Identity theft is the kind of threat most people ignore until it happens to them. But once a criminal begins opening accounts, moving money, or impersonating you, recovering your identity can become a time-consuming nightmare. Maureen’s story shows how quickly the damage can escalate—and the simple steps you can take to protect yourself from identity theft.

At first, it looked like ordinary credit card fraud.
Someone had used Maureen’s personal information to apply for new financial accounts and make purchases on credit cards she already owned. She canceled the fraudulent applications, updated her passwords, enabled two-factor authentication, froze her credit, added fraud alerts, and requested an IRS Identity Protection PIN.
In other words, she did what most identity theft prevention articles tell you to do.
But the attacks did not stop.
Months later, criminals began targeting account after account. They took over credit bureau profiles, changed contact information, impersonated Maureen with financial institutions, submitted fake checks, initiated wire transfers, and gained access to bank accounts that were supposedly protected by passwords, two-factor authentication, and security words.
At one point, Maureen closed and reopened the same Bank of America account four separate times. Fraudulent activity would return within days—sometimes before she had used the new account or even received its debit card.
What began as a few suspicious transactions turned into hundreds of hours spent calling banks, disputing charges, recovering accounts, documenting conversations, and trying to determine where the criminals might attack next.
Her story reveals an uncomfortable truth about identity theft:
A strong password and a single security feature are not enough to stop identity theft.
You need several independent layers of protection. And when something goes wrong, you need a plan that helps you act before the damage spreads.
Maureen’s Protection Strategy
- Freeze it: Prevent criminals from opening new accounts.
- Layer it: Never rely on a single password or security control.
- Verify it: Independently confirm suspicious requests, callers, and account changes.
Maureen’s experience and the specific resources in this article are based on the United States, where a Social Security number can function as a master key to financial and government systems. Readers in other countries will need to identify the equivalent credit, tax, banking, and national identity systems where they live. The underlying principles, however, apply almost anywhere.
Buy the Book
If your identity has been stolen or you’re already seeing fraudulent purchases or new accounts, it’s important that you act fast to fix it. Be sure to grab Maureen’s Survival Guide to Identity Theft to get step-by-step instructions on what to do next.
How Do Criminals Steal Your Identity?
Identity theft does not always begin with someone hacking your computer. A criminal may already have enough information to impersonate you. That information could come from a corporate data breach, a phishing message, malware, stolen mail, a compromised phone, or documents found online.
Once criminals have your name, address, phone number, date of birth, Social Security number, or other identifying information, they can attack your identity in several ways.
- They open new accounts in your name
- They take over accounts you already own
- They steal or bypass your login credentials
- They exploit weak customer service procedures
- They attack the systems connecting your accounts
Let’s look at each of these individually.
1. They Open New Accounts in Your Name
New-account fraud happens when a criminal uses your identity to apply for a product or service, such as:
- A credit card
- A checking or savings account
- A personal or auto loan
- A utility account
- A mobile phone plan
- An unemployment claim
- A fraudulent tax refund

You might not immediately know that the account exists. The first warning could be an unfamiliar inquiry on your credit report (if you even check your credit report!), a sudden drop in your credit score, a bill in the mail, or a loan application that is unexpectedly denied.
That is what made Maureen’s first attack so concerning. The criminals were not only charging purchases to existing cards; they were also applying for new bank and credit accounts using her identity.
2. They Take Over Accounts You Already Own
An account takeover occurs when a criminal gains control of an account you have already created.
The attacker may try to:
- Reset your password.
- Replace your email address or phone number.
- Change your mailing address.
- Request a new debit or credit card.
- Add a new transfer destination.
- Convince customer service to remove your security controls.
- Close the account and transfer the funds elsewhere.

This does not necessarily require a sophisticated technical attack. Maureen’s attackers called financial institutions while pretending to be her. They also submitted a fictitious authorization document with a fake Florida driver’s license containing her real information.
When a criminal knows your Social Security number, previous addresses, phone number, and other personal details, traditional identity questions may not distinguish between you and the impersonator.
Note: Data brokers are selling your personal data
You can minimize the risk of identity theft and unwanted spam by having your personal data removed from the hundreds of data brokers on the internet. You can do this yourself, but we use and recommend DeleteMe (20% off!).
3. They Steal or Bypass Your Login Credentials
Passwords remain important, but a password can be stolen through:
- Phishing emails and websites
- Malware or keyloggers
- Data breaches
- Password reuse
- A compromised email account
- Manipulation of the account recovery process
Even two-factor authentication can be intercepted or bypassed (especially SMS text 2FA). Criminals may take over your phone number through SIM swapping, trick you into sharing a one-time code, send repeated approval prompts, or persuade customer service to reset the account. This is why identity protection must extend beyond the login screen.
4. They Exploit Weak Customer-Service Procedures
Your bank’s application might be secure while its account-recovery process is not.
An attacker can call customer service and claim to have:
- Forgotten the password
- Lost access to the registered phone
- Changed email addresses
- Moved to a new address
- Been locked out of the account

