Expert Advice for Avoiding Identity Theft

Aug 17, 2020 | Security

Featured article by Veronika Biliavska, Independent Technology Author

Identity theft is a global crisis that affects millions of consumers each year. It’s quite an alarming number, and so are the statistics to back it:

– The FTC received 3.2 million identity theft and fraud reports in 2019.
– Over 246,763 people reported fraudulent credit cards opened in their name.
– More than 57,600 websites were compromised by form-jacking in 2018.

It’s easy to compartmentalize such large numbers as simply statistics, until it happens to you. To help you avoid becoming another statistic, we’ve put together some expert advice for avoiding identity theft.

Keep your software up-to-date

Software gets developed. Software has security holes. Cybercriminals exploit security holes. Developers patch the holes, protecting their users. It’s really quite simple, and yet people need to be dragged kicking and screaming into downloading updates.

Like okay, it’s a little inconvenient when you’re in the middle of working, and your PC asks to reboot because of an automatic update. It’s understandable to postpone rebooting until later. But disabling automatic updates? It’s shooting yourself in the foot.

This goes for your operating system, software, browser, mobile phone, even your Smart fridge firmware. If it has software, it needs to be regularly updated, because cybercriminals are constantly finding new security flaws to exploit.

Monitor your online identity

With so many data breaches and online dumps of personally identifiable information, consumers often don’t know their social security number, address, and more are floating around on the internet, until it’s too late.

Services exist like HaveIBeenPwned.com to quickly check if any of your emails and passwords are included in known data breach dumps, but this requires actually remembering to check. With an identity protection tool like Identity Guard, you’ll have a wide range of automatic tools at your disposal, including dark web monitoring that can automatically alert you the instant any of your information is compromised.

Stay informed on the latest scams and phishing techniques

It’s not enough to know that your inbox is full of scams (though it helps to be cynical). You should know the latest techniques and scams that cyber criminals are running, so you can immediately recognize them for what they are.

For example, criminals have been targeting work-from-home employees during the COVID-19 pandemic by creating fake Zoom-related domains, with malicious scripts and fake teleconference software for download.

The old “only visit HTTPS websites” advice is rather outdated as well, as over half of phishing websites are found to be using legitimate SSL certificates. This is due to the availability of free TLS and SSL certificates since HTTPS protocol has become more widespread across the internet.

At the end of the day, it’s a good practice to question the legitimacy of everything online. 

Monitor your credit scores

You have the right to three free credit reports per year, which you can obtain from Experian, Transunion, and Equifax.

These three credit bureaus work in tandem through AnnualCreditReport.com, which allows you to request all three reports at once.

While reviewing your credit score, check to see if there are any new credit cards, loans, or other transactions using your information that you did not enroll for. Take immediate action against any suspicious activity.

For example, if your credit card information has been stolen or used, have the card immediately frozen and a new one issued (which your bank will automatically do once you alert them in most cases anyways). In most U.S. states, you have the right to a free credit freeze, and in states where such a legal mandate is not provided to consumers, the big credit bureaus often provide credit freezing programs at very low cost.

About the Author

Veronika Biliavska is an independent copywriter. She is passionate about rocket science and ancient Greek literature.

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more