research capability to a commodity one within roughly two years, and the audio required to build a usable clone fell to the length of a voicemail greeting. The vendor's model must generalise across a population; the attacker's model only has to fool it once, and the attacker can iterate against the target offline.

This is the structural asymmetry we set out in the piece on detection debt. Detection loses when generation improves faster than classification and the attacker gets unlimited attempts with feedback. Voice authentication has both conditions.

What the surveys say, and how much weight to put on them

Industry surveys published across 2025 and 2026 consistently report that large majorities of contact centre and fraud leaders regard synthetic voice as a significant threat, and that a substantial share of them do not believe they can reliably detect it. Vendors serving the insurance sector have reported steep year on year increases in suspected synthetic voice contacts, with one figure describing a several hundred percent rise circulating widely in trade coverage.

Treat all of these numbers as directional rather than measured, and understand why. They come from two sources with the same structural bias. Surveys of fraud leaders are self selecting and ask people to estimate a threat they have just told you they cannot detect. Vendor telemetry counts what the vendor's own product flagged, across the vendor's own customer base, which is neither a random sample nor a census, and which cannot by construction count the attacks that succeeded silently. The widely repeated increase figures are also difficult to trace to a primary publication, and we would not build a business case on any specific one of them.

What survives the scepticism is the direction and the mechanism, and those are sufficient. The cost of producing a convincing voice has collapsed. The value of a successful policy change has not. You do not need a precise growth rate to know which way that goes.

The second reason to reduce reliance on voiceprints

A voiceprint is biometric data. Wherever it is held, it carries the regulatory treatment that attaches to biometric identifiers, including consent, retention and disclosure obligations, and in some jurisdictions a private right of action. Insurers have therefore built a permanent, breachable, regulated data asset in order to run a control that is now being defeated. Reducing dependence on it improves the fraud position and the privacy position at the same time, which is a rare alignment and worth saying out loud in the business case.

Why does the mailed confirmation letter not save you?

Every carrier has this control. A change of any significance triggers a letter to the address on record, so the policyholder finds out and can object.

The attacker's answer is sequencing, and it is the single most important operational detail in this post.

Change the address first, on its own call, weeks earlier. It is a low salience request that triggers little scrutiny, because on its face an address change moves no money. The confirmation letter for the address change goes to the old address, where a fraud aware policyholder might catch it, so the attacker accepts that risk once and picks targets where it is unlikely to matter.

Then make the real change. Now the confirmation letter goes to the address the attacker controls. The control has been repointed by the attacker before it was needed. The same logic defeats callback verification, since the number on file was also updated, and it defeats email confirmation for the same reason.

This is why the enabling changes deserve the same protection as the money moving ones, and it is a general pattern rather than an insurance quirk. We made the same argument about banking in the post on why adding a payee is the real transaction: the step everyone hardens is the payment, and the step that decides the outcome is the one that changes the shape of the account. The insurer's version of an account shape change is the contact record. And as the teardown of callback verification sets out, calling a number the attacker supplied is not verification.

How do you move the authorisation off the call?

The design is deliberately narrow. Nothing here restricts what a representative may discuss, explain or help with, and that matters both for customer experience and for getting the change adopted by an operations team that is measured on service.

The rule is that conversation happens on the call and authorisation happens on the policyholder's own enrolled device. The representative takes the request, keys it as pending, and the system sends a signing request. The policyholder opens it, sees the specific change rendered on their own screen, and signs. The carrier stores the resulting receipt against the policy record.

