Identity theft: Difference between revisions

From Wikipedia, the free encyclopedia
Jump to navigation Jump to search
imported>MrOllie
Reverted 2 edits by PageVoyager (talk): Refspam
imported>Jameboy
moved identity theft titles to disambiguation page
 
Line 1: Line 1:
{{Short description|Deliberate use of someone else's identity}}
{{Short description|Deliberate use of someone else's identity}}
{{About|the concept of identity theft|the 2004 film|Identity Theft (film)|the 2013 film|Identity Thief|the 1953 film|Stolen Identity}}
{{About|the concept of identity theft|the 2013 film|Identity Thief|the 1953 film|Stolen Identity|other uses|}}


{{Multiple issues|
{{Multiple issues|
Line 7: Line 7:
}}
}}
[[File:Figure 2 Example of a Successful Identity Theft Refund Fraud Attempt (28356288536).jpg|thumb|upright=1.3|Example of an identity theft crime: 1. The fraudster files tax return paperwork in the victim's name, claiming a refund. 2. The IRS issues a refund to the fraudster. 3. The victim submits their legitimate tax return. 4. The IRS rejects the return as a duplicate.]]
[[File:Figure 2 Example of a Successful Identity Theft Refund Fraud Attempt (28356288536).jpg|thumb|upright=1.3|Example of an identity theft crime: 1. The fraudster files tax return paperwork in the victim's name, claiming a refund. 2. The IRS issues a refund to the fraudster. 3. The victim submits their legitimate tax return. 4. The IRS rejects the return as a duplicate.]]
'''Identity theft''', '''identity piracy''' or '''identity infringement''' occurs when someone uses another's personal identifying information, like their name, identifying number, or [[credit card number]], without their permission, to commit fraud or other crimes. The term ''identity theft'' was coined in 1964.<ref>{{cite web|date=September 2007|title=Oxford English Dictionary online|url=http://dictionary.oed.com/cgi/entry/50111220/50111220se23|access-date=27 September 2010|publisher=Oxford University Press}}</ref> Since that time, the definition of identity theft has been legally defined throughout both the UK and the [[United States|U.S.]] as the theft of personally identifiable information. Identity theft deliberately uses someone else's [[personally identifiable information|identity]] as a method to gain financial advantages or obtain credit and other benefits.<ref>Synthetic ID Theft [http://www.unc.edu/~dubal/idtheft/synthetic.htm Cyber Space Times] {{webarchive |url=https://web.archive.org/web/20151009122632/http://www.unc.edu/~dubal/idtheft/synthetic.htm |date=9 October 2015 }}</ref><ref>{{Cite SSRN |title=Identity Theft: Making the Known Unknowns Known |last=Hoofnagle|first=Chris Jay |date=13 March 2007 |ssrn = 969441}}</ref> The person whose identity has been stolen may suffer adverse consequences,<ref name="BloombergIdentityTheftEssay">{{cite news |author=Drew Armstrong | url=https://www.bloomberg.com/news/articles/2017-09-13/my-three-years-in-identity-theft-hell | title=My Three Years in Identity Theft Hell | newspaper=Bloomberg.com | publisher=Bloomberg | date=13 September 2017 | archive-url=https://web.archive.org/web/20170919142519/https://www.bloomberg.com/news/articles/2017-09-13/my-three-years-in-identity-theft-hell | archive-date=19 September 2017 | access-date=20 September 2017 }}</ref> especially if they are falsely held responsible for the perpetrator's actions. Personally identifiable information generally includes a person's name, date of birth, social security number, driver's license number, bank account or credit card numbers, [[Personal identification number|PINs]], [[electronic signature]]s, fingerprints, [[password]]s, or any other information that can be used to access a person's financial resources.<ref>See, e.g., {{cite web|title=Wisconsin Statutes, Sec. 943.201. Unauthorized use of an individual's personal identifying information or documents.|url=https://docs.legis.wisconsin.gov/statutes/statutes/943/III/201|website=Wisconsin State Legislature|access-date=19 July 2017}}</ref>
'''Identity theft''', '''identity piracy''' or '''identity infringement''' occurs when someone uses another's personal identifying information, like their name, [[National identification number|identifying number]], or [[credit card number]], without their permission, to commit fraud or other crimes. The term ''identity theft'' was coined in 1964.<ref>{{cite web|date=September 2007|title=Oxford English Dictionary online|url=http://dictionary.oed.com/cgi/entry/50111220/50111220se23|access-date=27 September 2010|publisher=Oxford University Press}}</ref> Since that time, the definition of identity theft has been legally defined throughout both the [[United Kingdom|UK]] and the [[United States|U.S.]] as the theft of personally identifiable information. Identity theft deliberately uses someone else's [[personally identifiable information|identity]] as a method to gain financial advantages or obtain credit and other benefits.<ref>Synthetic ID Theft [http://www.unc.edu/~dubal/idtheft/synthetic.htm Cyber Space Times] {{webarchive |url=https://web.archive.org/web/20151009122632/http://www.unc.edu/~dubal/idtheft/synthetic.htm |date=9 October 2015 }}</ref><ref>{{Cite SSRN |title=Identity Theft: Making the Known Unknowns Known |last=Hoofnagle|first=Chris Jay |date=13 March 2007 |ssrn = 969441}}</ref> The person whose identity has been stolen may suffer adverse consequences,<ref name="BloombergIdentityTheftEssay">{{cite news |author=Drew Armstrong | url=https://www.bloomberg.com/news/articles/2017-09-13/my-three-years-in-identity-theft-hell | title=My Three Years in Identity Theft Hell | newspaper=Bloomberg.com | publisher=Bloomberg | date=13 September 2017 | archive-url=https://web.archive.org/web/20170919142519/https://www.bloomberg.com/news/articles/2017-09-13/my-three-years-in-identity-theft-hell | archive-date=19 September 2017 | access-date=20 September 2017 }}</ref> especially if they are falsely held responsible for the perpetrator's actions. Personally identifiable information generally includes a person's name, date of birth, [[Social Security number|social security number]], [[driver's license]] number, bank account or credit card numbers, [[Personal identification number|PINs]], [[electronic signature]]s, [[Fingerprint|fingerprints]], [[password]]s, or any other information that can be used to access a person's financial resources.<ref>See, e.g., {{cite web|title=Wisconsin Statutes, Sec. 943.201. Unauthorized use of an individual's personal identifying information or documents.|url=https://docs.legis.wisconsin.gov/statutes/statutes/943/III/201|website=Wisconsin State Legislature|access-date=19 July 2017}}</ref>


Determining the link between [[data breach]]es and identity theft is challenging, primarily because identity theft victims often do not know how their personal information was obtained. According to a report done for the FTC, identity theft is not always detectable by the individual victims.<ref>Federal Trade Commission – 2006 Identity Theft Survey Report, p. 4</ref> [[Identity fraud]] is often but not necessarily the consequence of identity theft. Someone can steal or misappropriate personal information without then committing identity theft using the information about every person, such as when a major data breach occurs. A [[Government Accountability Office|U.S. Government Accountability Office]] study determined that "most breaches have not resulted in detected incidents of identity theft".<ref>{{cite web |url=http://www.gao.gov/new.items/d07737.pdf |title=Data Breaches Are Frequent, but Evidence of Resulting Identity Theft Is Limited; However, the Full Extent Is Unknown |work=Highlights of GAO-07-737, a report to congressional requesters |publisher=gao.gov |access-date=22 September 2010}}</ref> The report also warned that "the full extent is unknown". A later unpublished study by [[Carnegie Mellon University]] noted that "Most often, the causes of identity theft is not known", but reported that someone else concluded that "the probability of becoming a victim to identity theft as a result of a data breach is ... around only 2%".<ref>{{cite web |url=http://www.heinz.cmu.edu/research/241full.pdf |title=Do Data Breach Disclosure Laws Reduce Identity Theft? |author=Sasha Romanosky |work=Heinz First Research Paper |publisher=heinz.cmu.edu |access-date=2009-05-27 |archive-date=2012-01-20 |archive-url=https://web.archive.org/web/20120120001255/http://www.heinz.cmu.edu/research/241full.pdf |url-status=dead }}</ref> For example, in one of the largest data breaches which affected over four million records, it resulted in only about 1,800 instances of identity theft, according to the company whose systems were breached.{{citation needed|date=May 2021}}
Determining the link between [[data breach]]es and identity theft is challenging, primarily because identity theft victims often do not know how their personal information was obtained. According to a report done for the FTC, identity theft is not always detectable by the individual victims.<ref>Federal Trade Commission – 2006 Identity Theft Survey Report, p. 4</ref> [[Identity fraud]] is often but not necessarily the consequence of identity theft. Someone can steal or misappropriate personal information without then committing identity theft using the information about every person, such as when a major data breach occurs. A [[Government Accountability Office|U.S. Government Accountability Office]] study determined that "most breaches have not resulted in detected incidents of identity theft".<ref>{{cite web |url=http://www.gao.gov/new.items/d07737.pdf |title=Data Breaches Are Frequent, but Evidence of Resulting Identity Theft Is Limited; However, the Full Extent Is Unknown |work=Highlights of GAO-07-737, a report to congressional requesters |publisher=gao.gov |access-date=22 September 2010}}</ref> The report also warned that "the full extent is unknown". A later unpublished study by [[Carnegie Mellon University]] noted that "Most often, the causes of identity theft is not known", but reported that someone else concluded that "the probability of becoming a victim to identity theft as a result of a data breach is ... around only 2%".<ref>{{cite web |url=http://www.heinz.cmu.edu/research/241full.pdf |title=Do Data Breach Disclosure Laws Reduce Identity Theft? |author=Sasha Romanosky |work=Heinz First Research Paper |publisher=heinz.cmu.edu |access-date=2009-05-27 |archive-date=2012-01-20 |archive-url=https://web.archive.org/web/20120120001255/http://www.heinz.cmu.edu/research/241full.pdf }}</ref> For example, in one of the largest data breaches which affected over four million records, it resulted in only about 1,800 instances of identity theft, according to the company whose systems were breached.{{citation needed|date=May 2021}}


An October 2010 article entitled "Cyber Crime Made Easy" explained the level to which hackers are using [[malicious software]].<ref name="Giles2010">{{cite journal | last=Giles | first=Jim | title=Cyber crime made easy | journal=New Scientist | publisher=Elsevier BV | volume=205 | issue=2752 | year=2010 | issn=0262-4079 | doi=10.1016/s0262-4079(10)60647-1 | pages=20–21}}</ref> As Gunter Ollmann,
An October 2010 article entitled "Cyber Crime Made Easy" explained the level to which hackers are using [[malicious software]].<ref name="Giles2010">{{cite journal | last=Giles | first=Jim | title=Cyber crime made easy | journal=New Scientist | publisher=Elsevier BV | volume=205 | issue=2752 | year=2010 | issn=0262-4079 | doi=10.1016/s0262-4079(10)60647-1 | pages=20–21}}</ref> As Gunter Ollmann,
Line 23: Line 23:
* Child identity theft.
* Child identity theft.


Identity theft may be used to facilitate or fund other crimes including [[illegal immigration]], [[terrorism]], [[phishing]] and [[espionage]]. There are cases of identity cloning to attack [[payment system]]s, including online credit card processing and [[medical insurance]].<ref>{{cite web |url=http://www.worldprivacyforum.org/medidtheft_consumertips.html |title=Medical Identity Theft: What to Do if You are a Victim (or are concerned about it) }}, World Privacy Forum</ref>
Identity theft may be used to facilitate or fund other crimes including [[illegal immigration]], [[terrorism]], [[phishing]] and [[espionage]]. There are cases of identity cloning to attack [[payment system]]s, including online credit card processing and [[medical insurance]].<ref>{{cite web |url=http://www.worldprivacyforum.org/medidtheft_consumertips.html |title=Medical Identity Theft: What to Do if You are a Victim (or are concerned about it) |access-date=2008-01-19 |archive-date=2012-09-21 |archive-url=https://archive.today/20120921/http://www.worldprivacyforum.org/medidtheft_consumertips.html }}, World Privacy Forum</ref>


=== Identity cloning and concealment ===
=== Identity cloning and concealment ===
Line 31: Line 31:
When a criminal fraudulently identifies themselves to police as another individual at the point of arrest, it is sometimes referred to as "Criminal Identity Theft." In some cases, criminals have previously obtained state-issued identity documents using credentials stolen from others, or have simply presented a [[fake ID]]. Provided the subterfuge works, charges may be placed under the victim's name, letting the criminal off the hook. Victims might only learn of such incidents by chance, for example by receiving a court summons, discovering their driver's licenses are suspended when stopped for minor traffic violations, or through [[background check]]s performed for employment purposes.
When a criminal fraudulently identifies themselves to police as another individual at the point of arrest, it is sometimes referred to as "Criminal Identity Theft." In some cases, criminals have previously obtained state-issued identity documents using credentials stolen from others, or have simply presented a [[fake ID]]. Provided the subterfuge works, charges may be placed under the victim's name, letting the criminal off the hook. Victims might only learn of such incidents by chance, for example by receiving a court summons, discovering their driver's licenses are suspended when stopped for minor traffic violations, or through [[background check]]s performed for employment purposes.


It can be difficult for the victim of criminal identity theft to clear their record. The steps required to clear the victim's incorrect [[criminal record]] depend on which jurisdiction the crime occurred and whether the true identity of the criminal can be determined. The victim might need to locate the original arresting officers and prove their own identity by some reliable means such as fingerprinting or DNA testing and may need to go to a court hearing to be cleared of the charges. Obtaining an [[expungement]] of court records may also be required. Authorities might permanently maintain the victim's name as an alias for the criminal's true identity in their criminal records databases. One problem that victims of criminal identity theft may encounter is that various [[data aggregators]] might still have incorrect criminal records in their databases even after court and police records are corrected. Thus a future background check may return the incorrect criminal records.<ref>{{cite web |url=http://www.privacyrights.org/fs/fs17g-CrimIdTheft.htm |title=Privacy Rights Clearinghouse |url-status=dead |archive-url=https://archive.today/20120921/http://www.privacyrights.org/fs/fs17g-CrimIdTheft.htm |archive-date=21 September 2012 }} - "Fact Sheet 17g: Criminal Identity Theft: What to Do If It Happens to You "</ref> This is just one example of the kinds of impact that may continue to affect the victims of identity theft for some months or even years after the crime, aside from the psychological trauma that being 'cloned' typically engenders.
It can be difficult for the victim of criminal identity theft to clear their record. The steps required to clear the victim's incorrect [[criminal record]] depend on which jurisdiction the crime occurred and whether the true identity of the criminal can be determined. The victim might need to locate the original arresting officers and prove their own identity by some reliable means such as fingerprinting or DNA testing and may need to go to a court hearing to be cleared of the charges. Obtaining an [[expungement]] of court records may also be required. Authorities might permanently maintain the victim's name as an alias for the criminal's true identity in their criminal records databases. One problem that victims of criminal identity theft may encounter is that various [[data aggregators]] might still have incorrect criminal records in their databases even after court and police records are corrected. Thus a future background check may return the incorrect criminal records.<ref>{{cite web |url=http://www.privacyrights.org/fs/fs17g-CrimIdTheft.htm |title=Privacy Rights Clearinghouse |archive-url=https://archive.today/20120921/http://www.privacyrights.org/fs/fs17g-CrimIdTheft.htm |archive-date=21 September 2012 }} - "Fact Sheet 17g: Criminal Identity Theft: What to Do If It Happens to You "</ref> This is just one example of the kinds of impact that may continue to affect the victims of identity theft for some months or even years after the crime, aside from the psychological trauma that being 'cloned' typically engenders.


