Language

Identity Theft

What is identity theft?

Identity theft is the unauthorized use of another person's personal or financial information to impersonate them or obtain something in their name. It can affect new applications, existing accounts, employment, benefits, and other services.
The information may include government identifiers, document images, account details, or login credentials. A breach can expose this material, although exposure alone does not establish that someone has used it fraudulently.

How do criminals use stolen identity information?

Attackers may obtain information through phishing, data breaches, malware, physical document theft, or social engineering. They can then:
  • Apply for credit or services in the victim's name
  • Submit false claims for payments or benefits
  • Manipulate recovery procedures to obtain account access
  • Create deceptive employment or contractor applications
  • Combine stolen attributes with other information to construct a synthetic identity
Different methods leave different evidence. An unauthorized new account requires investigation of the original application; a compromised existing account also requires examination of login, recovery, and account-change history.

How can businesses reduce misuse of stolen identities?

Businesses should verify both the evidence and the applicant. A genuine document may belong to a victim, so document authenticity alone cannot establish that the person presenting it is the holder.
For remote document-based verification, face comparison, liveness detection, and capture-security checks help assess the applicant. Chip authentication can add issuer-signed evidence when supported. Account security and carefully controlled recovery then reduce opportunities to misuse the established account.
The business must also protect the identity information it collects. Restricted access, appropriate encryption, and defined retention periods reduce the amount of reusable identity material exposed if its own systems are compromised.

How can Regula help protect against identity theft?

Regula Document Reader SDK checks the submitted document and extracts its portrait and identity data from the visual inspection zone, machine-readable zone (MRZ), barcodes, and supported NFC/RFID chips. Its database contains more than 16,500 document templates from 254 countries and territories. . Regula Face SDK can compare the applicant with that portrait and perform liveness detection.
These checks help businesses assess whether someone is using another person's identity evidence during onboarding or recovery. Regula SDKs support verification, investigation and correction of a victim's account records that require the organization's own procedures.

FAQ

Which identity data should businesses prioritize protecting?

Government identifiers, complete document images, account credentials, and biometric records can be especially damaging if misused. Credentials may be reset, but exposed document images or biometric information can create lasting risks. Protection should reflect how each data type could be exploited.

Can NFC passport verification prevent use of a stolen document image?

Reading and validating the chip's signed data provides evidence that a flat image alone cannot supply. The document still needs to be connected to the applicant and current verification attempt. A stolen physical passport can contain a genuine chip.

 

What should a business do when someone reports identity theft?

Verify the reporter through a trusted process, protect affected accounts, preserve relevant records, and investigate the disputed activity. Correct inaccurate information and communicate through verified channels. The response should avoid exposing additional customer data to an unverified caller.

 

Is a personal-data breach automatically an identity-theft case?

No. A breach may expose information that could later be misused. Incident response should assess both the exposure and any evidence of impersonation. Notification duties may apply to the breach independently of whether identity theft has been confirmed.

How should a business distinguish identity theft from a synthetic identity?

Identity theft commonly impersonates an existing person. A synthetic identity combines attributes into a fictitious identity, sometimes using stolen information. Investigators should determine whether records belong to one victim, several people, or invented details before correcting them.

 

Should verification images be retained for identity-theft investigations?

Retain them only where there is a documented purpose and an applicable retention basis. Images may help resolve disputes, but unnecessary copies create further exposure. The retention policy should also account for investigation holds, restricted access, and eventual deletion.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules