Skip to main content
Category

Personal Data Security

Protecting Your Personal & Financial Information

Identity theft and financial fraud can happen to anyone — and recovering from them is stressful, time-consuming, and costly. Fraud is no longer a distant threat: the FBI logged more than one million online financial crime complaints in 2025, with losses totaling nearly $21 billion, a 26% increase from the prior year.

A June 2026 survey by the CFP Board found that 3 in 5 Americans have either personally encountered financial fraud or know someone who has in the past three years.

Today’s scammers aren’t just sending clumsy emails full of typos. They use artificial intelligence to:

  • Clone voices
  • Generate convincing video calls, and
  • Create personalized messages that include your real name and account details

At the same time, some of the oldest tricks — like stealing a check from your mailbox — remain very much alive. The good news is that many of the most effective protections are simple, free, and take only a few minutes to put in place.

1.  Place a Credit Freeze

A Credit Freeze credit freeze – also called a security freeze – prevents lenders from accessing your credit report, which stops new accounts from being opened in your name. This is the single most effective step you can take to prevent identity theft. It is free, does not affect your credit score, and can be temporarily lifted whenever you need to apply for credit.

Freeze your credit at all four major bureaus:

•        Equifax — equifax.com | 1-800-685-1111

•        Experian — experian.com | 1-888-397-3742

•        TransUnion — transunion.com | 1-888-909-8872

•        Innovis — innovis.com | 1-800-540-2505

2.  Never Share Sensitive Information by Email

Email is not secure. An email account can be compromised in several ways. Emails can be intercepted, forwarded without your knowledge, stored indefinitely, and accessed if either your account or the recipient’s account is ever breached.

For these reasons, email should never be used to transmit sensitive personal or financial information.

Never include any of the following in an email:

  • Bank or investment account numbers — including routing numbers, brokerage account numbers, or wire transfer instructions
  • Social Security numbers — yours, your spouse’s, or your dependents’
  • Passwords, PINs, or security codes — for any account, device, or online service
  • Credit or debit card numbers — including expiration dates and CVV security codes
  • Driver’s license, passport, or Medicare/insurance ID numbers — these are high-value targets for medical and government identity fraud

What to do instead:

  • Call instead of emailing: when an institution needs sensitive information, provide it over the phone using their official published number.
  • Use secure portals: banks, brokerages, and financial advisors use encrypted client portals specifically for sharing sensitive documents. Always use these rather than email attachments.
  • If emailing documents is unavoidable: password-protect the file and communicate the password through a separate channel (such as a phone call), never in the same email.

3.  Use a Password Manager

Weak or reused passwords are one of the most common ways criminals gain access to financial accounts. The good news is that newer, more secure methods are often more convenient than traditional passwords.

Use a Password Manager

  • A password manager (such as Bitwarden, Apple Passwords, or 1Password) generates and stores strong, unique passwords for every account. It will also refuse to fill in credentials on a fake website — a powerful protection against phishing.
  • Never reuse passwords across different accounts. If one site is breached, criminals will try that same password everywhere else.
  • Use fake answers to security questions (e.g., “Mother’s maiden name: k7#mQzT9”) and store them in your password manager. Real answers to these questions are often findable online.

Use Passkeys When Available

Passkeys are a newer sign-in technology that replaces passwords entirely. When a website supports passkeys, use them — you cannot be tricked into giving a criminal your passkey the way you can with a password, because passkeys never leave your device.

Strengthen Two-Factor Authentication (2FA)

  • Enable 2FA on every financial, email, and social media account. Two-factor authentication requires a second form of verification before allowing access, making it significantly harder for someone who has obtained your password to get into your account.
  • Use a hardware security key (like a YubiKey) when available — it is the most secure 2FA option and cannot be intercepted.
  • Use an authenticator app (like Google Authenticator or Authy) as your next-best option. It is significantly safer than receiving codes by text message.
  • Avoid SMS text codes as your 2FA method whenever possible. Text-based codes can be intercepted through SIM-swap attacks.

4.  Protect Your Social Security Number

Your Social Security number (SSN) is the master key to your financial identity — guard it carefully.

