Methods of stealing identity: how they happen and how to prevent them

Updated: 8 hours ago
Identity theft does not always begin with a stolen passport or hacked bank account.
The methods of stealing identity range from phishing, SIM swapping and credential theft to business email compromise, payroll diversion, document theft and synthetic identities.
In 2024, the US Federal Trade Commission received more than 1.1 million identity theft reports, showing how widespread the problem remains.
This guide explains how identity theft happens, the most common methods criminals use, how businesses are targeted, the warning signs to watch for and the controls that can help reduce the risk.
Methods of stealing identity - Key Takeaways |
|
|
|
|
|
|
|
What is identity theft?
Identity theft is when someone uses your private or commercial information without authorisation to commit fraud, usually for financial gain. It may involve a name, birthdate, national ID number, bank account or login details; anything that lets a thief pose as someone else.
What are the differences between identity theft and general fraud?
Fraud is the wider category. It includes any act of deception for financial or personal gain, including scams that don't require someone's identity to be stolen, for example, a fake investment plan where the victim deliberately hands over their money to a scammer who uses their own name.
Identity theft is much more specific. It always involves someone using the true identifying facts of another person or organisation without their consent.
Every incident of identity theft is a type of fraud. However, not every fraud case involves identity theft.

Types of identity theft: personal, business, synthetic
There are different types of identity theft, but most cases fit into three broad categories:
Personal identity theft: someone's identity gets stolen, and then it's used to create new accounts, get access to pre-existing ones or carry out crimes under their name.
Business identity theft: a company's identity, qualifications or brand is impersonated to deceive its employees, clients or suppliers.
Synthetic identity theft: a thief combines genuine details (often a genuine ID number) with fabricated data to create a fictional identity that won't match any real victim's identity.
If you want to master this topic, we suggest you read our guide: Identity theft types.
Identity theft methods at a glance
Method | Target | How it works | Common warning signs |
Phishing | Individuals and businesses | Fake emails request credentials or sensitive information | Unexpected login or payment request |
Smishing | Individuals and employees | Fraudulent SMS directs the victim to a fake site or phone number | Urgent account, delivery or payment message |
Business email compromise | Businesses | An executive, supplier or employee is impersonated | Unusual payment or banking instruction |
Employee impersonation | Businesses | Criminal poses as an employee to HR, IT or a help desk | Password or MFA reset request |
Fake websites | Both | A cloned site captures login or payment information | Slightly misspelt domain |
SIM swapping | Individuals and employees | Phone number is transferred to an attacker-controlled SIM | Sudden loss of mobile service |
Credential stuffing | Both | Stolen username/password pairs are tested on other services | Unexpected login notifications |
Payroll diversion | Employees and businesses | Direct-deposit details are replaced | Unexpected payroll account change |
Card skimming | Individuals | Hidden equipment captures card data and PINs | Unauthorised card activity |
Synthetic identity fraud | Financial institutions and businesses | Genuine and fabricated identity data are combined | Identity records that do not reconcile |
Insider misuse | Businesses and customers | Someone abuses legitimate access to sensitive information | Unusual access or data extraction |
Biometric presentation attacks | Digital onboarding systems | Images, masks or other presentation techniques attempt to fool biometric checks | Failed or anomalous liveness checks |

