Identity Theft & Account Takeover: Break the Chain Before It Reaches You
Attackers rarely “break in.” They log in — with credentials that were already exposed, often years ago, without you ever knowing. This guide shows you the exact chain they follow, and how to cut it at every link.
Part of the Deliberate Digital Legacy resource library. This is a practical, self-help technical guide — not legal or financial advice. These steps meaningfully reduce your risk; they don’t eliminate it, and they’re not a substitute for law enforcement or professional incident response. Some tools below are US-specific — if you’re elsewhere, use your country’s equivalent. For disputes, fraud recovery, or legal decisions, consult a qualified professional.
The one idea: they log in, they don’t break in
Picture “account takeover” and you probably imagine a hacker cracking a password. That’s almost never how it happens. The overwhelming majority of account compromise starts with credentials that are already public — leaked in a data breach of some other company, bought or downloaded in bulk, and tried against your accounts automatically.
So the real risk isn’t one clever attack. It’s a chain:
A password leaks somewhere → you reused it → an attacker logs into an account → that account unlocks others → and eventually they have enough of you to open things in your name.
Identity theft is the last link in that chain, not the first. The good news: a chain breaks at any link. You don’t need to be un-hackable. You need to make sure that one exposed password can’t cascade into your whole life.
| Link in the chain | What the attacker does | Where you cut it |
|---|---|---|
| Exposure | Harvests your email + password from a breached site | Find out what’s already leaked (Step 1) |
| Reuse | Tries that password on your other accounts | Make every password unique (Step 2) |
| Takeover | Logs into an account the password still opens | Add a second factor a password can’t satisfy (Step 3) |
| Escalation | Uses your email or phone to reset everything else | Harden your master keys (Step 4) |
| Identity theft | Opens credit, files taxes, or transacts as you | Freeze the financial layer (Step 5) |
Work down the table and the chain never reaches the bottom.
Step 1: See what’s already exposed
You can’t fix leaks you don’t know about. Start by checking whether your credentials are already circulating.
- Have I Been Pwned (
haveibeenpwned.com) is the standard free tool. Enter an email address and it tells you which known breaches it appeared in. Check every email address you use, not just your main one. - Its companion list of breached sites shows which services were hit, so you know exactly which passwords to treat as burned.
- Assume the results are a floor, not a ceiling. Not every breach is public, so “no results” means “nothing known,” not “you’re clear.”
What to do with the results: any account tied to a breached password is a priority for Steps 2 and 3 — change it, make the new one unique, and turn on a second factor.
Step 2: Break the reuse chain
Reusing one password across sites is the single behavior that turns a minor breach into a full compromise. One leak, and every account sharing that password falls at once.
The fix isn’t willpower — no one can invent and remember dozens of strong, unique passwords. Use a password manager. It generates a long, random, different password for every account, stores them encrypted, and fills them in for you. You remember one strong master password; it remembers the rest.
This does three things at once: every account becomes unique (so a breach stays contained), every password becomes strong (so guessing fails), and — because a good manager only autofills on the real domain — it quietly protects you from fake login pages too.
Reality check: “I’ll just change the important ones” leaves the door open. Attackers pivot through the accounts you think don’t matter — an old forum, a dormant shopping site — because those often share a password with something that does. Uniqueness has to be the default, not the exception.
Step 3: Add a lock the password can’t open
Even a stolen password should not be enough to get in. That’s what a second factor (2FA / MFA) is for — a second proof of identity on top of the password. But not all second factors are equal, and the differences matter.
| Method | Strength | The catch |
|---|---|---|
| Passkeys | Strongest | Tied cryptographically to the real website, so a fake page can’t capture them. Not every service supports them yet. |
| Hardware security key (e.g. YubiKey) | Strongest | A physical key you tap or plug in; same phishing resistance as passkeys. Costs money; buy two so you have a backup. |
| Authenticator app (TOTP) | Strong | Generates codes on your device with no phone network involved, so SIM-swaps can’t touch it. The practical default for most accounts. |
| Push approval (“Approve this login?”) | Medium | Turn on number-matching if offered — it stops attackers from spamming you until you tap yes. |
| SMS text code | Weak | Better than nothing, but defeatable by SIM-swap fraud and fake login pages. Now formally discouraged in current US federal guidance. Use only as a last resort. |
The rule of thumb: put a passkey or hardware key on your highest-value accounts — primary email, banking, and any crypto — and an authenticator app on everything else. Treat SMS as the fallback you use only when a service offers nothing better.
Whatever method you pick, save the account’s backup/recovery codes in your password manager when you set it up. Losing your second factor without backups can lock you out as effectively as any attacker.
Step 4: Guard the master keys — your email and phone
Two things can reset almost everything else you own: your email inbox and your phone number. They’re the master keys, and attackers know it.
