A scammer does not need every detail about you — only the right combination of personal data, account access, or identity documents.
The Short Answer: Less Information Than You May Think
A scammer does not need your entire life story to steal or misuse your identity. They need enough information to pass a verification check, take control of an important account, or convince a person or organization that they are you.
Sometimes that means a name, date of birth, address, government identifier, and identity document. In other cases, a stolen password and one-time verification code may be enough to take over an existing account.
Even a small amount of personal information can become dangerous when criminals combine it with data from social media, public records, previous data breaches, stolen mail, or phishing attacks. Australian privacy guidance specifically warns that criminals may build a usable identity profile from limited information and additional public sources.
The level of risk depends on three things:
- What information the scammer has
- What account, service, or organization they are targeting
- What additional access or evidence they can obtain
There is no universal checklist that works against every bank, lender, mobile provider, government agency, or online platform.
The Three Things Scammers Usually Need
Most identity theft and impersonation attempts rely on one or more of the following categories.
1. Information That Matches Your Identity
This includes details that organizations use to locate your records or complete application forms:
- Full legal name
- Date of birth
- Current and previous addresses
- Phone number
- Email address
- Employer or occupation
- Government identification numbers
- Financial, tax, health, or insurance information
A single detail may have limited value. Several matching details can create a convincing identity profile.
2. Access to an Existing Account
For account takeover, a criminal may target:
- Usernames and email addresses
- Passwords or passphrases
- Banking PINs
- Password-reset links
- One-time verification codes
- Login approval prompts
- Backup authentication codes
- Active browser sessions
- Recovery email accounts or phone numbers
A stolen login session may allow someone to enter an account without typing the password again. This is why changing a password may not be enough unless you also sign out other devices and terminate active sessions.
3. Proof or Control That Passes Verification
Scammers may also need something that appears to prove they are you:
- A passport or driver’s license image
- A birth certificate
- A utility bill or bank statement
- A selfie or photograph of you holding an identity document
- Control of your email inbox
- Control of your phone number
- Answers to security questions
- Access to an already trusted device
The more independent pieces a criminal controls, the easier it may be to defeat weak identity checks.
What Different Information Combinations May Enable
The following examples show why context matters.
| What the scammer has | What it may enable | Typical concern |
|---|---|---|
| Name, email address, or phone number | Targeted phishing, impersonation, and further research | Limited alone |
| Name, birth date, and address | Customer-service impersonation or verification attempts | Moderate |
| Reused password and email address | Credential-stuffing attacks against multiple accounts | High |
| Password and verification code | Immediate account takeover | Very high |
| Access to your primary email account | Password resets and takeover of other accounts | Very high |
| Government identifier plus personal details | Credit, tax, benefit, employment, or account fraud attempts | High |
| Identity document image and proof of address | New-account or remote-verification fraud | Very high |
| Phone number plus mobile-account details | SIM swapping or phone-porting fraud | High |
| Bank login or card details | Unauthorized transfers, purchases, or financial impersonation | Urgent |
These are general risk levels, not guarantees. Strong organizations use layered checks that may stop an application even when a criminal has several correct details. Weak verification procedures may allow fraud with less.
Identity Theft, Identity Fraud, and Account Takeover Are Not the Same
The terms are often used interchangeably, but they describe different problems.
Identity theft generally involves obtaining or taking someone’s personal or financial information.
Identity fraud involves using that information to impersonate the person, obtain money, open accounts, claim benefits, or access services.
Account takeover occurs when someone gains control of an existing email, banking, social media, shopping, cloud-storage, or government account.
Payment fraud may involve unauthorized purchases or transfers without broader impersonation.
This distinction matters because each attack requires different information. A criminal may take over your email with a password and verification code without having enough information to open a loan in your name.
What Information Is Most Valuable to Identity Thieves?
Basic Personal Details
Basic information helps scammers identify the right person, locate related records, complete forms, and make phishing messages sound believable.
Commonly targeted details include:
- Full name
- Date of birth
- Home address
- Address history
- Phone number
- Email address
- Employer
- Family relationships
- Public usernames
Your name and address are usually not enough by themselves to open a major financial account. They can still help a scammer search breached databases, impersonate a service provider, contact your relatives, answer basic customer-service questions, or pressure you into revealing more.
Government Identifiers and Identity Documents
Government-issued numbers and documents are valuable because they help connect a claimed identity to official records.
| Country | Commonly targeted identity information |
|---|---|
| United States | Social Security number, driver’s license, passport, taxpayer information and Medicare details |
| United Kingdom | Passport, driving license, National Insurance number and address history |
| Australia | Driver license, passport, Medicare card and Tax File Number |
| Canada | Social Insurance Number, driver’s license and passport |
These identifiers are not master passwords. Having one does not automatically give a scammer access to every account or government service.