The employee wants to help the customer regain access. Unfortunately, that helpfulness can become a vulnerability when the caller is an impersonator.
Maureen had accounts protected by security words, but she discovered that a security word is only useful when the institution reliably protects it. In one case, representatives revealed the account’s security word and allowed it to be changed without the safeguards she expected.
No security feature works when social engineering can easily persuade an employee to remove it.
5. They Attack the Systems Connecting Your Accounts
Banks, lenders, credit bureaus, payment networks, data aggregators, mobile carriers, and government agencies all exchange information. That interconnected system creates convenience, but it can also create unexpected paths to your data.
Maureen discovered this when newly opened bank accounts repeatedly experienced fraud. The pattern led her to Early Warning Services (EWS), a financial technology company associated with products such as Zelle and Paze.
Understanding those connections became a critical part of understanding why closing one account did not necessarily end the attack.
Take Action: Freeze It, Layer It, Verify It

You cannot remove all your personal information from every database. You also cannot guarantee that a criminal will never target you. What you can do is make each attack more difficult, reduce the amount of damage an attacker can cause, and detect suspicious activity much faster.
Here are nine practical steps to protect yourself from identity theft:
- Freeze your credit
- Don’t Stop with just 3 credit bureaus
- Layer your security
- Protect your phone number
- Turn on alerts & lock cards
- Secure your tax & government accounts
- Learn how your bank verifies your identity
- Understand Early Warning Services (EWS)
- Prepare an Identity Theft Emergency Plan
1. Freeze Your Credit at the Three Major Bureaus
The most important place to begin is with a credit freeze. In the United States, create an account and freeze your credit at:
A credit freeze restricts a lender’s access to your credit report. That makes it much harder for someone to open a new credit card or loan in your name.
A freeze does not:
- Lower your credit score
- Close your existing accounts
- Stop your current credit cards from working
- Prevent you from reviewing your own credit report
When you legitimately apply for new credit, you can temporarily thaw the freeze. Choose a time period, complete the application, and allow the freeze to resume automatically.
Yes, this adds an extra step when applying for credit. That small inconvenience is much easier to manage than trying to remove thousands of dollars of fraudulent debt.
Credit freeze vs. fraud alert
A credit freeze and a fraud alert are not the same thing.
- A credit freeze blocks access to your report for new lending. It is your primary defense.
- A fraud alert places a warning on your report asking a lender to perform additional identity verification. It is useful, but an employee may still approve the application.
As Maureen puts it, a fraud alert is a notification. A freeze is a block.
2. Do Not Stop With the Three Major Credit Bureaus
Equifax, Experian, and TransUnion are the most important places to start, but they are not the only organizations compiling consumer information.
Other reporting systems may include:
- Innovis: An additional credit reporting bureau
- ChexSystems: Banking and checking-account history
- LexisNexis: Identity, public record, and risk information
- NCTUE: Telecommunications and utility account information

There are also niche bureaus serving medical, utility, subprime lending, rental, and short-term loan markets.
Most people do not need to freeze every obscure reporting agency immediately. Begin with the three major credit bureaus. However, if you are experiencing ongoing bank-account, utility, rental, or loan fraud, determine which specialty reporting agencies are involved.
Maureen recommends creating a ChexSystems account in addition to the three principal credit bureaus. She also recommends freezing your NCTUE file to make it more difficult for someone to open utility or telecommunications services using your identity.
3. Layer the Security on Your Most Important Accounts
A password should be one layer of your account security—not the entire defense. Start building strong security protections for the accounts that can be used to take over everything else:
- Your primary email account
- Your password manager
- Your mobile carrier
- Your financial accounts
- Your credit bureau accounts
- Your tax and government accounts
For each important account:
- Use a unique password that you have never used elsewhere.
- Store the password in a reputable password manager.
- Enable two-factor authentication.
- Prefer an authenticator application or hardware security key when supported.
- Securely store your recovery and backup codes.
- Review the available account-recovery methods.
- Remove old phone numbers, email addresses, and devices.
Maureen also recommends creating a separate email alias address used only for financial accounts. Because this address is not used for newsletters, shopping, or ordinary communication, it is less likely to appear in unrelated data breaches or phishing campaigns.
The goal is not to find one perfect security method. It is to install several controls so that the failure of one does not immediately expose the account.
4. Protect Your Phone Number From SIM Swapping
Your phone number is often a recovery key for your email, bank, credit card, and social media accounts. That makes it valuable to an identity thief.

