Loading


How to Tell If Someone Is Using Your Identity

Identity misuse can hide across credit, banking, tax, medical, phone, and online accounts, so checking several systems is essential for early detection.

Start With the Checks Most Likely to Find Identity Misuse

There is no single search, database, credit report, or monitoring service that can prove your identity is completely safe.

Someone may use your personal information to open credit accounts, take over existing accounts, redirect your mail, claim government benefits, obtain medical treatment, register a phone service, or impersonate you online. Some of this activity appears on a credit report, but much of it does not.

To check whether someone is using your identity, start with these five actions:

  1. Review every bank, card, payment, and investment account.
  2. Obtain credit reports from all major reporting agencies in your country.
  3. Inspect your primary email account for unknown logins, forwarding rules, and recovery details.
  4. Check your mobile carrier, tax, benefits, insurance, and other important accounts.
  5. Investigate every account, application, transaction, or personal-detail change you did not authorize.

Unknown accounts or confirmed applications made with your information are much stronger evidence of identity misuse than a suspicious message, data-breach notification, or leaked password.

Identity Exposure and Identity Misuse Are Different

Terminology varies between countries and agencies. Some distinguish between identity theft, identity fraud, and identity misuse, while others use “identity theft” as a broad term covering both the theft and use of personal information.

The practical distinction is simpler:

  • Identity exposure means information such as your name, address, date of birth, identification number, password, or driver’s license details may have been stolen or leaked.
  • Identity misuse means someone has used that information without permission.

A data-breach notification means your information may be at risk. It does not prove that fraud has occurred.

An unfamiliar credit application, tax filing, medical claim, account login, address change, phone contract, or government-benefit claim is stronger evidence that someone may be impersonating you.

Warning Signs Someone May Be Using Your Identity

Identity misuse is not always immediately visible. Watch for activity that cannot be explained by your normal financial, online, or administrative behavior.

Financial and credit warning signs

  • Transactions, transfers, or withdrawals you do not recognize
  • Credit cards, loans, payment accounts, or phone contracts you did not open
  • Credit inquiries from companies you have not contacted
  • Debt-collection letters for purchases or accounts that are not yours
  • Rejection for credit despite an otherwise healthy financial history
  • An unexplained credit-score change accompanied by unfamiliar report entries
  • New payees, linked accounts, authorized users, or changed payment details

A changing credit score alone does not prove identity theft. Examine the underlying credit report to determine what caused the change.

Online account warning signs

  • Password-reset messages or login codes you did not request
  • Logins from unfamiliar devices
  • Unknown recovery email addresses or phone numbers
  • Messages you did not send
  • New multifactor authentication methods
  • Changes to your name, address, phone number, or payment information
  • Security alerts that have been deleted or moved automatically

Phone and mail warning signs

  • Your mobile service suddenly stops working
  • You receive an unexpected SIM, eSIM, or number-transfer notice
  • New devices, lines, or contracts appear on your mobile account
  • Regular bills or bank statements stop arriving
  • A replacement card or identity document never reaches you
  • You receive confirmation of a mail-forwarding request you did not make
  • Financial or government mail arrives for an unfamiliar person

Government, tax, and medical warning signs

  • A tax return or refund appears that you did not submit
  • Government benefits are claimed or redirected without permission
  • Employment or income records appear for work you did not perform
  • Medical bills, prescriptions, or insurance claims relate to treatment you never received
  • Your health insurer says your benefits have been used or exhausted
  • Government agencies contact you about debts, payments, licenses, or businesses you do not recognize

Official consumer guidance in the United States and Australia identifies unknown accounts, debts, financial activity, missing mail, government-benefit activity, and data exposure as important warning signs.

1. Review Every Financial Account

Start with your bank and payment accounts because unauthorized transactions may require immediate action.

Do not check only your main checking account. Review:

  • Checking and savings accounts
  • Credit and debit cards
  • Digital wallets and payment apps
  • Investment, retirement, and pension accounts
  • Cryptocurrency accounts
  • Buy now, pay later services
  • Store-credit accounts
  • Joint and business accounts connected to your identity

Look through several months of activity. Pay particular attention to small test charges, unfamiliar merchants, new payees, transfers, cash withdrawals, replacement-card requests, and changes to your contact information.