What identity theft methods target businesses?
Businesses are attractive targets because one compromised account or payment process can provide access to significant sums of money, customer data or wider corporate systems.
Business email compromise (BEC)
One of the most dangerous types of fraud, Business email compromise, or BEC, occurs when a criminal compromises or impersonates a trusted email account to persuade someone to send money or sensitive information.
A criminal may pretend to be:
a CEO requesting an urgent transfer;
a supplier providing new payment instructions;
an employee asking for payroll details to be changed;
another trusted business contact.
The FBI describes BEC as one of the most financially damaging forms of online crime and documents scenarios involving false invoices, executives, vendors and payment instructions.
The attack does not necessarily require sophisticated malware. It can succeed simply because the request looks familiar and feels urgent.
Employee impersonation scams
Employee impersonation is one of the most common methods of stealing identity. It's a criminal may obtain enough information about an employee to impersonate them when contacting IT or a corporate help desk.
The attacker may claim that:
they have lost their phone;
their password no longer works;
they cannot access MFA;
they urgently need an account reset.
The FBI has documented attacks in which criminals obtained credentials, impersonated employees and contacted IT or help-desk personnel to change login information and gain access to corporate networks.
This is why password-reset and MFA-reset procedures should verify the employee independently rather than relying only on information the caller can provide.
Vendor or supplier impersonation
A criminal may impersonate a supplier with whom the organisation already does business.
One of the most dangerous versions involves a message saying:
Our bank account has changed. Please send all future payments to these new details.
The invoice may appear genuine. The supplier relationship may be real. Only the destination bank account has changed.
The FBI specifically recommends independently verifying changes to payment or bank information using contact information already on file, rather than phone numbers or details supplied in the suspicious message.
Fake domain and website cloning
This is a classic when we talk about methods of stealing identity.
Criminals register a domain that nearly exactly resembles that of a real firm, interchanging one letter, incorporating a hyphen or using a completely different top-level domain and create a duplicate website.
Employees or customers end up on the fake webpage, provide their login credentials or payment information, and thus hand these right over to the attacker.
Payroll diversion fraud
An attacker pretends to be an employee, mostly via a compromised or spoofed email account and tells HR or payroll to modify their direct deposit details.
When the next pay period arrives, the employee's wages get deposited directly into the criminal's account instead.
Internal credential theft and privilege escalation
Attackers frequently do not need to compromise an organisation's most privileged account immediately.
They may first obtain access to a normal user account using:
phishing;
malware;
breached credentials;
social engineering;
credential stuffing.
From there, they may attempt to gain access to additional systems or higher privileges.
The FBI defines account takeover as unauthorised access to an online financial, payroll, health-savings or other account to steal funds or information.
Strong identity and access management, MFA, restricted privileges and monitoring of unusual authentication events can make this progression more difficult.
Synthetic business identity creation
The business equivalent of synthetic identity fraud. It's a more advanced and hard-to-detect method of stealing identity.
Criminals put together some actual sign-up information, such as a genuine company number and a real registered address, with fabricated ownership information to create a completely false business entity.
That entity could then seek out business credit, open accounts, or deceive genuine suppliers using this fabricated identity.
Read more about Synthetic transaction monitoring
Third-party vendor exploitation
Very large companies are quite well-protected. However, their suppliers, particularly smaller ones, very often aren't.
The criminals focus on a weaker point within their supply chain, breach it and then use that established relationship as a way of getting into the target organisation's systems or finances.
Read also: The types of fraud in business

Protect Your Business From Identity Fraud
Verify customers and businesses, detect suspicious identities and strengthen compliance with azakaw. Leverage the most advanced AI technology to safeguard your business.