  • Never carry your Social Security card in your wallet. Store it in a locked, secure location at home.
  • Do not provide your SSN unless absolutely required. Ask why it is needed and how it will be protected before sharing it.
  • Create a “my Social Security” account at ssa.gov/myaccount to prevent someone else from creating one in your name.
  • Activate SIM-swap protection with your mobile carrier. SIM swapping is a fraud technique where a criminal convinces your carrier to transfer your phone number to their device, giving them access to text-based verification codes. Call your carrier and ask them to add a PIN or passcode requirement before any changes can be made to your account.

5.  Monitor Your Credit & Financial Accounts

Early detection is critical. The CFP Board survey found that more than 2 in 5 fraud victims discovered the fraud within 24 hours — and acting quickly in that window significantly improves the odds of limiting losses and recovering funds.

  • Review your free credit reports at AnnualCreditReport.com — you are entitled to one free report per bureau per year. Review all three.
  • Sign up for free credit monitoring through your bank, credit card issuer, or a service like Credit Karma or Experian.
  • Set up account alerts through your bank and brokerage. Most institutions let you receive a notification for transactions above a threshold you set, login activity from new devices, and password or contact information changes.
  • Review your Social Security earnings record annually at ssa.gov/myaccount to check for fraudulent employment reported in your name.
  • If a data breach occurs at any institution where you have an account, change your login credentials immediately — even if you have not been directly notified by that institution.

6.  Watch Out for Phishing & Scams

Most identity theft does not involve sophisticated hacking — it involves tricking you. According to the CFP Board survey, fraud arrives most commonly through text message (57% of victims reported this channel), email (55%), and phone calls (54%). No single channel is safe; the fact that a message arrives through a channel you use every day does not make it legitimate.

The Golden Rule: You Initiate Contact

  • Do not reply to suspicious emails, texts, or calls
  • Do not click links from unrecognized sources
  • Do not provide any information to someone who has contacted you
  • Instead, contact the institution yourself using a trusted method: type their URL directly into your browser, use a saved bookmark, call the number on the back of your card, or use their official mobile app. Caller ID can be spoofed, so the name on your screen is not proof of identity.

Watch for Urgency — It’s the Biggest Red Flag

A sense of urgency — “your account will be closed,” “act within 24 hours,” “your grandson is in jail and needs bail money now” — is one of the most reliable warning signs of a scam. Legitimate organizations do not pressure you to act immediately. Pause before acting on any message that creates urgency.

Common Scam Types

  • Phishing (email) and smishing (text): these were the two most commonly reported forms of fraud in the CFP Board survey. Suspicious messages urge urgent action — verifying your account, claiming a package is stuck, or warning of a breach. Go directly to the company’s website rather than clicking any link.
  • Vishing (phone) and imposter scams: someone poses as a trusted organization — the IRS, Social Security, Medicare, your bank, or tech support. Hang up on unsolicited callers requesting account numbers, Social Security numbers, or passwords.
  • AI-driven impersonation: scammers increasingly use AI-generated voices and deepfake video to convincingly impersonate a family member or someone you trust. A call that sounds exactly like a loved one in distress is not proof that it is them.
  • Investment fraud: be skeptical of any unsolicited investment opportunity, particularly those involving cryptocurrency, offshore accounts, or promises of guaranteed or unusually high returns. If someone you don’t know well is enthusiastically steering you toward an investment, that is a red flag.
  • Romance and relationship scams: someone builds rapport with you online over time, then eventually asks for money.
  • Lottery and sweepstakes scams: you’ve supposedly won a prize but must pay a fee or taxes first to claim it.
  • Family impersonation scams: if you receive a call or message from someone claiming to be a family member in trouble and asking for money, hang up. Reach out directly to that person using the contact information already saved in your phone.

Be Careful What You Share on Social Media

Scammers routinely mine public profiles for personal details — your birthday, your hometown, family members’ names, recent travel — that make their impersonation attempts more convincing. The less publicly available information a scammer has about you, the harder it is for them to sound credible.

7.  Secure – or Shred – Your Mail & Physical Documents

Physical mail and paper documents remain a surprisingly common source of identity theft, and check theft in particular has been making a quiet comeback.

Thieves steal checks directly from mailboxes and USPS collection boxes — sometimes using long tools with adhesive tips to fish envelopes out of drop boxes. Once they have a check, they use a chemical process called “check washing” to erase the payee’s name and replace it with their own, often increasing the dollar amount as well.