Also check whether someone has linked a new external account, device, card, or digital wallet to your profile.

When you find suspicious activity, contact the financial institution through its official app, website, a trusted statement, or the number printed on your card. Do not use contact details from an unexpected email, text message, or phone call.

2. Check All of Your Credit Reports

Credit reports are one of the best places to find loans, credit cards, phone accounts, and other credit products opened in your name.

Review each report for:

  • Accounts you did not open
  • Applications or hard inquiries you did not authorize
  • Lenders or debt collectors you do not recognize
  • Addresses where you have never lived
  • Incorrect names, employers, or phone numbers
  • Accounts wrongly marked late, unpaid, or in default
  • Recently opened credit with unfamiliar providers

Check every major credit-reporting agency available in your country. Different agencies may receive information from different lenders, so one report may contain activity that another does not.

CountryCredit reports to checkImportant protection options
United StatesEquifax, Experian, and TransUnion through AnnualCreditReportDispute fraudulent entries and consider a security freeze or fraud alert
United KingdomEquifax, Experian, and TransUnionDispute errors with the agency and lender; consider Cifas Protective Registration
AustraliaEquifax and ExperianDispute unknown activity and request a temporary credit ban
CanadaEquifax and TransUnionDispute unknown activity and ask both agencies about fraud alerts
Other countriesEvery major national or regional credit-reporting bodyContact each reporting agency and affected lender directly

People in the United States can obtain free online reports from all three nationwide agencies once a week through the authorized AnnualCreditReport service.

The United Kingdom’s three main consumer credit-reference agencies are Equifax, Experian, and TransUnion.

Australians can request a free credit report every three months and can request a temporary ban if they believe someone may apply for credit in their name.

Canadians should review reports from both Equifax and TransUnion and can ask both organizations to place a fraud alert when identity theft is suspected.

3. Inspect Your Primary Email Account

Your email account can be used to reset passwords for banking, shopping, social media, cloud storage, government services, and other accounts.

Open the account’s security and privacy settings and check for:

  • Recent logins from unknown devices
  • Password changes you did not make
  • Recovery addresses or phone numbers you do not recognize
  • Automatic forwarding rules
  • Filters that hide bank or security messages
  • Connected applications you did not approve
  • Unknown app passwords
  • Changes to multifactor authentication
  • Messages in your sent or deleted folders that you did not create

Attackers sometimes create forwarding rules or filters so they can receive password-reset messages while hiding security warnings from the account owner.

When you find suspicious changes, remove them, sign out other sessions, change the password from a trusted device, and enable strong multifactor authentication.

Secure the email account before changing passwords on services that rely on it for account recovery.

A login location alone is not reliable proof of compromise. Mobile networks, corporate systems, virtual private networks, and internet providers can make a legitimate login appear to come from another city or country. Check the device, browser, time, and actions taken.

4. Check Your Mobile Phone Account

A criminal who controls your phone number may be able to intercept calls and text-message verification codes.

Possible signs of a SIM swap or mobile account takeover include:

  • Your phone unexpectedly loses cellular service
  • Your SIM or eSIM is shown as replaced
  • You receive a number-transfer or porting notice
  • An unknown device or line appears on the account
  • Your carrier password or account PIN stops working
  • New contracts, devices, or charges appear on the bill
  • Your voicemail PIN or forwarding settings change

Contact your carrier immediately if your service disappears without explanation. Ask whether anyone requested a SIM change, eSIM activation, device upgrade, account recovery, or number transfer.

Add an account PIN and a number-transfer or port-out lock where available.

Use an authenticator app, passkey, or physical security key instead of text-message authentication when an important account supports a stronger method.

5. Review Tax, Benefits, and Government Accounts

Identity misuse does not always involve conventional credit. Someone may use your information to claim a tax refund, receive unemployment payments, redirect benefits, register a business, or change government account details.