What methods do criminals use to steal personal identities?
Most personal identity theft relies on one of two approaches:
tricking the victim into disclosing information, or
obtaining the information without the victim's knowledge.
Here are the most common techniques.
Phishing and email scams
Phishing uses deceitful emails, presented as a bank, government agency or well-known firm, to trick people into giving away their passwords, credit card numbers or very sensitive information.
Email continues to be frequently mentioned as a contact method within the FTC's 2023 fraud statistics, related to over 358,000 reports.
Smishing and phone-based fraud
Smishing is phishing done via SMS.
Common examples include fake messages that pretend to come from a delivery company, a bank or even a government department.
All trying to get you to press a link or dial a number to 'fix' a problem.
Voice-based scams operate quite similarly over a telephone call too, and the FTC determined that phone-based fraud sustained the highest average monetary loss out of any contact method in 2023, at $1485 per individual victim.
The message usually creates a reason to act immediately: an account is supposedly locked, a payment is overdue or suspicious activity has been detected.
Fake websites and impersonation pages
A cloned login page can closely resemble a genuine banking, payroll or government website.
The victim enters their username and password, but instead of being authenticated, the details are sent to the attacker.
The FBI has documented sophisticated phishing websites that imitate legitimate financial and employee-service portals, including domains with very small spelling differences.
For important services, navigating through a saved bookmark or manually entering a known address reduces the risk of reaching a fraudulent page through a malicious advertisement or message.
Malware, spyware, and keyloggers
Malicious programs set up on a device, quite often without the user even noticing, can record every keystroke made, capture screens or quietly send stored passwords and files back to an attacker.
The infections mostly arrive through malicious attachments, spurious software downloads or compromised websites.
SIM card swapping
SIM swap fraud involves persuading your mobile carrier to move your phone number onto a new SIM card held by the perpetrator.
When this is achieved, SMS-based 2-factor authentication codes are immediately sent to the attacker, thus allowing them to skip one of the most well-known account security barriers.
A sudden and unexplained loss of mobile service can therefore be a warning sign.
Data breaches and leaked credentials
Data breaches can expose usernames and passwords that attackers later reuse elsewhere.
Credential stuffing is the automated testing of username/password combinations obtained from one breach against other websites. This works because people frequently reuse credentials.
OWASP defines credential stuffing as injecting stolen username/password pairs into login forms to obtain unauthorised access and specifically notes that password reuse allows one breach to affect accounts on unrelated services.
Using a unique password for every service limits the damage one stolen password can cause.
ATM skimming and card cloning
Physical skimming devices, fitted over a card reader or PIN keypad, capture card details and PINs when someone withdraws cash. This data is subsequently used to manufacture a copy of the card or make out-and-out fraudulent transactions.
Skimmers have become a lot more advanced, although the core technique hasn't evolved much in the past few years.
Inspecting payment terminals, covering the keypad and using chip or contactless payments where available can reduce exposure.
Social engineering and manipulation
Social engineering is not a single technology or method of stealing identity. It is the manipulation technique behind many identity attacks.
The criminal may use:
urgency;
authority;
fear;
familiarity;
curiosity;
trust.
The objective is to persuade someone to disclose information or bypass a security process that they would normally follow.
The FBI has documented social-engineering campaigns involving employee impersonation, SIM swaps, phishing and help-desk manipulation.
Biometric data theft and spoofing
As fingerprint, facial and voice recognition become more established security measures, crooks have created ways of getting around them.
Biometric spoofing utilises highly detailed photographs, 3D printed masks or even AI-created videos, so as to deceive systems that don't have good 'liveness detection' mechanisms into thinking that a real human being is actually there.

