You can't authenticate her, you only have some data about her that is easy to find out: Name, email, last 4 digits of credit card, etc. You have to make a judgement call so you can be social engineered.
I am wondering how frequent are these edge cases like this, and how do you deal with them.