How ADR Contained a Rewards Program Fraud Incident in Under 20 Minutes | Case Study
Case Study — Fraud Incident Response

Fraud Detected. Program Isolated. Restored — All Within Hours.

When a health and wellness client flagged unauthorized redemptions, ADR’s incident response team contained the breach in 20 minutes — without taking a single legitimate participant offline permanently.

20 Min to isolation*
<5% Participants affected*
100% Program restored*

* Metrics represent outcomes for this engagement. Results vary by incident scope.

Immediate containment
Affected marketplaces isolated within 20 minutes — before fraud could escalate
Surgical precision
Unaffected marketplaces restored individually — not as a blanket reactivation
Trust preserved
Most participants experienced no visible disruption during the incident
Post-incident hardening
Additional authentication controls implemented as post-incident best practice
Background

A long-term client. An unfamiliar threat.

For years, this mid-size health and wellness company had operated its participant incentive program on ADR’s RewardSTACK™ platform. The program drove meaningful engagement — rewarding members for healthy behaviors, program participation, and milestone achievement.

Then the pattern broke. Multiple participant accounts began showing redemptions that didn’t match their behavioral history. The redemptions weren’t tied to known participant segments. The timing was off. Something was wrong.

The client’s team flagged the anomaly and contacted ADR. Their concern was straightforward: stop the fraud without destroying participant confidence in the program they’d spent years building.

“We couldn’t pinpoint where things were going wrong — and we couldn’t afford to lose trust with our members.”

— Health & Wellness Program Manager (client, anonymized)
About ADR’s platform

ADR’s RewardSTACK™ platform manages enterprise incentive programs across health & wellness, market research, employee recognition, and channel sales verticals — serving programs with thousands of active participants.

The Challenge

An external threat targeting participant accounts

The pattern pointed toward an external credential threat — bad actors using participant login information obtained outside the program to access legitimate accounts and redeem points they didn’t earn. This type of attack, known as account takeover (ATO), targets participant credentials, not the rewards platform itself.

Account takeover is an industry-wide threat that can affect any incentive program where participant authentication is managed at the program level. The RewardSTACK™ platform showed no signs of breach. The challenge was detecting and containing external misuse before it reached more accounts — without shutting down the entire program and locking out thousands of legitimate participants in the process.

Challenge Summary
Fraud type
External account takeover (ATO) — participant credentials targeted outside the platform
Platform status
RewardSTACK™ not compromised — threat was external
Primary risk
Ongoing redemption loss and participant trust erosion
Key constraint
Legitimate participants must remain served throughout
Incident Response

ADR’s response: step by step

A controlled, surgical response — not a panic shutdown.

T + 0 min — Notification received
Client flags unusual redemption pattern
The client’s team contacted ADR reporting anomalous redemptions across multiple participant accounts. Transaction velocity and account behavior were inconsistent with normal program activity. The ADR incident response protocol was immediately activated.
T + 20 min — Containment initiated
All client marketplaces taken offline
ADR temporarily suspended all client-facing marketplaces — a deliberate containment decision, not a system failure. RewardSTACK™’s architecture supports marketplace-level isolation without affecting platform infrastructure or other clients. “It was the safest move to protect the client’s program and their members,” said Kim Robinson, ADR’s Director of Platform Solutions.
T + [X hrs] — Joint investigation
Root cause confirmed: external credential threat
ADR and the client’s team worked together through transaction data to identify the pattern. The joint investigation confirmed what the initial pattern suggested: participant credentials had been compromised through external means — outside the rewards platform entirely. RewardSTACK™ showed no signs of breach. With the origin confirmed, affected accounts were flagged and isolated, and unaffected accounts were cleared for restoration.
T + [X hrs] — Selective restoration begins
Marketplaces restored one at a time with client approval
ADR restored individual marketplaces sequentially, with explicit client “Go Live” confirmation at each step. Unaffected participant accounts regained full access immediately. Compromised accounts remained suspended pending remediation. “It was like turning the lights back on one room at a time,” the client’s security lead noted.
T + [X hrs] — Full restoration
All marketplaces returned to active status
All client marketplaces were fully restored. The majority of participants experienced no service interruption. Those affected saw their issues resolved quickly. The incident was contained without permanently locking out a single legitimate participant.
Post-incident — Security hardening
Collaborative review and additional controls implemented
ADR and the client collaborated on a post-incident security review. Additional authentication controls were put in place to strengthen participant account protection going forward — a best practice ADR recommends for all programs managing external-facing participant authentication. The program emerged with a stronger security posture than it had before the incident.