=== Synthetic identity theft ===
=== Synthetic identity theft ===
A variation of identity theft that has recently become more common is ''synthetic identity theft'', in which identities are completely or partially fabricated.<ref>{{Cite web|url=https://www.leagle.com/decision/2009567417bbr1501566|archiveurl=https://web.archive.org/web/20150719051854/http://www.leagle.com/decision/2009567417bbr150_1566|url-status=dead|title=In Re Colokathis &#124; 417 B.R. 150 (2009)|archive-date=19 July 2015|website=Leagle}}</ref> The most common technique involves combining a real [[social security number]] with a name and birthdate other than the ones that are simply associated with the number. Synthetic identity theft is more difficult to track as it doesn't show on either person's credit report directly but may appear as an entirely new file in the [[credit bureau]] or as a subfile on one of the victim's credit reports. Synthetic identity theft primarily harms the creditors who unwittingly grant the fraudsters credit. Individual victims can be affected if their names become confused with the synthetic identities, or if negative information in their subfiles impacts their credit ratings.<ref>{{cite web |url=http://www.bankrate.com/brm/news/pf/identity_theft_20070516_a1.asp |title=Detecting synthetic identity fraud |access-date=21 September 2008 |last=McFadden |first=Leslie |date=16 May 2007 |work=Bankrate.com |pages=1–2 }}</ref>
A variation of identity theft that has recently become more common is ''synthetic identity theft'', in which identities are completely or partially fabricated.<ref>{{Cite web|url=https://www.leagle.com/decision/2009567417bbr1501566|archive-url=https://web.archive.org/web/20150719051854/http://www.leagle.com/decision/2009567417bbr150_1566|title=In Re Colokathis &#124; 417 B.R. 150 (2009)|archive-date=19 July 2015|website=Leagle}}</ref> The most common technique involves combining a real [[social security number]] with a name and birthdate other than the ones that are simply associated with the number. Synthetic identity theft is more difficult to track as it doesn't show on either person's credit report directly but may appear as an entirely new file in the [[credit bureau]] or as a subfile on one of the victim's credit reports. Synthetic identity theft primarily harms the creditors who unwittingly grant the fraudsters credit. Individual victims can be affected if their names become confused with the synthetic identities, or if negative information in their subfiles impacts their credit ratings.<ref>{{cite web |url=http://www.bankrate.com/brm/news/pf/identity_theft_20070516_a1.asp |title=Detecting synthetic identity fraud |access-date=21 September 2008 |last=McFadden |first=Leslie |date=16 May 2007 |work=Bankrate.com |pages=1–2 }}</ref>


=== Medical identity theft ===
=== Medical identity theft ===
Line 40: Line 40:
[[File:Figure 2- Risk of Identity Theft with Medicare Card under CMS’s Three Proposed Options (7802334168).jpg|thumb|US [[Government Accountability Office]] diagram showing the identity theft risk associated with social security numbers on [[Medicare (United States)|Medicare cards]]]]
[[File:Figure 2- Risk of Identity Theft with Medicare Card under CMS’s Three Proposed Options (7802334168).jpg|thumb|US [[Government Accountability Office]] diagram showing the identity theft risk associated with social security numbers on [[Medicare (United States)|Medicare cards]]]]


Privacy researcher Pam Dixon, the founder of the World Privacy Forum,<ref>{{Cite web|url=https://www.worldprivacyforum.org/|title=World Privacy Forum|website=www.worldprivacyforum.org|accessdate=25 December 2023}}</ref> coined the term medical identity theft and released the first major report about this issue in 2006. In the report, she defined the crime for the first time and made the plight of victims public. The report's definition of the crime is that medical identity theft occurs when someone seeks medical care under the identity of another person. Insurance theft is also very common, if a thief has your insurance information and or your insurance card, they can seek medical attention posing as yourself.<ref>{{Cite web|url=http://www.igrad.com/articles/8-types-of-identity-theft|title=Get to Know These Common Types of ID Theft|website=iGrad|access-date=29 September 2016}}</ref>  In addition to risks of financial harm common to all forms of identity theft, the thief's medical history may be added to the victim's [[medical record]]s. Inaccurate information in the victim's records is difficult to correct and may affect future insurability or cause doctors to rely on misinformation to deliver inappropriate care. After the publication of the report, which contained a recommendation that consumers receive notifications of medical data breach incidents, California passed a law requiring this, and then finally [[Health Insurance Portability and Accountability Act|HIPAA]] was expanded to also require medical breach notification when breaches affect 500 or more people.<ref>{{cite web|url=http://www.worldprivacyforum.org/medicalidentitytheft.html|title=The Medical Identity Theft Information Page|publisher=World Privacy Forum|access-date=26 November 2012|url-status=dead|archive-url=https://archive.today/20130416062351/http://www.worldprivacyforum.org/medicalidentitytheft.html|archive-date=16 April 2013}}</ref><ref>{{cite web |url=http://www.idtheftcenter.org/artman2/publish/v_fact_sheets/Fact_Sheet_130_A_Correcting_Misinformation_on_Medical_Records.shtml |title=Correcting Misinformation on Medical Records |publisher=Identity Theft Resource Center |archive-url=https://web.archive.org/web/20130123025205/http://www.idtheftcenter.org/artman2/publish/v_fact_sheets/Fact_Sheet_130_A_Correcting_Misinformation_on_Medical_Records.shtml |archive-date=23 January 2013 |url-status=dead }}</ref> Data collected and stored by hospitals and other organizations such as medical aid schemes is up to 10 times more valuable to cybercriminals than credit card information.
Privacy researcher Pam Dixon, the founder of the World Privacy Forum,<ref>{{Cite web|url=https://www.worldprivacyforum.org/|title=World Privacy Forum|website=www.worldprivacyforum.org|access-date=25 December 2023}}</ref> coined the term medical identity theft and released the first major report about this issue in 2006. In the report, she defined the crime for the first time and made the plight of victims public. The report's definition of the crime is that medical identity theft occurs when someone seeks medical care under the identity of another person. Insurance theft is also very common, if a thief has your insurance information and or your insurance card, they can seek medical attention posing as yourself.<ref>{{Cite web|url=http://www.igrad.com/articles/8-types-of-identity-theft|title=Get to Know These Common Types of ID Theft|website=iGrad|access-date=29 September 2016}}</ref>  In addition to risks of financial harm common to all forms of identity theft, the thief's medical history may be added to the victim's [[medical record]]s. Inaccurate information in the victim's records is difficult to correct and may affect future insurability or cause doctors to rely on misinformation to deliver inappropriate care. After the publication of the report, which contained a recommendation that consumers receive notifications of medical data breach incidents, California passed a law requiring this, and then finally [[Health Insurance Portability and Accountability Act|HIPAA]] was expanded to also require medical breach notification when breaches affect 500 or more people.<ref>{{cite web|url=http://www.worldprivacyforum.org/medicalidentitytheft.html|title=The Medical Identity Theft Information Page|publisher=World Privacy Forum|access-date=26 November 2012|archive-url=https://archive.today/20130416062351/http://www.worldprivacyforum.org/medicalidentitytheft.html|archive-date=16 April 2013}}</ref><ref>{{cite web |url=http://www.idtheftcenter.org/artman2/publish/v_fact_sheets/Fact_Sheet_130_A_Correcting_Misinformation_on_Medical_Records.shtml |title=Correcting Misinformation on Medical Records |publisher=Identity Theft Resource Center |archive-url=https://web.archive.org/web/20130123025205/http://www.idtheftcenter.org/artman2/publish/v_fact_sheets/Fact_Sheet_130_A_Correcting_Misinformation_on_Medical_Records.shtml |archive-date=23 January 2013 }}</ref> Data collected and stored by hospitals and other organizations such as medical aid schemes is up to 10 times more valuable to cybercriminals than credit card information.


=== Child identity theft ===
=== Child identity theft ===
Line 49: Line 49:
Not only are children in general big targets of identity theft but children who are in foster care are even bigger targets. This is because they are most likely moved around quite frequently and their SSN is being shared with multiple people and agencies. Foster children are even more victims of identity theft within their own families and other relatives. Young people in foster care who are victims of this crime are usually left alone to struggle and figure out how to fix their newly formed bad credit.<ref name=":5" />
Not only are children in general big targets of identity theft but children who are in foster care are even bigger targets. This is because they are most likely moved around quite frequently and their SSN is being shared with multiple people and agencies. Foster children are even more victims of identity theft within their own families and other relatives. Young people in foster care who are victims of this crime are usually left alone to struggle and figure out how to fix their newly formed bad credit.<ref name=":5" />


The emergence of children's identities on social media has also contributed to a rise in incidents of digital kidnapping and identity theft. [[Digital kidnapping]] involves individuals stealing online images of children and misrepresenting them as their own.<ref>{{Cite journal |last1=Berg |first1=Valeska |last2=Arabiat |first2=Diana |last3=Morelius |first3=Evalotte |last4=Kervin |first4=Lisa |last5=Zgambo |first5=Maggie |last6=Robinson |first6=Suzanne |last7=Jenkins |first7=Mark |last8=Whitehead |first8=Lisa |date=2024-02-21 |title=Young Children and the Creation of a Digital Identity on Social Networking Sites: Scoping Review |journal=JMIR Pediatrics and Parenting |language=EN |volume=7 |issue=1 |pages=e54414 |doi=10.2196/54414|doi-access=free |pmid=38381499 |pmc=10918551 }}</ref>
The emergence of children's identities on social media has also contributed to a rise in incidents of digital kidnapping and identity theft. [[Digital kidnapping]] involves individuals stealing online images of children and misrepresenting them as their own.<ref>{{Cite journal |last1=Berg |first1=Valeska |last2=Arabiat |first2=Diana |last3=Morelius |first3=Evalotte |last4=Kervin |first4=Lisa |last5=Zgambo |first5=Maggie |last6=Robinson |first6=Suzanne |last7=Jenkins |first7=Mark |last8=Whitehead |first8=Lisa |date=2024-02-21 |title=Young Children and the Creation of a Digital Identity on Social Networking Sites: Scoping Review |journal=JMIR Pediatrics and Parenting |language=EN |volume=7 |issue=1 |article-number=e54414 |doi=10.2196/54414|doi-access=free |pmid=38381499 |pmc=10918551 }}</ref>


=== Financial identity theft ===
=== Financial identity theft ===
Line 56: Line 56:
=== Tax identity theft ===
=== Tax identity theft ===
{{see also|Tax evasion}}
{{see also|Tax evasion}}
One of the major identity theft categories is '''tax-related identity theft'''. The most common method is to use a person's authentic name, address, and [[Social Security Number]] to file a tax return with false information, and have the resulting refund direct-deposited into a bank account controlled by the thief. The thief in this case can also try to get a job and then their employer will report the income of the real taxpayer, this then results in the taxpayer getting in trouble with the IRS.<ref name=":03">{{Cite web|url=https://www.citrincooperman.com/In-Focus-Resource-Center|title=In Focus Resource Center from Citrin Cooperman &#124; Ideas That Count|website=www.citrincooperman.com|accessdate=25 December 2023}}</ref>
One of the major identity theft categories is '''tax-related identity theft'''. The most common method is to use a person's authentic name, address, and [[Social Security Number]] to file a tax return with false information, and have the resulting refund direct-deposited into a bank account controlled by the thief. The thief in this case can also try to get a job and then their employer will report the income of the real taxpayer, this then results in the taxpayer getting in trouble with the IRS.<ref name=":03">{{Cite web|url=https://www.citrincooperman.com/In-Focus-Resource-Center|title=In Focus Resource Center from Citrin Cooperman &#124; Ideas That Count|website=www.citrincooperman.com|access-date=25 December 2023}}</ref>


The 14039 Form to the [[Internal Revenue Service|IRS]] is a form that will help one fight against a theft like tax theft. This form will put the IRS on alert and someone who believed they have been a victim of tax-related theft will be given an Identity Protection Personal Identification Number (IP PIN), which is a 6 digit code used in replacing an SSN for filing tax returns.<ref name=":03" />
The 14039 Form to the [[Internal Revenue Service|IRS]] is a form that will help one fight against a theft like tax theft. This form will put the IRS on alert and someone who believed they have been a victim of tax-related theft will be given an Identity Protection Personal Identification Number (IP PIN), which is a 6 digit code used in replacing an SSN for filing tax returns.<ref name=":03" />
Line 63: Line 63:
Identity thieves typically obtain and exploit [[personally identifiable information]] about individuals, or various credentials they use to authenticate themselves, to impersonate them. Examples include:
Identity thieves typically obtain and exploit [[personally identifiable information]] about individuals, or various credentials they use to authenticate themselves, to impersonate them. Examples include:
* Using [[public records]] about individual citizens, published in official registers such as electoral rolls<ref>{{cite news | last=Loviglio | first=Joann| url= http://www.nbcnews.com/id/46874551| title= If Microsoft co-founder's ID isn't safe, is yours? | work= NBC News |date= March 2012 }}{{dead link|date=August 2024|bot=medic}}{{cbignore|bot=medic}}</ref>
* Using [[public records]] about individual citizens, published in official registers such as electoral rolls<ref>{{cite news | last=Loviglio | first=Joann| url= http://www.nbcnews.com/id/46874551| title= If Microsoft co-founder's ID isn't safe, is yours? | work= NBC News |date= March 2012 }}{{dead link|date=August 2024|bot=medic}}{{cbignore|bot=medic}}</ref>
* Stealing [[Cheque|cheques (checks)]] to acquire banking information, including account numbers and [[bank code]]s<ref>{{cite web |url=http://www.douglascountysheriff.org/idtheft/idtheftmain.htm |title=Identity Theft |access-date=2009-08-02 |archive-date=2012-07-28 |archive-url=https://archive.today/20120728/http://www.douglascountysheriff.org/idtheft/idtheftmain.htm |url-status=dead }}, Douglas County Sheriff's Office, Washington</ref>
* Stealing [[Cheque|cheques (checks)]] to acquire banking information, including account numbers and [[bank code]]s<ref>{{cite web |url=http://www.douglascountysheriff.org/idtheft/idtheftmain.htm |title=Identity Theft |access-date=2009-08-02 |archive-date=2012-07-28 |archive-url=https://archive.today/20120728/http://www.douglascountysheriff.org/idtheft/idtheftmain.htm }}, Douglas County Sheriff's Office, Washington</ref>
* Guessing Social Security numbers by using information found on Internet social networks such as [[Twitter]] and [[MySpace]]<ref>{{cite news |last=Olmos |first=David |url=https://www.bloomberg.com/apps/news?pid=newsarchive&sid=aKbjO.Ew4S2E |title=Social Security Numbers Can Be Guessed From Data, Study Finds |publisher=Bloomberg |date=6 July 2009 |access-date=4 January 2011 |url-status=dead |archive-url=https://web.archive.org/web/20130617002156/http://www.bloomberg.com/apps/news?pid=newsarchive&sid=aKbjO.Ew4S2E |archive-date=17 June 2013 }}</ref>
* Guessing Social Security numbers by using information found on Internet social networks such as [[Twitter]] and [[MySpace]]<ref>{{cite news |last=Olmos |first=David |url=https://www.bloomberg.com/apps/news?pid=newsarchive&sid=aKbjO.Ew4S2E |title=Social Security Numbers Can Be Guessed From Data, Study Finds |publisher=Bloomberg |date=6 July 2009 |access-date=4 January 2011 |archive-url=https://web.archive.org/web/20130617002156/http://www.bloomberg.com/apps/news?pid=newsarchive&sid=aKbjO.Ew4S2E |archive-date=17 June 2013 }}</ref>
In some cases, after obtaining a victim’s personal information, identity thieves may alter the victim’s contact details such as their mailing address, phone number, or email to prevent notifications from reaching them and to delay detection of fraudulent activity.<ref>{{Cite web |title=What is identity theft? Explanation with examples |url=https://nordprotect.com/blog/what-is-identity-theft/ |access-date=2025-10-22 |website=NordProtect |language=en}}</ref>