General Mail & Document Security

  • Retrieve mail promptly and consider a USPS PO box or mail hold when traveling.
  • Sign up for USPS Informed Delivery (informeddelivery.usps.com) to preview scanned images of your incoming mail each day.
  • Shred — don’t just discard — all documents containing your name, address, account numbers, or Social Security number. Use a cross-cut or micro-cut shredder.
  • Opt for paperless statements for bank, investment, and credit card accounts to reduce mail-based exposure.

Protecting Against Check Fraud

  • Avoid mailing checks whenever a digital alternative exists. Most banks offer free online bill pay, and most government agencies — including the IRS and state tax authorities — accept electronic payment. Zelle, wire transfers, and cashier’s checks are also safer alternatives for larger payments.
  • If you must write and mail a check, use a gel ink pen, which is significantly more resistant to chemical washing than ballpoint ink. Fill in the entire payee line completely, leaving no blank space a thief could alter.
  • Drop checks inside a post office rather than in a curbside collection box, a free-standing drop box, or your own mailbox. The USPS has acknowledged that blue collection boxes have been targeted by thieves in many communities.
  • Review your bank statements promptly each month, and look at the actual check images — not just the dollar amounts — for anything unfamiliar. Pay attention to the handwriting on the payee line; check washing often results in a change in ink or penmanship.
  • If you are expecting a mailed check to be cashed (for a tax payment, a charitable donation, or any other purpose), follow up within a few weeks if you haven’t received confirmation. Don’t wait months to verify.
  • Consider switching recurring payments entirely to electronic methods. Automatic bill pay through your bank eliminates the need to write checks for regular expenses like utilities, insurance premiums, and charitable giving.

8.  Protect Your Family, Too

Fraud is a family issue, not just an individual one. A CFP Board survey found that older Americans are notably less confident in their ability to detect fraud than younger Americans, and report encountering phishing and smishing at higher rates.

Grandparents and children under 18 are the least likely family members to successfully detect a fraud attempt — yet only 6% of Americans report having spoken with a grandparent about fraud in the past year.

  • Talk to your adult children and grandchildren about fraud — both the digital variety and check fraud. Ask them to flag anything unusual in your accounts or communications, and offer to do the same for them. Younger people face their own risks, particularly investment scams and fraud encountered on social media.
  • Establish a family code word that anyone can use to verify an urgent request for money, by phone, text, or email. If a caller cannot produce the code word, treat the request as fraudulent until proven otherwise — this is a simple but effective defense against AI voice-cloning scams.
  • Ask about designating a trusted contact on your financial accounts. This is a person — typically an adult child or close family member — whom your advisor or institution is authorized to reach out to if something raises concern. It is not a power of attorney and does not give that person authority over your accounts; it simply provides a way to loop in someone you trust when needed.
  • If you have an aging parent or grandparent, consider helping them set up account alerts, review statements with them periodically, and gently encourage them to call you before responding to any financial request they’re unsure about.
  • Watch for warning signs that a family member may already be a victim: unusual withdrawals, new “friends” unusually interested in their finances, confusion about recent transactions, or reluctance to discuss their accounts.

9.  If You Suspect Fraud, Act Fast – and Don’t Be Embarrassed

Speed matters enormously. If you suspect fraud, your first call should be to the relevant bank or credit card company. From there, contact law enforcement and, if appropriate, file a complaint with the FTC at ReportFraud.ftc.gov or the FBI’s Internet Crime Complaint Center at IC3.gov.

One barrier that keeps many victims from acting is shame. The CFP Board survey found that 1 in 4 fraud victims who did not report the fraud stayed silent because they felt embarrassed. Being targeted by fraud is not a reflection of your intelligence or judgment — these are professional criminals using sophisticated tools. The only real mistake is not reporting it promptly.

Treat your financial advisor as a first call, not a last resort, whenever something feels off. If you receive an unsolicited investment offer, hear about a “too good to be true” opportunity, or are simply uncertain whether a communication is legitimate, call us before you act.

-SM

Sources include the CFP Board of Standards (“Don’t Fall For It: Guarding Against Financial Fraud,” June 2026), the FBI Internet Crime Report 2025, and The New York Times.

Identity Fraud: A Cautionary Tale

Our colleague and MFA founder Susan Moore contributed the following article.

Over the last weeks, I’ve received six letters that went something like this:

“Dear Susan – We’ve received your application for a credit card. We are unable to act on your application at this time because we’ve received notification from [Experian/Equifax/Transunion] that you’ve placed a security freeze on your credit file.”

I expect that I’ll receive more letters like this in the coming weeks.

