Identity theft: what actually gets collected, and what it is used for
The word suggests something dramatic. The reality is administrative: enough fragments about you to convince an organisation that a stranger is you.
Nobody steals an identity in one move. They assemble one — a name from a breach, an address from a public record, a date of birth from a social post, a card number from a scam page. The defence is correspondingly unglamorous: make the fragments harder to join up.
The fragments that matter, and where they come from
Name and email arrive from data breaches, which are ordinary and frequent and not your fault. Date of birth is often volunteered: birthday posts, quizzes, a profile field nobody thought about. Address comes from public records or a delivery notification screenshot.
The card number is the part scams are for, and the one-time code is what turns a stolen password into an emptied account. Those last two are the only fragments a person actively hands over, which is why the habits below concentrate there.
Why a child’s identity is worth more
A child has no credit history to contradict a fraudulent application and nobody checking, which means an account opened in their name can run for years unnoticed. It typically surfaces at eighteen, when they apply for something ordinary and are refused.
The practical implication is narrow and worth acting on: a child’s date of birth, full name and address are not social-media material, and a school or club form is not a reason to publish them. That is rule three on the ten rules page, and this is the reason behind it.
What to do when a service you use is breached
Change the password there, and change it anywhere you reused it: reuse is what converts one breach into five compromised accounts. Start with the email account, because it is the reset route for everything else.
Then turn on two-factor authentication if it is offered. A breached password with a second factor in place is an inconvenience rather than an incident, and that is the whole of the difference.
Noticing early, without paying for it
The cheap version of monitoring is turning on transaction alerts with your bank and reading them. It is faster than any monthly report, and it is free.
Beyond that: check a credit report periodically where your country provides one free, and treat any unexpected letter about an account you did not open as urgent, not as junk. Speed is what limits the damage; almost nothing else does.
The version aimed at older adults
Older adults are targeted with the same fragments and a different script: a call from the bank’s fraud team, a refund that needs confirming, a family emergency. Reported losses in that group are large and rising, which is set out with the figures on the guidance for grandparents.
The countermeasure is the same single rule: nobody legitimate objects to being called back on a number you already have.
What you can require of the organisation involved
A fraudulent account is the organisation’s problem as much as yours, and it is worth approaching them on that footing. Ask them to confirm in writing that the account was opened fraudulently, to remove it from your record rather than merely close it, and to tell you what identity checks were used.
That last question is more useful than it sounds. If a name and a date of birth were sufficient, the failure was theirs, and saying so in writing tends to accelerate the correction.
Keep a dated log of every call: who you spoke to, what they undertook to do, and by when. Almost every case that drags on does so because the record lives only in a phone system, and a written record is what makes a correction stick.
What to do
- Do not publish a child’s full name, date of birth and address together.
- Use a different password for the email account than for anything else.
- Turn on two-factor authentication, email account first.
- Turn on bank transaction alerts and actually read them.
- After a breach, change the password there and anywhere it was reused.
- Treat an unexpected letter about an unknown account as urgent, not as junk.
Questions about identity theft
Is a paid identity-monitoring service worth it?
For most households, transaction alerts and a free credit check do the same job. The paid services notify you after the fact, which is what a bank alert also does, sooner.
My email address turned up in a breach. What now?
Change that password, and anywhere the same one was used. A breached address on its own is not the problem; a reused password is.
Should I freeze my child’s credit?
Where your country allows it, it is a low-cost precaution that closes the most damaging route. Availability varies, and it is worth asking instead of assuming.
How do birthday posts matter?
A date of birth is one of the three or four fields organisations use to confirm who you are. Published alongside a full name and a town, it removes a check that was doing real work.
What is the single most useful habit?
A unique password on the email account, protected by two factors. It is the reset route for every other account, which makes it the one worth over-protecting.
An account was opened in my name. Where do I start?
With the organisation that opened it, then your national fraud reporting body, and keep a dated record of every call. Written records are what make the correction stick.
Sources
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report · checked 2026-09-02
- Canadian Anti-Fraud Centre · checked 2026-09-02