== Individual identity protection ==
== Individual identity protection ==
Line 73: Line 74:
Identity thieves sometimes impersonate dead people, using personal information obtained from death notices, gravestones, and other sources to exploit delays between the death and the closure of the person's accounts, the inattentiveness of grieving families, and weaknesses in the processes for credit-checking. Such crimes may continue for some time until the deceased's families or the authorities notice and react to anomalies.<ref>[http://www.idtheftcenter.org/Fact-Sheets/fs-117.html IDtheftcenter.org<!-- Bot generated title -->] {{webarchive|url=https://web.archive.org/web/20160417074200/http://www.idtheftcenter.org/Fact-Sheets/fs-117.html|date=17 April 2016}}, Identity Theft Resource Center Fact Sheet 117 Identity Theft and the Deceased - Prevention and Victim Tips.</ref>
Identity thieves sometimes impersonate dead people, using personal information obtained from death notices, gravestones, and other sources to exploit delays between the death and the closure of the person's accounts, the inattentiveness of grieving families, and weaknesses in the processes for credit-checking. Such crimes may continue for some time until the deceased's families or the authorities notice and react to anomalies.<ref>[http://www.idtheftcenter.org/Fact-Sheets/fs-117.html IDtheftcenter.org<!-- Bot generated title -->] {{webarchive|url=https://web.archive.org/web/20160417074200/http://www.idtheftcenter.org/Fact-Sheets/fs-117.html|date=17 April 2016}}, Identity Theft Resource Center Fact Sheet 117 Identity Theft and the Deceased - Prevention and Victim Tips.</ref>


In recent years{{When|date=September 2018}}, commercial identity theft protection/insurance services have become available in many countries. These services purport to help protect the individual from identity theft or help detect that identity theft has occurred in exchange for a monthly or annual membership fee or premium.<ref>{{cite web |url=http://www.nextadvisor.com/identity_theft_protection_services/compare.php |title=Identity Theft Protection Services |access-date=2008-12-16 |archive-date=2012-09-07 |archive-url=https://archive.today/20120907/http://www.nextadvisor.com/identity_theft_protection_services/compare.php |url-status=dead }} retrieved on 16 December 2008</ref> The services typically work either by setting fraud alerts on the individual's credit files with the three major credit bureaus or by setting up [[credit report monitoring]] with the credit bureau. While identity theft protection/insurance services have been heavily marketed, their value has been called into question.<ref>{{cite web |url=http://www.pcworld.com/article/145077/identitytheft_protection_what_services_can_you_trust.html |title=Identity-Theft Protection: What Services Can You Trust? }} PC World.com, retrieved on 16 December 2008</ref>
In recent years{{When|date=September 2018}}, commercial identity theft protection/insurance services have become available in many countries. These services purport to help protect the individual from identity theft or help detect that identity theft has occurred in exchange for a monthly or annual membership fee or premium.<ref>{{cite web |url=http://www.nextadvisor.com/identity_theft_protection_services/compare.php |title=Identity Theft Protection Services |access-date=2008-12-16 |archive-date=2012-09-07 |archive-url=https://archive.today/20120907/http://www.nextadvisor.com/identity_theft_protection_services/compare.php }} retrieved on 16 December 2008</ref> The services typically work either by setting fraud alerts on the individual's credit files with the three major credit bureaus or by setting up [[credit report monitoring]] with the credit bureau. While identity theft protection/insurance services have been heavily marketed, their value has been called into question.<ref>{{cite web |url=http://www.pcworld.com/article/145077/identitytheft_protection_what_services_can_you_trust.html |title=Identity-Theft Protection: What Services Can You Trust? }} PC World.com, retrieved on 16 December 2008</ref>


== Potential outcomes ==
== Potential outcomes ==
Line 84: Line 85:


== Identity protection by organizations ==
== Identity protection by organizations ==
In their May 1998 testimony before the United States Senate, the [[Federal Trade Commission]] (FTC) discussed the sale of Social Security numbers and other personal identifiers by credit-raters and data miners. The FTC agreed to the industry's self-regulating principles restricting access to information on credit reports.<ref>{{cite web |url=http://www.ftc.gov/os/1998/05/identhef.htm |title=Testimony before the Subcommittee on Technology, Terrorism and Government Information |url-status=dead |archive-url=https://archive.today/20120801/http://www.ftc.gov/os/1998/05/identhef.htm |archive-date=1 August 2012 }}, Committee of the Judiciary, United States Senate 20 May 1998 pp 5,6</ref> According to the industry, the restrictions vary according to the category of customer. Credit reporting agencies gather and disclose personal and credit information to a wide business client base.
In their May 1998 testimony before the United States Senate, the [[Federal Trade Commission]] (FTC) discussed the sale of Social Security numbers and other personal identifiers by credit-raters and data miners. The FTC agreed to the industry's self-regulating principles restricting access to information on credit reports.<ref>{{cite web |url=http://www.ftc.gov/os/1998/05/identhef.htm |title=Testimony before the Subcommittee on Technology, Terrorism and Government Information |archive-url=https://archive.today/20120801/http://www.ftc.gov/os/1998/05/identhef.htm |archive-date=1 August 2012 }}, Committee of the Judiciary, United States Senate 20 May 1998 pp 5,6</ref> According to the industry, the restrictions vary according to the category of customer. Credit reporting agencies gather and disclose personal and credit information to a wide business client base.


Poor stewardship of personal data by organizations, resulting in unauthorized access to sensitive data, can expose individuals to the risk of identity theft. The Privacy Rights Clearinghouse has documented over 900 individual data breaches by US companies and government agencies since January 2005, which together have involved over 200 million total records containing sensitive personal information, many containing social security numbers.<ref>{{Cite web|url=http://www.privacyrights.org/ar/ChronDataBreaches.htm|archive-url=https://web.archive.org/web/20100613183200/http://www.privacyrights.org/ar/ChronDataBreaches.htm|url-status=dead|title=A Chronology of Data Breaches<!-- Bot generated title -->|archive-date=13 June 2010}}</ref> Poor corporate diligence standards which can result in data breaches include:
Poor stewardship of personal data by organizations, resulting in unauthorized access to sensitive data, can expose individuals to the risk of identity theft. The Privacy Rights Clearinghouse has documented over 900 individual data breaches by US companies and government agencies since January 2005, which together have involved over 200 million total records containing sensitive personal information, many containing social security numbers.<ref>{{Cite web|url=http://www.privacyrights.org/ar/ChronDataBreaches.htm|archive-url=https://web.archive.org/web/20100613183200/http://www.privacyrights.org/ar/ChronDataBreaches.htm|title=A Chronology of Data Breaches<!-- Bot generated title -->|archive-date=13 June 2010}}</ref> Poor corporate diligence standards which can result in data breaches include:
* failure to shred confidential information before throwing it into dumpsters
* failure to shred confidential information before throwing it into dumpsters
* failure to ensure adequate [[network security]]
* failure to ensure adequate [[network security]]
Line 163: Line 164:


=== France ===
=== France ===
In France, a person convicted of identity theft can be sentenced up to five years in prison and fined up to [[euro|€]]75,000.<ref>{{Cite web|url=http://www.journaldunet.com/juridique/juridique040309.shtml|title=Usurpation d'identité : la loi ou la technique pour se protéger ?|website=www.journaldunet.com|accessdate=25 December 2023}}</ref>
In France, a person convicted of identity theft can be sentenced up to five years in prison and fined up to [[euro|€]]75,000.<ref>{{Cite web|url=http://www.journaldunet.com/juridique/juridique040309.shtml|title=Usurpation d'identité: la loi ou la technique pour se protéger ?|website=www.journaldunet.com|access-date=25 December 2023}}</ref>


=== Hong Kong ===
=== Hong Kong ===
Line 178: Line 179:
{{Blockquote|SECTION 66C
{{Blockquote|SECTION 66C
PUNISHMENT FOR IDENTITY THEFT
PUNISHMENT FOR IDENTITY THEFT
Whoever, fraudulently or dishonestly makes use of the electronic signature, password, or any other unique identification feature of any other person, shall be  punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one [[lakh]].<ref>{{cite web |url=http://nicca.nic.in/pdf/itact2000.pdf |title=The Information Technology Act 2000 |access-date=2013-08-20 |archive-url=https://web.archive.org/web/20130724123617/http://nicca.nic.in/pdf/itact2000.pdf |archive-date=2013-07-24 |url-status=dead }}</ref>}}
Whoever, fraudulently or dishonestly makes use of the electronic signature, password, or any other unique identification feature of any other person, shall be  punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one [[lakh]].<ref>{{cite web |url=http://nicca.nic.in/pdf/itact2000.pdf |title=The Information Technology Act 2000 |access-date=2013-08-20 |archive-url=https://web.archive.org/web/20130724123617/http://nicca.nic.in/pdf/itact2000.pdf |archive-date=2013-07-24 }}</ref>}}


=== Philippines ===
=== Philippines ===
Social networking sites are one of the most famous spreaders of ''posers'' in the online community, giving the users the freedom to post any information they want without any verification that the account is being used by the real person.{{clarify|date=April 2021}}
Social networking sites are one of the most famous spreaders of ''posers'' in the online community, giving the users the freedom to post any information they want without any verification that the account is being used by the real person.{{clarify|date=April 2021}}


The Philippines, which ranks eighth in the numbers of users of [[Facebook]] and other social networking sites (such as [[Twitter]], [[Multiply (website)|Multiply]] and [[Tumblr]]), has been known as a source of various identity theft problems.<ref>{{Cite web|url=https://www.techunblocked.org/2015/06/facebook-users-by-country-wise.html|archive-url=https://web.archive.org/web/20160310213502/https://www.techunblocked.org/2015/06/facebook-users-by-country-wise.html|url-status=dead|title=List of Facebook Users by Country Wise Top ranking 2016 - Tech Unblocked|archive-date=10 March 2016}}</ref>  Identities of people who carelessly put personal information on their profiles can easily be stolen just by simple browsing. Some people meet online, get to know each other through Facebook chat, and exchange messages that share private information.  Others get romantically involved with online friends and end up sharing too much information (such as their social security number, bank account, home address, and company address).
The Philippines, which ranks eighth in the numbers of users of [[Facebook]] and other social networking sites (such as [[Twitter]], [[Multiply (website)|Multiply]] and [[Tumblr]]), has been known as a source of various identity theft problems.<ref>{{Cite web|url=https://www.techunblocked.org/2015/06/facebook-users-by-country-wise.html|archive-url=https://web.archive.org/web/20160310213502/https://www.techunblocked.org/2015/06/facebook-users-by-country-wise.html|title=List of Facebook Users by Country Wise Top ranking 2016 - Tech Unblocked|archive-date=10 March 2016}}</ref>  Identities of people who carelessly put personal information on their profiles can easily be stolen just by simple browsing. Some people meet online, get to know each other through Facebook chat, and exchange messages that share private information.  Others get romantically involved with online friends and end up sharing too much information (such as their social security number, bank account, home address, and company address).


This phenomenon leads to the creation of the [[Cybercrime Prevention Act of 2012]] (Republic Act No. 10175). Section 2 of this act states that it recognizes the importance of [[communication]] and [[multimedia]] for the development, exploitation, and dissemination of information{{clarify|date=April 2021}}, but violators will be punished by the law through imprisonment or a fine upwards of ₱200,000, but not exceeding ₱1,000,000, or (depending on the damage caused) both.
This phenomenon leads to the creation of the [[Cybercrime Prevention Act of 2012]] (Republic Act No. 10175). Section 2 of this act states that it recognizes the importance of [[communication]] and [[multimedia]] for the development, exploitation, and dissemination of information{{clarify|date=April 2021}}, but violators will be punished by the law through imprisonment or a fine upwards of ₱200,000, but not exceeding ₱1,000,000, or (depending on the damage caused) both.
Line 194: Line 195:
Legally, Sweden is an open society. [[Freedom of information legislation|The Principle of Public Access]] states that all information (e.g. addresses, incomes, taxes) kept by public authorities must be available for anyone, except in certain cases (for example, the addresses of people who need to hide are restricted). This makes fraud easier.
Legally, Sweden is an open society. [[Freedom of information legislation|The Principle of Public Access]] states that all information (e.g. addresses, incomes, taxes) kept by public authorities must be available for anyone, except in certain cases (for example, the addresses of people who need to hide are restricted). This makes fraud easier.


Until 2016, there were no laws that specifically prohibited using someone's identity. Instead, there were only laws regarding any indirect damages caused. Impersonating anyone else for financial gain is a [[type of fraud]] in the [[Criminal Code]] ({{langx|sv|brottsbalken}}). Impersonating anyone else to discredit them by hacking into their social media accounts and provoke{{clarify|date=April 2021}} is considered [[libel]]. However, it is difficult to convict someone of committing this crime. In late 2016, a new law was introduced which partially banned undetermined{{clarify|date=April 2021}} identity usage.<ref>{{Cite web|url=http://rkrattsdb.gov.se/SFSdoc/16/160485.PDF|title=SFS 2016:485 Lag om ändring i brottsbalken|accessdate=25 December 2023}}</ref>
Until 2016, there were no laws that specifically prohibited using someone's identity. Instead, there were only laws regarding any indirect damages caused. Impersonating anyone else for financial gain is a [[type of fraud]] in the [[Criminal Code]] ({{langx|sv|brottsbalken}}). Impersonating anyone else to discredit them by hacking into their social media accounts and provoke{{clarify|date=April 2021}} is considered [[libel]]. However, it is difficult to convict someone of committing this crime. In late 2016, a new law was introduced which partially banned undetermined{{clarify|date=April 2021}} identity usage.<ref>{{Cite web|url=http://rkrattsdb.gov.se/SFSdoc/16/160485.PDF|title=SFS 2016:485 Lag om ändring i brottsbalken|access-date=25 December 2023}}</ref>


=== United Kingdom ===
=== United Kingdom ===
In the United Kingdom, personal data is protected by the [[Data Protection Act 1998]]. The Act covers all personal data which an organization may hold, including names, birthday and anniversary dates, addresses, and telephone numbers.
In the United Kingdom, personal data is protected by the [[Data Protection Act 1998]]. The Act covers all personal data which an organization may hold, including names, birthday and anniversary dates, addresses, and telephone numbers.


Under [[English law]] (which extends to [[Wales]] but not to [[Northern Ireland]] or [[Scotland]]), the [[Deception (criminal law)|deception]] offences under the [[Theft Act 1968]] increasingly contend with identity theft situations. In ''R v Seward'' (2005) EWCA Crim 1941,<ref>{{Cite web|url=http://www.bailii.org/ew/cases/EWCA/Crim/2005/1941.html|title=Seward, R. v [2005] EWCA Crim 1941 (11 July 2005)|accessdate=25 December 2023}}</ref> the defendant was acting as the "frontman" in the use of stolen credit cards and other documents to obtain goods. He obtained goods to the value of £10,000 for others who are unlikely ever to be identified. The Court of Appeal considered a sentencing policy for deception offenses involving "identity theft" and concluded that a prison sentence was required. Henriques J. said at para 14: "Identity fraud is a particularly pernicious and prevalent form of dishonesty calling for, in our judgment, deterrent sentences."
Under [[English law]] (which extends to [[Wales]] but not to [[Northern Ireland]] or [[Scotland]]), the [[Deception (criminal law)|deception]] offences under the [[Theft Act 1968]] increasingly contend with identity theft situations. In ''R v Seward'' (2005) EWCA Crim 1941,<ref>{{Cite web|url=http://www.bailii.org/ew/cases/EWCA/Crim/2005/1941.html|title=Seward, R. v [2005] EWCA Crim 1941 (11 July 2005)|access-date=25 December 2023}}</ref> the defendant was acting as the "frontman" in the use of stolen credit cards and other documents to obtain goods. He obtained goods to the value of £10,000 for others who are unlikely ever to be identified. The Court of Appeal considered a sentencing policy for deception offenses involving "identity theft" and concluded that a prison sentence was required. Henriques J. said at para 14: "Identity fraud is a particularly pernicious and prevalent form of dishonesty calling for, in our judgment, deterrent sentences."


