
Pension fraud does not always begin with a fake investment opportunity or an unsolicited call.
Sometimes, the criminal’s goal is much simpler: become the pension member.
A fraudster obtains enough personal information to impersonate a legitimate customer, gains access to their pension account, changes important account details, and attempts to move money to an account they control.
For pension providers, this creates a difficult question:
How do you know that the person requesting a pension payment is actually the member?
The Pensions Regulator has specifically warned pension schemes and administrators about impersonation fraud involving unauthorised access to members’ accounts. Its analysis identified techniques including compromised email accounts, stolen member information and account credentials being used to impersonate members and change beneficiary bank details.
This means pension fraud prevention cannot stop at passwords and security questions. Providers need to establish confidence in the person behind the transaction.
How Pension Member Impersonation Works
A typical attack can happen in several stages.
1. The criminal collects information
Fraudsters may first gather information about a pension member.
This can come from compromised email accounts, data breaches, phishing, social engineering, publicly available information or previously compromised credentials.
The more information a criminal has, the easier it can become to convincingly impersonate the member.
They may know the person’s:
- Full name
- Date of birth
- Address
- Pension provider
- Previous correspondence
- Account information
- Contact details
- Employment history
- Other personal information
The criminal does not necessarily need to know everything about the victim.
They may only need enough information to sound legitimate.
2. The criminal gains access
The next objective is often access to the member’s pension account or communication channel.
This could involve compromised credentials, an email account takeover, social engineering or other methods of bypassing account protections.
Once inside, the criminal may look for information that can help them impersonate the member more convincingly.
3. The criminal changes the details
This is where the attack can become financially dangerous.
The fraudster may attempt to change:
- Bank account details
- Contact information
- Beneficiary information
- Communication preferences
- Passwords
- Other account information
The Pensions Regulator specifically identified cases where criminals obtained member information and then impersonated the member to change beneficiary bank account details with the intention of withdrawing pension funds.
4. The criminal requests the payment
Once the account has been manipulated, the fraudster can attempt to initiate a withdrawal, transfer or other payment.
From the provider’s perspective, the request may initially appear to come from the legitimate member.
That is the central problem.
The account may be genuine. The pension may be genuine. The information provided may be correct. But the person behind the interaction may be a criminal.
Why Passwords and Security Questions Are Not Enough
Traditional authentication remains an important component of account security.
But authentication based primarily on information can have a fundamental weakness:
Information can be stolen.
If a criminal has already obtained a member’s personal details, successfully answering questions about those details does not necessarily establish that the person is the legitimate account holder.
This is especially relevant in pension fraud because the information required to appear credible may have been gathered long before the fraudulent transaction takes place.
Providers therefore need to introduce controls that establish something beyond:
“Does this person know the member’s information?”
They need to establish:
“Is this actually the member?”
The Shift From Credential Verification to Identity Verification
Identity verification provides another layer of assurance by examining the relationship between the individual, their identity document and their biometric characteristics.
Instead of relying exclusively on information that a criminal may have obtained, a provider can require the individual to complete an identity verification process.
This can involve:
Identity document verification → Liveness detection → Face matching → Risk assessment

Each layer answers a different question.
Is the identity document genuine?
Document verification can help identify whether the presented identity document appears authentic and whether its information is consistent.
Is a real person physically present?
Liveness detection is designed to distinguish a live person from presentation attacks such as photographs, replayed media or other attempts to spoof biometric verification.
Does the person match the identity?
Face matching can compare the person’s face with the portrait contained in the identity document.
Together, these controls provide substantially more evidence about who is actually present than a password or security question alone.
Liveness Detection: A Critical Layer Against Remote Impersonation
Remote pension servicing introduces another challenge.
A fraudster does not necessarily need physical access to a pension office. They may attempt to impersonate a member entirely remotely.
That makes biometric liveness particularly relevant to high-risk digital interactions.
A liveness check can help determine whether the biometric presentation comes from a real person who is physically present rather than from a static image, replayed video or other presentation attack.
As deepfake and synthetic-media capabilities become increasingly accessible, this distinction becomes even more important.
For pension providers, liveness should not be viewed as a standalone fraud solution. It is one layer in a broader identity and risk framework.
The Most Important Moment: Before the Money Moves
Identity verification becomes particularly valuable when it is connected to high-risk events.
Not every interaction with a pension provider needs the same level of scrutiny.
A customer checking their pension balance is different from someone:
- changing their bank account;
- requesting a large withdrawal;
- transferring their pension;
- adding a new beneficiary;
- changing important personal information immediately before a withdrawal;
- or attempting several sensitive account changes in a short period.
These events can trigger additional verification.
For example:

A Layered Defence Against Pension Impersonation
The strongest approach is not one security tool.
It is a series of controls that create multiple opportunities to detect an attack.
Layer 1: Secure account access
Protect accounts with appropriate authentication and account-security controls.
Layer 2: Detect sensitive changes
Treat changes to bank accounts, beneficiaries and other critical information as higher-risk events.
Layer 3: Verify identity
When risk increases, verify the person’s identity rather than relying solely on credentials.
Layer 4: Confirm liveness
Use biometric liveness to help establish that a real person is physically present during remote verification.
Layer 5: Assess transaction risk
Look at the requested transaction in the context of the member’s activity and the receiving destination.
Layer 6: Escalate Higher-Risk Cases With Video KYC
When automated checks identify elevated risk or cannot provide sufficient confidence, pension providers can introduce an additional layer of verification through Video KYC.
Video KYC, or video-based Know Your Customer verification, is a remote identity verification process in which the customer verifies their identity through a live video interaction. Depending on the workflow, this can involve an identity document check, face match, liveness checks, aml screening, email and phone verification, and interaction with a trained verification agent.
For pension providers, Video KYC can be used as an escalation step when a sensitive request requires stronger assurance before funds are released or even as ultimate virtual branch. For example, if a member requests a significant withdrawal or changes their payout details and automated risk controls raise concerns, the provider can require a video-based verification before proceeding.
The additional interaction creates another opportunity to establish that the person requesting the transaction is genuinely the pension member and to identify inconsistencies that may warrant further investigation.
Rather than applying the highest level of verification to every customer, providers can use Video KYC selectively for higher-risk events, suspicious cases or situations where additional assurance is required.
How Identomat Can Help Pension Providers
Identomat provides a modular identity verification and financial crime compliance platform that can help pension providers strengthen their defences against impersonation and account takeover. Identomat’s solutions include ID Verification, Face Match, Liveness Check, Video KYC, Risk Assessment, AML Screening & Monitoring, and more, allowing providers to introduce stronger controls at the points where fraud risk is highest.
For pension providers, these capabilities can work together as part of a layered verification process. Identity document verification can establish the identity being presented, Face Match can compare the individual with their identity document, and Liveness Check can help confirm that a real person is physically present. When automated checks identify elevated risk or additional assurance is required, Video KYC can provide a further layer of verification through a live interaction.
Interested in seeing how Identomat’s solutions can help strengthen your fraud prevention strategy? Our team would be happy to walk you through the platform and show you how the solutions work in practice. Book a demo with our team to see Identomat in action.



