August 6, 2026
Estimated reading time: 2 minutes
Fraud tactics continue to evolve and AI is making it easier for bad actors to create convincing, personalized scams at scale. The fundamentals of account security are more important than ever and the most effective ways to reduce risk are straightforward: protect your credentials, pay attention to unexpected activity, and pause before acting on an unusual or unexpected request.
Dheeraj Bhat, Chief Information Security Officer at Flourish, leads the company’s efforts to identify emerging risks and strengthen the safeguards that protect client information and funds. In this Q&A, he explains the fraud trends affecting the financial services industry, the warning signs clients and advisors should recognize, and the practical steps they can take to strengthen their security. He also discusses how tools such as multifactor authentication, password managers, account alerts, and biometric login in the Flourish mobile app work together as part of a layered approach to protection.

Flourish: What fraud trends are you seeing most often today and how have scams become more sophisticated over the past year?
Dheeraj Bhat: Across financial services, two common trends are account takeovers and identity-based fraud. Account takeovers often begins outside the financial platform, for example, through a compromised email account, reused password, infected device, or someone who has gained access to a person’s credentials.
Identity fraud may involve stolen personal information or a combination of real and fabricated information used to create a false identity.
Both trends reinforce the importance of layered protection: strong identity verification by financial institutions and strong email, password, and device security by individuals.
Flourish: What are the most important steps advisors and clients can take to protect financial accounts and personal information?
Dheeraj: For advisors, familiarity with a client’s circumstances and typical financial activity can provide valuable context. Stay alert to requests that appear unusual for the client and verify unexpected changes or transactions using established contact information. Before sending a Flourish invitation, confirm that you know the recipient and that the email address is correct.
For clients, our fraud prevention guide outlines a number of steps, but three steps matter most:
Use a password manager, with a unique password for every site. Most account takeovers start with a password stolen somewhere else. A password manager also refuses to autofill on a lookalike domain, which catches phishing before you do.
Use an authenticator app, instead of SMS where available. Authenticator apps can provide additional protection against certain phone-number takeover schemes. At the same time, you should also reach out directly to your mobile carrier to request a "port-out" lock on your phone number, which can prevent bad actors from compromising your phone number even if you use authenticator apps.
Flourish: Why is securing your email account just as important as securing your financial accounts?
Dheeraj: Email is the master key to your online identity. It contains years of personal and financial information, receives password-reset links and account invitations, and serves as the destination for important security alerts.
If an email account is compromised, an attacker may be able to access sensitive information, reset credentials for other accounts, or intercept alerts before you see them. That is why it is essential to protect your email with a strong, unique password and multi-factor authentication, and to regularly review your recovery settings and forwarding rules.
Flourish: What warning signs should make someone pause before clicking a link, sharing information, or moving money?
Dheeraj: Key warning signs include:
Urgency. Any request to move money immediately, especially in cash, gift cards, or crypto. Legitimate institutions typically do not need a decision in ten minutes. Be cautious when someone creates an artificial deadline or pressures you to act before you can verify the request.
A refund request of money someone sent you. If a person overpays you or sends a check for more than you're owed and asks you to return the difference — don't. The original payment can be reversed after your refund clears, while the money you returned may be difficult or impossible to recover. This works the same way with checks, ACH transfers, and payment apps.
New payment instructions by email. Especially a “correction” to instructions you already had. This is very common during real estate or other investment closing steps when money is actually moved. Criminals may compromise an email account and wait for an opportunity to substitute fraudulent payment instructions.
A code you did not request. An unexpected code may indicate that someone is attempting to access your account. Never share a one-time security code with someone who contacts you unexpectedly. A legitimate institution should not ask you to read back a code intended to verify your identity.
Anyone asking you to weaken your own security. Turning off multi-factor authentication, adding a device, installing software, or sharing your screen. A legitimate support representative should not ask you to disable security protections or provide unrestricted access to your device.
Small deposits or transfers you did not initiate. Attackers test the connection with small amounts before moving anything meaningful.
Pressure to keep it private. "Don't tell your advisor." "Don't mention this to the bank." Secrecy is not a feature of any legitimate transaction. It exists to keep you away from the one person who would recognize the scam.
The rule that covers all of them: Stop and call back on a number you already have, such as from a statement, your card, or your contacts. Never a number from the message.
Flourish: How do tools such as multi-factor authentication, password managers, and biometric login help reduce risk?
Dheeraj: Security is built in multiple layers to compensate for failures or compromises in one layer, increasing the hurdles for an attacker. Each tool protects against a different type of threat.
A password manager helps people create unique credentials and can reduce the risk of entering a password on a lookalike website. Multi-factor authentication adds another verification step if a password is compromised. Biometric login allows clients to access their account using Face ID or Touch ID, helping protect access while making secure sign-in more convenient. No single tool eliminates risk, but together they make unauthorized access substantially more difficult.
Flourish: What should a client or advisor do immediately if they suspect an account, email address, or device has been compromised?
Dheeraj: If you are suspicious of a message or request, immediately contact your financial institution using a phone number you already trust, such as one from a statement, card, saved contact, or the institution’s official website. Do not use a phone number, link, or other contact method provided in the suspicious message, as it may be fraudulent.
If email or phone access may have been compromised, contact those providers as well, change affected passwords from a trusted device, review multi-factor authentication settings, and check accounts for unfamiliar activity. Advisors should escalate concerns promptly rather than waiting for certainty.
Flourish clients and advisors should contact the Flourish Support team promptly so the team can review the account and determine the appropriate protective steps.
Flourish is an online platform through which investors can access financial services and products. Flourish’s offerings are provided by different entities and are subject to different terms, investor protections, and risks. Flourish Cash is offered by Flourish Financial LLC, a registered broker-dealer and FINRA member. Flourish Financial LLC is not a bank. Check the background of Flourish Financial LLC and its personnel on FINRA's BrokerCheck. Flourish Lending is offered by SoraFinance, Inc. (d/b/a Flourish Lending), a licensed mortgage broker (NMLS #2355841). SoraFinance, Inc. is not a lender. To verify SoraFinance, Inc., visit NMLS Consumer Access. The Flourish entities mentioned above are all wholly-owned subsidiaries of Flourish Holding Company LLC. Please review the Legal section of our website for more information and account terms. The role of the investment advisor or other firm that invited you to Flourish may vary between different Flourish services and products, as further described in your terms of service. © 2026 Flourish. All rights reserved.