Statistics released by [[CIFAS]] (UK's Fraud Prevention Service) show that there were 89,000 victims of identity theft in the UK in 2010 and 85,000 victims in 2009.<ref>{{cite web |url=http://www.cifas.org.uk/identity_fraud |title=CIFAS: your identity  }}, CIFAS</ref><ref>{{cite web |url=http://id-theft-uk.blogspot.com/2010/02/uk-fraud-prevention-agency-say-id-theft.html |title=UK Fraud Prevention Agency Say ID Theft Increase of 32% in 2009 |access-date=2010-02-03 |archive-date=2012-07-01 |archive-url=https://archive.today/20120701/http://id-theft-uk.blogspot.com/2010/02/uk-fraud-prevention-agency-say-id-theft.html |url-status=dead }}, Identity Theft UK Blog, 3 February 2010</ref>{{Unreliable source?|date=December 2015}} Men in their 30s and 40s are the most common victims.<ref>{{cite web |url=http://blog.protectmyid.co.uk/index.php/the-most-likely-victims-of-identity-fraud-men-in-their-late-30s-and-early-40s/ |title=The most likely victims of identity fraud: men in their late 30s and early 40s |url-status=dead |archive-url=https://archive.today/20120708/http://blog.protectmyid.co.uk/index.php/the-most-likely-victims-of-identity-fraud-men-in-their-late-30s-and-early-40s/ |archive-date=8 July 2012 }}, Protect MY ID Blog, 21 January 2011</ref>{{Unreliable source?|date=December 2015}} Identity fraud now accounts for nearly half of all frauds recorded.<ref>{{cite web |url=http://www.cifas.org.uk/press_release_twentyeleven_c |title=Fraudscape: report reveals the UK's fraud landscape in 2010  }}, CIFAS</ref>
Statistics released by [[CIFAS]] (UK's Fraud Prevention Service) show that there were 89,000 victims of identity theft in the UK in 2010 and 85,000 victims in 2009.<ref>{{cite web |url=http://www.cifas.org.uk/identity_fraud |title=CIFAS: your identity  }}, CIFAS</ref><ref>{{cite web |url=http://id-theft-uk.blogspot.com/2010/02/uk-fraud-prevention-agency-say-id-theft.html |title=UK Fraud Prevention Agency Say ID Theft Increase of 32% in 2009 |access-date=2010-02-03 |archive-date=2012-07-01 |archive-url=https://archive.today/20120701/http://id-theft-uk.blogspot.com/2010/02/uk-fraud-prevention-agency-say-id-theft.html }}, Identity Theft UK Blog, 3 February 2010</ref>{{Unreliable source?|date=December 2015}} Men in their 30s and 40s are the most common victims.<ref>{{cite web |url=http://blog.protectmyid.co.uk/index.php/the-most-likely-victims-of-identity-fraud-men-in-their-late-30s-and-early-40s/ |title=The most likely victims of identity fraud: men in their late 30s and early 40s |archive-url=https://archive.today/20120708/http://blog.protectmyid.co.uk/index.php/the-most-likely-victims-of-identity-fraud-men-in-their-late-30s-and-early-40s/ |archive-date=8 July 2012 }}, Protect MY ID Blog, 21 January 2011</ref>{{Unreliable source?|date=December 2015}} Identity fraud now accounts for nearly half of all frauds recorded.<ref>{{cite web |url=http://www.cifas.org.uk/press_release_twentyeleven_c |title=Fraudscape: report reveals the UK's fraud landscape in 2010  }}, CIFAS</ref>


=== United States ===
=== United States ===
{{See also|Identity theft in the United States}}
{{See also|Identity theft in the United States}}
The increase in crimes of identity theft led to the drafting of the Identity Theft and Assumption Deterrence Act.<ref>{{cite web |url=http://www.ftc.gov/os/statutes/itada/itadact.htm |title=FTC.gov |url-status=dead |archive-url=https://archive.today/20120801/http://www.ftc.gov/os/statutes/itada/itadact.htm |archive-date=1 August 2012 }}, Public Law 105-318, 112 Stat. 3007 (30 October 1998)</ref> In 1998, The Federal Trade Commission appeared before the United States Senate.<ref>{{cite web |url=http://www.ftc.gov/os/1998/05/identhef.htm |title=Prepared Statement of the Federal Trade Commission on "Identity Theft" |url-status=dead |archive-url=https://archive.today/20120801/http://www.ftc.gov/os/1998/05/identhef.htm |archive-date=1 August 2012 }}, 20 May 1998</ref> The FTC discussed crimes which exploit consumer credit to commit loan fraud, [[mortgage fraud]], lines-of-credit fraud, [[credit card fraud]], commodities and services frauds. The Identity Theft Deterrence Act (2003)[ITADA] amended [https://www.law.cornell.edu/uscode/text/18/1028A- U.S. Code Title 18, § 1028] ("Fraud related to activity in connection with identification documents, authentication features, and information"). The statute now makes the possession of any "means of identification" to "knowingly transfer, possess, or use without lawful authority" a federal crime, alongside unlawful possession of identification documents. However, for federal jurisdiction to prosecute, the crime must include an "identification document" that either: (a) is purportedly issued by the United States, (b) is used or intended to defraud the United States, (c) is sent through the mail, or (d) is used in a manner that affects interstate or foreign commerce. ''See'' {{usc|18|1028}}(c). Punishment can be up to 5, 15, 20, or 30 years in federal [[prison]], plus fines, depending on the underlying crime per {{usc|18|1028}}(b). In addition, punishments for the unlawful use of a "means of identification" were strengthened in § 1028A ("Aggravated Identity Theft"), allowing for a consecutive sentence under specific enumerated felony violations as defined in § 1028A(c)(1) through (11).<ref>Doyle, Charles. (2013). [https://fas.org/sgp/crs/misc/R42100.pdf Mandatory Minimum Sentencing: Federal Aggravated Identity Theft.] {{webarchive |url=https://web.archive.org/web/20161011031227/https://fas.org/sgp/crs/misc/R42100.pdf |date=11 October 2016 }} Washington, D.C.: [[Congressional Research Service]].</ref>
The increase in crimes of identity theft led to the drafting of the Identity Theft and Assumption Deterrence Act.<ref>{{cite web |url=http://www.ftc.gov/os/statutes/itada/itadact.htm |title=FTC.gov |archive-url=https://archive.today/20120801/http://www.ftc.gov/os/statutes/itada/itadact.htm |archive-date=1 August 2012 }}, Public Law 105-318, 112 Stat. 3007 (30 October 1998)</ref> In 1998, The Federal Trade Commission appeared before the United States Senate.<ref>{{cite web |url=http://www.ftc.gov/os/1998/05/identhef.htm |title=Prepared Statement of the Federal Trade Commission on "Identity Theft" |archive-url=https://archive.today/20120801/http://www.ftc.gov/os/1998/05/identhef.htm |archive-date=1 August 2012 }}, 20 May 1998</ref> The FTC discussed crimes which exploit consumer credit to commit loan fraud, [[mortgage fraud]], lines-of-credit fraud, [[credit card fraud]], commodities and services frauds. The Identity Theft Deterrence Act (2003)[ITADA] amended [https://www.law.cornell.edu/uscode/text/18/1028A- U.S. Code Title 18, § 1028] ("Fraud related to activity in connection with identification documents, authentication features, and information"). The statute now makes the possession of any "means of identification" to "knowingly transfer, possess, or use without lawful authority" a federal crime, alongside unlawful possession of identification documents. However, for federal jurisdiction to prosecute, the crime must include an "identification document" that either: (a) is purportedly issued by the United States, (b) is used or intended to defraud the United States, (c) is sent through the mail, or (d) is used in a manner that affects interstate or foreign commerce. ''See'' {{usc|18|1028}}(c). Punishment can be up to 5, 15, 20, or 30 years in federal [[prison]], plus fines, depending on the underlying crime per {{usc|18|1028}}(b). In addition, punishments for the unlawful use of a "means of identification" were strengthened in § 1028A ("Aggravated Identity Theft"), allowing for a consecutive sentence under specific enumerated felony violations as defined in § 1028A(c)(1) through (11).<ref>Doyle, Charles. (2013). [https://fas.org/sgp/crs/misc/R42100.pdf Mandatory Minimum Sentencing: Federal Aggravated Identity Theft.] {{webarchive |url=https://web.archive.org/web/20161011031227/https://fas.org/sgp/crs/misc/R42100.pdf |date=11 October 2016 }} Washington, D.C.: [[Congressional Research Service]].</ref>


The Act also provides the [[Federal Trade Commission]] with authority to track the number of incidents and the dollar value of losses. Their figures relate mainly to consumer financial crimes and not the broader range of all identification-based crimes.<ref>[http://www.consumer.gov/idtheft/ Federal Trade Commission]. Retrieved 30 June 2006.  {{webarchive |url=https://web.archive.org/web/20060131210801/http://www.consumer.gov/idtheft/ |date=31 January 2006 }}</ref>
The Act also provides the [[Federal Trade Commission]] with authority to track the number of incidents and the dollar value of losses. Their figures relate mainly to consumer financial crimes and not the broader range of all identification-based crimes.<ref>[http://www.consumer.gov/idtheft/ Federal Trade Commission]. Retrieved 30 June 2006.  {{webarchive |url=https://web.archive.org/web/20060131210801/http://www.consumer.gov/idtheft/ |date=31 January 2006 }}</ref>
Line 211: Line 212:
If charges are brought by state or local law enforcement agencies, different penalties apply to depend on the state.
If charges are brought by state or local law enforcement agencies, different penalties apply to depend on the state.


Six Federal agencies conducted a joint task force to increase the ability to detect identity theft. Their joint recommendation on "red flag" guidelines is a set of requirements on financial institutions and other entities which furnish credit data to credit reporting services to develop written plans for detecting identity theft. The FTC has determined that most medical practices are considered creditors and are subject to requirements to develop a plan to prevent and respond to patient identity theft.<ref>Michael, Sara {{cite web |url=http://www.physicianspractice.com/index/fuseaction/newsletterArticles.view/articleID/87.htm |title=Getting Red Flag Ready |access-date=2009-07-02 |archive-date=2012-09-11 |archive-url=https://archive.today/20120911/http://www.physicianspractice.com/index/fuseaction/newsletterArticles.view/articleID/87.htm |url-status=dead }} PhysiciansPractice.com, 21 May 2009. Retrieved 2 July 2009.</ref> These plans must be adopted by each organization's board of directors and monitored by senior executives.<ref>[http://www.ftc.gov/os/fedreg/2007/december/071213factafurnisheraccuracy.pdf 72 Fed. Reg. 70944 ] {{webarchive |url=https://web.archive.org/web/20130217151554/http://www.ftc.gov/os/fedreg/2007/december/071213factafurnisheraccuracy.pdf |date=17 February 2013 }} (PDF). Retrieved 29 January 2008.</ref>
Six Federal agencies conducted a joint task force to increase the ability to detect identity theft. Their joint recommendation on "red flag" guidelines is a set of requirements on financial institutions and other entities which furnish credit data to credit reporting services to develop written plans for detecting identity theft. The FTC has determined that most medical practices are considered creditors and are subject to requirements to develop a plan to prevent and respond to patient identity theft.<ref>Michael, Sara {{cite web |url=http://www.physicianspractice.com/index/fuseaction/newsletterArticles.view/articleID/87.htm |title=Getting Red Flag Ready |access-date=2009-07-02 |archive-date=2012-09-11 |archive-url=https://archive.today/20120911/http://www.physicianspractice.com/index/fuseaction/newsletterArticles.view/articleID/87.htm }} PhysiciansPractice.com, 21 May 2009. Retrieved 2 July 2009.</ref> These plans must be adopted by each organization's board of directors and monitored by senior executives.<ref>[http://www.ftc.gov/os/fedreg/2007/december/071213factafurnisheraccuracy.pdf 72 Fed. Reg. 70944 ] {{webarchive |url=https://web.archive.org/web/20130217151554/http://www.ftc.gov/os/fedreg/2007/december/071213factafurnisheraccuracy.pdf |date=17 February 2013 }} (PDF). Retrieved 29 January 2008.</ref>


Identity theft complaints as a percentage of all fraud complaints decreased from 2004 to 2006.<ref name="autogenerated1">{{Cite web|url=http://www.ftc.gov/bcp/edu/microsites/idtheft/downloads/clearinghouse_2006.pdf|archiveurl=https://web.archive.org/web/20080911044319/http://www.ftc.gov/bcp/edu/microsites/idtheft/downloads/clearinghouse_2006.pdf|url-status=dead|title=Law Enforcement Contact1 January 1 December 31, 2001|archive-date=11 September 2008}}</ref> The Federal Trade Commission reported that fraud complaints in general were growing faster than ID theft complaints.<ref name="autogenerated1" /> The findings were similar in two other FTC studies done in 2003 and 2005. In 2003, 4.6 percent of the US population said they were a victim of ID theft. In 2005, that number had dropped to 3.7 percent of the population.<ref name=SR_1>{{cite web| title=Federal Trade Commission – Identity Theft Survey Report| url=https://www.ftc.gov/sites/default/files/documents/reports/federal-trade-commission-identity-theft-program/synovatereport.pdf| publisher=[[Federal Trade Commission]]| date=September 2002| access-date=5 January 2024}}</ref><ref>{{Cite web|url=https://www.ftc.gov/reports/federal-trade-commission-2006-identity-theft-survey-report-prepared-commission-synovate|archiveurl=https://web.archive.org/web/20080911044311/http://www.ftc.gov/os/2007/11/SynovateFinalReportIDTheft2006.pdf|url-status=dead|title=Federal Trade Commission: 2006 Identity Theft Survey Report: Prepared for the Commission by Synovate|date=1 November 2007|archive-date=11 September 2008|website=Federal Trade Commission}}</ref> The commission's 2003 estimate was that identity theft accounted for some $52.6 billion of losses in the preceding year alone and affected more than 9.91 million Americans;<ref>{{cite web |url=http://www.ftc.gov/opa/2003/09/idtheft.shtm |title=FTC.gov<!-- Bot generated title --> |url-status=dead |archive-url=https://archive.today/20120731/http://www.ftc.gov/opa/2003/09/idtheft.shtm |archive-date=31 July 2012 }}, releases Survey of Identity Theft in U.S. 27.3 Million Victims in past 5 Years, Billions in Losses for Businesses and Consumers</ref> the figure comprises $47.6 billion lost by businesses and $5 billion lost by consumers.
Identity theft complaints as a percentage of all fraud complaints decreased from 2004 to 2006.<ref name="autogenerated1">{{Cite web|url=http://www.ftc.gov/bcp/edu/microsites/idtheft/downloads/clearinghouse_2006.pdf|archive-url=https://web.archive.org/web/20080911044319/http://www.ftc.gov/bcp/edu/microsites/idtheft/downloads/clearinghouse_2006.pdf|title=Law Enforcement Contact1 January 1 December 31, 2001|archive-date=11 September 2008}}</ref> The Federal Trade Commission reported that fraud complaints in general were growing faster than ID theft complaints.<ref name="autogenerated1" /> The findings were similar in two other FTC studies done in 2003 and 2005. In 2003, 4.6 percent of the US population said they were a victim of ID theft. In 2005, that number had dropped to 3.7 percent of the population.<ref name=SR_1>{{cite web| title=Federal Trade Commission – Identity Theft Survey Report| url=https://www.ftc.gov/sites/default/files/documents/reports/federal-trade-commission-identity-theft-program/synovatereport.pdf| publisher=[[Federal Trade Commission]]| date=September 2002| access-date=5 January 2024}}</ref><ref>{{Cite web|url=https://www.ftc.gov/reports/federal-trade-commission-2006-identity-theft-survey-report-prepared-commission-synovate|archive-url=https://web.archive.org/web/20080911044311/http://www.ftc.gov/os/2007/11/SynovateFinalReportIDTheft2006.pdf|title=Federal Trade Commission: 2006 Identity Theft Survey Report: Prepared for the Commission by Synovate|date=1 November 2007|archive-date=11 September 2008|website=Federal Trade Commission}}</ref> The commission's 2003 estimate was that identity theft accounted for some $52.6 billion of losses in the preceding year alone and affected more than 9.91 million Americans;<ref>{{cite web |url=http://www.ftc.gov/opa/2003/09/idtheft.shtm |title=FTC.gov<!-- Bot generated title --> |archive-url=https://archive.today/20120731/http://www.ftc.gov/opa/2003/09/idtheft.shtm |archive-date=31 July 2012 }}, releases Survey of Identity Theft in U.S. 27.3 Million Victims in past 5 Years, Billions in Losses for Businesses and Consumers</ref> the figure comprises $47.6 billion lost by businesses and $5 billion lost by consumers.