Need stronger identity checks?
azakaw combines document verification, biometric checks and liveness detection to help businesses identify suspicious onboarding attempts.
Read also: What is a deepfake attack?
Public Wi-Fi interception
Public, unsecured Wi-Fi networks in cafes, airports, and hotels are often targeted by man-in-the-middle attacks.
A criminal sits between your device and the network to seize unencrypted data, including login details and payment information, entered during that session.
What are the offline methods of identity theft?
Offline identity theft happens when criminals obtain personal or business information through physical means rather than digital attacks.
Common methods of stealing identity include stealing mail or identity documents, retrieving sensitive information from discarded paperwork, and misusing legitimate access to records through insider theft.
Physical document theft
Mail theft continues to be a very simple method for harvesting your personal information:
bank statements
pre-approved credit offers
tax documents
government correspondence
All these documents contain enough info to open fraudulent accounts.
Stolen ID cards, passports and sensitive papers taken from homes, cars or unlocked office drawers function in the same way.
Dumpster diving and physical breaches
Documents discarded instead of being shredded will still hold account numbers, dates of birth and other identifying information.
Individuals looking for this type of un-shredded paper are literally digging for it by searching through bins outside homes or offices; criminals who do so are after documents carelessly discarded rather than properly disposed of.
Insider threats or corrupted employees
It is not always an external attack that causes a leak.
Employees with legitimate access to client or worker records will occasionally leak or sell that information; this may be due to financial reasons, coercion, or simply holding a grudge.
Insider threats are difficult to spot because the access is permitted.
Related content: Types of employee fraud
How can you detect identity theft early?
You can detect identity theft early by watching for unusual financial activity, unexpected account changes, unfamiliar login attempts, password reset requests you did not make, and new credit accounts or inquiries you do not recognise.
The earlier these anomalies are investigated, the greater the chance of limiting further fraud or account misuse.
Financial warning signs
Unexpected declines on a card that should have an available balance, bills or statements for accounts that you've never been signed up for and calls from debt collectors regarding debts that you don't recognise are all very obvious first signs.
Account behaviour anomalies
Login notifications coming from unknown devices or locations, password reset emails that you haven't requested or being logged out of an account without reason are all evidence that someone else might be getting in.
Notifications of new credit inquiries or accounts
Alerts for a new account or hard credit inquiries through a credit monitoring service that you didn't start are some of the clearest signals you'll get.
Regularly checking a credit report, even in the absence of an alert, will catch activity that slips past automated notifications.

How can businesses reduce identity fraud?
Businesses need controls at the human, identity, payment and system-access levels.
Verify payment changes out of band
Any request to alter:
supplier bank details;
beneficiary information;
wire instructions;
payroll information
Should be confirmed using contact information that was already independently verified.
The FBI specifically advises organisations to verify changes in payment information using the known contact on file rather than contact information contained in the request itself.
Strengthen help-desk identity verification
Help desks should not reset passwords or MFA solely because the caller knows employee information.
The FBI has documented attacks in which criminals impersonate employees and manipulate IT staff into changing account credentials.
High-risk resets should therefore use stronger independent verification.
Apply role-based access and least privilege
A compromised employee account should not provide unrestricted access to critical data.
CISA recommends role-based access control and the principle of least privilege so users receive only the permissions necessary to perform their functions.
Monitor lookalike domains
Attackers can register domains that closely resemble a legitimate company.
The FBI recommends domain-protection services that alert organisations when similar domains are registered.
Assess suppliers and third parties
Third-party access should be treated as part of the organisation's own attack surface.
NIST recommends structured cybersecurity supply-chain risk management and supplier due diligence rather than relying solely on the supplier's reputation or size.
Train employees continuously
Identity attacks evolve. Training should therefore cover real scenarios such as:
phishing;
BEC;
help-desk impersonation;
payroll diversion;
fake domains;
vendor payment changes;
MFA requests.
FBI guidance specifically recommends regularly educating help-desk and customer-support personnel on social-engineering and phishing schemes.

Shield Your Business Against Identity Fraud
Turn Identity Verification into your first line of defence. azakaw brings KYC, KYB, identity verification, screening and ongoing monitoring into one compliance platform.

