Answers library

Start with your situation

The same stolen identifier can create very different work. Choose the reader path that matches what you know now, then move sideways only when new evidence points there.

12 guides

I think my identity was stolen

Contain active misuse, create the right records, and repair the accounts or reports that were actually affected.

Back to top ↑
I think my identity was stolen

Reading a Credit Report for Signs of Fraud

Read a credit report as an evidence document: separate unknown accounts and inquiries from harmless stale data, then log each suspicious item precisely.

I think my identity was stolen

SIM Swap: How It Happens and How to Block It

A SIM swap or fraudulent port moves control of your phone number to an attacker; harden the carrier account and move critical authentication away from SMS.

7 guides

A specific kind of identity theft

Follow the branch that matches tax, medical, child, criminal, employment, bank-account, or breach evidence.

Back to top ↑
A specific kind of identity theft

Tax-Related Identity Theft: Signs and Steps

Treat tax identity theft as an IRS-account problem first: follow the rejection or notice instructions, file the real return, and use Form 14039 only when the IRS process calls for it.

A specific kind of identity theft

Medical Identity Theft: Fixing Your Records and Bills

Medical identity theft can corrupt bills, insurance claims, and clinical records; recover both the financial record and the health record instead of treating it as ordinary credit fraud.

A specific kind of identity theft

Child Identity Theft: How to Check and What to Do

A child may have no credit file at all; if a file or account exists unexpectedly, close the fraud, freeze the child’s reports, and keep guardian documentation organized.

A specific kind of identity theft

Synthetic Identity Fraud: Why It's Hard to Catch

Synthetic identity fraud can pair a real SSN with invented identity details, so monitoring only your name may miss a file that is being built around your identifier.

A specific kind of identity theft

Someone Is Working Under Your SSN

If wages or employment verification appear under your SSN, correct the Social Security and tax records and use myE-Verify controls where they fit.

13 guides

Locking down before anything happens

Reduce new-account, account-recovery, tax, phone, and data-exposure risk before an incident forces the decision.

Back to top ↑
Locking down before anything happens

Getting an IRS Identity Protection PIN (IP PIN)

An IRS IP PIN is a six-digit, one-calendar-year filing credential; get it through the IRS, retrieve the current year’s number, and keep it out of email and text messages.

Locking down before anything happens

Setting Up a Password Manager and Passkeys

A password manager eliminates reuse; passkeys remove the shared secret entirely on supported sites. Set recovery before migrating your most important accounts.

Locking down before anything happens

Multi-Factor Auth: Which Types Resist Phishing

Choose MFA by attack resistance: SMS is better than password-only, authenticator codes are stronger, and passkeys or security keys best resist phishing.

Locking down before anything happens

Protecting Your Tax Refund Every Filing Season

File a legitimate return on the timeline that fits your tax situation; filing early can reduce the window for a fraudulent refund return but does not replace identity controls.

Locking down before anything happens

Securing a Home Network in an Hour

Change the router administrator password, use WPA3 or WPA2 with a strong Wi-Fi passphrase, and apply current firmware before tuning optional features.

Locking down before anything happens

Securing the Phone That Unlocks Everything

A phone can unlock email, banking, password resets, cloud backups, and carrier accounts, so its screen lock is part of identity protection.

5 guides

Responsible for security at a very small org

Build a realistic baseline for a tiny team, then handle vendors, incidents, breach obligations, and compliance triggers without enterprise theater.

Back to top ↑
Responsible for security at a very small org

An Intro to Compliance Frameworks for Small Organizations

Compliance frameworks answer different questions: PCI DSS concerns payment-card environments, HIPAA applies to covered health contexts, GLBA and the FTC Safeguards Rule apply to covered financial institutions, and state privacy laws depend on jurisdiction and thresholds.

5 guides

Someone tried to scam me

Classify what happened, stop irreversible payments or account access, and preserve the evidence that matters for the next step.

Back to top ↑
Someone tried to scam me

Gift Card, Wire, and "Pay to Fix It" Scams

Gift cards, wires, crypto, and cash are common scam payment methods because they move value quickly and are difficult to reverse; stop the next payment first.

Someone tried to scam me

Romance and "Pig Butchering" Investment Scams

Long-con investment scams build trust first, then move victims to fake trading platforms; stop sending money and preserve the transaction trail before the scammer disappears.

Someone tried to scam me

Protecting an Older Parent From Scams

Protect an older parent through agreed safeguards—alerts, freezes, trusted contacts, and a verification routine—without taking away control by surprise.