For example, the U.K. government states that a National Insurance number is a reference number used to match a record, not proof that the person presenting it is the genuine holder.
The danger increases when an identifier is combined with a date of birth, address history, document image, account credentials, phone access, or proof of address.
Passwords and Email Access
A stolen password can be more immediately useful than a stolen identity number.
Criminals frequently test credentials stolen from one website against email, banking, retail, social media, cloud-storage, and government accounts. This works because many people reuse passwords.
Primary email access is particularly dangerous. A criminal controlling your inbox may be able to:
- Request password resets
- Read security alerts
- Find stored identity documents
- Search for banking and tax information
- Change account recovery details
- Hide messages from financial institutions
- Create forwarding rules that copy future emails
- Take over additional accounts
When several accounts may be compromised, secure your primary email account first.
One-Time Codes and Login Approvals
A verification code may be all a scammer needs to complete an attack that is already underway.
The criminal may already have your password. They then call or message while pretending to represent your bank, employer, mobile provider, fraud department, or technology company. When you provide the code, you complete the login for them.
The U.S. Federal Trade Commission warns that a caller unexpectedly asking for a verification code is attempting to use that code to prove they are the account holder.
Treat these requests as fraudulent:
- “Read back the code we just sent.”
- “Approve the login so we can cancel it.”
- “Scan this QR code to secure your account.”
- “Move your money while we investigate.”
- “Tell us the code to confirm your identity.”
Never approve an unexpected login notification, device-registration request, or password-reset prompt.
Control of Your Phone Number
A phone number alone will not normally provide access to your financial accounts. Control of the number can be much more serious.
In a SIM-swap or phone-porting attack, a criminal impersonates you to your mobile provider and transfers your number to a SIM or account they control. Calls and text messages — including SMS authentication codes — then go to the criminal.
Information used to attempt a phone-number takeover may include:
- Your name and address
- Mobile number
- Date of birth
- Provider account number
- Account PIN
- Driver’s license details
- Answers to customer-service questions
A sudden unexplained loss of mobile service can be an urgent warning sign.
Identity Documents, Selfies, and Proof of Address
A clear image of a passport or driver’s license may contain several verified data points in one place:
- Legal name
- Photograph
- Date of birth
- Document number
- Signature
- Expiration date
- Address, depending on the document
Scammers may combine the image with a utility bill, bank statement, tax notice, or selfie to attempt remote identity verification.
Frequently targeted materials include:
- Passports
- Driver’s licenses
- National identity cards
- Birth certificates
- Medicare or health cards
- Utility bills
- Bank statements
- Tax statements
- Photos of a person holding an ID
IDCARE identifies passports, driver licenses, Medicare cards, bank statements, tax statements, and utility bills among the physical credentials targeted by identity criminals.
Financial, Tax, and Medical Information
Financial information may support direct theft or help make an impersonation attempt more convincing.
Criminals may target:
- Credit or debit card details
- Bank account numbers
- Routing or transit information
- Online banking credentials
- Loan or mortgage documents
- Investment and retirement accounts
- Tax records
- Health insurance numbers
- Medical account details
Medical identity theft can involve using someone’s name, government number, insurance details, or Medicare information to obtain treatment, prescription drugs, equipment, or insurance payments.
Personal Facts Used for Recovery Questions
Seemingly harmless facts may help criminals answer account-recovery questions or manipulate customer-service staff.
Examples include:
- Mother’s maiden name
- Birthplace
- First school
- First car
- Pet names
- Wedding date
- Children’s names
- Favorite sports team
- Employer and job title
Many of these details can be found in social media posts, family profiles, public records, online biographies, and old questionnaires.
When a website requires security questions, use random answers stored in a password manager rather than truthful answers that can be researched or guessed.
Can Someone Steal Your Identity With Only One Detail?
Can Someone Steal Your Identity With Your Name and Address?
Usually not by themselves. However, a name and address can help a scammer locate additional information, create convincing messages, redirect mail, or impersonate you during a weak customer-service interaction.
Is Your Date of Birth Enough?
A birth date alone is rarely enough for serious financial identity fraud. Combined with a name, address, government identifier, or document details, it becomes much more useful.
Can Someone Steal Your Identity With Your Phone Number?
A phone number alone is more commonly used for phishing, impersonation, account discovery, or harassment. The risk becomes much higher if the scammer can transfer the number, intercept messages, or use it to reset accounts.
Is a Social Security, National Insurance, Tax, or Social Insurance Number Enough?
Not necessarily. These numbers usually need to be combined with other information or evidence.
They are still highly sensitive because they may support credit, tax, employment, benefit, or government-account fraud. Canadian guidance warns that misuse of a Social Insurance Number can affect credit, benefits, tax records, and employment history.
What Can a Scammer Do With a Photo of Your ID?
