CIPA Fraud Detection Techniques & Reporting 5 — Questions and Answers
Question 1: When investigating potential elder financial exploitation, a CIPA advisor should look for which red flag first?
- The elder has recently updated their will
- Sudden changes in banking activity, new authorized users, or large cash withdrawals inconsistent with lifestyle (Correct answer)
- The elder has multiple bank accounts
- Family members frequently accompany the elder to appointments
Correct answer: Sudden changes in banking activity, new authorized users, or large cash withdrawals inconsistent with lifestyle
Abrupt changes in financial behavior, especially when a new person gains financial control, are primary indicators of elder financial exploitation.
Question 2: A 'bust-out' fraud scheme in the credit card context involves:
- Stealing credit card numbers from data breaches and selling them
- Building credit legitimately over time then maxing out all available credit with no intent to repay (Correct answer)
- Using cloned cards at gas station pumps
- Filing false insurance claims after a card is reported stolen
Correct answer: Building credit legitimately over time then maxing out all available credit with no intent to repay
In a bust-out scheme, fraudsters establish credit legitimacy, max out all lines of credit simultaneously, then disappear without repaying.
Question 3: Which of the following best describes 'mule account' fraud?
- An account used by a minor under a parent's name
- An account controlled by a fraudster but opened in a victim's name, used to receive and transfer stolen funds (Correct answer)
- A dormant account reactivated without the owner's knowledge
- A corporate account used to process fraudulent invoices
Correct answer: An account controlled by a fraudster but opened in a victim's name, used to receive and transfer stolen funds
Mule accounts are used to receive and quickly transfer stolen funds, creating distance between the fraudster and the crime.
Question 4: Real-time fraud scoring systems assign risk scores to transactions based on:
- The customer's credit score alone
- Multiple weighted variables analyzed simultaneously at the point of transaction (Correct answer)
- Manual review by a fraud analyst before approval
- Static rules updated quarterly by the compliance team
Correct answer: Multiple weighted variables analyzed simultaneously at the point of transaction
Real-time scoring evaluates dozens of risk factors simultaneously (velocity, location, device, behavior) to generate a risk score within milliseconds.
Question 5: A CIPA professional advising a victim of tax-related identity theft should direct them to file which form with the IRS?
- Form SS-4
- Form 14039 (Identity Theft Affidavit) (Correct answer)
- Form 4506-T
- Form W-9
Correct answer: Form 14039 (Identity Theft Affidavit)
IRS Form 14039 is the Identity Theft Affidavit that victims file to alert the IRS that their SSN was used fraudulently to file a tax return.
Question 6: Credential stuffing attacks differ from brute-force attacks because credential stuffing:
- Uses specially crafted malware to extract passwords from browsers
- Automates login attempts using stolen username/password pairs from prior data breaches (Correct answer)
- Systematically tries every possible password combination
- Exploits password reset mechanisms to gain account access
Correct answer: Automates login attempts using stolen username/password pairs from prior data breaches
Credential stuffing leverages leaked credentials from one breach to access accounts on other platforms where users reuse passwords.
Question 7: Under the Red Flags Rule, covered financial institutions must implement a written Identity Theft Prevention Program that includes:
- Annual employee background checks and biometric verification
- Policies to identify, detect, and respond to red flags of identity theft in covered accounts (Correct answer)
- Mandatory cybersecurity insurance and breach bond requirements
- Daily reconciliation of all transactions against customer-provided records
Correct answer: Policies to identify, detect, and respond to red flags of identity theft in covered accounts
The Red Flags Rule (FTC/banking regulators) requires a formal program with four elements: identify relevant red flags, detect them, respond appropriately, and update the program periodically.
When investigating potential elder financial exploitation, a CIPA advisor should look for which red flag first?