Somewhere along the line, elements of my identifying information, including my Social Security number, have been hacked. That’s not really surprising.

Identity fraud is a growing concern in today’s digital age, impacting millions of people each year. As your financial planners, we want to provide you with the information and tools to help you protect yourself from this pervasive threat.

The Scope of Identity Fraud

Identity fraud affects a significant portion of the population in the United States. According to a report from Javelin Strategy & Research, approximately 33% of U.S. adults have experienced some form of identity theft. This means one in three people have had their personal information compromised, leading to financial loss and emotional distress.

How Is Information Stolen?

Fraudsters use various methods to steal personal information. Here are some common ways:

  1. Data Breaches: Large-scale data breaches at companies can expose millions of individuals’ personal information, including Social Security numbers, addresses, and financial data.
  2. Phishing Scams: Fraudsters use emails, texts, social media messages, or phone calls that appear to be from legitimate sources, tricking individuals into providing personal information.
  3. Skimming: Devices placed on ATMs or point-of-sale terminals capture card information during transactions.
  4. Mail Theft: Stealing mail can give criminals access to bank statements, credit card bills, and other personal information.
  5. Social Engineering: Manipulating individuals into divulging confidential information through deceitful tactics.

Notable Companies Affected by Data Breaches

A number of high-profile companies have experienced data breaches, exposing millions of people’s personal information, and the list keeps growing. A few of these include:

  • Equifax: In 2017, the credit reporting bureau Equifax suffered a data breach affecting over 147 million people, compromising Social Security numbers, birth dates, addresses, and driver’s license numbers.
  • Target: In 2013, Target experienced a data breach that affected 40 million customers’ credit and debit card information.
  • Yahoo: Yahoo faced a series of data breaches between 2013 and 2016, affecting all 3 billion user accounts.
  • Marriott: In 2018, Marriott disclosed a data breach that exposed information on approximately 500 million guests.

How to Place a Credit Freeze

Placing a freeze on your credit report can prevent fraudsters from opening new accounts in your name.

Even though the fraudsters who tried to open accounts in my name has my Social Security number, their efforts failed because I have a freeze on my credit reports.

Here are instructions for placing a freeze with each of the three major credit bureaus:

  1. Visit the credit bureau’s website or call them
  2. Provide the required personal information
  3. Create a PIN to manage your freeze
  4. Confirm the freeze through the method provided (online, phone, or mail)

And here is the contact information for each of the major credit bureaus:

Equifax

Experian

TransUnion

It’s important to put a freeze on your records at all three of the above agencies. And although the above three companies are the largest credit reporting agencies, there is another one: Innovis. You can place a freeze on your records there by calling 1-866-712-4546 or going to their website.

Additional Tips to Protect Against Credit Fraud

  • Use Extreme Caution in Sharing Your Personal Information. Don’t share personal information over the phone or online unless you are certain of the recipient’s identity. Don’t assume that because you’ve been asked for information, you need to provide it.
  • Example 1:if filling out a new client/account/patient form that asks for your SS number, try leaving it blank, and see if you’re asked again to provide it.
  • Example 2:If you receive a phone call asking for personal info, it most likely is an attempt to steal your information for fraudulent purposes. Be suspicious of these calls. Ask them to send you a request in email or snail mail. (Don’t ask for a phone number where you can call them back; they often have set up fake phone numbers to trick you.)
  • Monitor Your Credit Reports: Regularly review your credit reports from Equifax, Experian, and TransUnion to check for unauthorized activity. You can get a free report annually from each bureau at AnnualCreditReport.com.
  • Use Strong Passwords: Create strong, unique passwords for your online accounts, and update them regularly. Consider using a password manager to keep track of them.
  • Enable Two-Factor Authentication (2FA): Add an extra layer of security to your online accounts by enabling 2FA, which requires a second form of verification.
  • Shred Personal Documents: Shred any documents containing personal information before disposing of them.
  • Secure Your Devices: Use antivirus software, keep your operating system updated, and be cautious when downloading apps or software.

Identity fraud is a serious threat that requires vigilance and proactive measures to mitigate.

By understanding how fraudsters operate and taking steps to protect your personal information, you can significantly reduce the risk of falling victim to identity theft.

If you suspect your identity has been compromised, act quickly to minimize potential damage. As always, feel free to reach out for assistance or guidance in safeguarding your financial future.