A clear identity-document image can support fraudulent applications, forged documents, account-recovery attempts, and remote verification.
The risk is especially serious when the criminal also has:
- A selfie
- Proof of address
- Your government identifier
- Access to your email
- Control of your phone number
What Can Scammers Do With a Stolen Identity?
Take Over Existing Accounts
A criminal may need:
- Your username or email address
- Your password
- A verification code or login approval
- Access to your recovery email or phone
- A stolen active session
Email access can become the entry point for many other accounts.
Open New Accounts in Your Name
A fraudulent application may require:
- Full legal name
- Date of birth
- Current or previous address
- Government identifier
- Identity document information
- Proof of address
- Contact details controlled by the criminal
- A selfie or biometric check
Exact requirements vary by institution and jurisdiction.
Commit Tax, Benefit, Employment, or Medical Fraud
Stolen information may be used to:
- File a fraudulent tax return
- Claim unemployment or government benefits
- Obtain employment
- Access health services
- Submit insurance claims
- Open utility or mobile accounts
The FTC identifies tax, employment, medical, credit, and benefit fraud among the potential uses of stolen personal information.
Hijack Your Phone Number
Once a criminal controls your number, they may intercept calls and messages, reset passwords, and receive authentication codes.
Create a Synthetic Identity
A criminal does not always impersonate one person exactly. They may combine real information — such as a genuine government identifier — with invented names, addresses, or dates of birth.
This creates a partially fabricated identity that may be used to build credit, open accounts, or conceal other fraud.
Misuse a Child’s Identity
Children can also become identity-theft victims. A criminal may use a child’s name, birth date, address, or government identifier to apply for benefits, services, employment, or credit.
The fraud may remain undetected for years because children do not usually review credit records or file financial applications. The FTC advises U.S. parents and guardians that they can request a free credit freeze for a child under 16.
How Scammers Collect the Pieces
Identity theft often involves information gathered from several places rather than one catastrophic leak.
Data Breaches
Breached organizations may expose:
- Names and contact details
- Passwords
- Dates of birth
- Account numbers
- Security questions
- Government identifiers
- Identity documents
Criminals can combine information from separate breaches to create a more complete profile.
Phishing and Impersonation
Fake emails, websites, text messages, phone calls, QR codes, and social media messages are designed to collect passwords, financial information, identity documents, or verification codes.
Common pretexts include:
- A suspicious payment
- A missed delivery
- An account suspension
- A tax refund
- A fraud investigation
- A job application
- A relationship or investment opportunity
- A request to verify your identity
Australian cyber guidance warns that phishing may target banking credentials, passwords, verification codes, device-linking PINs, and QR-based account registration.
Public Records and Social Media
Public information can reveal:
- Birth dates
- Family relationships
- Employment history
- Addresses
- Travel plans
- Photographs
- Personal interests
- Answers to security questions
Public information may not be enough alone, but it can fill gaps in breached data and make impersonation more convincing.
Stolen Mail, Wallets, and Documents
Offline identity theft remains a real threat. Criminals may target:
- Unlocked mailboxes
- Discarded statements
- Utility bills
- Tax documents
- Insurance records
- Wallets
- Passports
- Driver’s licenses
Shred sensitive documents before disposal and secure important mail and identity documents.
Malware and Remote-Access Scams
Malicious software and remote-access tools may expose:
- Saved passwords
- Email accounts
- Banking sessions
- Personal files
- Browser data
- Tax and identity documents
A scammer posing as technical support may ask you to install software or share your screen. Once connected, the criminal may watch what you type, access files, or enter accounts while pretending to solve a problem.
Warning Signs Someone Is Using Your Identity
Watch for several suspicious events occurring close together.
Warning signs include:
- Password-reset messages you did not request
- Unexpected verification codes
- Login approval prompts from unknown devices
- Recovery information changed without permission
- Email forwarding rules you did not create
- Sudden loss of mobile service
- Unrecognized transactions
- New credit inquiries or accounts
- Bills or debt notices for unfamiliar services
- Missing mail
- Unexpected address changes
- Government benefits or tax filings you did not submit
- Medical bills for care you did not receive
- Rejected applications because an account already exists
- Friends receiving unusual messages from your accounts
- Notifications that an identity document was used
Do not wait for financial loss before acting. An unexplained password reset, mobile outage, or account-change notice may be the first stage of a larger attack.
What to Do When Your Information Has Been Exposed
Your response should match the information involved.
If a Password Was Exposed
- Change it immediately.
- Change it anywhere else it was reused.
- Sign out all active sessions and devices.
- Check recovery phone numbers and email addresses.
- Remove unknown app passwords and connected applications.
- Review email forwarding rules and filters.
- Enable stronger multifactor authentication.