POST /v1/sign
{
  "action": "policy.beneficiary.change",
  "policy": "L-4471902",
  "payload": {
    "effective":   "2026-09-29",
    "removes":     ["sha256:c41f8b2e…"],
    "adds":        ["sha256:8e20af71…"],
    "percentages": [100],
    "requested_via": "contact_center",
    "rep_id": "csr_2214"
  }
}

# Receipt stored on the policy record. Verifies offline against the
# published Ed25519 key, with no callback to us and no vendor dependency.
{
  "receipt":      "rcp_b71e04",
  "signer":       "ph_88213",
  "signed_at":    "2026-09-29T14:02:11Z",
  "payload_hash": "sha256:1d9a77c0…"
}

Three properties of that receipt matter to an insurer specifically. It is bound to this exact change rather than to a session, so it cannot be replayed against a different instruction. It is verifiable offline against a published key, which means it is still checkable in eleven years when the claim is made and the vendor relationship may have ended. And it names the representative and channel, which turns a disputed change into a matter of record rather than a matter of recollection. That last property also protects staff, which is the argument that gets the contact centre on side.

Which changes get the control

Not everything. The point of classifying is to spend the friction where the loss is.

Servicing actionLoss potentialReversibleTypical discoveryAuthorise by
Coverage question, claim status, premium queryNonen/an/aVoice is fine
Duplicate documents, statement reissueLow, informationaln/an/aVoice is fine
Address, phone, email changeEnabling, not directYesWeeks, if everSignature
Payout or premium bank detailsDirectRarelyDays to weeksSignature
Policy loan or partial withdrawalDirectPartlyWeeksSignature
Full surrenderDirect, largeNoDays to monthsSignature, plus hold period
Beneficiary designationDirect, largeNo, once paidYearsSignature, hold period, independent notice

The two right hand columns are the argument. An insurer that reads this table and applies signatures only to the bottom four rows has removed most of the exposure while touching a small minority of calls.

The layered control for beneficiary changes

Because beneficiary designation has the worst properties, it deserves more than a signature. Three additions, in order of value.

A hold period during which the change is recorded but not yet effective. This is not a new idea in insurance, and it converts an instantaneous irreversible act into one with a window for objection.

Notice through a channel that was not modified in the same window. If the address changed within the notice period, send to the previous address as well as the current one. This is a small piece of logic and it defeats the sequencing attack directly, which makes it the highest value change in this entire post relative to its implementation cost.

An optional co signer nominated by the policyholder, which is the same trusted contact pattern we described for protecting older customers from voice clone scams. It is opt in, it is revocable by the policyholder alone, and it is particularly appropriate for exactly the population most exposed here.

What about policyholders who cannot use an app?

This is the objection the industry will raise first, and it is legitimate rather than an excuse. The average life policyholder is older than the average consumer of most digital products, and a design that assumes a smartphone will exclude a real and substantial group of people at the moment they need service.

Three things need saying honestly.

First, the population is less excluded than assumed and the gap is closing every year, but it is not zero and will not become zero, so plan for a permanent minority rather than a transitional one.

Second, enrolment is easiest where a human being is already present. Insurers have distribution that most sectors lack: agents, brokers and branches. Enrolment at the point of sale, at annual review, or during an in person visit is a far better experience than a self service flow, and it produces a stronger binding.

Third, the staffed fallback must be designed as a normal path and not as an exception. In person signing at an agent, or a mailed instrument with independent verification, has to be routine, adequately resourced, and free of a shame penalty for using it. The failure mode to design against is a fallback so slow that representatives are pressured into routing around it, because a bypass used routinely becomes the new attack surface. That is the same lesson as break glass access in any other system.

Honest limits

What to do this week

  1. List every change a representative can make on a call. Every one. Most carriers have never written this list down in one place, and the exercise reliably surfaces two or three that surprise the people who own the process.
  2. Score each on the table above. Loss potential, reversibility, discovery time. The ones that are irreversible and slowly discovered are your control targets, and there will be fewer than you expect.
  3. Fix the sequencing gap first. Add independent notice for any material change where the contact record was modified within the preceding ninety days. It is a small piece of logic, it needs no new vendor, and it defeats the most effective version of this attack.
  4. Reclassify voice biometrics. Move it from authorisation to triage in your control documentation. Keep running it; stop letting it authorise a surrender on its own.
  5. Measure handling time by change type. Not blended. The blend will hide the fact that most calls get faster when the interrogation is removed.
  6. Design the staffed fallback before the digital path. If the fallback is an afterthought it will be bypassed, and the bypass will become the attack.
  7. Start enrolment where a human is present. Point of sale, annual review, agent visit. See the signing demo for what the policyholder experience looks like, and the developer documentation for the change endpoint integration.

