Identity theft and financial fraud can happen to anyone — and recovering from them is stressful, time-consuming, and costly. Fraud is no longer a distant threat: the FBI logged more than one million online financial crime complaints in 2025, with losses totaling nearly $21 billion, a 26% increase from the prior year.
A June 2026 survey by the CFP Board found that 3 in 5 Americans have either personally encountered financial fraud or know someone who has in the past three years.
Today’s scammers aren’t just sending clumsy emails full of typos. They use artificial intelligence to:
- Clone voices
- Generate convincing video calls, and
- Create personalized messages that include your real name and account details
At the same time, some of the oldest tricks — like stealing a check from your mailbox — remain very much alive. The good news is that many of the most effective protections are simple, free, and take only a few minutes to put in place.
1. Place a Credit Freeze
A Credit Freeze credit freeze – also called a security freeze – prevents lenders from accessing your credit report, which stops new accounts from being opened in your name. This is the single most effective step you can take to prevent identity theft. It is free, does not affect your credit score, and can be temporarily lifted whenever you need to apply for credit.
Freeze your credit at all four major bureaus:
• Equifax — equifax.com | 1-800-685-1111
• Experian — experian.com | 1-888-397-3742
• TransUnion — transunion.com | 1-888-909-8872
• Innovis — innovis.com | 1-800-540-2505
2. Never Share Sensitive Information by Email
Email is not secure. An email account can be compromised in several ways. Emails can be intercepted, forwarded without your knowledge, stored indefinitely, and accessed if either your account or the recipient’s account is ever breached.
For these reasons, email should never be used to transmit sensitive personal or financial information.
Never include any of the following in an email:
- Bank or investment account numbers — including routing numbers, brokerage account numbers, or wire transfer instructions
- Social Security numbers — yours, your spouse’s, or your dependents’
- Passwords, PINs, or security codes — for any account, device, or online service
- Credit or debit card numbers — including expiration dates and CVV security codes
- Driver’s license, passport, or Medicare/insurance ID numbers — these are high-value targets for medical and government identity fraud
What to do instead:
- Call instead of emailing: when an institution needs sensitive information, provide it over the phone using their official published number.
- Use secure portals: banks, brokerages, and financial advisors use encrypted client portals specifically for sharing sensitive documents. Always use these rather than email attachments.
- If emailing documents is unavoidable: password-protect the file and communicate the password through a separate channel (such as a phone call), never in the same email.
3. Use a Password Manager
Weak or reused passwords are one of the most common ways criminals gain access to financial accounts. The good news is that newer, more secure methods are often more convenient than traditional passwords.
Use a Password Manager
- A password manager (such as Bitwarden, Apple Passwords, or 1Password) generates and stores strong, unique passwords for every account. It will also refuse to fill in credentials on a fake website — a powerful protection against phishing.
- Never reuse passwords across different accounts. If one site is breached, criminals will try that same password everywhere else.
- Use fake answers to security questions (e.g., “Mother’s maiden name: k7#mQzT9”) and store them in your password manager. Real answers to these questions are often findable online.
Use Passkeys When Available
Passkeys are a newer sign-in technology that replaces passwords entirely. When a website supports passkeys, use them — you cannot be tricked into giving a criminal your passkey the way you can with a password, because passkeys never leave your device.
Strengthen Two-Factor Authentication (2FA)
- Enable 2FA on every financial, email, and social media account. Two-factor authentication requires a second form of verification before allowing access, making it significantly harder for someone who has obtained your password to get into your account.
- Use a hardware security key (like a YubiKey) when available — it is the most secure 2FA option and cannot be intercepted.
- Use an authenticator app (like Google Authenticator or Authy) as your next-best option. It is significantly safer than receiving codes by text message.
- Avoid SMS text codes as your 2FA method whenever possible. Text-based codes can be intercepted through SIM-swap attacks.
4. Protect Your Social Security Number
Your Social Security number (SSN) is the master key to your financial identity — guard it carefully.
- Never carry your Social Security card in your wallet. Store it in a locked, secure location at home.
- Do not provide your SSN unless absolutely required. Ask why it is needed and how it will be protected before sharing it.
