The Identity Theft Resource Center (ITRC- https://www.idtheftcenter.org/) is a non-profit organization that educates the public on how to prevent identity theft in their lives and helps victims of identity theft to recover from crimes as a result of identity theft. As a result of its work, the ITRC collects data on identity theft. The ITRC periodically publishes reports based on this data.
The recently published 2026 Trends in Identity Report (TIR)
provides insights into how criminals steal identities and the effects those
thefts have on the lives of their victims.
Your Personal Identity Information (PII) can be compromised in one
of 5 ways,
·
Scams- Scams are the leading method of identity compromise at 36% of
all reported cases. This represents a 7% decrease compared to its 2025 TIR. The
report notes that scams require the victim’s participation for the criminal to
receive the PII. Criminals will use psychological techniques known as social
engineering to get the victim into an emotional state and to convince the victim
that they need to act often to pay some money and to give over their identity
information.
·
Unauthorized Device Access- This is where a cybercriminal inserts
malware that extracts information useful to the criminal into your PC, laptop,
tablet, or smart phone. A leading method for this type of attack is a phishing
email or text message. But malware can also be inserted into your device
through a website that you visit that may not be from a reputable company or
organization. 27% of all cases reported to ITRC involved unauthorized device
access, a 12% increase from the year before. Having access to your device gives
cybercriminals access to all of your personal information stored in it.
·
Physical Theft- Physical theft of a document or device (such as a smartphone,
laptop, or tablet computer) amounted to 16% of all cases reported. Documents that
are stolen and are the building blocks of an identity include driver’s licenses
and state ID’s (23%), Social Security cards (20%), credit and payment cards
(12%), and birth certificates (10%). Theft of phones and tablets, which can be
a treasure chest of personal information, was about (7%).
·
Data Breaches- This was 10% of all reported cases; a decline compared to last
year. The victim will not know about a data breach unless they are notified by
the holder of the data.
·
PII on the Dark Web- 4% of cases involved PII on the Dark Web. The Dark Web is
especially murky but often include purchases of stolen PII by people who use it
to perform criminal acts.
Now that the criminal has
your PII, what do they do with it?
·
Account Takeover- Cyber criminals often take over (or try to) one of your accounts.
Accounts that they often target include 1. Checking accounts, 2. Credit cards,
3. Email accounts, 4. Social media, 5. Cell phone accounts, 6. P2P payment
apps. While an account takeover is easiest to discover, this is where prevention
techniques become important such as Multifactor Authentication (MFA) or
passkeys to prevent unauthorized persons from entering your accounts. Frequently
monitoring your accounts can help you detect unusual account activity early.
·
New Account Fraud. If the criminal has enough information about you, they may open
a new account in your name. This can be a new credit card account, a loan, or
they sign a lease. The most common accounts that cybercriminals take out
include 1. Credit cards, 2. Checking accounts, 3. Personal loans, 4. Cell phone
accounts, 5. Auto loans, 6, Mortgage loans, 7. Federal student loans. The
victim often has no idea that a new account has been taken out in their name. If
there is discovery the method is more passive and takes longer, often weeks or
months after the act. The primary detection method is a notice, from usually a
financial institution, that alerts the victim that an account has been taken
out in their name. Regularly checking your credit reports can lead to
discovery. The most jarring discovery method is a notice from a collection
agency that you owe for unpaid bills. To prevent new account fraud, freeze your
credit with the 3 credit reporting agencies.
Some crimes just are not on the victim’s radar as far as
detection. There is no statement to review, no login to check, no balance to
monitor. The hardest crimes to detect include,
·
Fraudulent Employment. If someone applies for a job in your name you have no idea that they
have gained employment by impersonating you. You may discover this crime at
some point if you apply for a government benefit and learn that it has already
been claimed. Or you might learn that income has been reported under your SSN. Fraudulent
employment is the most common crime against children giving it a
disproportionate impact on kids. A child’s SSN is clean, making it most
valuable to criminals. Also, most parents and guardians are not checking their
child’s existing credit history or employment record. Therefore, a criminal can
use a child’s identity for years before being discovered.
·
IRS Misuse. This is where a criminal files an income tax return in the
victim’s name using the victim’s information. This victim most often finds out through
a notification from the IRS or another government agency. A few might find out when
they check on their account when an expected refund did not arrive or was
issued to an account that they did not recognize.
·
Criminal Identity Theft. If someone commits a crime then uses
your name when contacted by police, the discovery is a complete shock.
Discovery frequently comes with contact with police, such as during a traffic
stop. Others learn of the crime during a background check applying for a job.
Still others learn about it from an employer.
To effectively protect yourself from these crimes you need to use “layered
defenses;” that is steps that help you cover several situations. For example,
·
Credit report monitoring helps guard against new account fraud but
does not help with account takeover.
·
Account activity monitoring helps protect against existing account
takeover but not employment fraud.
·
Credit freezes prevent creation of a new account but does not help
with protecting existing accounts.
·
Using MFA or Passkeys protects against device compromise.
For more insights from the Trends in Identity report go to- https://www.idtheftcenter.org/wp-content/uploads/2026/06/The-2026-ITRC-Trends-in-Identity-Report.pdf
Identity Theft Resource Center:
https://www.idtheftcenter.org/