Identity Theft
What is identity theft?
How do criminals use stolen identity information?
- Apply for credit or services in the victim's name
- Submit false claims for payments or benefits
- Manipulate recovery procedures to obtain account access
- Create deceptive employment or contractor applications
- Combine stolen attributes with other information to construct a synthetic identity
How can businesses reduce misuse of stolen identities?
How can Regula help protect against identity theft?
FAQ
Which identity data should businesses prioritize protecting?
Government identifiers, complete document images, account credentials, and biometric records can be especially damaging if misused. Credentials may be reset, but exposed document images or biometric information can create lasting risks. Protection should reflect how each data type could be exploited.
Can NFC passport verification prevent use of a stolen document image?
Reading and validating the chip's signed data provides evidence that a flat image alone cannot supply. The document still needs to be connected to the applicant and current verification attempt. A stolen physical passport can contain a genuine chip.
What should a business do when someone reports identity theft?
Verify the reporter through a trusted process, protect affected accounts, preserve relevant records, and investigate the disputed activity. Correct inaccurate information and communicate through verified channels. The response should avoid exposing additional customer data to an unverified caller.
Is a personal-data breach automatically an identity-theft case?
No. A breach may expose information that could later be misused. Incident response should assess both the exposure and any evidence of impersonation. Notification duties may apply to the breach independently of whether identity theft has been confirmed.
How should a business distinguish identity theft from a synthetic identity?
Identity theft commonly impersonates an existing person. A synthetic identity combines attributes into a fictitious identity, sometimes using stolen information. Investigators should determine whether records belong to one victim, several people, or invented details before correcting them.
Should verification images be retained for identity-theft investigations?
Retain them only where there is a documented purpose and an applicable retention basis. Images may help resolve disputes, but unnecessary copies create further exposure. The retention policy should also account for investigation holds, restricted access, and eventual deletion.