Simon Glairy is a prominent figure in the insurance landscape, renowned for his expertise in risk management and the evolving intersection of technology and claims validation. As insurers face increasingly sophisticated social engineering attacks, his insights into the vulnerabilities of telephony channels have become essential for firms looking to protect their assets and their customers. Today, we explore the subtle psychology behind voice-based fraud, the operational gaps in modern call centers, and the multi-layered strategies required to close the loop between digital security and human interaction.
The following discussion delves into the alarming success rates of help desk impersonation and the inherent difficulties of spotting “vishing” compared to easily trackable digital anomalies. We explore how fragmented data sets—where telephony, policy, and claims information are stored in silos—create blind spots that fraudsters are quick to exploit. Furthermore, we examine the necessity of cross-sector intelligence-sharing and a four-pronged defense strategy that integrates specialized staff training, such as national vocational qualifications, with advanced voice-pattern recognition technology to combat a record-breaking surge in fraudulent activity.
Computer giant IBM recently conducted an experiment where they called client help desks to see if they could impersonate employees for password resets, and the results were quite shocking. What is it about the telephony channel that makes it such a persistent blind spot for even the most tech-savvy organizations?
The results of that experiment, where the deception was successful every single time, highlight a chilling reality about the power of the human voice. In a world where we have become obsessed with digital signals like hidden IP addresses or erratic typing speeds, we have inadvertently left the front door open through our call centers. A voice interaction carries a level of social pressure and perceived urgency that a login screen simply cannot replicate, making it a playground for social engineering. David Phillips from NFU Mutual has noted that while digital signals are immediately obvious to security systems, voice-based signifiers are much harder to pin down because they rely on psychological red flags. When a fraudster calls in, they aren’t just presenting data; they are performing a role, and our frontline staff are often trained to be helpful rather than suspicious, which creates a natural vulnerability.
When we look at the difference between digital fraud detection and voice-based detection, the former seems much more scientific and data-driven. How do you train a person or a system to identify a “psychological red flag” during a live conversation?
Digital fraud detection is incredibly robust because it relies on anomalies we can see in the code—things like a user jumping from one IP address to another or using a recently created email address. However, voice-based fraud is far more elusive because it involves audio inconsistencies and unusual requests that might seem legitimate in isolation. The difficulty lies in the fact that many of these calls involve withheld or spoofed numbers, which makes real-time denylist checks almost impossible to execute effectively. We have to look for behavioral deviations that don’t fit the standard customer profile, such as a caller who is overly aggressive or, conversely, someone who is unusually knowledgeable about internal processes. It’s a delicate balance because if your risk appetite is too narrow, you end up stopping genuine customer journeys and creating a poor experience for the people you are actually trying to serve.
There seems to be a significant disconnect between the high-level fraud strategies designed in boardrooms and the reality of what a call center agent experiences. What are the primary obstacles preventing frontline workers from identifying high-risk calls in real time?
The biggest gap we see is exactly what David Pritchard at NFU Mutual pointed out: the difference between strategy and what a colleague can see live on their screen. Often, the data is fragmented, with telephony, policy, and claims data sitting in entirely separate silos, which makes it nearly impossible to join the dots during a five-minute phone call. If an agent can’t see that a caller’s number has been flagged in an external feed or doesn’t have the tools to perform a spoofing check instantly, they are essentially flying blind. This lack of joined-up intelligence means that genuine risk signals are hard to evidence quickly, leaving the agent to rely solely on their gut feeling. To fix this, we need to ensure that internal denylists and external sector data are overlaid directly onto the agent’s interface so they can make informed decisions without having to dig through multiple systems.
You’ve mentioned that fraudsters often “test” their methods in other sectors before targeting insurance companies. How would a more collaborative approach to data sharing across industries like telecommunications and e-commerce change the defense landscape?
Fraudsters are incredibly opportunistic, and they often use sectors like e-commerce or telecommunications as a laboratory to build synthetic identities or test stolen credentials. According to reports from Cifas, there has been a notable rise in fraud targeting these adjacent sectors, which serves as a precursor to more complex insurance scams. If we could share intelligence across these sectors in real time, we could disrupt the fraud lifecycle much earlier, before the bad actor even picks up the phone to call an insurer. Matthew Crabtree at Allianz has been vocal about this, noting that because fraudulent voice calls come through the telecoms industry, we need to work directly with those providers to flag suspicious traffic. By the time a fraudster attempts to use a bank account or a specific email address with us, we should already have a red flag in our system thanks to data shared by a partner in a completely different industry.
Allianz utilizes a four-pronged strategy to disrupt fraud internally, focusing on people, technology, skills, and intelligence. Could you walk us through how these elements interact to create a safety net that is stronger than the sum of its parts?
It truly is a jigsaw puzzle where you cannot afford to have a single missing piece because fraud is constantly evolving. First, you have the people—both customers and staff—who are educated to spot things that don’t look right, with many staff members now earning national vocational qualifications (NVQs) in fraud detection to sharpen their instincts. Then comes the technology, where we use advanced US-based systems to monitor incoming calls for voice patterns that suggest a high risk of vishing. When the tech flags a call, the third piece—skills—kicks in, bringing in expert fraud investigators who listen to the recordings and use machine learning models to identify data patterns that feel off. Finally, there is the intelligence piece, where a dedicated financial crime team ensures that every bank account, email, or phone number associated with past fraud is loaded into the operating system to trigger an immediate alert if that fraudster ever returns.
With the National Fraud Database recording over 444,000 cases in 2025—a 6% increase from the previous year—the scale of the problem is clearly growing. How can insurance firms maintain an agile defense when the volume of attacks is reaching these record highs?
The numbers are staggering and serve as a wake-up call that we can never truly sit back and assume our systems are “perfect.” Reaching over 444,000 cases in a single year means the scammers are scaling their operations just as fast, if not faster, than we are. To stay agile, an insurer must be willing to constantly push their own boundaries and identify the gaps where scammers might start creeping in. It requires an iterative approach where you learn from every successful deception and immediately feed that intelligence back into your training and your AI models. If you don’t have a plan that is flexible enough to adapt to new vishing tactics or synthetic identity trends, you will quickly find yourself overwhelmed by the sheer volume of fraudulent attempts.
What is your forecast for the future of telephony-based fraud in the insurance sector?
I believe we are entering an era where the “human” element of the call center will become the primary battleground for security. As digital defenses become nearly impenetrable due to multi-factor authentication and AI-driven behavior analytics, fraudsters will pivot even more heavily toward vishing and social engineering to bypass those technical hurdles. We will likely see a massive push toward voice biometrics and real-time sentiment analysis to assist agents, but the core of the struggle will remain the same: the battle for the agent’s trust. The insurers who survive this surge will be those who successfully integrate cross-sector intelligence, allowing them to see the fraudster’s footprints long before the first “hello” is even spoken on a call.
