Overview
Identity theft occurs when someone uses your personal or financial information without your permission. The person may use your name, Social Security number, payment-card information, bank-account information, health-insurance information, login credentials, or identity documents to impersonate you or obtain a benefit.
Identity theft can involve existing accounts or entirely new activity. Examples include taking over an online account, making unauthorized purchases, opening credit or utility accounts, obtaining medical care, applying for employment or government benefits, filing a tax return, or using another person's identity during a law-enforcement encounter.
The loss or exposure of personal information does not always mean identity theft has occurred. It creates a risk that should be evaluated based on what information was involved and whether there are signs that someone has used it.
How It Works
Personal information can be obtained through:
- Phishing email, scam text messages, phone calls, fake websites, or fraudulent forms.
- Data breaches affecting a business, government agency, school, service provider, or other organization.
- Stolen mail, wallets, identity documents, checks, or devices.
- Malicious software, compromised accounts, reused passwords, or unauthorized remote access.
- Public records, social media, people-search sites, and other information available online.
- A person who already has legitimate access to records, accounts, documents, or devices and misuses that access.
The information may then be used for:
- Existing-account fraud, such as unauthorized purchases, withdrawals, transfers, password changes, or account takeovers.
- New-account fraud, such as opening a credit card, loan, phone, utility, or payment account in your name.
- Tax identity theft, such as filing a return using your Social Security number to claim a refund.
- Employment or benefits fraud, such as using your identity to obtain work, unemployment payments, or government benefits.
- Medical identity theft, such as using your health-insurance or personal information to obtain care or submit claims.
- Criminal identity misuse, such as providing your identity to law enforcement.
Different types of identity theft require different recovery steps. Start with the organization where the misuse occurred and use IdentityTheft.gov for a recovery plan tailored to the situation.
Warning Signs
Possible signs of identity theft include:
- Purchases, withdrawals, transfers, or account changes you do not recognize.
- Bills, collection notices, credit cards, account statements, or packages for accounts you did not open.
- Expected mail or statements that stop arriving because someone changed your address.
- New accounts, inquiries, addresses, or debts on your credit report that are not yours.
- Password-reset notices, MFA prompts, sign-in alerts, forwarding rules, or profile changes you did not initiate.
- A tax return being rejected because one was already filed using your Social Security number, or an unexpected notice from the IRS or a state tax agency.
- Medical bills, insurance claims, prescriptions, or explanations of benefits for care you did not receive.
- A notice about wages, employment, unemployment claims, or government benefits that you do not recognize.
- A business denying credit or service because of information that does not match your activity.
- A data-breach notice involving sensitive information, especially when combined with unfamiliar account or credit activity.
An unexpected message claiming that your identity was stolen may itself be a scam. Do not transfer money, provide codes, or contact an “agent” using information in the message. Verify the claim directly with the organization involved.
How to Protect Yourself
- Use strong, unique passwords and MFA. A password manager can help create and store unique passwords. Approve only MFA requests you initiated.
- Protect your Social Security number and identity documents. Provide them only when there is a legitimate need and the recipient and method have been verified.
- Secure physical records and mail. Store sensitive documents safely, retrieve mail promptly, and destroy records appropriately before disposal.
- Review account and financial statements. Investigate unfamiliar transactions, changes, or missing bills promptly.
- Check your credit reports. Use AnnualCreditReport.com, the federally authorized source, and review reports for accounts, inquiries, and personal information you do not recognize.
- Consider a credit freeze. A freeze can make it harder for someone to open a new credit account in your name. It does not prevent every form of identity theft and does not block activity on existing accounts.
- Use account alerts. Enable notifications for sign-ins, password changes, purchases, transfers, and profile updates when available.
- Keep devices and applications updated. Use screen locks, install security updates, and obtain applications from official sources.
- Respond carefully to breach notices. Verify the notice through the organization's official website and follow guidance appropriate to the specific information involved.
- Limit unnecessary public information. Details such as full birth dates, addresses, travel plans, family relationships, and employment information can support impersonation and account-recovery attacks.
What You Should Do at UM
If the incident involves a UM account, UM device, university email, student or employee information, or data held by UM:
- Contact the UM IT Helpdesk or UM Information Security Office. Provide a brief description of what information or account may be affected.
- Change your UM password through the normal UM account-management process if it was entered on an unfamiliar site, shared with another person, or may have been exposed.
- Deny unexpected MFA requests and do not share verification codes. Contact UM support if you approved a request you did not initiate.
- Preserve relevant messages and records. Do not forward sensitive information more broadly than necessary.
- Contact the relevant UM office through a trusted UM channel if the issue affects payroll, benefits, student records, financial aid, purchasing, or another university process.
If the suspected identity theft began with a phishing email in your UM mailbox, use Outlook's Report Message tool and report the message as phishing. Delete the message after reporting it. The Report Message tool may remove it automatically.
UM can assess and assist with university accounts, devices, messages, and data. Recovery for personal bank accounts, credit reports, taxes, medical records, government benefits, or personal online accounts must also be handled with the organization responsible for those records or services.
What to Do if Your Identity Was Used
Take the steps that match what happened:
- Contact the organization where the fraud occurred. Ask for its fraud or security department, explain which activity is unauthorized, and request that affected accounts be secured or closed.
- Contact your financial institution or payment provider immediately when a bank account, payment card, check, transfer, or payment application is involved.
- Secure affected online accounts. Change passwords from a trusted device, sign out other sessions when available, review MFA methods and recovery information, and remove changes you did not make.
- Report the identity theft at IdentityTheft.gov. The site provides a personal recovery plan, an FTC Identity Theft Report, and sample letters for different types of identity theft.
- Review your credit reports and consider a credit freeze or fraud alert. Follow the current instructions provided by the credit bureaus and the FTC.
- Follow the responsible agency's process for specialized identity theft. For example, use current IRS guidance for tax-related identity theft and contact the health insurer or medical provider for medical identity theft.
- Keep records. Save dates, names, confirmation numbers, letters, reports, statements, screenshots, and copies of documents sent or received.
- Consider a police report when needed. A business may request one, or local circumstances may warrant reporting theft, forgery, coercion, or other criminal activity.
Do not pay a person who contacts you unexpectedly and promises to repair your credit, recover stolen funds, or make identity theft disappear. Recovery services and credit-monitoring products may be useful in some circumstances, but they do not replace direct reports to affected organizations or the recovery steps provided by government resources.
Additional Questions
For identity theft involving a UM account, UM device, university message, or university-held information, contact the UM IT Helpdesk and the UM Information Security Office. Involve the relevant UM payroll, benefits, financial-aid, student-records, financial, or business office when a university process is affected.
For personal identity theft:
- Contact the financial institution, card issuer, account provider, medical provider, insurer, government agency, or business where the unauthorized activity occurred.
- Use IdentityTheft.gov for a personal recovery plan and FTC Identity Theft Report.
- Use AnnualCreditReport.com to obtain credit reports and review the FTC's current guidance on credit freezes and fraud alerts.
- Follow IRS Identity Theft Central guidance for tax-related identity theft.
- Contact local law enforcement when there is theft, forgery, coercion, an immediate safety concern, or a police report is needed for the recovery process.
Additional Resources