How can you protect yourself from identity theft?
No single control prevents every type of identity theft. Protection works best when several layers are combined.
Use a unique password for every important account
Reusing passwords allows a breach at one service to compromise accounts elsewhere.
NIST recommends password managers as a practical way to generate and store long, unique passwords and notes that distinct passwords help prevent credential-stuffing attacks.
Use stronger multi-factor authentication
MFA provides an important additional layer of protection, but not all MFA methods provide the same level of security.
NIST and CISA recommend phishing-resistant authentication such as FIDO/WebAuthn for higher-risk accounts. SMS and manually entered one-time codes can still be vulnerable to phishing or SIM-related attacks.
Do not act directly from unexpected messages
If a message tells you that something urgent has happened:
do not use the link or phone number in the message;
open the organisation's app or known website independently;
contact the organisation through a verified channel.
This approach is recommended by both the FTC and FBI for phishing and account-takeover attempts.
Protect physical documents
Keep identity documents and financial records secure and destroy sensitive paperwork before disposal.
The US Postal Inspection Service recommends shredding or otherwise destroying documents containing personal information.
Which control helps prevent each identity-theft method?
The strongest defence is rarely one technology. Effective identity-fraud prevention combines identity proofing, authentication, access control, human verification and ongoing monitoring.
Threat | Control to prioritise |
Phishing | Phishing-resistant MFA + employee awareness |
BEC | Independent payment verification + email security |
Employee impersonation | Strong help-desk identity verification |
Vendor impersonation | Out-of-band confirmation of bank-detail changes |
Fake domains | Domain monitoring + URL verification |
Credential stuffing | Unique passwords + MFA |
SIM swapping | Avoid SMS as the only protection for high-risk accounts |
Forged identity documents | Document authentication + identity verification |
Biometric spoofing | Liveness/presentation-attack detection |
Excessive internal access | Role-based access + least privilege |
Third-party compromise | Supplier due diligence + access restrictions |
Synthetic identity fraud | Multi-source identity proofing and regular checks |

Put Fraud Controls Into Practice
Powered by AI, azakaw helps businesses strengthen identity verification with document checks, biometric and liveness verification, KYC/KYB, screening and ongoing monitoring.
What role do KYC and KYB play in preventing identity fraud?
For regulated businesses, identity fraud can start during customer onboarding.
A criminal may attempt to:
submit a forged identity document;
impersonate another person;
use inconsistent identity information;
create or control a suspicious legal entity;
conceal beneficial ownership;
bypass biometric verification.
This is where Know Your Customer (KYC) and Know Your Business (KYB) controls become relevant.
Effective onboarding can combine:
identity-document verification;
data consistency checks;
biometric and liveness verification;
business-registration checks;
director and beneficial-owner verification;
sanctions and PEP screening;
risk scoring;
ongoing monitoring.
NIST identity-proofing guidance explicitly requires controls against remote biometric impersonation and presentation attacks, while modern digital KYC/KYB platforms use multiple signals rather than relying on a single uploaded document.

Stop Identity Fraud at Onboarding
azakaw's solution supports automated identity and business verification, document checks, biometric/liveness verification and screening workflows. Our platform also supports transaction monitoring and ongoing compliance processes.
Do identity monitoring services help?
Identity and credit monitoring can help detect some forms of misuse, but they do not prevent every type of identity theft.
The FTC explains that credit-monitoring services may alert users to changes appearing in credit reports, while broader identity-monitoring services may search additional databases for information associated with the user.
However, monitoring cannot substitute for:
secure passwords;
MFA;
careful review of financial accounts;
credit freezes where appropriate;
prompt investigation of suspicious activity.
Monitoring works best as a detection layer rather than the only security control.
What should you do if your identity is stolen?
Act quickly. Start by securing the affected accounts, then document what happened and report it through the appropriate channels.
Step-by-step response plan
Immediately lock down the affected accounts and change every password connected to the compromised information.
Put a fraud alert or credit lock with the relevant credit bureaus so nobody can open a new account in your name.
Make a record of everything: dates, amounts, correspondence; you will need this for disputes and any police report.
Tell your bank, card issuer, and any platform where the fraudulent activity happened about the incident.
File a report with the relevant authority, so there is an official record of the incident.
Who to contact
Start with your bank or card provider, then the national reporting body for your country:
UAE: Report cybercrime through the Ministry of Interior, Dubai Police eCrime or Abu Dhabi Police Aman. Businesses should also determine whether the incident must be reported to the UAE Data Office or the relevant free-zone/sector regulator.
Saudi Arabia: Report cybercrime through the Ministry of Interior's cybercrime reporting services. Businesses subject to the PDPL may also need to notify SDAIA through the National Data Governance Platform within 72 hours of becoming aware of a qualifying personal-data breach.
the FTC's IdentityTheft.gov in the US
Action Fraud in the UK
or the local equivalent cybercrime unit.
Businesses must inform their affected customers and, when necessary, the relevant data protection regulator too.
How to recover your accounts and reputation
Recovery takes several weeks or even months, not days. Create a written log for each call and email made. Follow up with a written letter after a phone conversation to build a paper trail.
For businesses, being transparent and keeping customers informed promptly preserves trust much better than staying silent will.
What should a business do after an identity-related attack?
If a business account or payment process has been compromised:
Contact the financial institution immediately if funds have been transferred.
Disable or reset compromised accounts and credentials.
Preserve logs, emails and other evidence.
Identify what information or systems were accessed.
Notify internal security, compliance and legal teams.
Assess regulatory and contractual notification requirements.
Report the incident to the relevant authorities.
Review the control that failed and prevent the same attack from succeeding again.
For account-takeover and fraudulent-wire incidents, the FBI stresses the importance of contacting the financial institution and reporting the incident as quickly as possible because rapid action may improve the chance of recovering funds.
Data-breach notification obligations vary significantly between jurisdictions, so legal and compliance teams should determine which regulatory requirements apply to the specific incident.

