ADVERTISEMENT

Identity theft explained: what can be done with just your name

Identity theft explained
Vėjūnė Rimašiūtė
June 27, 2025 Updated: June 27, 2025 8 min read
Key takeaways:

What can be done with just your name

Understanding identity theft

Scammers are now after employers

Behind the identity theft schemes

ADVERTISEMENT

Online data gathering

  • Phishing, smishing, vishing. In these types of thefts, scammers pose as legitimate organizations and try to deceive people to extract their data. Phishing works via email letters, smishing is done via text message, and vishing involves a person calling on the phone.
  • Data breaches. Massive user data leaks often stem from corporate data breaches, where large volumes of personal information are stored and exposed. Once compromised, this data is typically sold in bulk on the dark web, with the exact contents varying based on the nature of the breached organization. Some of these breaches – like a supermassive Mother of all Breaches or the more recent one exposing 16 billion passwords – were uncovered by the Cybernews research team.
  • Malware. A range of malicious software – such as RATs, stealers, keyloggers, and spyware – is commonly used for data theft. Infections typically occur through phishing emails, malicious downloads, or visits to compromised websites. Once deployed, this malware can steal browser data, collect saved passwords, record what you type, and watch what you're doing on your device in real-time.
  • Social media scraping. Threat actors often deploy scraping bots to harvest personal information from social media platforms – details like full names, locations, relationship status, employment history, and even family member names. This data is then leveraged in targeted phishing campaigns and social engineering attacks to increase effectiveness.

Offline data gathering

  • Skimming. Criminals attach hidden data-capturing devices to ATMs, payment terminals, or gas pumps to steal credit/debit card information during legitimate transactions.
  • Mail theft. Physical theft of personal mail can expose sensitive documents, including bank statements, new credit cards, and other financial or identity-related information.
  • Loss or theft of a wallet. Stolen wallets give thieves direct access to personal data such as credit cards, driver's licenses, and government-issued IDs.
  • Dumpster diving. Threat actors search residential or commercial trash for discarded documents – like bills, bank statements, or pre-approved credit offers – that may contain valuable personal information.

What happens when scammers get your data

  • Financial identity theft. Often the most damaging form, it can involve criminals draining bank accounts, opening and maxing out credit cards, or taking out loans in the victim's name – particularly quick loans that require less stringent identity verification. The result can be serious debt and a ruined credit score.
  • Criminal identity theft. Occurs when a criminal uses someone else's identity during a crime or arrest. This can result in the victim facing legal consequences, failing background checks, or being wrongfully fined or prosecuted.
  • Tax identity theft. Fraudsters use a victim's personal information – often including their Social Security number – to file false tax returns and claim refunds. This can lead to the victim's legitimate return being rejected by the IRS.
  • Synthetic identity theft. A more sophisticated tactic where attackers combine real and fake information to create a new, fictitious identity. For example, they may use a real SSN with fabricated name and address details. While this often harms financial institutions, it can also negatively impact the real person tied to the SSN.
  • Child’s identity theft. Children's Social Security numbers are especially attractive due to their clean credit histories. Criminals may use them to open accounts, apply for loans, or access government benefits – often remaining undetected for years until the child grows up and applies for credit.

Identity theft is costing millions in the US

Protecting yourself from identity theft

  • Use a strong password. An easy to guess or compromised password is an easy target for cybercriminals. Make sure your password is unique and contains uppercase and lowercase letters, numbers, and symbols. And don’t write it down in visible places or share it with others.
  • Enable two-factor authentication. This secures your data with an additional lock. Even if your password is compromised, no one will be able to log into your account without authentication from your device.
  • Don’t overshare sensitive data. Sharing personal information such as full name, address, or phone number can help cybercriminals collect your data and use it to access your accounts.
  • Regularly monitor accounts. Keeping track of your accounts helps to quickly identify suspicious activity or unauthorized transactions. If you notice something suspicious, contact relevant institutions.
  • Use secure connections. Public networks are unsecured and generally unsafe, leaving many security loopholes that cybercriminals can exploit. If you can’t access a private network, use a VPN. It encrypts an internet connection and creates a secure tunnel for data.
  • Learn about phishing scams. Understanding how phishing attacks work and what tactics are used can help you prepare effective countermeasures. So, educating yourself on this topic is always a good practice.

Final remarks

ADVERTISEMENT