What Is Identity Theft? A Plain-English Definition
Identity theft is the crime of stealing another person’s personal information and using it without their permission — almost always to commit fraud, gain financial benefits, or avoid legal consequences.
It is not, as many people assume, a crime that only happens to careless people or to the very wealthy. It is one of the most common crimes in America, affecting more than a million people every year across every age group, income level, and walk of life. And in the majority of cases, victims had no idea it was happening until significant damage had already been done.
This article explains exactly what identity theft means, how it works at a practical level, the most common real-world examples, and what distinguishes identity theft from related crimes like fraud or data breaches.
—
The Legal Definition of Identity Theft
Under the Identity Theft and Assumption Deterrence Act of 1998 — the primary federal law governing identity theft in the United States — identity theft is defined as knowingly transferring, possessing, or using, without lawful authority, a means of identification of another person with the intent to commit, or to aid or abet, or in connection with, any unlawful activity.
In plain language: stealing someone’s identifying information and using it to do something illegal.
Federal penalties for identity theft can reach up to 15 years in prison for basic identity theft, and up to 30 years if the crime involves terrorism, drug trafficking, or certain other serious offenses. Aggravated identity theft — where your identity is used in connection with a specific serious crime — carries a mandatory additional two-year sentence on top of any other penalties.
Every state also has its own identity theft laws, most of which carry significant criminal penalties.
—
How Identity Theft Actually Happens — Step by Step
Understanding the mechanics helps you understand what to protect. Here is how a typical identity theft plays out:
Step 1: The thief acquires your personal information.
This can happen in dozens of ways — a data breach at a company you use, a phishing email you click, a skimmer on an ATM or gas pump, mail theft, a lost or stolen wallet, or even someone close to you who has access to your documents. Sometimes it’s as low-tech as someone looking over your shoulder while you enter a PIN.
Step 2: The thief verifies the information is usable.
Before committing to large-scale fraud, many thieves test the stolen data — making a small purchase on a stolen card number, or checking whether a Social Security number returns a valid credit file.
Step 3: The thief commits fraud using your identity.
Depending on what information they have, this could mean opening new credit cards, taking out loans, filing a tax return, getting a job, receiving medical care, or giving your name to police.
Step 4: You discover the theft — often much later.
The average victim of identity theft doesn’t discover the crime for months. In some cases, particularly with child identity theft, it can be years before the theft is detected.
Step 5: You begin the recovery process.
This involves reporting the theft to the FTC, placing fraud alerts and credit freezes, disputing fraudulent accounts, and potentially filing a police report. Recovery can take anywhere from weeks to years.
—
The Most Common Ways Thieves Steal Your Information
Data Breaches
When companies you do business with are hacked, your stored personal information — email, passwords, Social Security numbers, credit card numbers — can end up for sale on the dark web. Major breaches (Equifax in 2017, which exposed 147 million people; the National Public Data breach in 2024, which exposed 2.9 billion records) have put enormous amounts of personal data into criminal hands.
Phishing
Phishing emails, text messages, and phone calls trick you into voluntarily handing over your personal information — by impersonating your bank, the IRS, Amazon, PayPal, or another trusted source. Phishing is now the leading delivery mechanism for identity theft. → See: What Is Phishing? (https://www.scammed.org/phishing/)
Mail Theft
Pre-approved credit card offers, tax documents, bank statements, new debit cards, and checks are all valuable to identity thieves. Physical mail theft remains a significant vector, particularly in apartment buildings and areas with accessible mailboxes.
Skimming Devices
Small devices attached to ATMs, gas pumps, and payment terminals can read and store your card information when you swipe. Modern skimmers are nearly invisible to the untrained eye.
Dumpster Diving
Bank statements, medical bills, pre-approved offers, and other discarded documents with personal information are a low-tech but effective source of data for thieves.
Synthetic Identity Fraud
A sophisticated form of identity theft where a thief combines your real Social Security number with fabricated information (a fake name, fake date of birth) to create a brand-new synthetic identity that has no real victim to notice the fraud. It is particularly difficult to detect.
Insider Theft
Someone with legitimate access to your information — an employee at a hospital, a financial institution, a government agency — misuses that access to steal your data. This is more common than most people realize.
—
Real-World Examples of Identity Theft
Example 1: The New Credit Card
You pull your credit report and find three credit cards you never opened, all maxed out, with addresses linked to an apartment across the country. Your SSN was purchased in a data breach two years ago and a thief finally used it to establish new lines of credit.
Example 2: The Rejected Tax Return
You sit down to file your taxes in February and the IRS rejects your return — a return has already been filed under your Social Security number. The refund went to a prepaid debit card. You are now a victim of tax identity theft.
Example 3: The Medical Bill
You receive an EOB (Explanation of Benefits) from your health insurer for a three-day hospital stay you never had. Someone used your insurance information to receive medical care. Your medical records now include blood type, medications, and diagnoses that aren’t yours.
Example 4: The Warrant
You are pulled over for a routine traffic stop and the officer tells you there is an outstanding warrant for your arrest — for a crime committed in a state you’ve never been to. Someone gave your name and ID information when they were arrested.
Example 5: The College Application
Your 18-year-old applies for a student loan and discovers they have a credit history going back to when they were six years old — with late payments, collections, and maxed-out accounts. Their SSN was stolen and used for years while they were a child.
—
Identity Theft vs. Identity Fraud — What’s the Difference?
These terms are often used interchangeably, but they technically describe different things.
Identity theft is the act of stealing someone’s personal information.
Identity fraud is what happens when that stolen information is used to commit a crime.
You can be a victim of identity fraud without your identity being “stolen” in the traditional sense — for example, if someone intercepts a single credit card transaction and uses the card number to make purchases, that’s card fraud, not necessarily full identity theft.
True identity theft involves the theft and ongoing use of your core identifying credentials — your Social Security number, name, date of birth — to impersonate you across multiple contexts.
—
How Long Does Identity Theft Last?
This depends heavily on the type of theft and how quickly it’s caught.
Financial identity theft, if caught early, can often be resolved within a few weeks to a few months by freezing credit, filing disputes, and closing fraudulent accounts.
Tax identity theft typically takes six months to a year to resolve, as it involves the IRS’s internal review process.
Criminal identity theft can take years to clear from public records, and may require a court order.
Medical identity theft is among the most difficult to resolve, as it involves correcting records across multiple healthcare providers and insurers.
The single most important factor in recovery time is how quickly the theft is discovered. Every month a thief operates undetected means more accounts to dispute, more creditors to contact, and more damage to undo.
—
Related Reading
– The 6 Types of Identity Theft: https://www.scammed.org/identity-theft/types/
– 10 Warning Signs of Identity Theft: https://www.scammed.org/identity-theft/warning-signs/
– How to Prevent Identity Theft: https://www.scammed.org/identity-theft/how-to-prevent/
– Identity Theft Prevention — Complete Guide (Pillar): https://www.scammed.org/identity-theft/