According to the [[Bureau of Justice Statistics|U.S. Bureau of Justice Statistics]], in 2010, 7% of US households experienced identity theft - up from 5.5% in 2005 when the figures were first assembled, but broadly flat since 2007.<ref name="Bureau of Justice Statistics">{{cite web | url=http://bjs.gov/content/pub/pdf/itrh0510.pdf | title=Identity Theft Reported by Households, 2005-2010 | publisher=Bureau of Justice Statistics | year=2011 | access-date=24 June 2013}}</ref> In 2012, approximately 16.6 million persons, or 7% of all U.S. residents age 16 or older, reported being victims of one or more incidents of identity theft.<ref>Harrell, Erika and Lynn Langton. (2013). [http://www.bjs.gov/content/pub/pdf/vit12.pdf Victims of Identity Theft, 2012.] {{webarchive |url=https://web.archive.org/web/20160907043423/http://www.bjs.gov/content/pub/pdf/vit12.pdf |date=7 September 2016 }} Washington, D.C. [[United States Department of Justice|U.S. Department of Justice]], [[Bureau of Justice Statistics]].</ref>
According to the [[Bureau of Justice Statistics|U.S. Bureau of Justice Statistics]], in 2010, 7% of US households experienced identity theft - up from 5.5% in 2005 when the figures were first assembled, but broadly flat since 2007.<ref name="Bureau of Justice Statistics">{{cite web | url=http://bjs.gov/content/pub/pdf/itrh0510.pdf | title=Identity Theft Reported by Households, 2005-2010 | publisher=Bureau of Justice Statistics | year=2011 | access-date=24 June 2013}}</ref> In 2012, approximately 16.6 million persons, or 7% of all U.S. residents age 16 or older, reported being victims of one or more incidents of identity theft.<ref>Harrell, Erika and Lynn Langton. (2013). [http://www.bjs.gov/content/pub/pdf/vit12.pdf Victims of Identity Theft, 2012.] {{webarchive |url=https://web.archive.org/web/20160907043423/http://www.bjs.gov/content/pub/pdf/vit12.pdf |date=7 September 2016 }} Washington, D.C. [[United States Department of Justice|U.S. Department of Justice]], [[Bureau of Justice Statistics]].</ref>


At least two states, [[California]]<ref>{{cite web |url=http://www.privacyprotection.ca.gov/ |title=California Office of Identity Protection |access-date=2009-01-08 |archive-date=2012-08-05 |archive-url=https://archive.today/20120805/http://www.privacyprotection.ca.gov/ |url-status=dead }}</ref> and [[Wisconsin]]<ref>{{Cite web|url=https://datcp.wi.gov/Pages/Programs_Services/IdentityTheft.aspx|title=DATCP Home Identity Theft Protection|website=datcp.wi.gov|accessdate=25 December 2023}}</ref> have created an Office of Privacy Protection to assist their citizens in avoiding and recovering from identity theft.
At least two states, [[California]]<ref>{{cite web |url=http://www.privacyprotection.ca.gov/ |title=California Office of Identity Protection |access-date=2009-01-08 |archive-date=2012-08-05 |archive-url=https://archive.today/20120805/http://www.privacyprotection.ca.gov/ }}</ref> and [[Wisconsin]]<ref>{{Cite web|url=https://datcp.wi.gov/Pages/Programs_Services/IdentityTheft.aspx|title=DATCP Home Identity Theft Protection|website=datcp.wi.gov|access-date=25 December 2023}}</ref> have created an Office of Privacy Protection to assist their citizens in avoiding and recovering from identity theft.


In 2009, Indiana created an Identity Theft Unit within their Office of Attorney General to educate and assist consumers in avoiding and recovering from identity theft as well as assist law enforcement in investigating and prosecuting identity theft crimes.<ref>{{cite web|url=http://www.in.gov/legislative/ic/code/title4/ar6/ch13.pdf |title=Indiana General Assembly |access-date=3 October 2013 |url-status=live |archive-url=https://web.archive.org/web/20131004215445/http://www.in.gov/legislative/ic/code/title4/ar6/ch13.pdf |archive-date=4 October 2013 }}</ref><ref>{{cite web |url=http://www.in.gov/attorneygeneral/2853.htm |title=Attorney General: ID Theft Prevention |publisher=In.gov |date=6 December 2013 |access-date=24 January 2014 |archive-date=11 January 2014 |archive-url=https://web.archive.org/web/20140111062848/http://www.in.gov/attorneygeneral/2853.htm |url-status=dead }}</ref>
In 2009, Indiana created an Identity Theft Unit within their Office of Attorney General to educate and assist consumers in avoiding and recovering from identity theft as well as assist law enforcement in investigating and prosecuting identity theft crimes.<ref>{{cite web|url=http://www.in.gov/legislative/ic/code/title4/ar6/ch13.pdf |title=Indiana General Assembly |access-date=3 October 2013 |url-status=live |archive-url=https://web.archive.org/web/20131004215445/http://www.in.gov/legislative/ic/code/title4/ar6/ch13.pdf |archive-date=4 October 2013 }}</ref><ref>{{cite web |url=http://www.in.gov/attorneygeneral/2853.htm |title=Attorney General: ID Theft Prevention |publisher=In.gov |date=6 December 2013 |access-date=24 January 2014 |archive-date=11 January 2014 |archive-url=https://web.archive.org/web/20140111062848/http://www.in.gov/attorneygeneral/2853.htm }}</ref>


In Massachusetts in 2009–2010, Governor [[Deval Patrick]] committed to balancing consumer protection with the needs of small business owners. His Office of Consumer Affairs and Business Regulation announced certain adjustments to Massachusetts' identity theft regulations that maintain protections and also allow flexibility in compliance. These updated regulations went into effect on 1 March 2010. The regulations are clear that their approach to data security is a risk-based approach important to small businesses and might not handle a lot of personal information about customers.<ref>[http://www.mass.gov/?pageID=ocatopic&L=3&L0=Home&L1=Consumer&L2=Identity+Theft&sid=Eoca "Consumer Identity Theft"]. Commonwealth of Massachusetts, 2010  {{webarchive |url=https://web.archive.org/web/20111105045936/http://www.mass.gov/?pageID=ocatopic&L=3&L0=Home&L1=Consumer&L2=Identity+Theft&sid=Eoca |date=5 November 2011 }}</ref><ref>[http://www.mass.gov/Eoca/docs/idtheft/201CMR17faqs.pdf "Frequently Asked Question Regarding 201 CMR 17.00"] {{webarchive |url=https://web.archive.org/web/20110811054640/http://www.mass.gov/Eoca/docs/idtheft/201CMR17faqs.pdf |date=11 August 2011 }}, Commonwealth of Massachusetts, Office of Consumer Affairs and Business Regulation, 3 November 2009</ref>
In Massachusetts in 2009–2010, Governor [[Deval Patrick]] committed to balancing consumer protection with the needs of small business owners. His Office of Consumer Affairs and Business Regulation announced certain adjustments to Massachusetts' identity theft regulations that maintain protections and also allow flexibility in compliance. These updated regulations went into effect on 1 March 2010. The regulations are clear that their approach to data security is a risk-based approach important to small businesses and might not handle a lot of personal information about customers.<ref>[http://www.mass.gov/?pageID=ocatopic&L=3&L0=Home&L1=Consumer&L2=Identity+Theft&sid=Eoca "Consumer Identity Theft"]. Commonwealth of Massachusetts, 2010  {{webarchive |url=https://web.archive.org/web/20111105045936/http://www.mass.gov/?pageID=ocatopic&L=3&L0=Home&L1=Consumer&L2=Identity+Theft&sid=Eoca |date=5 November 2011 }}</ref><ref>[http://www.mass.gov/Eoca/docs/idtheft/201CMR17faqs.pdf "Frequently Asked Question Regarding 201 CMR 17.00"] {{webarchive |url=https://web.archive.org/web/20110811054640/http://www.mass.gov/Eoca/docs/idtheft/201CMR17faqs.pdf |date=11 August 2011 }}, Commonwealth of Massachusetts, Office of Consumer Affairs and Business Regulation, 3 November 2009</ref>


The [[Internal Revenue Service|IRS]] has created{{when|date=August 2017}} the IRS Identity Protection Specialized Unit to help taxpayers' who are victims of federal tax-related identity theft.<ref>{{cite web|title=Taxpayer Guide to Identity Theft|url=https://www.irs.gov/newsroom/article/0,,id=251501,00.html|work=IRS.gov|publisher=US Internal Revenue Service|access-date=29 June 2012 }}</ref> Generally, the identity thief will use a stolen SSN to file a forged tax return and attempt to get a fraudulent refund early in the filing season. A taxpayer will need to fill out Form 14039, [https://www.irs.gov/pub/irs-pdf/f14039.pdf ''Identity Theft Affidavit''].<ref>{{cite web|title=Form 14039|url=https://www.irs.gov/pub/irs-pdf/f14039.pdf|work=IRS website|publisher=US Internal Revenue Service|access-date=29 June 2012}}</ref><ref name="ALERT: Beware of Phishing Scam Mentioning TAS">{{cite web | url=http://www.taxpayeradvocate.irs.gov/Individuals/Identity-Theft | title=ALERT: Beware of Phishing Scam Mentioning TAS | publisher=Taxpayer Advocate | access-date=18 December 2014 | url-status=dead | archive-url=https://web.archive.org/web/20141218162516/http://www.taxpayeradvocate.irs.gov/Individuals/Identity-Theft | archive-date=18 December 2014 }}</ref>
The [[Internal Revenue Service|IRS]] has created{{when|date=August 2017}} the IRS Identity Protection Specialized Unit to help taxpayers' who are victims of federal tax-related identity theft.<ref>{{cite web|title=Taxpayer Guide to Identity Theft|url=https://www.irs.gov/newsroom/article/0,,id=251501,00.html|work=IRS.gov|publisher=US Internal Revenue Service|access-date=29 June 2012 }}</ref> Generally, the identity thief will use a stolen SSN to file a forged tax return and attempt to get a fraudulent refund early in the filing season. A taxpayer will need to fill out Form 14039, [https://www.irs.gov/pub/irs-pdf/f14039.pdf ''Identity Theft Affidavit''].<ref>{{cite web|title=Form 14039|url=https://www.irs.gov/pub/irs-pdf/f14039.pdf|work=IRS website|publisher=US Internal Revenue Service|access-date=29 June 2012}}</ref><ref name="ALERT: Beware of Phishing Scam Mentioning TAS">{{cite web | url=http://www.taxpayeradvocate.irs.gov/Individuals/Identity-Theft | title=ALERT: Beware of Phishing Scam Mentioning TAS | publisher=Taxpayer Advocate | access-date=18 December 2014 | archive-url=https://web.archive.org/web/20141218162516/http://www.taxpayeradvocate.irs.gov/Individuals/Identity-Theft | archive-date=18 December 2014 }}</ref>


As for the future of medical care and Medicaid, people are mostly concerned about [[cloud computing]]. The addition of using cloud information within the United States medicare system would institute easily accessible health information for individuals, but that also makes it easier for identity theft. Currently, new technology is being produced to help encrypt and protect files, which will create a smooth transition to cloud technology in the healthcare system.<ref>Hyde, J. (2017). Preventing Identity Theft and Strengthening the American Health Care System. Policy & Practice (19426828), 75(5), 26–34.</ref>
As for the future of medical care and Medicaid, people are mostly concerned about [[cloud computing]]. The addition of using cloud information within the United States medicare system would institute easily accessible health information for individuals, but that also makes it easier for identity theft. Currently, new technology is being produced to help encrypt and protect files, which will create a smooth transition to cloud technology in the healthcare system.<ref>Hyde, J. (2017). Preventing Identity Theft and Strengthening the American Health Care System. Policy & Practice (19426828), 75(5), 26–34.</ref>


==== Notification ====
==== Notification ====
Many states followed California's lead and enacted mandatory [[data breach notification laws]]. As a result, companies that report a data breach typically report it to all their customers.<ref>{{cite web |url=http://www.naag.org/states-offer-data-breach-protection.php |title=States Offer Data Breach Protection |url-status=dead |archive-url=https://archive.today/20120913/http://www.naag.org/states-offer-data-breach-protection.php |archive-date=13 September 2012 }}</ref>
Many states followed California's lead and enacted mandatory [[data breach notification laws]]. As a result, companies that report a data breach typically report it to all their customers.<ref>{{cite web |url=http://www.naag.org/states-offer-data-breach-protection.php |title=States Offer Data Breach Protection |archive-url=https://archive.today/20120913/http://www.naag.org/states-offer-data-breach-protection.php |archive-date=13 September 2012 }}</ref>


== Spread and impact ==
== Spread and impact ==
Line 234: Line 235:
Surveys in the US from 2003 to 2006 showed a decrease in the total number of identity fraud victims and a decrease in the total value of identity fraud from US$47.6 billion in 2003 to $15.6 billion in 2006.{{citation needed|date=May 2021}} The average fraud per person decreased from $4,789 in 2003 to $1,882 in 2006. A Microsoft report shows that this drop is due to statistical problems with the methodology, that such survey-based estimates are "hopelessly flawed" and exaggerate the true losses by orders of magnitude.<ref>{{cite web|url=http://research.microsoft.com/pubs/149886/SexLiesandCybercrimeSurveys.pdf |title=Sex, Lies and Cybercrime Surveys |publisher=Microsoft |date=15 June 2011 |access-date=11 March 2015}}</ref>
Surveys in the US from 2003 to 2006 showed a decrease in the total number of identity fraud victims and a decrease in the total value of identity fraud from US$47.6 billion in 2003 to $15.6 billion in 2006.{{citation needed|date=May 2021}} The average fraud per person decreased from $4,789 in 2003 to $1,882 in 2006. A Microsoft report shows that this drop is due to statistical problems with the methodology, that such survey-based estimates are "hopelessly flawed" and exaggerate the true losses by orders of magnitude.<ref>{{cite web|url=http://research.microsoft.com/pubs/149886/SexLiesandCybercrimeSurveys.pdf |title=Sex, Lies and Cybercrime Surveys |publisher=Microsoft |date=15 June 2011 |access-date=11 March 2015}}</ref>


