The Complete Guide to Identity Theft and Account Security
How identity theft and account takeover happen, the sign-in methods that stop them, what to do after a data breach, and how to recover if it happens.

It starts with a password reset email you did not ask for. Then another. An hour later you cannot sign in to your email at all, and friends start asking why you sent them a strange link. By the evening, someone has used your email to reset your social media, your shopping account and your cloud storage. You never clicked anything suspicious; your password simply matched one leaked from a website you had forgotten you used.
Account takeover and identity theft have become everyday crimes because so much of our lives now depends on a handful of logins, and because personal details leak constantly through data breaches, phishing and oversharing.
This guide explains how identity theft and account takeover happen, which sign-in methods actually stop them, how to protect your email, phone number and documents, what to do after a data breach, how to spot the warning signs, and how to recover if the worst happens. The advice applies wherever you live, with pointers to reporting services in several countries.
Identity theft and account takeover: what they are
- Account takeover: someone gets into an account you already have, such as email, banking, social media or a messaging app, and uses it as if they were you.
- Identity theft or identity fraud: someone uses your personal details, such as your name, date of birth, ID numbers or address, to pretend to be you, for example to open accounts, take loans, claim refunds or pass checks.
The two are often connected. A taken-over email account reveals documents and details that make identity fraud easier, and stolen identity details help attackers pass the security questions that protect accounts.
How criminals get your details
- Data breaches: a company you used is hacked and its customer data leaks, sometimes including passwords.
- Password reuse: attackers try leaked email and password pairs on other sites automatically. If you reused the password, they get in.
- Phishing: fake sign-in pages and messages collect passwords and codes. See our complete guide to phishing.
- Malware: malicious apps and files that steal saved passwords and session cookies from your device.
- Oversharing: birthdays, pets' names, schools, addresses and photos of documents posted online.
- SIM swap: your phone number is moved to a criminal's SIM so they receive your codes. Read SIM swap fraud.
- Physical theft: stolen phones, wallets, post and documents thrown away without shredding.
Why your email is the master key
Almost every online account lets you reset its password by email. That makes your main email account the single most valuable thing to protect: whoever controls it can reset and take over most of your other accounts, read your receipts and documents, and impersonate you to your contacts.
If you do nothing else after reading this guide, give your main email account a unique password or a passkey, turn on the strongest two-step verification it offers, and check its recovery settings.
Passwords that actually protect you
Password advice has changed. The US National Institute of Standards and Technology's current guidance says services should not force people to change passwords on a schedule or impose rules about mixing character types, and that passwords used on their own should be at least 15 characters long. The UK's National Cyber Security Centre recommends combining three random words.
- Length beats complexity. copper-lantern-mango is far stronger than P@ssw0rd1, and easier to remember.
- Never reuse a password. This matters more than anything else about passwords.
- Use a password manager to create and remember a different password for every account. You then only need to remember one strong passphrase.
- Change a password when there is a reason: a breach, a phishing mistake or suspicious activity.
For a team-focused version, see passwords your staff will remember and attackers won't guess.
Two-step verification, ranked
Two-step verification (also called multi-factor authentication) means a stolen password alone is not enough. Not all methods are equal.
| Method | Strength | Weakness |
|---|---|---|
| Passkey | Strongest for most people. Tied to the real website, so it cannot be phished | Not yet offered by every service |
| Physical security key | Very strong and phishing-resistant | Costs money; keep a backup key |
| Authenticator app code | Strong and widely available | Codes can still be typed into a fake page |
| Push approval with number matching | Convenient and fairly strong | People can be pressured into approving; see MFA fatigue |
| Text message code | Much better than nothing | Vulnerable to SIM swap and phishing |
Use the strongest option each account offers, starting with email, banking, mobile money, cloud storage and social media.
Account recovery settings: the forgotten back door
Attackers often go around your password by abusing the recovery process. Check these settings on your important accounts:
- Recovery email and phone number are current and belong to you.
- Backup codes are saved somewhere safe, such as your password manager or a printed copy at home.
- Security questions do not have guessable answers. Your mother's maiden name or first school may be findable online; use a random answer stored in your password manager instead.
- Trusted devices and active sessions are ones you recognise. Sign out of anything unfamiliar.
After a data breach
If a company tells you your data was exposed, or you find your email address on a breach-checking service such as Have I Been Pwned:
- Change the password for that service, and for any other account where you used the same one.
- Turn on two-step verification if it was not already on.
- Expect targeted phishing. Criminals use leaked details to make messages convincing, including messages pretending to be from the breached company.
