When a health and wellness client flagged unauthorized redemptions, ADR’s incident response team contained the breach in 20 minutes — without taking a single legitimate participant offline permanently.
* Metrics represent outcomes for this engagement. Results vary by incident scope.
For years, this mid-size health and wellness company had operated its participant incentive program on ADR’s RewardSTACK™ platform. The program drove meaningful engagement — rewarding members for healthy behaviors, program participation, and milestone achievement.
Then the pattern broke. Multiple participant accounts began showing redemptions that didn’t match their behavioral history. The redemptions weren’t tied to known participant segments. The timing was off. Something was wrong.
The client’s team flagged the anomaly and contacted ADR. Their concern was straightforward: stop the fraud without destroying participant confidence in the program they’d spent years building.
“We couldn’t pinpoint where things were going wrong — and we couldn’t afford to lose trust with our members.”
— Health & Wellness Program Manager (client, anonymized)ADR’s RewardSTACK™ platform manages enterprise incentive programs across health & wellness, market research, employee recognition, and channel sales verticals — serving programs with thousands of active participants.
The pattern pointed toward an external credential threat — bad actors using participant login information obtained outside the program to access legitimate accounts and redeem points they didn’t earn. This type of attack, known as account takeover (ATO), targets participant credentials, not the rewards platform itself.
Account takeover is an industry-wide threat that can affect any incentive program where participant authentication is managed at the program level. The RewardSTACK™ platform showed no signs of breach. The challenge was detecting and containing external misuse before it reached more accounts — without shutting down the entire program and locking out thousands of legitimate participants in the process.
A controlled, surgical response — not a panic shutdown.
* Exact restoration windows vary by incident scope and client response coordination.
The incident became a proof point for ADR’s operational resilience — not a liability.
Unauthorized redemptions stopped within 20 minutes of notification — before the incident could escalate to a larger population of participant accounts.
The selective restoration approach meant the vast majority of participants experienced no visible disruption. Those affected received rapid, targeted resolution.
Post-incident authentication hardening means the program now operates with stronger controls than existed before the external fraud event.
“ADR saved us from what could have been a disaster. The fraud was contained, our members never lost trust in the program, and we came out of it with a stronger platform than we went in with.”
— Health & Wellness Program Manager (client, anonymized)Most rewards platforms operate as monolithic environments — when fraud hits one area, the options are: do nothing, or shut everything down. ADR’s RewardSTACK™ platform is built differently.
RewardSTACK™ supports marketplace-level isolation, meaning individual client marketplaces can be suspended and restored independently, without impacting the broader platform, other clients, or program infrastructure. This is what allowed ADR to take surgical action rather than a blunt-force shutdown.
Common questions from program managers evaluating fraud risk and incident response readiness.
Talk to ADR’s team about your program’s security posture — before an incident forces the conversation.
ADR manages enterprise rewards programs across health & wellness, market research, employee recognition, and channel sales verticals.