* Exact restoration windows vary by incident scope and client response coordination.

Outcome

Contained. Restored. Stronger.

The incident became a proof point for ADR’s operational resilience — not a liability.

Fraud contained

Unauthorized redemptions stopped within 20 minutes of notification — before the incident could escalate to a larger population of participant accounts.

Participant trust maintained

The selective restoration approach meant the vast majority of participants experienced no visible disruption. Those affected received rapid, targeted resolution.

Program integrity strengthened

Post-incident authentication hardening means the program now operates with stronger controls than existed before the external fraud event.

“ADR saved us from what could have been a disaster. The fraud was contained, our members never lost trust in the program, and we came out of it with a stronger platform than we went in with.”

— Health & Wellness Program Manager (client, anonymized)
Why it worked

Architecture built for exactly this scenario

Most rewards platforms operate as monolithic environments — when fraud hits one area, the options are: do nothing, or shut everything down. ADR’s RewardSTACK™ platform is built differently.

RewardSTACK™ supports marketplace-level isolation, meaning individual client marketplaces can be suspended and restored independently, without impacting the broader platform, other clients, or program infrastructure. This is what allowed ADR to take surgical action rather than a blunt-force shutdown.

On the record: In this incident, the RewardSTACK™ platform itself was never compromised. The threat originated externally — from bad actors using participant credentials obtained outside the program. ADR’s role was detection, containment, and recovery. The platform performed exactly as designed.
RewardSTACK™ Security Capabilities
  • Marketplace-level isolation controls
  • Real-time transaction monitoring
  • Anomaly detection and alerting
  • Account-by-account selective restoration
  • 20-minute incident response SLA activation
  • Post-incident security review and hardening
FAQ

Frequently asked questions: rewards program fraud

Common questions from program managers evaluating fraud risk and incident response readiness.

Rewards program fraud is typically identified through unusual redemption velocity, account activity that deviates from historical patterns, or redemptions originating from unexpected locations or devices. ADR’s RewardSTACK™ platform includes real-time transaction monitoring that flags anomalous activity across participant accounts. Importantly, account takeover fraud targets participant credentials — not the rewards platform itself — making rapid detection and marketplace-level isolation the critical response levers.
Immediate containment is the priority — isolating affected marketplaces or accounts before further redemptions occur. ADR’s incident response protocol allows individual client marketplaces to be taken offline independently, without shutting down the entire program. This minimizes disruption to legitimate participants while stopping fraudulent activity at the source.
Yes — with selective restoration. Rather than bringing the entire program back online at once, ADR restores individual marketplaces one at a time as each is confirmed clean. Most participants experience no visible disruption, and those affected see resolution quickly. When handled correctly, participants often don’t know an incident occurred at all. Trust is preserved through speed and surgical precision.
ADR’s standard incident response SLA begins within 20 minutes of notification. Full marketplace restoration time depends on the scope of compromise, but ADR’s architecture supports selective, marketplace-by-marketplace restoration — meaning unaffected participants typically regain access within hours, not days. The client controls Go Live confirmation for each marketplace restored.
ADR’s RewardSTACK™ platform includes real-time transaction monitoring, anomaly detection, marketplace-level isolation controls, and an incident response protocol tested across enterprise health and wellness programs. ADR also works with clients post-incident to implement additional authentication controls — a best practice for all programs managing external-facing participant authentication.

Concerned about fraud exposure in your rewards program?

Talk to ADR’s team about your program’s security posture — before an incident forces the conversation.

ADR manages enterprise rewards programs across health & wellness, market research, employee recognition, and channel sales verticals.