- If ID numbers, bank or card details were exposed, tell your bank, watch your statements and consider a credit freeze or fraud alert where available.
Protecting your phone, devices and documents
Your phone and number
- Use a screen lock and turn on "find my device" so you can locate or wipe a lost phone.
- Ask your mobile network about a SIM PIN or extra protection against SIM changes.
- Keep the phone and apps updated, and install apps only from official stores.
Your identity documents
- Share copies of passports, ID cards and bank statements only when necessary, and ask why they are needed.
- When you must send a copy, add a watermark such as "Copy for [company] account opening, [date]" so it is less useful if leaked.
- Shred documents with personal details before throwing them away.
- Never post photos of tickets, boarding passes, ID or cards on social media.
Your financial identity
In some countries you can stop criminals opening credit in your name. In the United States, a credit freeze blocks lenders from checking your credit file, and fraud alerts ask them to verify your identity first. In the United Kingdom, Cifas Protective Registration asks member organizations to carry out extra checks on applications in your name. Elsewhere, ask your bank and national credit bureau what protections exist.
Oversharing: what not to post
Many identity checks still rely on facts about you, and social media hands those facts to anyone who looks. Before posting, think about what a stranger could do with it.
- Birthdays, full names and hometowns answer common security questions and help fill in application forms.
- Photos of documents, cards, tickets and boarding passes can contain numbers and barcodes that are useful to criminals.
- Holiday posts in real time tell people your home is empty and that you may be hard to reach for verification.
- Quizzes and games that ask your first pet or first car are sometimes built to collect security answers.
Review your privacy settings so that only people you know can see personal details, and keep public profiles minimal.
If your phone is lost or stolen
A phone holds your email, banking apps, codes and photos of documents, so treat its loss as an account security incident.
- Lock or wipe it remotely using your phone maker's "find my device" service.
- Call your mobile network to block the SIM, so the number cannot receive your codes.
- Call your bank and mobile money provider to block app access and cards stored on the phone.
- Change your email password from another device and sign the lost phone out of your accounts.
- Report the theft to the police if it was stolen, and keep the reference number.
Protecting children's and older relatives' identities
Children's details are sometimes misused for years before anyone notices, because nobody checks a child's credit record. Older relatives are often targeted because scammers expect them to trust a confident caller.
- Share children's details sparingly, with schools, clubs and apps that genuinely need them.
- Help older relatives set up two-step verification, a password manager or a simple written system kept at home, and saved official contact numbers.
- Agree a family rule that nobody ever shares a code, PIN or password, whoever asks.
Warning signs your accounts or identity are being misused
| Sign | What it may mean |
|---|---|
| Password reset or sign-in alerts you did not trigger | Someone is trying to get into the account, or already has |
| Sent messages or posts you did not write | The account has been taken over |
| New forwarding rules or unknown devices in settings | An attacker has quietly kept access |
| Your phone suddenly has no service | Possible SIM swap |
| Letters or emails about accounts or loans you never opened | Identity fraud |
| Unexpected debt collection calls | Credit taken in your name |
| Refused credit or a sudden change in your credit record | Applications made in your name |
Illustrative examples, with the red flags explained
These examples are fictional and written for this guide. Links have been broken on purpose so they cannot be clicked.
hxxps://account-security-review[.]com/secure- Alarm designed to make you click fast, and a link to "secure" your account.
- An address that does not belong to your email provider.
- What to do: open the app or type the website address yourself and check your security settings and recent activity there.
- Codes you did not ask for mean someone has your password and is trying to sign in.
- No genuine company asks you to read a code back.
- What to do: never share the code. Change your password from a trusted device and check the account's security settings.
- You made no application, and the money went to an account that is not yours.
- What to do: contact the lender using contact details from its official website, not this message, report identity fraud, and tell your bank.
Unsure whether an alert is real? Paste it into CyberWatch AI Scan for a free second opinion. Then check your account directly in the official app or website, which is always the safest confirmation.
How to recover a taken-over account
- Start with your email. Use the provider's official recovery process from a clean device, then set a new unique password and the strongest two-step verification available.
- Sign out everywhere and remove unfamiliar devices, apps and forwarding rules.
- Work outwards: change passwords on accounts that reset through that email, starting with banking, mobile money and social media.
- Warn your contacts through another channel that messages from the account may not be from you.
- Check your devices for malware if you cannot explain how the account was taken.
- Keep a log of what happened, when, and who you contacted.
How to respond to identity fraud
- Contact the organization where the fraudulent account or loan was opened, using its official contact details, and ask for it to be closed and flagged as fraud.