Prevent the Next Identity Attack
Once the incident is contained, strengthen the controls that failed. azakaw helps businesses verify identities, detect suspicious activity and manage ongoing compliance.
Real examples of how identity theft happens
Three cases, from three very different settings, illustrate how identity theft plays out quite differently, and what each case teaches us.
Smishing in the UAE
The UAE authorities have continually pointed out smishing campaigns pretending to be immigration and telecom authorities, sending residents text messages saying their Emirates ID or account has been suspended.
If victims click on the link and provide their details, they give away enough information to open fraudulent accounts. Dubai Police and the UAE Cybercrime Prosecution have repeatedly warned the public about this exact pattern.
Lesson: even highly digitally literate populations remain vulnerable to smishing if the message convincingly pretends to be an official authority and produces a sense of urgency.
Japan's My Number data breaches
Japan's national identification system, My Number, experienced a six-fold increase in reported data breach cases in 2024 as opposed to the previous year, based on data provided by the Japanese government, with the National Police Agency recording over 250 arrests related to online access fraud utilising compromised credentials.
Lesson: centralising all identity data into one national system increases the stakes of a single breach; the same credentials could then unlock access to a far wider variety of services.
The Equifax breach
In 2017, credit agency Equifax experienced a breach that exposed the personal data of roughly 147 million people, including their Social Security numbers, dates of birth, and home addresses. Equifax settled with the FTC for $575 million.
The stolen data was sold on illicit markets for many years afterwards, making it possible for thieves to make false loan applications and steal tax returns long after the initial breach.
Lesson: a breach's damage won't cease even when the incident has been contained. The stolen data continues creating new frauds many years after the headlines have faded away.
Read also: Identity theft cases worldwide

