Identity Theft & Account Takeover: Break the Chain Before It Reaches You

Print / Save as PDF

Attackers rarely “break in.” They log in — with credentials that were already exposed, often years ago, without you ever knowing. This guide shows you the exact chain they follow, and how to cut it at every link.

Part of the Deliberate Digital Legacy resource library. This is a practical, self-help technical guide — not legal or financial advice. These steps meaningfully reduce your risk; they don’t eliminate it, and they’re not a substitute for law enforcement or professional incident response. Some tools below are US-specific — if you’re elsewhere, use your country’s equivalent. For disputes, fraud recovery, or legal decisions, consult a qualified professional.


The one idea: they log in, they don’t break in

Picture “account takeover” and you probably imagine a hacker cracking a password. That’s almost never how it happens. The overwhelming majority of account compromise starts with credentials that are already public — leaked in a data breach of some other company, bought or downloaded in bulk, and tried against your accounts automatically.

So the real risk isn’t one clever attack. It’s a chain:

A password leaks somewhere → you reused it → an attacker logs into an account → that account unlocks others → and eventually they have enough of you to open things in your name.

Identity theft is the last link in that chain, not the first. The good news: a chain breaks at any link. You don’t need to be un-hackable. You need to make sure that one exposed password can’t cascade into your whole life.

Link in the chainWhat the attacker doesWhere you cut it
ExposureHarvests your email + password from a breached siteFind out what’s already leaked (Step 1)
ReuseTries that password on your other accountsMake every password unique (Step 2)
TakeoverLogs into an account the password still opensAdd a second factor a password can’t satisfy (Step 3)
EscalationUses your email or phone to reset everything elseHarden your master keys (Step 4)
Identity theftOpens credit, files taxes, or transacts as youFreeze the financial layer (Step 5)

Work down the table and the chain never reaches the bottom.


Step 1: See what’s already exposed

You can’t fix leaks you don’t know about. Start by checking whether your credentials are already circulating.

What to do with the results: any account tied to a breached password is a priority for Steps 2 and 3 — change it, make the new one unique, and turn on a second factor.


Step 2: Break the reuse chain

Reusing one password across sites is the single behavior that turns a minor breach into a full compromise. One leak, and every account sharing that password falls at once.

The fix isn’t willpower — no one can invent and remember dozens of strong, unique passwords. Use a password manager. It generates a long, random, different password for every account, stores them encrypted, and fills them in for you. You remember one strong master password; it remembers the rest.

This does three things at once: every account becomes unique (so a breach stays contained), every password becomes strong (so guessing fails), and — because a good manager only autofills on the real domain — it quietly protects you from fake login pages too.

Reality check: “I’ll just change the important ones” leaves the door open. Attackers pivot through the accounts you think don’t matter — an old forum, a dormant shopping site — because those often share a password with something that does. Uniqueness has to be the default, not the exception.


Step 3: Add a lock the password can’t open

Even a stolen password should not be enough to get in. That’s what a second factor (2FA / MFA) is for — a second proof of identity on top of the password. But not all second factors are equal, and the differences matter.

MethodStrengthThe catch
PasskeysStrongestTied cryptographically to the real website, so a fake page can’t capture them. Not every service supports them yet.
Hardware security key (e.g. YubiKey)StrongestA physical key you tap or plug in; same phishing resistance as passkeys. Costs money; buy two so you have a backup.
Authenticator app (TOTP)StrongGenerates codes on your device with no phone network involved, so SIM-swaps can’t touch it. The practical default for most accounts.
Push approval (“Approve this login?”)MediumTurn on number-matching if offered — it stops attackers from spamming you until you tap yes.
SMS text codeWeakBetter than nothing, but defeatable by SIM-swap fraud and fake login pages. Now formally discouraged in current US federal guidance. Use only as a last resort.

The rule of thumb: put a passkey or hardware key on your highest-value accounts — primary email, banking, and any crypto — and an authenticator app on everything else. Treat SMS as the fallback you use only when a service offers nothing better.

Whatever method you pick, save the account’s backup/recovery codes in your password manager when you set it up. Losing your second factor without backups can lock you out as effectively as any attacker.


Step 4: Guard the master keys — your email and phone

Two things can reset almost everything else you own: your email inbox and your phone number. They’re the master keys, and attackers know it.


Step 5: Freeze the financial layer

If the chain does reach the money — someone trying to open credit in your name — a credit freeze stops it cold. This is the most powerful single move most people never make, and in the US it’s free by law.

Three tools get confused. Here’s the clean version:

How to freeze: place a freeze at all three bureaus — Equifax, Experian, and TransUnion — online or by phone. Save each bureau’s login/PIN, because you’ll need it to thaw briefly when you legitimately apply for a card, loan, or apartment. Freeze once; thaw only when you need to.

While you’re there, pull your reports free every week at AnnualCreditReport.com and scan for accounts, inquiries, or address changes you didn’t make — those are the early fingerprints of identity theft.


Step 6: If it’s already happened

If someone is already using your identity, don’t spiral — work a plan.

  1. Go to IdentityTheft.gov (the FTC’s official recovery site) or call 1-877-438-4338. Answer the questions and it builds you a personalized recovery plan and an official Identity Theft Report — a document that proves to businesses that you were victimized and unlocks certain legal rights.
  2. Place a fraud alert or freeze (Step 5) so no further accounts can be opened.
  3. Call the fraud department of each business where a fraudulent account was opened or charge was made; use your Identity Theft Report to dispute them.
  4. Change passwords and second factors on every affected account, starting with email.
  5. Consider a police report for your local jurisdiction — some creditors ask for one.

A note on scams that prey on victims: after any breach, expect a wave of convincing phishing — fake “breach notification” emails and calls. Never click links in them or give information to an inbound caller. Go directly to the service’s real website or the official numbers above.


Quick recap


References

Confirm current details on the official sites before relying on them — tools and terms change.

Check your exposure

Official recovery (US)

Credit reports & freezes (US)

Stronger logins

Outside the US, use your national equivalents — e.g. your country’s data-protection authority, national cybercrime reporting body, and local credit bureaus.


Deliberate Digital Legacy provides practical, self-help technical guides. We do not provide legal advice or estate execution services. Security steps reduce risk but cannot guarantee protection, and this guide is not a substitute for law enforcement or professional incident response. For legal drafting, disputes, or complex matters, consult a qualified professional.