During a SIM swap or port-out attack, a criminal convinces your mobile carrier to transfer your number to a device the criminal controls. Once that happens, the attacker may be able to receive your calls and SMS verification codes.
Contact your mobile carrier and ask about:
- An account PIN
- A port-out PIN
- A number-transfer lock
- Additional verification before account changes
- Notifications when a new SIM or device is activated
The exact name of the feature varies by carrier. Maureen compares a carrier PIN to a credit freeze for your phone number: the carrier should require the PIN before transferring the number to another device.
You should also avoid approving unexpected authentication requests. If you receive a code or approval prompt you did not initiate, assume someone may be trying to access the account.
5. Turn On Alerts and Lock Cards You Rarely Use
Prevention is important, but fast detection can dramatically reduce the damage.
Enable notifications for:
- Purchases above a chosen amount
- ATM withdrawals
- ACH payments
- Wire transfers
- International transactions
- Online or card-not-present purchases
- New payees or external accounts
- Password changes
- Changes to your email, phone number, or mailing address
Choose thresholds that are low enough to be useful without creating so many notifications that you begin ignoring them.
Maureen set withdrawal alerts at $100. In some cases, these notifications were the first indication that the attackers had returned. Her custom alerts also arrived faster than some of the general fraud warnings sent by the banks.
For credit cards you rarely use, open the issuer’s application and look for a feature labeled Lock Card, Freeze Card, or Card Controls. Temporarily locking an unused card prevents new transactions while allowing you to unlock it when needed.
6. Secure Your Tax and Government Accounts
Identity thieves do not limit themselves to banks and credit cards.
They may also use your identity to:
- File a fraudulent tax return (and redirect the tax refund!)
- Submit an unemployment claim
- Access Social Security information
- Apply for government benefits
U.S. residents can request a six-digit IRS Identity Protection PIN. The PIN helps prevent another person from filing a federal tax return using your Social Security number or Individual Taxpayer Identification Number.

You will need the PIN when filing your taxes, so store it somewhere secure that you can access when it is time to file your taxes.
Maureen also recommends creating an online Social Security account even if you are not currently receiving retirement or Medicare benefits. Establishing and protecting the legitimate account now can make it harder for someone else to create or control it first.
Depending on where you live, you may also be able to create and secure an account with your state unemployment agency.
7. Learn How Your Bank Verifies Your Identity
Do not assume that a secure banking application means the entire institution is secure.
Ask your bank:
- Can someone change my contact information over the phone?
- What information does customer service use to verify a caller?
- Can I add a permanent verbal PIN or security word?
- Can that PIN be changed remotely?
- Will I be notified when my email address or phone number changes?
- Can I require in-person verification for major account changes?
- Can I lower my daily wire or transfer limits?
- Can I disable external transfers that I do not use?
- What happens if an attacker submits a written authorization and photo ID?
A physical branch can be valuable during an active account takeover. Walking into a branch with identification may be faster than spending hours on the phone attempting to prove that you—not the caller who changed the account—is the legitimate customer.
Walking into a branch with identification may be faster than spending hours on the phone attempting to prove that you.
A security word can provide another layer, but do not assume it is foolproof. Ask how the institution stores, verifies, and resets that word. Maureen learned that a control is only as strong as the procedures and training behind it.
8. Understand Early Warning Services and Your Bank’s Data Connections
Early Warning Services, commonly abbreviated as EWS, is a financial technology company associated with payment products such as Zelle and Paze. It was founded by several major banks and maintains financial information used to evaluate risk and fraud.
It is not officially one of the three main credit bureaus, but Maureen describes it as performing a similar consumer-reporting function for financial institutions.