The industry has spent several years buying better ears. The attacker's cost of producing a convincing voice is now a rounding error, and no amount of listening fixes a channel that was never designed to carry authorisation. Let the call be a conversation. Put the decision somewhere the clone cannot reach.

Frequently asked questions

How do insurers stop voice deepfake fraud in the call centre? Stop treating the call as the authorisation channel. Let the contact centre help the caller with anything informational, and require the policyholder's signature from their enrolled device for the small set of changes that move money or change who receives it: beneficiary, payout bank details, address, surrender and loan. A cloned voice can hold a convincing conversation. It cannot produce a signature from a device it does not have.

What is synthetic voice fraud in insurance? An attacker uses a cloned or generated voice to impersonate a policyholder on a service line, then requests a change the insurer processes on the strength of that call. The distinguishing feature in insurance is what the caller can reach: not just account access but claims intake, payout routing, and beneficiary designation, which are high value, infrequent, and often discovered long after the fact.

Can knowledge based authentication be bypassed? Routinely. Knowledge based authentication asks for facts about the policyholder, and those facts are exactly what large scale data breaches have made available: date of birth, address history, policy numbers, family names, prior addresses. A control built on secrets that are no longer secret verifies that the caller did research, not that the caller is the policyholder. It has become a formality that generates handling time without producing assurance.

Are voice biometrics still worth running? As a signal, often yes. As an authorisation control for irreversible changes, no. Voiceprint matching was a genuine improvement over interrogating callers, and it still raises the cost of casual impersonation. But it is a detector in a contest where generation improves faster than detection, and voiceprints are biometric data carrying their own regulatory exposure. Keep it for triage and routing; stop letting it authorise a surrender.

How should beneficiary changes be verified? With a signature from the policyholder's enrolled device over the specific change, plus a notice period during which the change is visible but not yet effective and the policyholder is notified through a channel that was not modified in the same session. Beneficiary designation deserves the strongest control an insurer runs, because it is irreversible once paid and may not be discovered for years.

What happens to policyholders who cannot use a smartphone? They get a staffed path, and it is designed as a normal route rather than an exception. That means in person signing at an agent or branch, a mailed instrument with independent verification, or a pre designated trusted contact who can co sign. The design failure to avoid is a fallback so inconvenient that staff route around it, because a bypass used routinely becomes the new attack surface.

Does moving authorisation off the call slow down the contact centre? For most calls it speeds them up, because the identity interrogation disappears and the representative can help immediately. Handling time increases only for the small subset of changes that require a signature, and much of that increase is the customer signing rather than the representative waiting. Insurers should measure this per change type rather than as a blended average, which hides the effect.

Sources

  1. FBI Internet Crime Complaint Center, annual Internet Crime Reports and public service announcements on account takeover and impersonation fraud. ic3.gov
  2. Financial Crimes Enforcement Network, alert on fraud schemes involving deepfake media and financial institutions. fincen.gov
  3. Federal Trade Commission, work on voice cloning and impersonation, including the Voice Cloning Challenge. ftc.gov
  4. National Association of Insurance Commissioners, model regulations on privacy, unfair claims settlement practices and market conduct. naic.org
  5. Coalition Against Insurance Fraud, research on fraud typologies and industry cost. insurancefraud.org
  6. ISO/IEC 30107, biometric presentation attack detection, for the framing of detection as a bounded control. iso.org
  7. NIST, biometric evaluation programmes and guidance on authenticator assurance. nist.gov
Let the call be a conversation. Put the decision somewhere the clone cannot reach.