A Scammer Has My Information: What They Can Do and How to Fix It
Independently fact-checked against primary sources (last audited October 3, 2026). · 17 primary sources cited on this page. How we verify our legal content

What a scammer can do with your information depends on exactly what they got. A Social Security number is mainly a key to new things in your name: credit cards, phone and utility accounts, a tax refund. A bank login, a texted code or a card number is a key to money in accounts you already have. And control of your phone number can hand a scammer the verification codes that protect everything else.
The fixes that matter most are free, and order matters. Contact your bank or card issuer first if anything touching money was exposed. Then freeze your credit at Equifax, Experian and TransUnion, which federal law makes free (15 U.S.C. § 1681c-1(i)). If a scammer used information you were tricked into sharing to move money out of your account, the Consumer Financial Protection Bureau (CFPB) says that transfer is an unauthorized electronic fund transfer under Regulation E, which gives you rights to an investigation and limits on your losses.
Information last verified on October 2, 2026. This article has not been reviewed by a licensed lawyer.
Jurisdiction scope: This guide covers US federal law and federal agency guidance: the Fair Credit Reporting Act (credit freezes, fraud alerts, the identity theft block), Regulation E and Regulation Z (bank and card losses), the federal identity theft statute, IRS and Social Security Administration programs, and Federal Communications Commission (FCC) rules for phone carriers. State identity theft laws, state freeze laws and individual company policies are not covered except where noted. If you already sent money to a scammer, our guide to getting money back after a scam covers refund rights by payment method.
What to do first: the order that matters
Scammers are professionals, and handing over information to a convincing caller or a perfect copy of your bank's website is common. What matters now is speed and order. Work through these steps, skipping any that do not apply to what you gave away.
- Money first. If the scammer has a bank login, a debit or credit card number, a one-time code, or remote access to a device you bank on, call the bank or card issuer now. The FTC says to use "the number on the back of your card or log in to your account online or through their app."
- Take back your email and phone. Change your email password (and anywhere you reused it), turn on two-factor authentication, and call your mobile carrier if your phone suddenly lost service.
- Freeze your credit at all three nationwide bureaus: Equifax, Experian and TransUnion.
- Report or check in at IdentityTheft.gov. The FTC says that if a scammer used your Social Security number, "Go to IdentityTheft.gov to report it. Get a customized recovery plan based on your situation." If the scammer did not use it or you are not sure, it points you to IdentityTheft.gov/databreach.
- Lock down your tax return with an IRS Identity Protection PIN.
- Keep a record of who you called, when, and what they said. Dates matter, because several federal protections run on deadlines measured from when you report.
What each piece of information lets a scammer do
| What the scammer got | What they can try to do | First free step | Main federal protection |
|---|---|---|---|
| Social Security number | Open credit, phone or utility accounts in your name; file a tax return to take your refund; use it for a job or medical care | Credit freeze at all three bureaus; IdentityTheft.gov | Free freeze (15 U.S.C. § 1681c-1); identity theft block (15 U.S.C. § 1681c-2) |
| Bank login or bank account number | Take money out of your account | Call your bank's fraud line | Regulation E unauthorized-transfer rules (12 C.F.R. §§ 1005.6, 1005.11) |
| Debit card number | Take money out of the linked account | Call your bank and ask for a new card | Regulation E (the CFPB lists a debit card number among information that leads to unauthorized transfers) |
| Credit card number | Run up charges | Call the card issuer | $50 liability cap (12 C.F.R. § 1026.12(b)) |
| One-time verification code | Finish logging in to your account as you | Contact the company; change the password | Regulation E if money moves (CFPB EFT FAQ) |
| Phone number (SIM swap or port-out) | Receive your calls and texts, including login codes | Call your carrier immediately | Carrier account-authentication and change-notice rules (47 C.F.R. § 64.2010(a)-(f)); SIM-swap rules adopted but not yet required |
| Email password | Take over your email and lock you out | Change the password; account recovery | None specific; federal crime if misused |
| Remote access to a computer or phone | Watch you log in; take information | Update security software, scan, change passwords | Regulation E if money moves (CFPB EFT FAQ) |
| Photo of a driver's license or ID | Use your ID number, name, address and birth date to pose as you | Credit freeze; watch for warning signs | Federal identity theft crime (18 U.S.C. § 1028) |
| Address and date of birth | Answer security questions; combine with other stolen data | Credit freeze; add PINs to accounts | Federal identity theft crime (18 U.S.C. § 1028) |
Using any of this against you can be a federal crime. Under 18 U.S.C. § 1028(a)(7), it is a crime to "knowingly" transfer, possess or use, "without lawful authority, a means of identification of another person" with the intent to commit, aid or abet, or in connection with, unlawful activity that violates federal law or is a felony under state or local law. The statute's definition of "means of identification" in § 1028(d)(7) expressly includes a "social security number, date of birth, official State or government issued driver's license or identification number," as well as a "unique electronic identification number, address, or routing code."