FAQs on identity theft methods
Can someone steal my identity without my SSN/passport?
Yes. Thieves often steal identities by simply using your name, birthdate, and address or via account credentials stolen through phishing or a data breach.
Having your Social Security number or passport certainly makes things easier for them, but it isn't essential; with just a few pieces of your personal information scattered around, they can easily build a new account.
Are businesses at risk of identity fraud?
Yes. Businesses get targeted with specific schemes such as business email compromise, vendor impersonation, payroll diversion, and creating synthetic business identities.
What is synthetic identity fraud?
Synthetic identity fraud involves creating an identity using a combination of genuine and fabricated information.
A legitimate identifier may be combined with a fictitious name, address or date of birth. Because the complete identity does not correspond neatly to one victim, synthetic identities may be more difficult to detect through conventional identity-verification processes.
Is biometric data theft a real threat?
Yes. Biometric systems can be targeted by presentation attacks designed to make the system accept an impersonator.
Examples studied by NIST include printed photographs, digital images and appearance-altering techniques. This is why NIST's current digital-identity guidance includes presentation-attack-detection requirements for remote biometric identity proofing.
Can multi-factor authentication stop identity theft?
MFA can significantly improve account security, but it does not prevent every type of identity attack.
Some methods, including SMS codes and manually entered one-time passwords, can still be targeted through phishing, SIM swapping or social engineering.
For accounts protecting sensitive data or privileged access, NIST and CISA recommend moving toward phishing-resistant authentication such as FIDO/WebAuthn.
Can identity theft happen without a data breach?
Yes.
Attackers can obtain information through:
phishing;
stolen documents;
malicious software;
social engineering;
skimming;
insider misuse;
fake websites.
A large-scale data breach is only one possible source of stolen identity information.
What is the biggest warning sign of business identity fraud?
There is no single warning sign, but an unexpected request to change money, identity or access information deserves immediate verification.
Examples include:
changed supplier bank details;
a password reset requested by an employee;
a new payroll account;
urgent executive payment instructions;
an unexpected MFA reset.
Rather than responding through the same communication channel, verify the request independently.
Conclusion
Identity theft happens when criminals use stolen, manipulated or fabricated information to impersonate a person or business and commit fraud.
Individuals can reduce their exposure through unique passwords, stronger authentication, careful verification of unexpected requests and regular account monitoring.
Businesses need additional controls, including identity verification, KYC/KYB, document and biometric checks, payment verification, access controls and ongoing monitoring.
The goal is not only to respond to identity fraud after it happens, but to detect suspicious identities and activity before they cause damage.

Smarter AML Compliance Tool
Discover how azakaw combines AI-powered KYC, KYB, screening, transaction monitoring and ongoing compliance in one automated platform, helping businesses detect risk earlier, streamline operations and stay compliant.
Related articles
Identity theft methods - video
Sources
Federal Trade Commission — Consumer Sentinel Network Data Book 2024. More than 1.1 million identity-theft reports were received in 2024.
Javelin Strategy & Research — Identity Fraud research. Estimates of US identity-fraud and scam losses in 2024.
Federal Trade Commission — What To Know About Identity Theft. Definitions, warning signs, monitoring and consumer protection guidance.
Federal Reserve — Synthetic Identity Payments Fraud. Definition and explanation of synthetic identities.
FBI — Business Email Compromise. BEC, executive and vendor impersonation techniques.
FBI Internet Crime Complaint Center — Cyber Criminals Target Victims Using Social Engineering Techniques. Employee impersonation, help-desk fraud and SIM-swap tactics.
FBI — Cybercriminals Impersonating Employee Self-Service Websites. Fake domains, payroll diversion and credential theft.
Federal Trade Commission — Top Text Scams of 2024. Smishing trends and reported losses.
Federal Communications Commission — SIM Swapping and Port-Out Fraud. Description of fraudulent SIM transfers.
OWASP — Credential Stuffing. Definition and relationship with password reuse.
Federal Bureau of Investigation — Skimming. ATM/POS skimming methods and prevention.
NIST — Digital Identity Guidelines. Identity proofing, biometric security and presentation-attack detection.
Federal Trade Commission — Are Public Wi-Fi Networks Safe? Current guidance on HTTPS and public Wi-Fi.
United States Postal Inspection Service — Personal Identifying Information Theft. Mail, discarded documents and physical-data theft.
CISA — Insider Threat Mitigation Guide. Definition and management of insider threats.
NIST — Cybersecurity Supply Chain Risk Management. Supplier and third-party cybersecurity risk.
NIST — Digital Identity Guidelines / Password Guidance. Password managers, unique passwords and authentication recommendations.
CISA — Multi-Factor Authentication guidance. Phishing-resistant MFA and FIDO/WebAuthn.
Federal Trade Commission — Equifax settlement. Scale and consequences of the 2017 Equifax breach.
US Department of Justice — Insider financial-institution identity theft cases. Examples of employee misuse of customer identity data.
FTC IdentityTheft.gov — Recovery Steps. Account recovery, fraud alerts, reporting and documentation.






