Identity Theft and Financial Impersonation
6 steps · one page
In short
The reason identity theft is harder to detect than account takeover is that nothing you own changes.
Scope. Account Security covers someone taking control of an account you already have. This article covers something structurally different: someone using your identity to create relationships you never had, or persuading an institution that they are you. No product, vendor, credit reporting agency or service is named. Where to report and where to check are the subject of the last article in this pillar.
The fraud happens in institutions you have no relationship with, using your name. There is no balance to notice, no statement to reconcile, and no login to be locked out of. The event is invisible from where the victim is standing, and stays invisible until something reaches them from outside.
Why the material already exists
Know Your Customer and Anti-Money-Laundering Obligations explains that firms are legally required to collect identity documents, addresses and dates of birth.
That set of information is exactly what is needed to impersonate someone, and the reason is structural rather than accidental. Institutions do not verify people. They verify data about people, because data is what can be transmitted, stored and checked at scale.
The asymmetry that makes this different from every other security problem on this portal. Identity verification is data verification, and data can be copied without being taken away. A password compromised once can be changed, which resets the exposure to zero. A date of birth cannot be changed. Nor can a place of birth, a mother's maiden name, a national identifier, or the address history sitting in a dozen archives. Which means a disclosure of identity data is permanent in a way a credential disclosure is not, and the exposure does not decay. Information disclosed in a breach years ago remains usable, and frequently is used long after the breach stops being news. So the practical posture cannot be to protect the data, because the data is already distributed across every institution that was obliged to collect it. It has to be to interfere with what the data can be used to do.
How it becomes visible
Detection is almost always indirect, and the routes are worth knowing in advance because they arrive without warning.
A credit file showing an enquiry or an account the person did not open. Correspondence about a product never applied for. A tax notice referring to income from an unknown employer. A collector pursuing a debt that is not theirs. A refused application, from someone who has no reason to expect refusal.
Each of these is a late signal. By the time any of them arrives, the account-opening has already happened.
Prevention and detection are not the same thing
This distinction is routinely blurred, including by the services sold to address the problem.
| Mechanism | What it does | When it acts |
|---|---|---|
| Restricting access to a credit file | Prevents a new creditor from pulling the file, so the application cannot be assessed and the account cannot be opened | Before |
| Monitoring or alerting | Reports that something has happened | After |
Both are useful and they are not substitutes. A restriction on file access attacks the mechanism at the only point where it can be stopped, because opening a credit account generally requires the file to be read. Monitoring cannot prevent anything; it shortens the interval before a victim finds out, which matters, but the account exists by then.
Availability, cost and the procedure differ by jurisdiction, and in some places the restriction is free by law — in the United States, placing and lifting a credit freeze at each of the nationwide credit bureaus has been free by federal law since 2018, and each bureau must also provide free credit reports on request. Where to do it is in the last article of this pillar.
Two variants worth naming
Synthetic identity combines real data with fabricated data, so the resulting person is partly genuine and partly invented. Because no single real individual is fully impersonated, no single individual notices — which is why it disproportionately uses the identifiers of people who do not check credit files, including children.
Impersonation of a person to a firm has become materially easier, and one specific assumption now fails. Voice was for a long time treated as informal authentication, on the reasonable basis that a familiar voice was hard to counterfeit. It is no longer hard to counterfeit. A voice on a telephone, including a voice that sounds like a relative or a colleague, is no longer evidence of who is speaking — which extends the conclusion from Account Security that inbound contact cannot be authenticated by the person receiving it, to inbound contact that sounds like someone you know.
What the recovery actually costs, stated plainly because the usual reassurance understates it. Liability for fraudulent accounts is often limited by law, and the money is frequently recovered. That is the reassuring half and it is true. The other half is that the reconstruction is done by the victim. Establishing which accounts are not yours, to each institution separately, each with its own process, its own evidence requirements and its own timetable, while the consequences continue to arrive, is work that cannot be delegated and takes as long as it takes. The money may be recoverable. The time is not. Which is the honest case for the preventive mechanism above being worth the inconvenience it causes.
Frequently asked
8 questions
How is this different from account takeover?
Account takeover uses an account you already have. This is someone creating relationships you never had, in institutions you have no relationship with. Nothing you own changes, so there is no balance to notice and no statement to reconcile.
Why is the necessary information already available?
Because firms are legally required to collect identity documents, addresses and dates of birth, and that set is exactly what impersonation needs. Institutions do not verify people, they verify data about people, because data is what can be transmitted, stored and checked at scale.
Why can this not be fixed by protecting the data?
Because the data is already distributed across every institution obliged to collect it, and it cannot be changed. A compromised password can be changed, resetting the exposure to zero. A date of birth cannot. Information disclosed years ago remains usable and frequently is used long after the breach stops being news.
How do people find out?
Indirectly and late: a credit file showing an unfamiliar enquiry or account, correspondence about a product never applied for, a tax notice referring to an unknown employer, a collector pursuing someone else's debt, or an unexpected refusal. By the time any of these arrives, the account has already been opened.
What is the difference between a freeze and monitoring?
Restricting access to a credit file prevents a new creditor from reading it, so the application cannot be assessed and the account cannot be opened. Monitoring reports that something has happened. The first acts before, the second after, and they are not substitutes. In the United States a freeze is free by federal law.
What is a synthetic identity?
A combination of real and fabricated data, so the resulting person is partly genuine and partly invented. Because no single real individual is fully impersonated, no single individual notices, which is why it disproportionately uses the identifiers of people who do not check credit files, including children.
Can I trust a familiar voice on the phone?
No. Voice was long treated as informal authentication because a familiar voice was hard to counterfeit. It is no longer hard to counterfeit, so a voice that sounds like a relative or colleague is not evidence of who is speaking.
Is the money recoverable?
Often yes, and liability is frequently limited by law. But the reconstruction is done by the victim, institution by institution, each with its own process and timetable, while consequences continue to arrive. The money may be recoverable. The time is not.
References
- Federal Trade Commission — IdentityTheft.gov (recovery steps and sample letters) —
- Federal Trade Commission — What To Know About Credit Freezes and Fraud Alerts (freezes free by law under the Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018) —
- Consumer Financial Protection Bureau — What is a credit freeze? —
- Financial Crimes Enforcement Network — customer identification and beneficial ownership requirements (why the identity data exists) —
Educational and informational only — not investment advice, a recommendation, or an offer to buy or sell any security. Investing involves risk, including the possible loss of principal. Worked examples use fictional companies and figures.