The 2003 survey from the Identity Theft Resource Center<ref>{{Cite web|url=https://www.idtheftcenter.org/|title=Home Page|website=ITRC|accessdate=25 December 2023}}</ref> found that:
The 2003 survey from the Identity Theft Resource Center<ref>{{Cite web|url=https://www.idtheftcenter.org/|title=Home Page|website=ITRC|access-date=25 December 2023}}</ref> found that:
* Only 15% of victims find out about the theft through proactive action taken by a business
* Only 15% of victims find out about the theft through proactive action taken by a business
* The average time spent by victims resolving the problem is about 330 hours
* The average time spent by victims resolving the problem is about 330 hours
* 73% of respondents indicated the crime involved the thief acquiring a credit card
* 73% of respondents indicated the crime involved the thief acquiring a credit card
In a widely publicized account,<ref>{{cite web |url=http://www.privacyrights.org/cases/victim9.htm |title=Verbal Testimony by Michelle Brown |url-status=dead |archive-url=https://archive.today/20120921/http://www.privacyrights.org/cases/victim9.htm |archive-date=21 September 2012 }}, July 2000, U.S. Senate Committee Hearing on the Judiciary Subcommittee on Technology, Terrorism and Government Information{{spaced ndash}}"Identity Theft: How to Protect and Restore Your Good Name"</ref> Michelle Brown, a victim of identity fraud, testified before a U.S. Senate Committee Hearing on Identity Theft. Ms. Brown testified that: "over a year and a half from January 1998 through July 1999, one individual impersonated me to procure over $50,000 in goods and services. Not only did she damage my credit, but she escalated her crimes to a level that I never truly expected: she engaged in drug trafficking. The crime resulted in my erroneous arrest record, a warrant out for my arrest, and eventually, a prison record when she was booked under my name as an inmate in the Chicago Federal Prison."
In a widely publicized account,<ref>{{cite web |url=http://www.privacyrights.org/cases/victim9.htm |title=Verbal Testimony by Michelle Brown |archive-url=https://archive.today/20120921/http://www.privacyrights.org/cases/victim9.htm |archive-date=21 September 2012 }}, July 2000, U.S. Senate Committee Hearing on the Judiciary Subcommittee on Technology, Terrorism and Government Information{{spaced ndash}}"Identity Theft: How to Protect and Restore Your Good Name"</ref> Michelle Brown, a victim of identity fraud, testified before a U.S. Senate Committee Hearing on Identity Theft. Ms. Brown testified that: "over a year and a half from January 1998 through July 1999, one individual impersonated me to procure over $50,000 in goods and services. Not only did she damage my credit, but she escalated her crimes to a level that I never truly expected: she engaged in drug trafficking. The crime resulted in my erroneous arrest record, a warrant out for my arrest, and eventually, a prison record when she was booked under my name as an inmate in the Chicago Federal Prison."


In [[Australia]], identity theft was estimated to be worth between A$1billion and A$4 billion per annum in 2001.<ref>[http://www.acpr.gov.au/research_idcrime.asp Identity Crime Research and Coordination] {{webarchive |url=https://web.archive.org/web/20051230021614/http://www.acpr.gov.au/research_idcrime.asp |date=30 December 2005 }}, Australasian Center for Policing Research. Retrieved 30 June 2006.</ref>
In [[Australia]], identity theft was estimated to be worth between A$1billion and A$4 billion per annum in 2001.<ref>[http://www.acpr.gov.au/research_idcrime.asp Identity Crime Research and Coordination] {{webarchive |url=https://web.archive.org/web/20051230021614/http://www.acpr.gov.au/research_idcrime.asp |date=30 December 2005 }}, Australasian Center for Policing Research. Retrieved 30 June 2006.</ref>


In the United Kingdom, the Home Office reported that identity fraud costs the UK economy £1.2 billion annually<ref>{{cite web |url=http://www.identitytheft.org.uk/ |title=What is Identity theft? |author=Home Office |date=26 May 2004 |publisher=identitytheft.co.uk |access-date=27 September 2010 |author-link=Home Office }}</ref> (experts believe that the real figure could be much higher)<ref>{{cite web |url=https://bestidprotection.com/guides/10-ways-to-prevent-identity-theft/ |title=Free help, tips and advice on avoiding and dealing with Identity Theft |website=bestidprotection.com|date=9 February 2022 }}</ref> although privacy groups object to the validity of these numbers, arguing that they are being used by the government to push for introduction of [[British national identity card|national ID cards]]. Confusion over exactly what constitutes identity theft has led to claims that statistics may be exaggerated.<ref>{{cite web |url=http://www.schneier.com/blog/archives/2005/11/identity_theft.html |title=Identity Theft Over-Reported |author=Bruce Schneier |access-date=30 June 2006 |author-link=Bruce Schneier }}</ref>
In the United Kingdom, the Home Office reported that identity fraud costs the UK economy £1.2 billion annually<ref>{{cite web |url=http://www.identitytheft.org.uk/ |title=What is Identity theft? |author=Home Office |date=26 May 2004 |publisher=identitytheft.co.uk |access-date=27 September 2010 |author-link=Home Office }}</ref> (experts believe that the real figure could be much higher)<ref>{{cite web |url=https://bestidprotection.com/guides/10-ways-to-prevent-identity-theft/ |title=Free help, tips and advice on avoiding and dealing with Identity Theft |website=bestidprotection.com|date=9 February 2022 }}</ref> although privacy groups object to the validity of these numbers, arguing that they are being used by the government to push for introduction of [[British national identity card|national ID cards]]. Confusion over exactly what constitutes identity theft has led to claims that statistics may be exaggerated.<ref>{{cite web |url=http://www.schneier.com/blog/archives/2005/11/identity_theft.html |title=Identity Theft Over-Reported |author=Bruce Schneier |access-date=30 June 2006 |author-link=Bruce Schneier }}</ref>
An extensively reported<ref>{{cite news |url=https://www.bbc.co.uk/news/technology-13726085 |title=Hi-tech crime and sexual partner surveys 'biased' |date= 10 June 2011|publisher= BBC}}</ref><ref>{{cite news |url=http://www.economist.com/node/21532263 |title=Measuring the black web  |date= 15 October 2011|newspaper= The Economist}}</ref>  study from Microsoft Research<ref>{{cite web |url=http://research.microsoft.com/pubs/149886/SexLiesandCybercrimeSurveys.pdf |title=Sex, Lies and Cybercrime Surveys |first1=D. |last1=Florencio |first2=C. |last2=Herley |date=June 2011 |publisher= Proc. WEIS}}</ref> in 2011 finds that estimates of identity theft losses contain enormous exaggerations, writing that surveys "are so compromised and biased that no faith whatever can be placed in their findings."
An extensively reported<ref>{{cite news |url=https://www.bbc.co.uk/news/technology-13726085 |title=Hi-tech crime and sexual partner surveys 'biased' |date= 10 June 2011|publisher= BBC}}</ref><ref>{{cite news |url=https://www.economist.com/international/2011/10/15/measuring-the-black-web |title=Measuring the black web  |date= 15 October 2011|newspaper= The Economist}}</ref>  study from Microsoft Research<ref>{{cite web |url=http://research.microsoft.com/pubs/149886/SexLiesandCybercrimeSurveys.pdf |title=Sex, Lies and Cybercrime Surveys |first1=D. |last1=Florencio |first2=C. |last2=Herley |date=June 2011 |publisher= Proc. WEIS}}</ref> in 2011 finds that estimates of identity theft losses contain enormous exaggerations, writing that surveys "are so compromised and biased that no faith whatever can be placed in their findings."


== See also ==
== See also ==
Line 314: Line 315:
* [http://www.usdoj.gov/criminal/fraud/websites/idtheft.html Identity Theft and Fraud] – [[United States Department of Justice]]
* [http://www.usdoj.gov/criminal/fraud/websites/idtheft.html Identity Theft and Fraud] – [[United States Department of Justice]]
* [https://web.archive.org/web/20070401000301/http://www.msnbc.msn.com/id/17805134/ Dateline NBC investigation] 'To Catch an ID Thief'
* [https://web.archive.org/web/20070401000301/http://www.msnbc.msn.com/id/17805134/ Dateline NBC investigation] 'To Catch an ID Thief'
* {{cite news|title=Transcript of Attorney General Alberto R. Gonzales and FTC Chairman Deborah Platt Majoras Announcing the Release of the President's Identity Theft Task Force |date=23 April 2007 |url=http://www.usdoj.gov/ag/speeches/2007/ag_speech_0704231.html |archive-url=https://archive.today/20070911112747/http://www.usdoj.gov/ag/speeches/2007/ag_speech_0704231.html |url-status=dead |archive-date=11 September 2007 |work=US Department of Justice |access-date=24 April 2007
* {{cite news|title=Transcript of Attorney General Alberto R. Gonzales and FTC Chairman Deborah Platt Majoras Announcing the Release of the President's Identity Theft Task Force |date=23 April 2007 |url=http://www.usdoj.gov/ag/speeches/2007/ag_speech_0704231.html |archive-url=https://archive.today/20070911112747/http://www.usdoj.gov/ag/speeches/2007/ag_speech_0704231.html |archive-date=11 September 2007 |work=US Department of Justice |access-date=24 April 2007
}}
}}
* {{cite news |url= https://abcnews.go.com/US/wireStory/woman-prison-time-total-identity-theft-18809034 |title=Woman Gets Prison Time in 'Total Identity Theft' - ABC News |first=Hegeman |last=Roxana |work=ABC News |date=25 March 2013 |access-date=27 March 2013}}
* {{cite news |url= https://abcnews.go.com/US/wireStory/woman-prison-time-total-identity-theft-18809034 |title=Woman Gets Prison Time in 'Total Identity Theft' - ABC News |first=Hegeman |last=Roxana |work=ABC News |date=25 March 2013 |access-date=27 March 2013}}

Latest revision as of 00:53, 30 October 2025

Template:Short description Script error: No such module "about".

Template:Multiple issues

File:Figure 2 Example of a Successful Identity Theft Refund Fraud Attempt (28356288536).jpg
Example of an identity theft crime: 1. The fraudster files tax return paperwork in the victim's name, claiming a refund. 2. The IRS issues a refund to the fraudster. 3. The victim submits their legitimate tax return. 4. The IRS rejects the return as a duplicate.

Identity theft, identity piracy or identity infringement occurs when someone uses another's personal identifying information, like their name, identifying number, or credit card number, without their permission, to commit fraud or other crimes. The term identity theft was coined in 1964.[1] Since that time, the definition of identity theft has been legally defined throughout both the UK and the U.S. as the theft of personally identifiable information. Identity theft deliberately uses someone else's identity as a method to gain financial advantages or obtain credit and other benefits.[2][3] The person whose identity has been stolen may suffer adverse consequences,[4] especially if they are falsely held responsible for the perpetrator's actions. Personally identifiable information generally includes a person's name, date of birth, social security number, driver's license number, bank account or credit card numbers, PINs, electronic signatures, fingerprints, passwords, or any other information that can be used to access a person's financial resources.[5]

Determining the link between data breaches and identity theft is challenging, primarily because identity theft victims often do not know how their personal information was obtained. According to a report done for the FTC, identity theft is not always detectable by the individual victims.[6] Identity fraud is often but not necessarily the consequence of identity theft. Someone can steal or misappropriate personal information without then committing identity theft using the information about every person, such as when a major data breach occurs. A U.S. Government Accountability Office study determined that "most breaches have not resulted in detected incidents of identity theft".[7] The report also warned that "the full extent is unknown". A later unpublished study by Carnegie Mellon University noted that "Most often, the causes of identity theft is not known", but reported that someone else concluded that "the probability of becoming a victim to identity theft as a result of a data breach is ... around only 2%".[8] For example, in one of the largest data breaches which affected over four million records, it resulted in only about 1,800 instances of identity theft, according to the company whose systems were breached.Script error: No such module "Unsubst".

An October 2010 article entitled "Cyber Crime Made Easy" explained the level to which hackers are using malicious software.[9] As Gunter Ollmann, Chief Technology Officer of security at Microsoft, said, "Interested in credit card theft? There's an app for that."[10] This statement summed up the ease with which these hackers are accessing all kinds of information online. The new program for infecting users' computers was called Zeus, and the program is so hacker-friendly that even an inexperienced hacker can operate it. Although the hacking program is easy to use, that fact does not diminish the devastating effects that Zeus (or other software like Zeus) can do on a computer and the user. For example, programs like Zeus can steal credit card information, important documents, and even documents necessary for homeland security. If a hacker were to gain this information, it would mean nationwide identity theft or even a possible terrorist attack. The ITAC said that about 15 million Americans had their identity stolen in 2012.[11]

Types

Script error: No such module "labelled list hatnote". Sources such as the Non-profit Identity Theft Resource Center[12] sub-divide identity theft into five categories:

  • Criminal identity theft (posing as another person when apprehended for a crime)
  • Financial identity theft (using another's identity to obtain credit, goods, and services)
  • Identity cloning (using another's information to assume his or her identity in daily life)
  • Medical identity theft (using another's identity to obtain medical care or drugs)
  • Child identity theft.

Identity theft may be used to facilitate or fund other crimes including illegal immigration, terrorism, phishing and espionage. There are cases of identity cloning to attack payment systems, including online credit card processing and medical insurance.[13]

Identity cloning and concealment

In this situation, the identity thief impersonates someone else to conceal their own true identity. Examples are illegal immigrants hiding their illegal status, people hiding from creditors or other individuals and those who simply want to become "anonymous" for personal reasons. Another example is posers, a label given to people who use someone else's photos and information on social networking sites. Posers mostly create believable stories involving friends of the real person they are imitating. Unlike identity theft used to obtain credit which usually comes to light when the debts mount, concealment may continue indefinitely without being detected, particularly if the identity thief can obtain false credentials to pass various authentication tests in everyday life.

Criminal identity theft

When a criminal fraudulently identifies themselves to police as another individual at the point of arrest, it is sometimes referred to as "Criminal Identity Theft." In some cases, criminals have previously obtained state-issued identity documents using credentials stolen from others, or have simply presented a fake ID. Provided the subterfuge works, charges may be placed under the victim's name, letting the criminal off the hook. Victims might only learn of such incidents by chance, for example by receiving a court summons, discovering their driver's licenses are suspended when stopped for minor traffic violations, or through background checks performed for employment purposes.

It can be difficult for the victim of criminal identity theft to clear their record. The steps required to clear the victim's incorrect criminal record depend on which jurisdiction the crime occurred and whether the true identity of the criminal can be determined. The victim might need to locate the original arresting officers and prove their own identity by some reliable means such as fingerprinting or DNA testing and may need to go to a court hearing to be cleared of the charges. Obtaining an expungement of court records may also be required. Authorities might permanently maintain the victim's name as an alias for the criminal's true identity in their criminal records databases. One problem that victims of criminal identity theft may encounter is that various data aggregators might still have incorrect criminal records in their databases even after court and police records are corrected. Thus a future background check may return the incorrect criminal records.[14] This is just one example of the kinds of impact that may continue to affect the victims of identity theft for some months or even years after the crime, aside from the psychological trauma that being 'cloned' typically engenders.

Synthetic identity theft

A variation of identity theft that has recently become more common is synthetic identity theft, in which identities are completely or partially fabricated.[15] The most common technique involves combining a real social security number with a name and birthdate other than the ones that are simply associated with the number. Synthetic identity theft is more difficult to track as it doesn't show on either person's credit report directly but may appear as an entirely new file in the credit bureau or as a subfile on one of the victim's credit reports. Synthetic identity theft primarily harms the creditors who unwittingly grant the fraudsters credit. Individual victims can be affected if their names become confused with the synthetic identities, or if negative information in their subfiles impacts their credit ratings.[16]

Medical identity theft

Script error: No such module "Labelled list hatnote".