Consumers can request an EWS consumer disclosure. When Maureen requested hers, she says it included extensive information about her financial relationships, including complete bank account numbers.
This discovery came after she had closed and reopened a bank account four times. Each new account experienced fraudulent activity within days, even before she had begun using it. She concluded that the pattern suggested her new account information was being exposed through a system connecting the participating institutions.
The practical takeaway is broader than one company: learn which third parties receive information from your bank.
Ask about connections to:
- Payment networks
- Bank-account verification services
- Financial data aggregators
- Peer-to-peer payment systems
- Consumer reporting agencies
You may not be able to opt out of every system, but awareness can help you understand how information moves and where another weak point may exist.
9. Prepare an Identity Theft Emergency Plan
When identity theft is actively happening, it is difficult to think clearly. Having a written plan available so you are not searching for instructions while a criminal is moving money or changing your accounts can be invaluable.
Maureen recommends prioritizing the actions that stop additional damage before spending hours filing reports.
Step 1: Stop the bleeding
- Freeze compromised bank or credit accounts.
- Freeze your credit reports.
- Contact each institution through a trusted number.
- Dispute unauthorized transactions.
- Change passwords, PINs, and authentication settings.
- Remove unfamiliar phone numbers, email addresses, devices, and payees.
Use the phone number printed on your card, statement, or the institution’s official website. Do not call a number contained in a suspicious email or text.
Step 2: Inspect every account
Create a complete list that includes:
- Checking and savings accounts
- Credit cards
- Store cards
- Retirement accounts
- Investment accounts
- Loans
- Payment applications
Review recent activity and turn on notifications. Continue inspecting statements for at least the next several months.
Step 3: Document everything
Record:
- The institution
- The date and time
- The representative’s name
- The fraudulent amounts
- The case or dispute number
- What the representative promised
- Your next follow-up date
Save emails, letters, screenshots, statements, and certified-mail receipts. Some disputes can take weeks, and you may need to prove that you reported the fraud.
Step 4: File FTC and police reports
After the immediate accounts are secured, submit an identity theft report through IdentityTheft.gov. Save the resulting report and case number.
Then file a police report when appropriate or when a financial institution requires one. These documents may support disputes, extended fraud alerts, and requests to remove fraudulent accounts.
Maureen intentionally places these reports after the urgent account actions. The FTC and police documentation can help with the recovery process, but filing a report does not immediately stop an attacker from moving money or opening another account.
Quick Identity Theft Protection Checklist
Start with these actions:
- Freeze your credit at Equifax, Experian, and TransUnion.
- Add fraud alerts as a secondary precaution.
- Create and protect your ChexSystems account.
- Freeze your NCTUE consumer file.
- Use unique passwords for important accounts.
- Enable authenticator-based 2FA or a hardware security key.
- Protect your mobile number with a carrier PIN or transfer lock.
- Turn on transaction and account-change alerts.
- Lock credit cards you rarely use.
- Request an IRS Identity Protection PIN.
- Create and secure your Social Security account.
- Learn how your bank verifies callers and resets accounts.
- Keep a complete list of your financial accounts.
- Prepare an identity theft response plan.
You do not have to complete everything in one afternoon. Start by freezing your three main credit reports, securing your email account, and protecting your phone number. Then work through the remaining steps.
Frequently Asked Questions About Identity Theft Protection
Below are some of the most common questions people ask about identity theft protection:
No. A credit freeze does not lower your score. It restricts access to your credit report for new applications.
Yes. A credit freeze does not close or disable your existing credit cards, loans, or bank accounts. It primarily affects applications for new credit.
No. A fraud alert asks a lender to verify your identity, but it does not necessarily block the application. A freeze is the stronger primary defense because it restricts access to your report.
No security feature can prevent every form of identity theft. Two-factor authentication is an important layer, but criminals may use phishing, malware, SIM swapping, account recovery, or social engineering to bypass it.
Monitoring can alert you to suspicious activity and may provide recovery assistance. It cannot guarantee that a criminal will be unable to steal or use your personal information. Treat monitoring as one tool within a larger security strategy.
Secure the accounts currently under attack. Freeze affected accounts and credit reports, contact the institutions, dispute unauthorized activity, and remove any contact information or devices added by the attacker. After stopping the immediate damage, document the incident and file the appropriate FTC and police reports.
You Cannot Prevent Every Attack—but You Can Be Prepared
You cannot control every company that stores your personal information. You cannot retrieve a Social Security number that has already been exposed, and no password can fix a bank’s weak identity-verification procedures.
But you are not powerless.
A criminal should not be able to move from one leaked piece of information to complete control of your financial identity without encountering resistance.
Freeze the reports that can be used to open new accounts. Layer independent security controls around your most valuable accounts. Verify unexpected requests through a communication channel you trust.
Freeze it. Layer it. Verify it.
That will not make you invincible. It will make you a much harder target—and it will leave you far better prepared to respond when something goes wrong.


