CSCU Mitigating Identity Theft 2 — Questions and Answers
Question 1: What is synthetic identity theft?
- Stealing someone's identity using synthetic materials
- Creating a new fictitious identity by combining real and fabricated personal information (Correct answer)
- Using artificial intelligence to impersonate someone online
- Copying someone's physical appearance
Correct answer: Creating a new fictitious identity by combining real and fabricated personal information
Synthetic identity theft involves combining real data elements (like a legitimate Social Security number) with fake information (name, date of birth) to create an entirely new, fictitious identity for fraud.
Synthetic identity theft is one of the fastest-growing forms of financial fraud. Unlike traditional identity theft where a criminal takes over an existing person's identity, synthetic identity theft creates a completely new, fictitious identity by blending real personal data elements (often a stolen Social Security number, frequently from children, elderly, or deceased individuals) with fabricated information such as a fake name and date of birth. The fraudster builds credit history for this synthetic identity over time, eventually 'busting out' by maxing out credit lines and disappearing. This type of fraud is particularly difficult to detect because no single real person is alerted to suspicious activity. It costs financial institutions billions annually and is challenging for traditional fraud detection systems that look for anomalies in existing accounts.
Question 2: How does a credit freeze help protect against identity theft?
- It prevents you from using your existing credit cards
- It restricts access to your credit report, preventing new accounts from being opened in your name (Correct answer)
- It freezes all funds in your bank account
- It stops all credit card transactions temporarily
Correct answer: It restricts access to your credit report, preventing new accounts from being opened in your name
A credit freeze restricts access to your credit report, making it impossible for identity thieves to open new credit accounts in your name since creditors cannot check your credit history.
A credit freeze (also called a security freeze) is a free tool that restricts access to your credit report at the three major credit bureaus (Equifax, Experian, TransUnion). When a freeze is in place, potential creditors cannot access your credit report, which means they cannot approve new credit applications. Since most legitimate creditors require a credit check before opening accounts, a freeze effectively prevents identity thieves from opening new accounts in your name—even if they have your personal information. You can temporarily lift the freeze using a PIN when you want to apply for credit yourself. Unlike a fraud alert (which only requires creditors to verify identity), a credit freeze completely blocks access. Under federal law, placing, lifting, and removing credit freezes is free for all consumers.
Question 3: What is credential stuffing and how does it relate to identity theft?
- Physically stealing someone's ID cards
- Using stolen username/password combinations from one data breach to gain access to accounts on other services where users reused the same credentials (Correct answer)
- Creating fake credentials for a job application
- Filling out online forms with random information
Correct answer: Using stolen username/password combinations from one data breach to gain access to accounts on other services where users reused the same credentials
Credential stuffing exploits the common habit of password reuse by automatically testing username/password pairs leaked from one breach against many other websites and services.
Credential stuffing is an automated cyberattack where stolen username and password combinations from data breaches are systematically tested against other websites and online services. Because many people reuse the same password across multiple accounts, a significant percentage of these attempts succeed. Attackers use large databases of breached credentials (often available on the dark web) and automated tools that can test thousands of login combinations per minute. Once successful, attackers can access email accounts, banking services, social media, and other platforms—enabling identity theft, financial fraud, and further data exposure. Protection requires using unique passwords for each account (ideally via a password manager), enabling multi-factor authentication, and monitoring accounts for unauthorized access. Services like HaveIBeenPwned allow users to check if their credentials have appeared in known breaches.
Question 4: Why should you regularly review your bank and credit card statements for identity theft prevention?
- To calculate your monthly spending budget
- To detect unauthorized transactions that may indicate someone is using your financial accounts (Correct answer)
- To verify your credit score has not changed
- To check if interest rates have increased
Correct answer: To detect unauthorized transactions that may indicate someone is using your financial accounts
Regular statement review helps detect unauthorized transactions early, as identity thieves often start with small test charges before making larger fraudulent purchases.
Regularly reviewing bank and credit card statements is one of the most effective early-warning measures against identity theft and financial fraud. Identity thieves often begin with small test transactions (sometimes called 'card testing')—charges of a few dollars—to verify that stolen account information works before making larger fraudulent purchases. These small charges are easy to overlook if you are not reviewing your statements carefully. Early detection is critical because it limits financial losses, allows faster account freezing, and improves the chances of catching the perpetrator. Most financial institutions have fraud liability protections, but they often require timely reporting (typically within 60 days). Setting up real-time transaction alerts via your bank's app provides even faster notification of potentially unauthorized activity.
Question 5: What is the purpose of a fraud alert on your credit report?
- It automatically rejects all credit applications
- It notifies creditors to take extra steps to verify your identity before approving new credit applications (Correct answer)
- It sends you a daily credit score update
- It locks your bank account from all transactions
Correct answer: It notifies creditors to take extra steps to verify your identity before approving new credit applications
A fraud alert flags your credit report to warn creditors that they should verify the applicant's identity through additional steps before opening new credit accounts.
A fraud alert is a notice placed on your credit report that warns creditors to take additional steps to verify your identity before approving new credit applications. When a creditor sees a fraud alert, they are required to use reasonable policies and procedures to verify that the person applying for credit is actually the person associated with the credit file. There are three types of fraud alerts: an initial fraud alert (lasts one year, available to anyone), an extended fraud alert (lasts seven years, requires a police report or FTC Identity Theft Report), and an active duty military alert (lasts one year). Unlike a credit freeze, a fraud alert does not block access to your credit report—it only requires extra verification. Placing an alert at one bureau automatically applies it at all three. Fraud alerts are free and can be placed alongside a credit freeze for additional protection.
Question 6: How can data broker websites contribute to identity theft risks?
- They slow down internet connection speeds
- They aggregate and sell personal information that criminals can use to build profiles for identity theft (Correct answer)
- They only contain publicly available business information
- They encrypt all personal data they collect
Correct answer: They aggregate and sell personal information that criminals can use to build profiles for identity theft
Data brokers collect and sell personal information such as addresses, phone numbers, relatives, and financial details, which identity thieves can use to answer security questions or impersonate victims.
Data broker websites (such as Spokeo, WhitePages, BeenVerified, and others) aggregate vast amounts of personal information from public records, social media profiles, purchase histories, and other sources. They compile detailed profiles including names, addresses, phone numbers, email addresses, relatives, property records, court records, and sometimes financial information. While these services have legitimate uses (background checks, reconnecting with family), they also provide a rich resource for identity thieves who can purchase comprehensive personal profiles. This information helps criminals answer security questions, impersonate victims in social engineering attacks, file fraudulent tax returns, or apply for credit. Consumers can request removal from major data broker sites, though the process is time-consuming and must be repeated regularly as information reappears. Several services now automate data broker opt-out requests.
What is synthetic identity theft?