Check for:

  • Tax returns you did not file
  • Refunds sent to an unfamiliar account
  • Benefit or unemployment claims you did not submit
  • Changed addresses, phone numbers, or banking details
  • Employment or income records that are not yours
  • New tax numbers, licenses, or business registrations
  • Authentication codes or login attempts you did not request
  • Letters concerning debts, earnings, or payments you do not recognize

Access government services by typing the official address yourself, using a trusted bookmark, or opening the official app. Do not sign in through an unexpected message.

Contact the relevant agency directly when something does not match your records.

6. Review Medical and Insurance Records

Medical identity theft occurs when someone uses another person’s information to receive treatment, obtain prescriptions or medical equipment, or submit insurance claims.

Review:

  • Medical bills
  • Health-insurance claims
  • Prescription histories
  • Treatment summaries
  • Explanation of Benefits statements
  • Medicare or public-health records
  • Changes to your insurance profile
  • Collection notices for medical debts

Unknown treatment, prescriptions, providers, or claims may indicate that someone has used your medical identity.

Correct both the financial charge and the medical record. Information belonging to another patient — such as diagnoses, medications, allergies, or blood type — could affect future treatment if it remains in your file.

7. Check Mail, Address Changes, and Relevant Public Records

Missing mail can be an early warning that someone has changed your address or redirected your post.

Investigate when:

  • Regular statements stop arriving
  • A replacement bank card or identity document goes missing
  • You receive an unauthorized forwarding confirmation
  • A company says your address was recently changed
  • Mail from lenders or debt collectors refers to unknown accounts
  • Financial mail for another person repeatedly arrives at your address

Contact the postal service and affected organizations to ask whether a forwarding request or address change has been added.

Additional public-record checks may be useful when your circumstances make them relevant. Consider searching official registers for:

  • Companies or directorships under your name
  • Professional or occupational licenses
  • Insolvency or court records
  • Property or mortgage activity
  • Business names or registrations

A name match alone is not proof of identity misuse, especially if your name is common. Compare addresses, dates, middle names, business details, and other identifying information.

The United Kingdom has a specific Companies House process for reporting companies that use someone’s personal details without permission.

8. Check for Known Data Breaches

A reputable breach-search service can show whether an email address or phone number appears in known leaked datasets.

Australia’s national cyber security guidance directs consumers to Have I Been Pwned for checking known breaches.

A breach result is a warning, not proof of identity misuse. It cannot tell you whether someone has successfully used the information, and it cannot search every stolen database, private criminal channel, or fraudulent application.

After finding exposed information:

  • Change exposed and reused passwords
  • Enable multifactor authentication
  • Review affected accounts
  • Check your credit reports
  • Watch for targeted phishing
  • Consider a credit freeze, ban, or fraud alert
  • Follow instructions from the organization or document issuer

Commercial dark-web monitoring has similar limits. Treat it as an alert system, not a guarantee that your identity is safe.

What Confirms That Your Identity Has Probably Been Misused?

The strongest evidence is unauthorized activity directly connected to your personal information.

Examples include:

  • A lender confirms that an application was made using your details
  • A credit report shows an account or inquiry you did not initiate
  • A bank confirms an unauthorized transaction or profile change
  • A mobile carrier confirms an unapproved SIM swap or contract
  • A government agency finds a claim, filing, or payment request you did not submit
  • An insurer confirms treatment or prescriptions billed under your identity
  • Your email contains an unknown forwarding rule or recovery method
  • A company, license, or account has been created using your identifying details

A phishing message, suspicious phone call, breach notice, or leaked password increases your risk but does not by itself confirm identity fraud.

What to Do Immediately If You Find Misuse

Your first action should depend on what has been compromised.

What happenedFirst action
Unauthorized bank transactionContact the financial institution and try to stop or reverse the transaction
Email account takeoverRecover and secure the email account, then protect linked accounts
SIM swap or lost phone serviceContact the carrier, restore control of the number, and protect financial accounts
Unknown credit accountContact the lender and every relevant credit-reporting agency
Tax or benefits fraudContact the responsible government agency
Medical identity misuseContact the insurer and provider, and correct the medical record
Stolen identity documentsReport the documents and ask the issuing authority whether they must be replaced

Contact the affected organization

Ask the organization to:

  • Lock or close the affected account
  • Stop pending transactions
  • Remove unauthorized users and contact details
  • Preserve application and access records
  • Begin its fraud investigation
  • Explain the dispute process
  • Confirm the case or reference number in writing

Do not delay securing an account or stopping a payment while trying to collect perfect evidence.

