Key Differences Between a Data Breach and Identity Theft
The easiest way to understand the difference is this:
A data breach exposes your personal information, while identity theft uses that information to commit fraud.
For example, if a retailer experiences a cyberattack and their customer account information is stolen, that is a data breach. If a criminal later uses that information to access a customer's bank account or open a new credit card, it becomes identity theft. Take a closer look at each below:
What Is a Data Breach?
A data breach happens when personal information is viewed, stolen, or shared without permission. Data breaches can happen electronically through cyberattacks or, in some cases, through the loss or theft of physical documents. Common information stolen in a data breach includes names, addresses, Social Security numbers, passwords, medical records, and financial information.
Data breaches can affect organizations of every size, from local businesses to major corporations, healthcare providers, schools, government agencies, and financial institutions. Often, consumers don’t learn their information has been exposed until the affected organization notifies them of the breach.
What Is Identity Theft?
Identity theft happens when someone steals your personal information and uses it without your permission. Stolen information is often obtained through data breaches, but can also be acquired through phishing scams, malware, mail theft, or other forms of fraud.
An identity thief may use your information to open new financial accounts or access existing ones, make unauthorized purchases, apply for loans, obtain medical services or create other accounts in your name.
Identity theft can cause stress and loss of money, and it often takes effort and time to fix. Victims may spend months fighting unauthorized charges, repairing their credit, and securing their accounts.
Why Are Data Breaches So Common?
Organizations collect and store more digital information than ever before, making them increasingly attractive targets for cybercriminals.
Even organizations with strong security programs can become targets. That's why consumers should always remain vigilant, regardless of where their information is stored.
While it’s certainly unsettling to learn that your personal information has been compromised in a data breach, it’s important to keep in mind that a data breach doesn’t automatically mean your identity will be stolen. The good news is that there are several steps you can take to help protect yourself.
How to Protect Yourself
While you can’t always prevent a data breach from happening, you can take steps to reduce the risk of identity theft and related fraud.
Consider these best practices:
1. Take Action Quickly After a Data Breach
If a company notifies you that your information was exposed in a data breach, don’t ignore the notice. Review what information was compromised and follow any recommended next steps. If passwords were exposed, change them immediately. If sensitive information such as your Social Security number was involved, consider placing a credit freeze or fraud alert on your credit reports. Acting quickly can help reduce the chances that your exposed information will be used to commit identity theft.
2. Use Strong, Unique Passwords for Every Account
Passwords are among the most common types of information exposed in data breaches. The dark web contains billions of compromised usernames and passwords collected from past breaches, and yours could be among them. That's why it's important to use a unique password for every online account. If one password is exposed, cybercriminals may try to use it to access your other accounts. Using unique passwords for every account, and changing any passwords that may have been exposed in a breach, can help protect your information and reduce the risk of identity theft.
3. Enable Multi-Factor Authentication
Multi-factor authentication (MFA) requires an extra step when you sign into an account, such as entering a code sent to your phone or generated by an authentication app. This extra layer of security can help prevent unauthorized access to your account if a criminal obtains your password in a data breach.
4. Monitor Your Financial Accounts
Review your bank and credit card statements regularly. Carefully review your transactions for any unfamiliar charges or unexpected withdrawals, no matter how small. Fraudsters often start with minor transactions to test whether an account is active before attempting a larger amount. You can also typically set up account notifications through your bank or credit card provider. Alerts can notify you of unusual transactions, login attempts, low balances, or changes to your account information.
5. Review Your Credit Reports Regularly
Checking your credit reports on a regular basis can help you identify new accounts, credit inquiries, or other activity that you didn’t authorize. Catching suspicious activity early can make it easier to limit the damage of identity theft.
6. Consider Freezing Your Credit
A credit freeze helps prevent identity thieves from opening new credit accounts in your name. When your credit is frozen, lenders generally cannot access your credit report, making it difficult for fraudsters to open accounts with your stolen information. You can place a credit freeze for free, at any time, through each of the three major credit bureaus. If you need to later apply for credit yourself, you can temporarily lift the freeze.
7. Limit Where You Share Your Social Security Number
Your Social Security number is one of the most valuable pieces of personal information a criminal can obtain. While some organizations legitimately require it, others may request it simply for identification purposes. Before providing your Social Security number, ask whether it's required and if another form of identification can be used instead. The fewer organizations that store your Social Security number, the fewer opportunities there are for it to be exposed in a future data breach.
Stay Alert and Protect What Matters Most
Data breaches and identity theft have become increasingly common, but understanding the differences between them can help you take the right steps to prevent exposed information from being used to commit fraud.
Monitor your accounts and credit reports regularly, sign up for alerts whenever they're available, and take suspicious activity seriously. If you notice anything unusual in your accounts, or receive unexpected notifications, report them to your financial institution or credit bureau immediately.
BankFive is committed to helping customers protect their accounts, safeguard their finances, and stay informed about the latest fraud prevention best practices. Monitor your credit report using our free Credit Score tool, and stay up to date on security alerts & tips on our website.