File:Figure 2- Risk of Identity Theft with Medicare Card under CMS’s Three Proposed Options (7802334168).jpg
US Government Accountability Office diagram showing the identity theft risk associated with social security numbers on Medicare cards

Privacy researcher Pam Dixon, the founder of the World Privacy Forum,[17] coined the term medical identity theft and released the first major report about this issue in 2006. In the report, she defined the crime for the first time and made the plight of victims public. The report's definition of the crime is that medical identity theft occurs when someone seeks medical care under the identity of another person. Insurance theft is also very common, if a thief has your insurance information and or your insurance card, they can seek medical attention posing as yourself.[18] In addition to risks of financial harm common to all forms of identity theft, the thief's medical history may be added to the victim's medical records. Inaccurate information in the victim's records is difficult to correct and may affect future insurability or cause doctors to rely on misinformation to deliver inappropriate care. After the publication of the report, which contained a recommendation that consumers receive notifications of medical data breach incidents, California passed a law requiring this, and then finally HIPAA was expanded to also require medical breach notification when breaches affect 500 or more people.[19][20] Data collected and stored by hospitals and other organizations such as medical aid schemes is up to 10 times more valuable to cybercriminals than credit card information.

Child identity theft

Child identity theft occurs when a minor's identity is used by another person for the impostor's personal gain. The impostor can be a family member, a friend, or even a stranger who targets children. The Social Security numbers of children are valued because they do not have any information associated with them. Thieves can establish lines of credit, obtain driver's licenses, or even buy a house using a child's identity. This fraud can go undetected for years, as most children do not discover the problem until years later. Child identity theft is fairly common, and studies have shown that the problem is growing. The largest study on child identity theft, as reported by Richard Power of the Carnegie Mellon Cylab with data supplied by AllClear ID, found that of 40,000 children, 10.2% were victims of identity theft.[21]

The Federal Trade Commission (FTC) estimates that about nine million people will be victims of identity theft in the United States per year. It was also estimated that in 2008; 630,000 people under the age of 19 were victims of theft. This then gave the victims a debt of about $12,799.[22]

Not only are children in general big targets of identity theft but children who are in foster care are even bigger targets. This is because they are most likely moved around quite frequently and their SSN is being shared with multiple people and agencies. Foster children are even more victims of identity theft within their own families and other relatives. Young people in foster care who are victims of this crime are usually left alone to struggle and figure out how to fix their newly formed bad credit.[22]

The emergence of children's identities on social media has also contributed to a rise in incidents of digital kidnapping and identity theft. Digital kidnapping involves individuals stealing online images of children and misrepresenting them as their own.[23]

Financial identity theft

The most common type of identity theft is related to finance. Financial identity theft includes obtaining credit, loans, goods, and services while claiming to be someone else.[24]

Tax identity theft

Script error: No such module "Labelled list hatnote". One of the major identity theft categories is tax-related identity theft. The most common method is to use a person's authentic name, address, and Social Security Number to file a tax return with false information, and have the resulting refund direct-deposited into a bank account controlled by the thief. The thief in this case can also try to get a job and then their employer will report the income of the real taxpayer, this then results in the taxpayer getting in trouble with the IRS.[25]

The 14039 Form to the IRS is a form that will help one fight against a theft like tax theft. This form will put the IRS on alert and someone who believed they have been a victim of tax-related theft will be given an Identity Protection Personal Identification Number (IP PIN), which is a 6 digit code used in replacing an SSN for filing tax returns.[25]

Techniques for obtaining and exploiting personal information

Identity thieves typically obtain and exploit personally identifiable information about individuals, or various credentials they use to authenticate themselves, to impersonate them. Examples include:

  • Using public records about individual citizens, published in official registers such as electoral rolls[26]
  • Stealing cheques (checks) to acquire banking information, including account numbers and bank codes[27]
  • Guessing Social Security numbers by using information found on Internet social networks such as Twitter and MySpace[28]

In some cases, after obtaining a victim’s personal information, identity thieves may alter the victim’s contact details such as their mailing address, phone number, or email to prevent notifications from reaching them and to delay detection of fraudulent activity.[29]

Individual identity protection

The acquisition of personal identifiers is made possible through serious breaches of privacy. For consumers, this is usually a result of them naively providing their personal information or login credentials to the identity thieves (e.g., in a phishing attack) but identity-related documents such as credit cards, bank statements, utility bills, checkbooks, etc. may also be physically stolen from vehicles, homes, offices, and not the least letterboxes, or directly from victims by pickpockets and bag snatchers. Guardianship of personal identifiers by consumers is the most common intervention strategy recommended by the US Federal Trade Commission, Canadian Phone Busters and most sites that address identity theft. Such organizations offer recommendations on how individuals can prevent their information from falling into the wrong hands.

Identity theft can be partially mitigated by not identifying oneself unnecessarily (a form of information security control known as risk avoidance). This implies that organizations, IT systems, and procedures should not demand excessive amounts of personal information or credentials for identification and authentication. Requiring, storing, and processing personal identifiers (such as Social Security number, national identification number, driver's license number, credit card number, etc.) increases the risks of identity theft unless this valuable personal information is adequately secured at all times. Committing personal identifiers to memory is a sound practice that can reduce the risks of a would-be identity thief from obtaining these records. To help in remembering numbers such as social security numbers and credit card numbers, it is helpful to consider using mnemonic techniques or memory aids such as the mnemonic Major System.

Identity thieves sometimes impersonate dead people, using personal information obtained from death notices, gravestones, and other sources to exploit delays between the death and the closure of the person's accounts, the inattentiveness of grieving families, and weaknesses in the processes for credit-checking. Such crimes may continue for some time until the deceased's families or the authorities notice and react to anomalies.[30]

In recent yearsTemplate:When, commercial identity theft protection/insurance services have become available in many countries. These services purport to help protect the individual from identity theft or help detect that identity theft has occurred in exchange for a monthly or annual membership fee or premium.[31] The services typically work either by setting fraud alerts on the individual's credit files with the three major credit bureaus or by setting up credit report monitoring with the credit bureau. While identity theft protection/insurance services have been heavily marketed, their value has been called into question.[32]

Potential outcomes

Identity theft is a serious problem in the United States. In a 2018 study, it was reported that 60 million Americans' identities had been wrongfully acquired.[33] In response, under advisement from the Identity Theft Resource Center, some new bills have been implemented to improve security such as requiring electronic signatures and social security verification.[33]

Several types of identity theft are used to gather information, one of the most common types occurs when consumers make online purchases.[34] A study was conducted with 190 people to determine the relationship between the constructs of fear of financial losses and reputational damages.[34] The conclusions of this study revealed that identity theft was a positive correlation with reputable damages.[34] The relationship between perceived risk and online purchase intention were negative.[34] The significance of this study reveals that online companies are more aware of the potential harm that can be done to their consumers, therefore they are searching for ways to reduce the perceived risk of consumers and not lose out on business.

Victims of identity theft may face years of effort proving to the legal system that they are the true person,[35] leading to emotional strain and financial losses. Most identity theft is perpetrated by a family member of the victim, and some may not be able to obtain new credit cards or open new bank accounts or loans.[35]

Identity protection by organizations

In their May 1998 testimony before the United States Senate, the Federal Trade Commission (FTC) discussed the sale of Social Security numbers and other personal identifiers by credit-raters and data miners. The FTC agreed to the industry's self-regulating principles restricting access to information on credit reports.[36] According to the industry, the restrictions vary according to the category of customer. Credit reporting agencies gather and disclose personal and credit information to a wide business client base.

Poor stewardship of personal data by organizations, resulting in unauthorized access to sensitive data, can expose individuals to the risk of identity theft. The Privacy Rights Clearinghouse has documented over 900 individual data breaches by US companies and government agencies since January 2005, which together have involved over 200 million total records containing sensitive personal information, many containing social security numbers.[37] Poor corporate diligence standards which can result in data breaches include:

  • failure to shred confidential information before throwing it into dumpsters
  • failure to ensure adequate network security
  • credit card numbers stolen by call center agents and people with access to call recordings
  • the theft of laptop computers or portable media being carried off-site containing vast amounts of personal information. The use of strong encryption on these devices can reduce the chance of data being misused should a criminal obtain them.
  • the brokerage of personal information to other businesses without ensuring that the purchaser maintains adequate security controls
  • Failure of governments, when registering sole proprietorships, partnerships, and corporations, to determine if the officers listed in the Articles of Incorporation are who they say they are. This potentially allows criminals access to personal information through credit rating and data mining services.

The failure of corporate or government organizations to protect consumer privacy, client confidentiality and political privacy has been criticized for facilitating the acquisition of personal identifiers by criminals.[38]

Using various types of biometric information, such as fingerprints, for identification and authentication has been cited as a way to thwart identity thieves, however, there are technological limitations and privacy concerns associated with these methods as well.

Market

There is an active market for buying and selling stolen personal information, which occurs mostly in darknet markets but also in other black markets.[39] People increase the value of the stolen data by aggregating it with publicly available data, and sell it again for a profit, increasing the damage that can be done to the people whose data was stolen.[40]

Legal responses

International

In March 2014, after it was learned two passengers with stolen passports were on board Malaysia Airlines Flight 370, which went missing on 8 March 2014. It came to light that Interpol maintains a database of 40 million lost and stolen travel documents from 157 countries, which Interpol makes available to governments and the public, including airlines and hotels. The Stolen and Lost Travel Documents (SLTD) database, however, is rarely used. Big News Network (which is based in the UAE) reported that Interpol Secretary-General Ronald K. Noble told a forum in Abu Dhabi in the previous month, "The bad news is that, despite being incredibly cost-effective and deployable to virtually anywhere in the world, only a handful of countries are systematically using SLTD to screen travelers. The result is a major gap in our global security apparatus that is left vulnerable to exploitation by criminals and terrorists."[41]

Australia

In Australia, each state has enacted laws that deal with different aspects of identity or fraud issues. Some states have now amended relevant criminal laws to reflect crimes of identity theft, such as the Criminal Law Consolidation Act 1935 (SA), Crimes Amendment (Fraud, Identity and Forgery Offences) Act 2009, and also in Queensland under the Criminal Code 1899 (QLD). Other states and territories are in states of development in respect of regulatory frameworks relating to identity theft such as Western Australia in respect of the Criminal Code Amendment (Identity Crime) Bill 2009.

At the Commonwealth level, under the Criminal Code Amendment (Theft, Fraud, Bribery & Related Offences) Act 2000 which amended certain provisions within the Criminal Code Act 1995,

<templatestyles src="Template:Blockquote/styles.css" />

135.1 General dishonesty

(3) A person is guilty of an offense if a) the person does anything with the intention of dishonestly causing a loss to another person; and b) the other person is a Commonwealth entity.

Penalty: Imprisonment for 5 years.

Script error: No such module "Check for unknown parameters".

Between 2014 and 2015 in Australia, there were 133,921 fraud and deception offences, an increase of 6% from previous year. The total cost reported by the Attorney General Department was:[42]

Total costs[42]
Fraud category Cost per incident Total direct cost
Commonwealth fraud $2,111 $353,866,740
Personal fraud $400 $656,550,506
Police recorded fraud $4,412 per unrecorded incident

$27,981 per recorded incident

$3,260,141,049

There are also high indirect costs associated as a direct result of an incident. For example, the total indirect costs for police recorded fraud is $5,774,081.[42]

Likewise, each state has enacted its own privacy laws to prevent the misuse of personal information and data. The Commonwealth Privacy Act applies only to Commonwealth and territory agencies and to certain private-sector bodies (where, for example, they deal with sensitive records, such as medical records, or they have more than $3 million in turnover PA).

Canada

Under section 402.2 of the Criminal Code,

<templatestyles src="Template:Blockquote/styles.css" />

Everyone commits an offense who knowingly obtains or possesses another person's identity information in circumstances giving rise to a reasonable inference that the information is intended to be used to commit an indictable offense that includes fraud, deceit, or falsehood as an element of the offense. is guilty of an indictable offense and liable to imprisonment for a term of not more than five years; or is guilty of an offense punishable on summary conviction.

Script error: No such module "Check for unknown parameters".

Under section 403 of the Criminal Code,

<templatestyles src="Template:Blockquote/styles.css" />

(1) Everyone commits an offense who fraudulently personates another person, living or dead,

(a) with intent to gain advantage for themselves or another person; (b) with intent to obtain any property or an interest in any property; (c) with intent to cause disadvantage to the person being personated or another person; or (d) with intent to avoid arrest or prosecution or to obstruct, pervert or defeat the course of justice.

is guilty of an indictable offense and liable to imprisonment for a term of not more than 10 years; or guilty of an offense punishable on summary conviction.

Script error: No such module "Check for unknown parameters".

In Canada, Privacy Act (federal legislation) covers only federal government, agencies and crown corporations. Each province and territory has its own privacy law and privacy commissioners to limit the storage and use of personal data. For the private sector, the purpose of the Personal Information Protection and Electronic Documents Act (2000, c. 5) (known as PIPEDA) is to establish rules to govern the collection, use, and disclosure of personal information; except for the provinces of Quebec, Ontario, Alberta and British Columbia where provincial laws have been deemed substantially similar.

Proposed legislation

France

In France, a person convicted of identity theft can be sentenced up to five years in prison and fined up to 75,000.[43]

Hong Kong

Under HK Laws. Chap 210 Theft Ordinance, sec. 16A Fraud:

<templatestyles src="Template:Blockquote/styles.css" />

(1) If any person by any deceit (whether or not the deceit is the sole or main inducement) and with intent to defraud induces another person to commit an act or make an omission, which results either-

(a) in benefit to any person other than the second-mentioned person; or (b) in prejudice or a substantial risk of prejudice to any person other than the first-mentioned person,

the first-mentioned person commits the offense of fraud and is liable on conviction upon indictment to imprisonment for 14 years.

Script error: No such module "Check for unknown parameters".

The Personal Data (Privacy) Ordinance (PDPO) regulates the collection, use and retention of personal information in Hong Kong. It also provides citizens the right to request information held by businesses and the government to the extent provided by this law. The PDPO establishes the Office of the Privacy Commissioner for Personal Data which enforces the law and advises on the use of personal data.

India

Under the Information Technology Act 2000 Chapter IX Sec 66C:

<templatestyles src="Template:Blockquote/styles.css" />

SECTION 66C

PUNISHMENT FOR IDENTITY THEFT

Whoever, fraudulently or dishonestly makes use of the electronic signature, password, or any other unique identification feature of any other person, shall be punished with imprisonment of either description for a term which may extend to three years and shall also be liable to fine which may extend to rupees one lakh.[44]

Script error: No such module "Check for unknown parameters".

Philippines

Social networking sites are one of the most famous spreaders of posers in the online community, giving the users the freedom to post any information they want without any verification that the account is being used by the real person.Template:Clarify

The Philippines, which ranks eighth in the numbers of users of Facebook and other social networking sites (such as Twitter, Multiply and Tumblr), has been known as a source of various identity theft problems.[45] Identities of people who carelessly put personal information on their profiles can easily be stolen just by simple browsing. Some people meet online, get to know each other through Facebook chat, and exchange messages that share private information. Others get romantically involved with online friends and end up sharing too much information (such as their social security number, bank account, home address, and company address).

This phenomenon leads to the creation of the Cybercrime Prevention Act of 2012 (Republic Act No. 10175). Section 2 of this act states that it recognizes the importance of communication and multimedia for the development, exploitation, and dissemination of informationTemplate:Clarify, but violators will be punished by the law through imprisonment or a fine upwards of ₱200,000, but not exceeding ₱1,000,000, or (depending on the damage caused) both.