Where available, prefer passkeys or security keys. Authenticator apps are generally stronger than SMS codes. CISA recommends phishing-resistant MFA when possible and notes that some MFA methods provide substantially stronger protection than others.
If You Shared a Verification Code
Contact the affected organization immediately using its official app, website, card number, or published contact details.
Then:
- Change the account password
- Sign out other devices
- Review transactions
- Check recovery settings
- Remove unfamiliar trusted devices
- Secure the email account connected to the service
Do not use contact details contained in the suspicious message.
If Your Email Account Was Accessed
Secure it before dealing with lower-value accounts.
Check:
- Password and multifactor authentication
- Recovery email and phone details
- Logged-in devices
- Forwarding addresses
- Inbox rules and filters
- Deleted and archived messages
- Recently sent messages
- Connected third-party applications
- Stored documents and identity images
Assume that any account linked to the inbox may also be at risk.
If Bank or Card Details Were Exposed
Contact your financial institution immediately.
Ask it to:
- Block or replace affected cards
- Secure online banking
- Review recent transfers and payments
- Reverse eligible unauthorized transactions
- Add appropriate fraud monitoring
- Check whether contact or recovery details were changed
If an Identity Document Was Stolen
Contact the issuing authority and ask whether the document should be canceled, replaced, or flagged.
Record:
- The document type and number
- When and how it was exposed
- The organization or scam involved
- Reports you have submitted
- Any evidence of attempted misuse
Monitor financial accounts and credit records for new applications.
If Your Phone Number Was Hijacked
Contact your mobile provider from another phone.
Ask it to:
- Restore your number
- Secure the account
- Review recent SIM or porting changes
- Add a strong account PIN
- Restrict unauthorized number transfers
Then secure your email, banking, government, and other high-value accounts.
If a Complete Identity Profile Was Exposed
Assume the information may be reused in the future.
Prioritize:
- Securing email and financial accounts
- Contacting identity-document issuers
- Adding available credit protections
- Reviewing credit reports
- Reporting confirmed fraud
- Keeping records of every action taken
- Watching for follow-up scams
Stolen identity information does not expire simply because no fraud appears immediately.
Where to Report Identity Theft
United States
Report identity theft through IdentityTheft.gov and follow the personalized recovery steps.
Consider placing a credit freeze with Equifax, Experian, and TransUnion. A freeze restricts access to your credit reports, making it harder to open new credit accounts in your name. It is free to place and lift, and it must be requested separately from each bureau.
A fraud alert is different. It tells potential creditors to verify your identity before extending credit but does not lock access to the report in the same way.
United Kingdom
Report fraud and cybercrime through Report Fraud in England, Wales, and Northern Ireland. The service replaced Action Fraud in December 2025. Fraud in Scotland should be reported to Police Scotland.
People at increased risk may consider Cifas Protective Registration. This places a warning against the person’s details so participating organizations perform additional checks when those details are used in an application.
Australia
Contact affected banks, mobile providers, government agencies, and document issuers immediately.
Cybercrime can be reported through ReportCyber, and IDCARE provides identity and cyber support. Australian guidance emphasizes acting quickly when identity information or accounts have been compromised.
Ask Australia’s credit-reporting bodies about placing a credit ban when new-account fraud is a concern.
Canada
Contact affected financial institutions, local police, and the relevant government agency.
Report fraud or cybercrime to the Canadian Anti-Fraud Centre through the national reporting service or by phone.
Contact Equifax Canada and TransUnion Canada to review your credit files and request fraud alerts. Depending on your province or territory, a security freeze may also be available.
If a Social Insurance Number may have been misused, contact Service Canada and follow its identity-fraud process.
How to Make Identity Theft Harder
Focus on protecting the information and accounts that criminals can combine.
- Use a unique password for every important account.
- Store passwords and random security answers in a password manager.
- Secure your primary email account with strong authentication.
- Use passkeys, security keys, or authenticator apps where available.
- Never share verification codes or approve unexpected login prompts.
- Add a strong PIN to your mobile account.
- Limit personal information visible on social media.
- Do not post images of passports, licenses, tickets, or official documents.
- Secure physical mail and shred sensitive paperwork.
- Review bank, credit, tax, insurance, and medical records.
- Check account recovery details regularly.
- Act immediately after a breach or suspicious notification.
Protect the Pieces That Prove You Are You
A scammer does not need every detail about your life. They need the right combination for the account, organization, or service they are targeting.
A name, phone number, or address may have limited value alone. The danger rises when personal details are combined with a reused password, email access, verification code, government identifier, identity document, proof of address, or control of your phone number.
Treat each of these as a separate security asset. Secure your email first, use unique passwords and strong authentication, protect identity documents, monitor financial activity, and respond quickly when sensitive information is exposed.
Identity theft becomes much harder when a criminal cannot connect the separate pieces needed to convincingly impersonate you.