Can confirm.
To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output how suspicious some activity is. Whether you're signing in to Gmail, returning a product, buying something with a credit card or booking an Uber, some form of score is computed and then used to allow/deny/delay/verify. Obviously this is well established in the insurance and finance industries, but make no mistake, it happens everywhere.
This approach is understandable from a business perspective, but imo deeply troubling for an open society. You don't have to squint much in order to see the similarities to social credit systems, EVEN if there is no grand totalitarian state-coordinated behind it.
As usual, the first step is transparency so we can actually discuss these issues based on accurate data, but that's very difficult today. Usually fraud and abuse prevention is among the most secretive departments, they never share anything.