- Create a “my Social Security” account at ssa.gov/myaccount to prevent someone else from creating one in your name.
- Activate SIM-swap protection with your mobile carrier. SIM swapping is a fraud technique where a criminal convinces your carrier to transfer your phone number to their device, giving them access to text-based verification codes. Call your carrier and ask them to add a PIN or passcode requirement before any changes can be made to your account.
5. Monitor Your Credit & Financial Accounts
Early detection is critical. The CFP Board survey found that more than 2 in 5 fraud victims discovered the fraud within 24 hours — and acting quickly in that window significantly improves the odds of limiting losses and recovering funds.
- Review your free credit reports at AnnualCreditReport.com — you are entitled to one free report per bureau per year. Review all three.
- Sign up for free credit monitoring through your bank, credit card issuer, or a service like Credit Karma or Experian.
- Set up account alerts through your bank and brokerage. Most institutions let you receive a notification for transactions above a threshold you set, login activity from new devices, and password or contact information changes.
- Review your Social Security earnings record annually at ssa.gov/myaccount to check for fraudulent employment reported in your name.
- If a data breach occurs at any institution where you have an account, change your login credentials immediately — even if you have not been directly notified by that institution.
6. Watch Out for Phishing & Scams
Most identity theft does not involve sophisticated hacking — it involves tricking you. According to the CFP Board survey, fraud arrives most commonly through text message (57% of victims reported this channel), email (55%), and phone calls (54%). No single channel is safe; the fact that a message arrives through a channel you use every day does not make it legitimate.
The Golden Rule: You Initiate Contact
- Do not reply to suspicious emails, texts, or calls
- Do not click links from unrecognized sources
- Do not provide any information to someone who has contacted you
- Instead, contact the institution yourself using a trusted method: type their URL directly into your browser, use a saved bookmark, call the number on the back of your card, or use their official mobile app. Caller ID can be spoofed, so the name on your screen is not proof of identity.
Watch for Urgency — It’s the Biggest Red Flag
A sense of urgency — “your account will be closed,” “act within 24 hours,” “your grandson is in jail and needs bail money now” — is one of the most reliable warning signs of a scam. Legitimate organizations do not pressure you to act immediately. Pause before acting on any message that creates urgency.
Common Scam Types
- Phishing (email) and smishing (text): these were the two most commonly reported forms of fraud in the CFP Board survey. Suspicious messages urge urgent action — verifying your account, claiming a package is stuck, or warning of a breach. Go directly to the company’s website rather than clicking any link.
- Vishing (phone) and imposter scams: someone poses as a trusted organization — the IRS, Social Security, Medicare, your bank, or tech support. Hang up on unsolicited callers requesting account numbers, Social Security numbers, or passwords.
- AI-driven impersonation: scammers increasingly use AI-generated voices and deepfake video to convincingly impersonate a family member or someone you trust. A call that sounds exactly like a loved one in distress is not proof that it is them.
- Investment fraud: be skeptical of any unsolicited investment opportunity, particularly those involving cryptocurrency, offshore accounts, or promises of guaranteed or unusually high returns. If someone you don’t know well is enthusiastically steering you toward an investment, that is a red flag.
- Romance and relationship scams: someone builds rapport with you online over time, then eventually asks for money.
- Lottery and sweepstakes scams: you’ve supposedly won a prize but must pay a fee or taxes first to claim it.
- Family impersonation scams: if you receive a call or message from someone claiming to be a family member in trouble and asking for money, hang up. Reach out directly to that person using the contact information already saved in your phone.
Be Careful What You Share on Social Media
Scammers routinely mine public profiles for personal details — your birthday, your hometown, family members’ names, recent travel — that make their impersonation attempts more convincing. The less publicly available information a scammer has about you, the harder it is for them to sound credible.
7. Secure – or Shred – Your Mail & Physical Documents
Physical mail and paper documents remain a surprisingly common source of identity theft, and check theft in particular has been making a quiet comeback.
Thieves steal checks directly from mailboxes and USPS collection boxes — sometimes using long tools with adhesive tips to fish envelopes out of drop boxes. Once they have a check, they use a chemical process called “check washing” to erase the payee’s name and replace it with their own, often increasing the dollar amount as well.