- Tell your bank and check all your accounts for unfamiliar activity.
- Report the identity theft. In the United States, IdentityTheft.gov creates a recovery plan. In England, Wales and Northern Ireland, report to Report Fraud. Elsewhere, report to the police and your national fraud or cybercrime service; our online scams guide lists several.
- Protect your credit file with a freeze, fraud alert or protective registration where available.
- Replace compromised documents if ID numbers or documents were stolen.
- Keep records of reports, reference numbers and conversations. You may need them for months.
A quarterly account security checkup
- Two-step verification is on for email, banking, mobile money, cloud storage and social media.
- Recovery email, phone and backup codes are current.
- No unknown devices, sessions or connected apps on key accounts.
- No passwords reused; your password manager's security report is clean.
- Your email address has been checked against breach notifications.
- Phone, computer and apps are updated.
Account security at work
Work accounts are high-value targets because one login can reach company email, files and payments. Organizations should enforce two-step verification, move administrators and finance staff to phishing-resistant sign-in, remove access promptly when people leave, and make it easy to report a suspicious sign-in prompt. Our guide to small business cybersecurity covers accounts and access for teams, and CyberWatch AI helps organizations train staff to recognise the phishing and social engineering that lead to account takeover.
Common myths about account security
- "Nobody would want my account." Every account has value: for sending scams to your contacts, for resale or as a route to your other accounts.
- "A complex eight-character password is strong." Length and uniqueness matter more than symbols.
- "Text codes make me safe." They help, but SIM swap and phishing can defeat them. Passkeys are stronger.
- "I'd know if I'd been hacked." Attackers often stay quiet, reading email and watching for payments.
- "Security questions protect me." Only if the answers cannot be found or guessed.
Frequently asked questions
What is the difference between identity theft and account takeover?
Account takeover is when someone gets into an account you already have, such as your email or bank. Identity theft is broader: using your personal details to pretend to be you, for example to open new accounts, take loans or claim benefits in your name.
What is the most important account to protect?
Your main email account. Most other accounts reset their passwords through email, so whoever controls it can take over almost everything else. Give it a unique password or passkey and the strongest two-step verification it offers.
Do I need to change my passwords regularly?
Not on a schedule. Current US government guidance from NIST says services should not force periodic changes. Change a password when there is a reason, such as a breach, a phishing mistake or signs of misuse.
What makes a strong password?
Length and uniqueness. A long passphrase, such as three or more random words, is stronger and easier to remember than a short complex one. Use a different password for every account, which is practical only with a password manager.
Which type of two-step verification is best?
Passkeys and physical security keys are the strongest because they cannot be used on fake sites. Authenticator apps are next. Text-message codes are better than nothing but can be intercepted through SIM swap or phishing.
My details were in a data breach. What should I do?
Change the password for that service and anywhere you reused it, turn on two-step verification, and watch for phishing that uses the leaked details. If financial or identity documents were exposed, consider a credit freeze or fraud alert where available and monitor your accounts.
How do I know if my email has been hacked?
Signs include password reset emails you did not request, messages in your sent folder you did not write, contacts receiving strange messages, new forwarding rules, and security alerts about unfamiliar devices or locations.
What is a credit freeze?
In some countries, including the US, you can ask credit bureaus to freeze your credit file so new lenders cannot check it, which blocks most new accounts being opened in your name. Availability and names vary by country; the UK, for example, has Cifas Protective Registration.
Someone opened an account in my name. Where do I report it?
Contact the company where the account was opened, then report the identity theft. In the US use IdentityTheft.gov; in England, Wales and Northern Ireland use Report Fraud; elsewhere report to the police and your national fraud or cybercrime service, and tell your bank.
Can CyberWatch AI tell me if a security alert email is real?
You can paste a suspicious security alert or its link into CyberWatch AI Scan for free, and it will explain what looks suspicious. For account alerts, the safest check is always to open the app or website yourself and look at your security settings.
Sources
- IdentityTheft.gov, US Federal Trade Commission
- What To Know About Credit Freezes and Fraud Alerts, US Federal Trade Commission
- Digital Identity Guidelines: Authentication (SP 800-63B), US National Institute of Standards and Technology
- Three random words, UK National Cyber Security Centre
- Turn on 2-step verification for your email, UK National Cyber Security Centre
- More than a password (multifactor authentication), US Cybersecurity and Infrastructure Security Agency
- Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
- Protective Registration, Cifas (UK)
- Have I Been Pwned, Troy Hunt