- Email is the reset hub. Whoever controls your primary email can trigger “forgot password” on every account attached to it. So your email deserves your strongest protection — a passkey or hardware key, not just a password. If email falls, the rest follows.
- Your phone number is a backdoor via SIM-swap. In a SIM-swap, an attacker convinces your mobile carrier to move your number to their SIM, then receives your SMS codes. Two defenses: move important accounts off SMS (Step 3), and ask your carrier to add a port-out PIN or SIM-swap lock to your account so your number can’t be moved without it.
- Reduce what’s out there to weaponize. Attackers combine breached passwords with your address, phone, and relatives’ names — bought from data-broker sites — to pass “security questions” and impersonate you to a call center. Removing yourself from the big data-broker sites breaks part of that chain.
Step 5: Freeze the financial layer
If the chain does reach the money — someone trying to open credit in your name — a credit freeze stops it cold. This is the most powerful single move most people never make, and in the US it’s free by law.
Three tools get confused. Here’s the clean version:
- Credit freeze — Blocks anyone (including you) from opening new credit in your name until you lift it. Free to place, lift, and re-place at each of the three bureaus. It does not lower your score and does not affect existing accounts. This is the strong one.
- Fraud alert — Asks lenders to take extra steps to verify it’s really you. Lighter than a freeze; you place it at one bureau and it propagates to the other two. Lasts one year (renewable), or seven years in extended form after confirmed theft.
- Credit “lock” — Does roughly what a freeze does but is usually a paid private product. If something is charging you monthly to “lock” your credit, you’re paying for what the free federal freeze already gives you.
How to freeze: place a freeze at all three bureaus — Equifax, Experian, and TransUnion — online or by phone. Save each bureau’s login/PIN, because you’ll need it to thaw briefly when you legitimately apply for a card, loan, or apartment. Freeze once; thaw only when you need to.
While you’re there, pull your reports free every week at AnnualCreditReport.com and scan for accounts, inquiries, or address changes you didn’t make — those are the early fingerprints of identity theft.
Step 6: If it’s already happened
If someone is already using your identity, don’t spiral — work a plan.
- Go to
IdentityTheft.gov(the FTC’s official recovery site) or call 1-877-438-4338. Answer the questions and it builds you a personalized recovery plan and an official Identity Theft Report — a document that proves to businesses that you were victimized and unlocks certain legal rights. - Place a fraud alert or freeze (Step 5) so no further accounts can be opened.
- Call the fraud department of each business where a fraudulent account was opened or charge was made; use your Identity Theft Report to dispute them.
- Change passwords and second factors on every affected account, starting with email.
- Consider a police report for your local jurisdiction — some creditors ask for one.
A note on scams that prey on victims: after any breach, expect a wave of convincing phishing — fake “breach notification” emails and calls. Never click links in them or give information to an inbound caller. Go directly to the service’s real website or the official numbers above.
Quick recap
- Attackers log in, they don’t break in — the risk is a chain, and it breaks at any link.
- Check what’s leaked (Have I Been Pwned), then treat those passwords as burned.
- One unique password per account, via a password manager — so one breach can’t cascade.
- Second factor on everything, ranked: passkey / hardware key › authenticator app › push › SMS (last resort).
- Protect email and phone hardest — they reset everything else. Add a carrier port-out PIN.
- Freeze your credit at all three bureaus (free, US) and read your reports weekly.
- If it happened:
IdentityTheft.govfor a recovery plan and an official Identity Theft Report.
References
Confirm current details on the official sites before relying on them — tools and terms change.
Check your exposure
- Have I Been Pwned — free breach lookup → https://haveibeenpwned.com
Official recovery (US)
- IdentityTheft.gov — FTC recovery plan & Identity Theft Report → https://www.identitytheft.gov
- FTC Consumer Advice — identity theft → https://consumer.ftc.gov/identity-theft-and-online-security
Credit reports & freezes (US)
- AnnualCreditReport.com — free weekly reports from all three bureaus → https://www.annualcreditreport.com
- Equifax credit freeze → https://www.equifax.com/personal/credit-report-services/credit-freeze/
- Experian credit freeze → https://www.experian.com/freeze/center.html
- TransUnion credit freeze → https://www.transunion.com/credit-freeze
Stronger logins
- FIDO Alliance — what passkeys are and where they work → https://fidoalliance.org/passkeys/
Outside the US, use your national equivalents — e.g. your country’s data-protection authority, national cybercrime reporting body, and local credit bureaus.
Deliberate Digital Legacy provides practical, self-help technical guides. We do not provide legal advice or estate execution services. Security steps reduce risk but cannot guarantee protection, and this guide is not a substitute for law enforcement or professional incident response. For legal drafting, disputes, or complex matters, consult a qualified professional.