Defensive Protocols to Prevent Identity Theft
Securing your personally identifiable information (PII) is the primary defensive objective. A significant
portion of your PII is highly accessible due to endemic third-party database breaches and public registry
indexing.
Implement the following comprehensive prevention protocol:
- Enforce Cryptographic MFA: Secure all online logins with TOTP or physical keys. Avoid SMS
authentication whenever possible to eliminate SIM-swapping risks. Use a dedicated password manager
to generate and store unique, complex credentials.
- Proactive Taxpayer Protection: Establish an online account with the IRS to monitor tax
transcripts. Proactively check your transcripts to verify no fraudulent income has been reported in
your name. Request an Identity Protection PIN (IP PIN) to block unauthorized electronic tax filings.
- Social Security Administration Safeguards: Establish a secure online portal account,
mySocialSecurity, with the Social Security Administration (Social Security Administration). This
prevents threat actors from registering an account in your name to redirect benefits or falsify
employment records, allows you to monitor contributions and income data, and verifies that no one is
using your SSN to claim benefits or sign up for unauthorized work.
- USPS Informed Delivery: Register for the U.S. Postal Service’s Informed Delivery service.
This provides daily digital previews of physical mail, allowing you to instantly detect unauthorized
change-of-address requests or mail theft.
- Rigorous Financial Statement Auditing: Scrutinize banking and credit card statements regularly.
Report discrepancies immediately. Under the Fair Credit Billing Act (FCBA), consumers have a 60-day
statutory window from the statement delivery date to dispute unauthorized charges with the card
issuer or lender.
- Retrieve Annual Credit Reports: Check your credit file annually via annualcreditreport.com at
each of the major credit reporting agencies— Equifax, Experian, and TransUnion—as well as the
specialty bureau Innovis, ensuring no unauthorized accounts have been opened under your name.
- Physical Document Security: Keep sensitive paper documents—such as your Social Security card,
passport, and birth certificate—in a high-security home vault or a safe-deposit box. Shred all documents
containing personal or account numbers before disposing of them.
- Device and Network Defense: Install firewalls and reputable antivirus software on all devices.
Regularly update these security features to protect your systems from emerging malware and exploits.
- Phishing Countermeasures: Be highly cautious of emails, text messages, or phone calls soliciting
personal details or directing you to suspicious links. Legitimate financial institutions will never request
sensitive data via unsecured channels. Report phone scams to the Federal Trade Commission (FTC)
at ReportFraud.ftc.gov, and use the streamlined form at DoNotCall.gov if no money was lost. Review
further guidance on FTC phone scams.
- Information Exposure Minimization: Be aware of to whom you disclose personal data, both online
and offline. Never disclose unnecessary details on social networks, public profiles, or to unverified
platforms.
- Encrypted Data Storage: Ensure all financial records are stored securely. Use strong, unique
passwords and robust encryption for all sensitive personal spreadsheets, tax returns, and local financial
data.
- Execute Credit Freezes: Place a permanent security freeze on your credit files with the major credit
bureaus. This blocks creditors from accessing your credit history, preventing identity thieves from
establishing unauthorized credit lines.
- ATM Skimming and Payment Defenses: Understand the mechanics of ATM skimming. Maximize
the use of contactless, tokenized payment methods (such as Apple Pay or Google Pay) or physical
EMV chip insertion; avoid swiping magnetic strips.