How Identity Theft Happens
Criminals use several methods to collect the personal information they need to impersonate you:- Data breaches: Companies that store your name, email, Social Security number, or payment card details are frequent targets. When their systems are compromised, your data can end up for sale on the dark web within hours.
- Phishing attacks: Fraudulent emails, text messages (smishing), and phone calls (vishing) are designed to trick you into voluntarily handing over credentials, account numbers, or other sensitive details.
- Physical theft: Stolen mail, dumpster-dived documents, or a skimmer on an ATM can yield enough information to open new credit lines in your name.
- Social engineering: Attackers scour social media profiles to piece together answers to your security questions or craft convincing impersonation attacks.
Warning Signs Your Identity May Be Compromised
Catching identity theft early limits the damage. Watch for these red flags:Monitor your financial accounts and credit reports regularly. Many victims only discover their identity has been stolen months or even years after the fact, by which point the financial damage can be severe.
- Unexpected charges or withdrawals on your bank or credit card statements
- Bills or collection notices for accounts you never opened
- Being denied credit unexpectedly despite a clean financial history
- Receiving tax notices about income you didn’t earn
- Unfamiliar accounts appearing on your credit report
- Missing expected mail — it may have been redirected by a fraudster
Protection Strategies in Depth
Use Strong, Unique Passwords for Every Account
Use Strong, Unique Passwords for Every Account
Password reuse is one of the most exploitable habits a person can have. When a data breach exposes your credentials from one site, attackers immediately try those same username-and-password combinations across hundreds of other services — a technique called credential stuffing. A single reused password can cascade into a full account takeover across your email, bank, and social media profiles.Use a reputable password manager to generate and store a unique, complex password for every account you own. A strong password is at least 16 characters long and mixes upper and lowercase letters, numbers, and symbols. You only need to remember one master password — the manager handles everything else.
Enable Multi-Factor Authentication (MFA) Everywhere
Enable Multi-Factor Authentication (MFA) Everywhere
Multi-factor authentication adds a second verification step beyond your password — typically a time-sensitive code sent to your phone, generated by an authenticator app, or provided by a hardware key. Even if an attacker obtains your password through a breach or phishing attempt, they cannot access your account without also controlling your second factor.Enable MFA on every account that supports it, prioritizing your email (which is the recovery gateway for almost everything else), banking apps, and cloud storage. Authenticator apps like those built into your device’s operating system or dedicated third-party apps are significantly more secure than SMS codes, which can be intercepted via SIM-swapping attacks.
Monitor Your Credit and Place a Fraud Alert or Freeze
Monitor Your Credit and Place a Fraud Alert or Freeze
You’re entitled to free credit reports from all three major bureaus annually. Review them carefully for any accounts or inquiries you don’t recognize. Consider signing up for a continuous credit monitoring service that alerts you in real time when new accounts are opened or your score changes significantly.If you suspect you’re at risk — or have already been a victim — place a credit freeze (also called a security freeze) with each bureau. A freeze prevents new creditors from pulling your credit file, which stops most fraudulent account openings in their tracks. It’s free to place and lift, and it doesn’t affect your existing accounts or credit score.
Shred Sensitive Documents Before Discarding Them
Shred Sensitive Documents Before Discarding Them
Physical document theft remains a highly effective and low-tech method of harvesting personal information. Bank statements, pre-approved credit card offers, medical bills, tax documents, and even utility bills contain enough detail to facilitate fraud.Cross-cut or micro-cut shredders make documents virtually impossible to reconstruct. Shred anything that contains your name alongside account numbers, Social Security numbers, dates of birth, or financial data. For documents you need to keep, store them in a locked filing cabinet rather than loose in a drawer.
Be Skeptical of Phishing Attempts
Be Skeptical of Phishing Attempts
Phishing emails are increasingly sophisticated — they mimic the branding, tone, and formatting of legitimate institutions almost perfectly. Be suspicious of any unsolicited message that creates a sense of urgency (your account will be suspended, a package couldn’t be delivered, a payment failed) and directs you to click a link or call a number.Go directly to the organization’s official website by typing the URL yourself rather than clicking embedded links. Legitimate companies will never ask you to confirm your full Social Security number, password, or full card number via email or text.
Secure Your Mailbox and Go Paperless Where Possible
Secure Your Mailbox and Go Paperless Where Possible
An unlocked mailbox is a low-effort target. Consider a locking mailbox for sensitive deliveries, use USPS Informed Delivery to preview incoming mail digitally, and switch to paperless billing and statements wherever possible. This eliminates the physical interception risk for the most sensitive documents your bank and government agencies send you.
What to Do If Your Identity Is Stolen
If you discover you’re a victim, act quickly:1
Place a Fraud Alert or Credit Freeze
Contact one of the three major credit bureaus to place a fraud alert — they’re required to notify the others. For stronger protection, place a credit freeze with all three bureaus simultaneously. This is the single most effective step you can take immediately.
2
Report to the FTC
File a report at IdentityTheft.gov (run by the U.S. Federal Trade Commission). The site walks you through creating a personalized recovery plan and generates an official identity theft report you’ll need for disputing fraudulent accounts.
3
Contact Affected Companies
Call the fraud department of every financial institution or company where you know unauthorized accounts were opened or fraudulent charges were made. Ask them to close the accounts and send written confirmation.
4
Change Compromised Passwords Immediately
Update the passwords for any accounts you believe were accessed, and enable MFA if it wasn’t already active. Start with your primary email account, then your financial and government service accounts.
5
File a Police Report If Necessary
Some creditors require a police report to process identity theft disputes. File one with your local law enforcement agency and keep a copy for your records.