Secure your most important accounts

From a device you trust:

  • Change compromised or reused passwords
  • Sign out unknown sessions
  • Remove unauthorized recovery methods
  • Enable strong multifactor authentication
  • Check linked devices and applications
  • Change important account PINs

Restrict new credit and report the incident

Available protections depend on where you live:

  • United States: Place a security freeze with Equifax, Experian, and TransUnion or add a fraud alert. Report identity theft through IdentityTheft.gov to receive a recovery plan.
  • United Kingdom: Contact all three credit-reference agencies and consider Cifas Protective Registration, which prompts participating organizations to perform additional identity checks. Report fraud through Report Fraud in England, Wales, and Northern Ireland, or Police Scotland in Scotland.
  • Australia: Request a temporary credit ban, report cybercrime through ReportCyber, and contact IDCARE for identity-recovery support. Scam-related incidents can also be reported to Scamwatch.
  • Canada: Contact Equifax and TransUnion, add fraud alerts, and report cybercrime or fraud through the national RCMP and Canadian Anti-Fraud Centre reporting service.

Preserve useful evidence

Keep copies of:

  • Credit reports
  • Statements and bills
  • Emails and text messages
  • Screenshots
  • Fraudulent application details
  • Case and reference numbers
  • Dates and times of calls
  • Names of representatives
  • Police or government report numbers

Maintain a simple timeline. Identity-recovery cases often involve multiple companies and agencies, and organized records can make disputes easier.

Check Children’s Identities When There Is a Reason for Concern

Children can become victims of identity theft even though they have never applied for credit.

Possible warning signs include debt-collection letters, benefit problems, tax notices, or credit offers addressed to a child.

In the United States, parents and guardians can ask the three nationwide credit bureaus to search for a child’s credit file. A child who has never used credit generally should not have one. Eligible parents and guardians can also request a free child credit freeze.

Procedures differ internationally, so contact the relevant credit-reporting agencies and government identity service in your country.

How Often Should You Check?

Check immediately after:

  • A data breach involving sensitive information
  • A lost or stolen wallet, phone, or identity document
  • Stolen or redirected mail
  • An account takeover
  • An unexpected credit rejection
  • A phishing incident in which you disclosed information
  • A burglary involving documents or devices

For routine monitoring, review financial activity frequently and check your available credit reports at least once a year. Check more often when information has been exposed or suspicious activity has already occurred.

Repeat checks matter because criminals may keep stolen information for weeks, months, or longer before using it. Australian cyber security guidance specifically warns that identity information may not be misused immediately.

Do Not Rely on One Monitoring Service

Credit monitoring can alert you to certain new inquiries, accounts, or report changes. It usually cannot detect every form of identity misuse.

It may miss:

  • Takeover of an existing bank account
  • Tax or benefits fraud
  • Medical identity misuse
  • SIM swaps
  • Email compromise
  • Unreported utility or phone accounts
  • Business or government registrations
  • Fraud outside the provider’s databases
  • Criminal use of forged identity documents

Use monitoring as one detection tool, not as proof that nothing has happened.

The Best Way to Check for Identity Misuse

The most reliable way to tell whether someone is using your identity is to compare activity across several parts of your life.

Review your financial accounts, credit reports, primary email, mobile service, government records, medical claims, mail delivery, and other important accounts. Focus on unfamiliar applications, new accounts, changed contact details, unexpected verification messages, unknown debts, and transactions you did not approve.

When something looks suspicious, verify it directly with the organization involved. When misuse is confirmed, secure the affected account, restrict new credit where possible, preserve essential evidence, and report the incident promptly.

No single check can reveal every type of identity fraud. A layered review gives you the best chance of detecting misuse early and preventing one unauthorized action from becoming a much larger recovery problem.