Identity Theft

Identity theft is the unauthorized acquisition and use of someone else’s personal information for financial or other gain. The term is used loosely, and one distinction matters more than the rest: the theft and the fraud are separate events, often separated by months or years, and almost everything that determines the outcome happens in between.

The theft Acquisition of personal data — breach, phishing, skimming, physical theft
The fraud Use of that data to obtain credit, benefits, services or access
Typical gap Months to years
Existing account fraud Misuse of accounts the victim already holds
New account fraud Accounts opened in the victim’s name
Other variants Medical, tax, employment and criminal identity theft
Usual discovery A credit rejection, a collections letter, or a rejected tax return
Why it recurs Data cannot be recalled once it circulates

Theft and fraud are different events

Conflating them produces the wrong mental model of the problem and the wrong controls.

The theft is a data event, and it usually happens somewhere the victim has no relationship with and no control over. A retailer is breached, a payroll provider is compromised, a phishing message succeeds. The victim did nothing and frequently never learns of it.

The fraud is a decision event. Someone presents that data to an institution, and the institution approves or declines. It might be a week later or three years later, and the same data can be used repeatedly by different parties, because it was sold rather than consumed.

The consequence is worth stating plainly: the institution that decides is never the institution that leaked. Breach response cannot prevent the fraud, and the lender approving the application has no visibility into how the applicant obtained the data. Everything defensive has to happen at the point of the decision.

The variants, and where each is caught

Variant What is obtained How the victim usually finds out
Existing account Access to accounts the victim already holds A statement, or the institution’s own alert
New account Credit or services in the victim’s name A rejection or a collections letter, months later
Medical Treatment or prescriptions Billing, or errors in their own medical record
Tax A fraudulent refund Their genuine return is rejected as a duplicate
Employment Work under the victim’s identifiers Unexplained income on a tax record
Criminal A false identity given on arrest A background check, or a warrant

The pattern down the third column is the important one. Existing account fraud is discovered quickly; everything else is discovered late, by accident, through a consequence rather than a notification. By then the damage is administrative as well as financial, and the burden of correction falls on the victim.

Why this matters for identity verification

The defense is not protecting data. That has been tried, the data is already circulating, and a control resting on an attacker not knowing a static fact about someone has been failing for years — which is the argument set out under dark web pricing.

The defense is at the decision. When an application arrives carrying correct personal data, the question is not whether the data matches — it will, because it is real — but whether the person presenting it is the person it describes. Bureau and database checks cannot answer that. They confirm the data is accurate, which is exactly what the attacker is relying on.

An authenticated identity document bound to a live face asks something stolen data cannot answer, and it is the only control positioned to distinguish a victim’s genuine application from a fraudster using their details. That is why identity document verification at account opening determines whether new account fraud succeeds, and why synthetic and stolen identity controls exist as a category separate from data protection.

The second point matters to institutions for a reason beyond loss. The victim of new account fraud is not the institution’s customer — they are someone whose life is disrupted by a decision the institution made, and who spends months correcting it. The control that prevents the loss is the same one that prevents that harm.

What controls can’t do

Data cannot be recalled. Once circulating it is copied indefinitely, so breach notification is information rather than remedy.

Monitoring detects, it does not prevent. Credit monitoring tells a victim that something has already happened.

Data matching confirms the data. Every identifier belongs to a real person, which is precisely why the check passes.

Freezes protect credit only. A credit freeze does nothing about medical, tax, employment or criminal identity theft.

Frequently asked questions

What is the difference between identity theft and identity fraud?

Identity theft is the acquisition of someone’s personal information; identity fraud is the use of it to obtain credit, services or benefits. They are separate events, frequently separated by months or years, and the institution that decides on an application is never the one that leaked the data.

How do people usually discover identity theft?

Late, and by accident. Existing account misuse surfaces quickly through statements or alerts. New account fraud typically surfaces as a credit rejection or a collections letter months later; tax identity theft surfaces when a genuine return is rejected as a duplicate.

Does a credit freeze prevent identity theft?

It prevents new credit being opened while the freeze is in place, which addresses one variant. It does nothing about medical identity theft, tax refund fraud, employment identity theft or criminal identity theft, all of which use the same stolen data through different channels.

Why can’t data checks stop identity theft?

Because the data is genuine. When an application carries a real person’s correct name, date of birth and identification number, matching it against bureau records confirms accuracy rather than entitlement. Establishing that the applicant is the person the data describes requires document and biometric evidence.

Related reading

  • New account fraud — where stolen identity data is most damagingly used
  • Fullz — the packaged form stolen identity data is sold in
  • Dark web — the market, and what its pricing implies for controls
  • Tax fraud — the refund variant, and how victims discover it

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data