How to Prevent Identity Theft: 12 Steps That Actually Work
Most identity theft is preventable. Not all of it — data breaches at companies you do business with are largely outside your control, and a determined, sophisticated thief who has already acquired your information can be difficult to stop completely. But the vast majority of identity theft victims could have significantly reduced their risk — or prevented it entirely — with the steps in this guide.
These twelve steps are listed roughly in order of effectiveness. If you do nothing else, do Step 1. If you complete all twelve, you will have meaningfully reduced your exposure to the most common forms of identity theft and put yourself in a position to catch any breach quickly before major damage is done.
—
Step 1 — Freeze Your Credit (The Single Most Effective Step)
A credit freeze, also called a security freeze, is a free tool that locks your credit file at each of the three major credit bureaus — Equifax, Experian, and TransUnion. When your credit is frozen, no new credit can be opened in your name, even if a lender has your Social Security number, date of birth, and all other required information.
It doesn’t affect your credit score. It doesn’t prevent you from using existing credit cards or accounts. It doesn’t stop your current creditors from seeing your file. It simply prevents new accounts from being opened.
To freeze your credit, you must contact each bureau individually — a freeze at Equifax does not automatically freeze Experian or TransUnion:
– Equifax: equifax.com/personal/credit-report-services/credit-freeze/
– Experian: experian.com/freeze/center.html
– TransUnion: transunion.com/credit-help/freeze-credit
Each freeze takes about 5–10 minutes online and is free by law (under the Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018).
When you need to apply for new credit, you can temporarily unfreeze (or “thaw”) your file at one or all bureaus — the process takes a few minutes online — and refreeze after your application is processed.
If you have children under 16, freeze their credit too. See our Child Identity Theft guide for the specific process.
—
Step 2 — Place a Fraud Alert
A fraud alert is a lighter-touch alternative or supplement to a credit freeze. When a fraud alert is on your file, any lender who pulls your credit is required to take extra steps to verify your identity before extending credit. An initial fraud alert lasts one year; an extended alert (for confirmed victims) lasts seven years.
Unlike a credit freeze, you only need to contact one bureau — they’re required to notify the other two.
A fraud alert is useful if you need new credit soon (a freeze would complicate applications) or as an additional layer on top of a freeze. It is not a substitute for a freeze if full protection is your goal.
—
Step 3 — Use Unique Passwords for Every Account
Password reuse is one of the most common doors through which identity thieves enter your financial life. When any company you use is breached and your email/password combination is exposed, thieves try those credentials on every major financial site, email provider, and social network. This attack — called “credential stuffing” — is highly automated and extremely effective against people who reuse passwords.
The solution is a password manager — an app that generates and securely stores a unique, complex password for every site you use. You remember one master password; the manager handles everything else.
Reputable password managers include Bitwarden (free, open-source), 1Password, and Dashlane. All of your existing passwords can be imported and updated systematically.
Your most critical passwords — email, banking, Social Security Administration account, IRS account — should be long (16+ characters), randomly generated, and unique to those sites.
—
Step 4 — Enable Two-Factor Authentication on Every Account That Supports It
Two-factor authentication (2FA) requires a second form of verification — beyond just a password — to access an account. Even if a thief has your password, they cannot get in without the second factor.
Enable 2FA on:
– Your primary and secondary email accounts
– Every financial account (bank, brokerage, credit cards)
– Your SSA.gov account
– Your IRS.gov account
– Your tax preparation software
– Any account that stores personal information
The strongest 2FA uses an authenticator app (Google Authenticator, Authy, or Microsoft Authenticator) rather than SMS text messages — SMS can be intercepted through SIM-swapping attacks. Use app-based 2FA where possible.
—
Step 5 — Monitor Your Credit Reports Weekly
You are entitled to free weekly credit reports from all three bureaus at AnnualCreditReport.com (a policy established permanently after 2020). Check your reports regularly — the same way you check your bank account — and look for:
– New accounts you didn’t open
– Hard inquiries from lenders you didn’t contact
– Addresses you don’t recognize associated with your file
– Unexpected changes in your balance or payment history
– Accounts in collections you don’t recognize
Many credit cards and banks also offer free credit score monitoring with alerts for significant changes. Enable every alert your financial institutions offer.
—
Step 6 — Shred Documents Containing Personal Information
Dumpster diving — physically searching through discarded mail and documents for personal information — remains a real and low-tech identity theft vector.
Documents that should be shredded before disposal:
– Bank and credit card statements
– Pre-approved credit card offers
– Medical bills and insurance documents (EOBs)
– Tax documents and anything with your SSN
– Old checkbooks and voided checks
– Pay stubs
– Investment statements
Use a cross-cut or micro-cut shredder, not a strip-cut model. Strip-cut shredders produce long strips that can be reassembled with patience. Cross-cut shredders produce confetti.
—
Step 7 — Guard Your Social Security Number
Your SSN is the master key to most forms of identity theft. Protecting it deserves specific attention:
Do not carry your Social Security card in your wallet. There is almost no situation in daily life that requires you to present your physical card. Store it at home in a secure location.
Question every request for your SSN. Medical offices, landlords, schools, and businesses often ask for your SSN as a habit when they don’t actually need it. Legitimate mandatory uses include: employers (for tax purposes), financial institutions (for credit applications), and government agencies (for legally required reporting). For everything else, ask why it’s needed and whether an alternative identifier can be used.
Never provide your SSN over the phone unless you initiated the call. If someone calls you and asks for your SSN — even if they claim to be from the IRS, Social Security Administration, or your bank — hang up and call the institution’s official number directly.