General Mail & Document Security
- Retrieve mail promptly and consider a USPS PO box or mail hold when traveling.
- Sign up for USPS Informed Delivery (informeddelivery.usps.com) to preview scanned images of your incoming mail each day.
- Shred — don’t just discard — all documents containing your name, address, account numbers, or Social Security number. Use a cross-cut or micro-cut shredder.
- Opt for paperless statements for bank, investment, and credit card accounts to reduce mail-based exposure.
Protecting Against Check Fraud
- Avoid mailing checks whenever a digital alternative exists. Most banks offer free online bill pay, and most government agencies — including the IRS and state tax authorities — accept electronic payment. Zelle, wire transfers, and cashier’s checks are also safer alternatives for larger payments.
- If you must write and mail a check, use a gel ink pen, which is significantly more resistant to chemical washing than ballpoint ink. Fill in the entire payee line completely, leaving no blank space a thief could alter.
- Drop checks inside a post office rather than in a curbside collection box, a free-standing drop box, or your own mailbox. The USPS has acknowledged that blue collection boxes have been targeted by thieves in many communities.
- Review your bank statements promptly each month, and look at the actual check images — not just the dollar amounts — for anything unfamiliar. Pay attention to the handwriting on the payee line; check washing often results in a change in ink or penmanship.
- If you are expecting a mailed check to be cashed (for a tax payment, a charitable donation, or any other purpose), follow up within a few weeks if you haven’t received confirmation. Don’t wait months to verify.
- Consider switching recurring payments entirely to electronic methods. Automatic bill pay through your bank eliminates the need to write checks for regular expenses like utilities, insurance premiums, and charitable giving.
8. Protect Your Family, Too
Fraud is a family issue, not just an individual one. A CFP Board survey found that older Americans are notably less confident in their ability to detect fraud than younger Americans, and report encountering phishing and smishing at higher rates.
Grandparents and children under 18 are the least likely family members to successfully detect a fraud attempt — yet only 6% of Americans report having spoken with a grandparent about fraud in the past year.
- Talk to your adult children and grandchildren about fraud — both the digital variety and check fraud. Ask them to flag anything unusual in your accounts or communications, and offer to do the same for them. Younger people face their own risks, particularly investment scams and fraud encountered on social media.
- Establish a family code word that anyone can use to verify an urgent request for money, by phone, text, or email. If a caller cannot produce the code word, treat the request as fraudulent until proven otherwise — this is a simple but effective defense against AI voice-cloning scams.
- Ask about designating a trusted contact on your financial accounts. This is a person — typically an adult child or close family member — whom your advisor or institution is authorized to reach out to if something raises concern. It is not a power of attorney and does not give that person authority over your accounts; it simply provides a way to loop in someone you trust when needed.
- If you have an aging parent or grandparent, consider helping them set up account alerts, review statements with them periodically, and gently encourage them to call you before responding to any financial request they’re unsure about.
- Watch for warning signs that a family member may already be a victim: unusual withdrawals, new “friends” unusually interested in their finances, confusion about recent transactions, or reluctance to discuss their accounts.
9. If You Suspect Fraud, Act Fast – and Don’t Be Embarrassed
Speed matters enormously. If you suspect fraud, your first call should be to the relevant bank or credit card company. From there, contact law enforcement and, if appropriate, file a complaint with the FTC at ReportFraud.ftc.gov or the FBI’s Internet Crime Complaint Center at IC3.gov.
One barrier that keeps many victims from acting is shame. The CFP Board survey found that 1 in 4 fraud victims who did not report the fraud stayed silent because they felt embarrassed. Being targeted by fraud is not a reflection of your intelligence or judgment — these are professional criminals using sophisticated tools. The only real mistake is not reporting it promptly.
Treat your financial advisor as a first call, not a last resort, whenever something feels off. If you receive an unsolicited investment offer, hear about a “too good to be true” opportunity, or are simply uncertain whether a communication is legitimate, call us before you act.
-SM
Sources include the CFP Board of Standards (“Don’t Fall For It: Guarding Against Financial Fraud,” June 2026), the FBI Internet Crime Report 2025, and The New York Times.