Identity Theft & Security

What can go wrong once your information is exposed, and how to protect yourself.

Credit Freeze (Security Freeze)

A restriction on your credit file that prevents new creditors from accessing it, which in turn blocks most new-account fraud.

Since 2018, federal law requires all three national bureaus — Equifax, Experian, and TransUnion — to place, lift, and remove freezes free of charge. A freeze must be set at each bureau separately. It does not affect your credit score, does not interfere with existing accounts, and can be lifted temporarily when you apply for credit. It is widely regarded as the single most effective identity-theft prevention step available to an individual.

Dark Web Monitoring

A service that scans criminal forums, breach dumps, and paste sites for your personal information and alerts you when it appears.

Useful as an early warning, but frequently oversold. Monitoring is detection, not prevention: it tells you data is already circulating and cannot retract it. Nor can it see everything, since much criminal trading happens in closed channels. Treat an alert as a prompt to freeze your credit and change reused passwords — and never mistake a quiet dashboard for evidence that you are safe.

Data Breach

An incident in which personal information is accessed, taken, or exposed without authorisation.

Breached records rarely stay put. They are traded, aggregated, and cross-referenced against other datasets, which is how a years-old breach can resurface combined with newer information and become useful again. Most US states require notification, and many breached companies offer free credit monitoring afterwards. The more useful response is structural rather than reactive: freeze your credit, change any reused passwords, and turn on multi-factor authentication.

Doxxing

Publishing someone's private or identifying information online — home address, phone number, workplace, family members — usually to harass, intimidate, or endanger them.

The information is often already technically public. What makes it doxxing is compiling it in one place and directing an audience at it. There is no general federal anti-doxxing law: it is a standalone crime in only a handful of states and is otherwise prosecuted as stalking or harassment. Most doxxing draws on people-search sites rather than any kind of hacking.

See our full guide to what doxxing is and how to protect yourself.

Full explainer: What Is Doxxing (or Doxing)? Meaning, Real Examples, and How to Protect Yourself →

Fraud Alert

A notice on your credit file asking lenders to verify your identity before extending credit in your name.

An initial fraud alert lasts one year, is free, and only needs to be placed with one bureau — that bureau is required to notify the other two. An extended alert lasts seven years and requires an identity theft report. A fraud alert is weaker than a credit freeze, because it requests verification rather than blocking access outright, but it is less disruptive if you apply for credit frequently.

Identity Theft

Using someone else's personal information without permission — typically to open accounts, obtain credit, file tax returns, or receive medical care in their name.

It is not one crime but a category: financial, medical, tax, criminal, and synthetic identity theft each work differently and are detected differently. The raw material is ordinary identifying information — name, date of birth, address history, Social Security number — most of which is assembled from public records and breach data rather than stolen directly from you. The federal recovery resource is IdentityTheft.gov.

Phishing

A fraudulent message designed to trick the recipient into revealing credentials or personal information, or into installing malware.

Phishing has moved well beyond obvious mass email. Targeted versions — "spear phishing" — reference your real employer, colleagues, or recent purchases, and the specific details that make them convincing are frequently bought from data brokers. Variants arrive by SMS (smishing) and voice call (vishing). The reliable defence is procedural rather than perceptual: verify through a channel you initiated yourself, never one the message handed you.

Social Engineering

Manipulating a person into granting access or disclosing information, rather than defeating a technical control.

It is the umbrella category that phishing, pretexting, and most account-takeover attacks belong to. Effective social engineering runs on accurate personal detail: knowing your address history, your relatives' names, or your employer is often enough to pass a call-centre identity check. That is the direct line between public data exposure and account compromise — security questions are very often answerable straight from a people-search profile.

Spoofing (Caller ID Spoofing)

Falsifying the number that appears on a recipient's caller ID.

Spoofing is cheap and trivially available, and it underpins most scam calls — including "neighbour spoofing," where the displayed number shares your area code and prefix to raise the odds you answer. It is illegal under the Truth in Caller ID Act when done with intent to defraud or cause harm, but enforcement is hard because the calls usually originate overseas. The practical defence is to treat caller ID as unverified: anyone can display any number, including your own bank's real one.

Swatting

Making a false emergency report in order to provoke an armed police response at someone else's home.

Swatting depends entirely on having a real, current address for the target, which is why it so often follows doxxing. It is prosecuted federally as making interstate threats, and sentences have grown substantially: in 2025 a serial swatter responsible for more than 375 calls received four years in federal prison. Some police departments accept advance notice from people at elevated risk, flagging the address in dispatch systems so a call is treated with extra scrutiny.

Understanding the terms is step one. Let us do the removal.

No spam. One email when Delist My Data opens for your area.