—
Step 8 — Secure Your Mailbox
Physical mail theft is a persistent identity theft vector, particularly for:
– New credit cards and debit cards
– Bank and brokerage statements
– Tax documents (W-2s, 1099s)
– Pre-approved credit offers
– Checks (personal, government, insurance settlements)
– Medicare cards and insurance documents
Consider a locking mailbox if you currently have an unlocked curbside box. If your building has centralized mailboxes, ensure your box locks and report any tampering to building management.
Consider going paperless for all financial statements and bills. Electronic delivery eliminates the risk of mail theft for those documents.
Use USPS Informed Delivery (informeddelivery.usps.com) — a free service that emails you a daily digest of incoming mail, so you know if something expected doesn’t arrive.
—
Step 9 — Use a VPN on Public Wi-Fi Networks
Public Wi-Fi networks in coffee shops, hotels, airports, and libraries are not encrypted and can be monitored by anyone on the same network. A technique called a “man-in-the-middle” attack allows a thief on the same network to intercept data traveling between your device and the sites you visit.
Never access bank accounts, email, or any sensitive site on an unsecured public network without a VPN. A VPN (Virtual Private Network) encrypts your connection and routes it through a secure server, making interception impractical.
Reputable VPN services include NordVPN, ExpressVPN, Mullvad, and ProtonVPN. Avoid free VPNs — many monetize by logging and selling your browsing data, which is the opposite of the privacy you’re seeking.
—
Step 10 — Learn to Recognize Phishing Attempts
Phishing — fraudulent emails, text messages, and phone calls designed to trick you into surrendering personal information — is now the leading vector for identity theft. The attacks have become increasingly sophisticated, with realistic-looking emails that closely mimic legitimate communications from banks, the IRS, Amazon, PayPal, USPS, and dozens of other trusted sources.
Warning signs of phishing:
– Unexpected urgency (“Your account will be closed in 24 hours”)
– Requests for personal information via email or text
– Links that don’t match the supposed sender’s actual domain
– Sender email addresses that are slightly misspelled or use generic domains
– Attachments you weren’t expecting
– Requests for payment by gift card, wire transfer, or cryptocurrency
When in doubt, do not click. Go directly to the company’s official website by typing the address manually and log in there to check any purported issues.
→ Complete phishing guide: https://www.scammed.org/phishing/
—
Step 11 — Set Up Account Alerts at Your Bank and Credit Card Issuers
Most banks and credit card companies offer free real-time transaction alerts — notifications sent to your phone or email when specific types of activity occur on your account:
– Any transaction above a set amount (set yours to $1 to catch everything)
– International transactions
– Online or card-not-present transactions
– ATM withdrawals
– New payees added to bill pay
– Login from a new device
Enable every alert your financial institutions offer. The goal is to know about unauthorized activity the moment it happens — not when you review a monthly statement weeks later.
—
Step 12 — Consider an Identity Theft Protection Service
Identity theft protection services — including LifeLock, Aura, Experian IdentityWorks, and others — provide ongoing monitoring of your personal information across credit bureaus, the dark web, court records, and other databases, alerting you when your information appears somewhere it shouldn’t.
They do not prevent identity theft, but they can significantly shorten the detection window — which is the most important variable in limiting damage.
These services are most valuable for:
– People who’ve already been victims of identity theft
– People whose SSN or personal information was exposed in a known data breach
– Seniors who may not independently monitor their credit
– People with significant assets to protect
– Parents who want ongoing monitoring for their children’s SSNs
→ Full comparison: https://www.scammed.org/identity-theft/protection-services/
—
How to Protect Children From Identity Theft
Children are among the most frequently targeted victims because their SSNs are clean and unmonitored. The single most effective step for parents is to freeze each child’s credit at all three bureaus as early as possible — the process is straightforward, free, and provides complete protection against new account fraud.
In addition:
– Monitor your child’s SSN in any identity protection service you use
– Be cautious about where you provide your child’s SSN (it is rarely required by schools or medical offices — always ask)
– Teach older children about phishing and password hygiene as they begin using online accounts
→ Full guide: https://www.scammed.org/identity-theft/types/child/
—
How to Protect Seniors From Identity Theft
Adults over 65 are disproportionately targeted for specific types of identity theft — particularly Social Security fraud, Medicare fraud, grandparent scams, and phone-based impersonation attacks. In addition to all 12 steps above:
– Help aging parents or relatives set up account alerts and credit freezes
– Review their SSA earnings record and Medicare EOBs together periodically
– Discuss phishing and impersonation scams — particularly the IRS and SSA impersonation calls that disproportionately target seniors
– Consider an identity protection service with a dedicated senior plan
→ Full guide: https://www.scammed.org/seniors/
—
Frequently Asked Questions
Q: What is the most effective way to prevent identity theft?
A: Freezing your credit at all three bureaus — Equifax, Experian, and TransUnion — is consistently ranked the most effective single step. It prevents new accounts from being opened in your name regardless of what other information a thief has.
Q: Does a credit freeze hurt my credit score?
A: No. A credit freeze has no effect on your credit score. It doesn’t prevent existing creditors from accessing your file or affect your ability to use current credit accounts.
Q: Can identity theft still happen if I do all 12 steps?
A: These steps significantly reduce your risk but cannot guarantee complete protection. Data breaches at companies you’ve legitimately shared information with are outside your individual control. The goal is to make theft harder to execute and faster to detect.