Sweden

Sweden has had relatively few problems with identity theft because only Swedish identity documents were accepted for identity verification. Stolen documents are traceable by banks and certain other institutionsTemplate:Which. Banks are required to check the identity of anyone withdrawing money or getting loans. If a bank gives money to someone using an identity document that has been reported as stolen, the bank must take this loss. Since 2008, any EU passport is valid in Sweden for identity verification, and Swedish passports are valid all over the EU. This makes it harder to detect stolen documents, but banks in Sweden still must ensure that stolen documents are not accepted.

Other types of identity theft have become more common in Sweden. One common example is ordering a credit card to someone who has an unlocked letterbox and is not home during the daytime. The thief steals the letter with the credit card and the letter with the code, which typically arrives a few days later. Usage of a stolen credit card is difficult in Sweden since an identity document or a PIN code is normally demanded. If a shop does not demand either, it must take the loss from accepting a stolen credit card. The practice of observing someone using their credit card's PIN code, stealing the credit card, or skimming it, and then using the credit card has become more common.

Legally, Sweden is an open society. The Principle of Public Access states that all information (e.g. addresses, incomes, taxes) kept by public authorities must be available for anyone, except in certain cases (for example, the addresses of people who need to hide are restricted). This makes fraud easier.

Until 2016, there were no laws that specifically prohibited using someone's identity. Instead, there were only laws regarding any indirect damages caused. Impersonating anyone else for financial gain is a type of fraud in the Criminal Code (Template:Langx). Impersonating anyone else to discredit them by hacking into their social media accounts and provokeTemplate:Clarify is considered libel. However, it is difficult to convict someone of committing this crime. In late 2016, a new law was introduced which partially banned undeterminedTemplate:Clarify identity usage.[46]

United Kingdom

In the United Kingdom, personal data is protected by the Data Protection Act 1998. The Act covers all personal data which an organization may hold, including names, birthday and anniversary dates, addresses, and telephone numbers.

Under English law (which extends to Wales but not to Northern Ireland or Scotland), the deception offences under the Theft Act 1968 increasingly contend with identity theft situations. In R v Seward (2005) EWCA Crim 1941,[47] the defendant was acting as the "frontman" in the use of stolen credit cards and other documents to obtain goods. He obtained goods to the value of £10,000 for others who are unlikely ever to be identified. The Court of Appeal considered a sentencing policy for deception offenses involving "identity theft" and concluded that a prison sentence was required. Henriques J. said at para 14: "Identity fraud is a particularly pernicious and prevalent form of dishonesty calling for, in our judgment, deterrent sentences."

Statistics released by CIFAS (UK's Fraud Prevention Service) show that there were 89,000 victims of identity theft in the UK in 2010 and 85,000 victims in 2009.[48][49]Script error: No such module "Unsubst". Men in their 30s and 40s are the most common victims.[50]Script error: No such module "Unsubst". Identity fraud now accounts for nearly half of all frauds recorded.[51]

United States

Script error: No such module "Labelled list hatnote". The increase in crimes of identity theft led to the drafting of the Identity Theft and Assumption Deterrence Act.[52] In 1998, The Federal Trade Commission appeared before the United States Senate.[53] The FTC discussed crimes which exploit consumer credit to commit loan fraud, mortgage fraud, lines-of-credit fraud, credit card fraud, commodities and services frauds. The Identity Theft Deterrence Act (2003)[ITADA] amended U.S. Code Title 18, § 1028 ("Fraud related to activity in connection with identification documents, authentication features, and information"). The statute now makes the possession of any "means of identification" to "knowingly transfer, possess, or use without lawful authority" a federal crime, alongside unlawful possession of identification documents. However, for federal jurisdiction to prosecute, the crime must include an "identification document" that either: (a) is purportedly issued by the United States, (b) is used or intended to defraud the United States, (c) is sent through the mail, or (d) is used in a manner that affects interstate or foreign commerce. See 18 U.S.C. Template:Trim/Template:Trim § Template:Trim(c). Punishment can be up to 5, 15, 20, or 30 years in federal prison, plus fines, depending on the underlying crime per 18 U.S.C. Template:Trim/Template:Trim § Template:Trim(b). In addition, punishments for the unlawful use of a "means of identification" were strengthened in § 1028A ("Aggravated Identity Theft"), allowing for a consecutive sentence under specific enumerated felony violations as defined in § 1028A(c)(1) through (11).[54]

The Act also provides the Federal Trade Commission with authority to track the number of incidents and the dollar value of losses. Their figures relate mainly to consumer financial crimes and not the broader range of all identification-based crimes.[55]

If charges are brought by state or local law enforcement agencies, different penalties apply to depend on the state.

Six Federal agencies conducted a joint task force to increase the ability to detect identity theft. Their joint recommendation on "red flag" guidelines is a set of requirements on financial institutions and other entities which furnish credit data to credit reporting services to develop written plans for detecting identity theft. The FTC has determined that most medical practices are considered creditors and are subject to requirements to develop a plan to prevent and respond to patient identity theft.[56] These plans must be adopted by each organization's board of directors and monitored by senior executives.[57]

Identity theft complaints as a percentage of all fraud complaints decreased from 2004 to 2006.[58] The Federal Trade Commission reported that fraud complaints in general were growing faster than ID theft complaints.[58] The findings were similar in two other FTC studies done in 2003 and 2005. In 2003, 4.6 percent of the US population said they were a victim of ID theft. In 2005, that number had dropped to 3.7 percent of the population.[59][60] The commission's 2003 estimate was that identity theft accounted for some $52.6 billion of losses in the preceding year alone and affected more than 9.91 million Americans;[61] the figure comprises $47.6 billion lost by businesses and $5 billion lost by consumers.

According to the U.S. Bureau of Justice Statistics, in 2010, 7% of US households experienced identity theft - up from 5.5% in 2005 when the figures were first assembled, but broadly flat since 2007.[62] In 2012, approximately 16.6 million persons, or 7% of all U.S. residents age 16 or older, reported being victims of one or more incidents of identity theft.[63]

At least two states, California[64] and Wisconsin[65] have created an Office of Privacy Protection to assist their citizens in avoiding and recovering from identity theft.

In 2009, Indiana created an Identity Theft Unit within their Office of Attorney General to educate and assist consumers in avoiding and recovering from identity theft as well as assist law enforcement in investigating and prosecuting identity theft crimes.[66][67]

In Massachusetts in 2009–2010, Governor Deval Patrick committed to balancing consumer protection with the needs of small business owners. His Office of Consumer Affairs and Business Regulation announced certain adjustments to Massachusetts' identity theft regulations that maintain protections and also allow flexibility in compliance. These updated regulations went into effect on 1 March 2010. The regulations are clear that their approach to data security is a risk-based approach important to small businesses and might not handle a lot of personal information about customers.[68][69]

The IRS has createdTemplate:When the IRS Identity Protection Specialized Unit to help taxpayers' who are victims of federal tax-related identity theft.[70] Generally, the identity thief will use a stolen SSN to file a forged tax return and attempt to get a fraudulent refund early in the filing season. A taxpayer will need to fill out Form 14039, Identity Theft Affidavit.[71][72]

As for the future of medical care and Medicaid, people are mostly concerned about cloud computing. The addition of using cloud information within the United States medicare system would institute easily accessible health information for individuals, but that also makes it easier for identity theft. Currently, new technology is being produced to help encrypt and protect files, which will create a smooth transition to cloud technology in the healthcare system.[73]

Notification

Many states followed California's lead and enacted mandatory data breach notification laws. As a result, companies that report a data breach typically report it to all their customers.[74]

Spread and impact

Script error: No such module "Unsubst". Surveys in the US from 2003 to 2006 showed a decrease in the total number of identity fraud victims and a decrease in the total value of identity fraud from US$47.6 billion in 2003 to $15.6 billion in 2006.Script error: No such module "Unsubst". The average fraud per person decreased from $4,789 in 2003 to $1,882 in 2006. A Microsoft report shows that this drop is due to statistical problems with the methodology, that such survey-based estimates are "hopelessly flawed" and exaggerate the true losses by orders of magnitude.[75]

The 2003 survey from the Identity Theft Resource Center[76] found that:

  • Only 15% of victims find out about the theft through proactive action taken by a business
  • The average time spent by victims resolving the problem is about 330 hours
  • 73% of respondents indicated the crime involved the thief acquiring a credit card

In a widely publicized account,[77] Michelle Brown, a victim of identity fraud, testified before a U.S. Senate Committee Hearing on Identity Theft. Ms. Brown testified that: "over a year and a half from January 1998 through July 1999, one individual impersonated me to procure over $50,000 in goods and services. Not only did she damage my credit, but she escalated her crimes to a level that I never truly expected: she engaged in drug trafficking. The crime resulted in my erroneous arrest record, a warrant out for my arrest, and eventually, a prison record when she was booked under my name as an inmate in the Chicago Federal Prison."

In Australia, identity theft was estimated to be worth between A$1billion and A$4 billion per annum in 2001.[78]

In the United Kingdom, the Home Office reported that identity fraud costs the UK economy £1.2 billion annually[79] (experts believe that the real figure could be much higher)[80] although privacy groups object to the validity of these numbers, arguing that they are being used by the government to push for introduction of national ID cards. Confusion over exactly what constitutes identity theft has led to claims that statistics may be exaggerated.[81] An extensively reported[82][83] study from Microsoft Research[84] in 2011 finds that estimates of identity theft losses contain enormous exaggerations, writing that surveys "are so compromised and biased that no faith whatever can be placed in their findings."

See also

Template:Div col

Types of fraud and theft

Template:Div col

Template:Div col end

Organizations

Template:Div col

Template:Div col end

Laws

Template:Div col

Template:Div col end

Notable identity thieves and cases

Template:Div col

Template:Div col end

Further reading

References

Template:Reflist

External links

Template:Sister project

Script error: No such module "Navbox". Template:Fraud Template:Privacy Template:Authority control

  1. Script error: No such module "citation/CS1".
  2. Synthetic ID Theft Cyber Space Times Template:Webarchive
  3. Template:Cite SSRN
  4. Script error: No such module "citation/CS1".
  5. See, e.g., Script error: No such module "citation/CS1".
  6. Federal Trade Commission – 2006 Identity Theft Survey Report, p. 4
  7. Script error: No such module "citation/CS1".
  8. Script error: No such module "citation/CS1".
  9. Script error: No such module "Citation/CS1".
  10. Script error: No such module "citation/CS1".
  11. Victims of Identity Theft, 2012 BJS
  12. Script error: No such module "citation/CS1".
  13. Script error: No such module "citation/CS1"., World Privacy Forum
  14. Script error: No such module "citation/CS1". - "Fact Sheet 17g: Criminal Identity Theft: What to Do If It Happens to You "
  15. Script error: No such module "citation/CS1".
  16. Script error: No such module "citation/CS1".
  17. Script error: No such module "citation/CS1".
  18. Script error: No such module "citation/CS1".
  19. Script error: No such module "citation/CS1".
  20. Script error: No such module "citation/CS1".
  21. Script error: No such module "citation/CS1".
  22. a b Script error: No such module "citation/CS1".
  23. Script error: No such module "Citation/CS1".
  24. Script error: No such module "citation/CS1".
  25. a b Script error: No such module "citation/CS1".
  26. Script error: No such module "citation/CS1".Template:Dead linkTemplate:Cbignore
  27. Script error: No such module "citation/CS1"., Douglas County Sheriff's Office, Washington
  28. Script error: No such module "citation/CS1".
  29. Script error: No such module "citation/CS1".
  30. IDtheftcenter.org Template:Webarchive, Identity Theft Resource Center Fact Sheet 117 Identity Theft and the Deceased - Prevention and Victim Tips.
  31. Script error: No such module "citation/CS1". retrieved on 16 December 2008
  32. Script error: No such module "citation/CS1". PC World.com, retrieved on 16 December 2008
  33. a b Script error: No such module "citation/CS1".
  34. a b c d Script error: No such module "Citation/CS1".
  35. a b Script error: No such module "citation/CS1".
  36. Script error: No such module "citation/CS1"., Committee of the Judiciary, United States Senate 20 May 1998 pp 5,6
  37. Script error: No such module "citation/CS1".
  38. Internet Identity Theft - A Tragedy for Victims Template:Webarchive, Software and Information Industry Association. Retrieved 30 June 2006.
  39. Script error: No such module "citation/CS1".
  40. Script error: No such module "citation/CS1".
  41. Script error: No such module "citation/CS1".Template:Cbignore
  42. a b c Script error: No such module "citation/CS1".
  43. Script error: No such module "citation/CS1".
  44. Script error: No such module "citation/CS1".
  45. Script error: No such module "citation/CS1".
  46. Script error: No such module "citation/CS1".
  47. Script error: No such module "citation/CS1".
  48. Script error: No such module "citation/CS1"., CIFAS
  49. Script error: No such module "citation/CS1"., Identity Theft UK Blog, 3 February 2010
  50. Script error: No such module "citation/CS1"., Protect MY ID Blog, 21 January 2011
  51. Script error: No such module "citation/CS1"., CIFAS
  52. Script error: No such module "citation/CS1"., Public Law 105-318, 112 Stat. 3007 (30 October 1998)
  53. Script error: No such module "citation/CS1"., 20 May 1998
  54. Doyle, Charles. (2013). Mandatory Minimum Sentencing: Federal Aggravated Identity Theft. Template:Webarchive Washington, D.C.: Congressional Research Service.
  55. Federal Trade Commission. Retrieved 30 June 2006. Template:Webarchive
  56. Michael, Sara Script error: No such module "citation/CS1". PhysiciansPractice.com, 21 May 2009. Retrieved 2 July 2009.
  57. 72 Fed. Reg. 70944 Template:Webarchive (PDF). Retrieved 29 January 2008.
  58. a b Script error: No such module "citation/CS1".
  59. Script error: No such module "citation/CS1".
  60. Script error: No such module "citation/CS1".
  61. Script error: No such module "citation/CS1"., releases Survey of Identity Theft in U.S. 27.3 Million Victims in past 5 Years, Billions in Losses for Businesses and Consumers
  62. Script error: No such module "citation/CS1".
  63. Harrell, Erika and Lynn Langton. (2013). Victims of Identity Theft, 2012. Template:Webarchive Washington, D.C. U.S. Department of Justice, Bureau of Justice Statistics.
  64. Script error: No such module "citation/CS1".
  65. Script error: No such module "citation/CS1".
  66. Script error: No such module "citation/CS1".
  67. Script error: No such module "citation/CS1".
  68. "Consumer Identity Theft". Commonwealth of Massachusetts, 2010 Template:Webarchive
  69. "Frequently Asked Question Regarding 201 CMR 17.00" Template:Webarchive, Commonwealth of Massachusetts, Office of Consumer Affairs and Business Regulation, 3 November 2009
  70. Script error: No such module "citation/CS1".
  71. Script error: No such module "citation/CS1".
  72. Script error: No such module "citation/CS1".
  73. Hyde, J. (2017). Preventing Identity Theft and Strengthening the American Health Care System. Policy & Practice (19426828), 75(5), 26–34.
  74. Script error: No such module "citation/CS1".
  75. Script error: No such module "citation/CS1".
  76. Script error: No such module "citation/CS1".
  77. Script error: No such module "citation/CS1"., July 2000, U.S. Senate Committee Hearing on the Judiciary Subcommittee on Technology, Terrorism and Government InformationTemplate:Spaced ndash"Identity Theft: How to Protect and Restore Your Good Name"
  78. Identity Crime Research and Coordination Template:Webarchive, Australasian Center for Policing Research. Retrieved 30 June 2006.
  79. Script error: No such module "citation/CS1".
  80. Script error: No such module "citation/CS1".
  81. Script error: No such module "citation/CS1".
  82. Script error: No such module "citation/CS1".
  83. Script error: No such module "citation/CS1".
  84. Script error: No such module "citation/CS1".