-SM

How to Respond to a Personal Data Breach

October is National Cybersecurity Awareness Month. In the spirit of promoting greater awareness of how to protect your data (see Personal Data Defense article from September), below are some tips on what to do if you are hacked.

  • Confirm the Breach: verify whether your personally identifiable information (PII) has indeed been compromised; check for unusual account activity, notifications from financial institutions, or alerts from the compromised service or organization.
  • Change Passwords: if the breach involves an online account, change the password immediately; use a strong, unique password for each account, and enable multi-factor authentication (MFA) where available.
  • Contact Affected Institutions: if your financial accounts or credit cards are involved, contact your bank or credit card company to report the incident; they can help you monitor your accounts for unauthorized transactions.
  • Credit Freeze / Alerts: consider placing a credit freeze on your credit reports with the major credit bureaus (Equifax, Experian, and TransUnion); this restricts access to your credit report, making it more challenging for identity thieves to open new accounts in your name. Alternately, you can place a fraud alert on your credit reports, which requires creditors to take extra steps to verify your identity before granting credit.
  • Monitor Your Accounts: continuously monitor your bank, credit card, and other financial statements for unusual or unauthorized transactions. Review your credit reports regularly to check for fraudulent accounts or activity.
  • File a Police Report: if you believe your identity has been stolen, file a police report; this documentation may be required by banks, creditors, or other organizations to prove that you’re a victim of identity theft.
  • Report to Government Agencies: contact the Federal Trade Commission at gov to report the identity theft or data breech; they provide resources and guidance for victims.
  • Notify Creditors and Utility Companies: inform your creditors and utility companies about the situation; they can help you investigate and resolve fraudulent accounts or charges.
  • Update Online Accounts: review your online accounts, including email and social media, for any signs of unauthorized access; change passwords and enable MFA where possible.
  • Document Everything: keep a detailed record of all communications and actions taken regarding the breach; this documentation may be necessary for resolving any issues that arise later.

If you’ve managed to avoid being hacked, that’s certainly a good thing! But knowing what to do if your data security is breached can save you time, aggravation, and money.

-RK

 

 

 

How to Play Digital Defense and Protect Your Personal Information

US Consumers lost $8.8 billion to financial fraud last year, up 44% from 2021, according to a recent Bloomberg News article. And cybercrime costs worldwide are set to grow to $19.5 trillion by 2025.

The Federal Trade Commission notes hundreds of thousands of cases where individuals have reported losing at least $1,000, as the chart below shows.

Many of us have been affected by cyber crime, either directly or indirectly by way of a relative or friend. Knowing what steps to take to create a more secure digital environment can give you greater peace of mind and hopefully allow you to avoid being scammed.

Here’s our Top Ten List for Playing Digital Defense and Protecting Your Personal Data:

  1. Use Strong, Unique Passwords: use a different password for each online account and consider using a reputable password manager to generate and store your passwords securely.
  2. Enable Multi-Factor Authentication (MFA): this adds an extra layer of security by requiring you to provide a second form of verification (e.g. a text message code) in addition to your password.
  3. Regularly Update Software and Apps: this helps to keep your computer and phone operating systems, software applications, and antivirus programs up to date.
  4. Use Secure Connections: ensure websites you visit have a secure connection (look for “https:// and a padlock icon in the address bar).
  5. Be Cautious with Emails and Links: verify the sender’s authenticity before clicking on links or downloading attachments, and don’t provide sensitive information through email unless your email is encrypted.
  6. Limit Your Data Sharing: be mindful of information you share on social media platforms and adjust your privacy settings to limit who can see your personal information.
  7. Monitor Your Financial Statements: regularly review your bank and credit card statements for unauthorized transactions and report suspicious activity immediately.
  8. Regularly Check Your Credit Reports: request free annual credit reports from each of the three major credit bureaus (Equifax, Experian, and Transunion).
  9. Freeze Your Credit: consider freezing your credit with the credit bureaus; this makes it more difficult for identity thieves to open new accounts in your name.
  10. Consider Using a Virtual Private Network (VPN): this provides an extra layer of protection when you access information through publicly available sources; using a VPN (provided by a vendor) makes it harder for observers to identify you and track your online movements.

Conducting an annual personal cyber safety audit is a worthwhile endeavor. It will help you determine if you’re at risk of having your identity stolen or becoming a victim of fraud. Here’s a checklist that will help you conduct your personal audit and improve the way you play digital defense.

RK