A scammer has my Social Security number
Your Social Security number does not move money by itself. Its danger is that it lets someone open things in your name. The FTC lists what identity thieves do with stolen information, including buying things with your credit cards, getting new credit cards in your name, opening "a phone, electricity, or gas account in your name," stealing your tax refund, getting a job or medical care, and pretending to be you if they are arrested.
Your free fixes, in order:
1. Freeze your credit at all three bureaus
A credit freeze is the strongest free tool against new-account fraud. The FTC says that while a freeze is in place, "nobody can open a new credit account in your name, including you," and that "There's no cost to place or lift a credit freeze, and it doesn't affect your credit score." A freeze "lasts until you lift it." You have to contact all three credit bureaus, Equifax, Experian and TransUnion, separately.
Federal law sets the deadlines. Under 15 U.S.C. § 1681c-1(i)(2)(A), a nationwide bureau "shall, free of charge, place the security freeze" no later than:
"(i) in the case of a request that is by toll-free telephone or secure electronic means, 1 business day after receiving the request directly from the consumer; or (ii) in the case of a request that is by mail, 3 business days after receiving the request directly from the consumer."
Lifting the freeze is also free. Under § 1681c-1(i)(3)(C), a bureau must remove it within 1 hour of a phone or online request (3 business days by mail), and you can ask for a temporary removal for a period you choose (§ 1681c-1(i)(3)(E)). The FTC suggests asking which bureau a lender uses and lifting the freeze only there, then putting it back.
You do not have to wait for proof of misuse. The FTC says: "You don't have to wait for your Social Security number or other information to be exposed in a data breach or misused by an identity thief to get a credit freeze. Anyone can do it, any time." For a child under 16, the FTC says to "request a free credit freeze," using a separate process each bureau publishes.
What a credit freeze does not cover
Two limits are worth knowing before you rely on a freeze.
- It covers only the three nationwide bureaus. The free-freeze subsection defines "consumer reporting agency" as "a consumer reporting agency described in section 1681a(p) of this title," meaning the nationwide bureaus. Other reporting companies are outside that statutory right. For example, ChexSystems, which the CFPB lists as a check and bank account screening company, "will freeze your consumer report if you request it," according to the CFPB's company listing; that is the company's practice as the CFPB describes it, and we did not verify its terms or cost.
- It is aimed at new credit, not accounts you already have. A security freeze is defined as a restriction on a bureau disclosing your credit report (§ 1681c-1(i)(1)(C)). The required consumer notice in the statute says a freeze "does not apply to a person or entity ... with which you have an existing account that requests information in your credit report for the purposes of reviewing or collecting the account." A freeze does not watch your bank account or stop charges on an existing card.
Our guide to credit freezes vs. fraud alerts compares the two tools in more depth.
2. Add a fraud alert (optional, and you can have both)
A fraud alert tells lenders to verify your identity before opening new credit, but it is weaker than a freeze. The FTC says: "Unlike a credit freeze, a fraud alert doesn't prevent businesses from seeing your credit report." You can place an alert even with a freeze in place.
- Initial fraud alert. Free, and you contact only one bureau, which "must tell the other two," according to the FTC. Under 15 U.S.C. § 1681c-1(a)(1), you can request one if you assert "in good faith a suspicion that the consumer has been or is about to become a victim of fraud or related crime, including identity theft," and it lasts "not less than 1 year." The FTC says you can renew it.
- Extended fraud alert. For people who have already experienced identity theft. The FTC says it is for people who "have completed an FTC identity theft report at IdentityTheft.gov or filed a police report." Under § 1681c-1(b)(1), it lasts for a "7-year period," and the bureaus must keep you off lists for unsolicited credit and insurance offers for 5 years.
3. Report to IdentityTheft.gov, or use its data-exposure steps
IdentityTheft.gov is the FTC's free reporting and recovery site. The FTC says it lets you "get a personal recovery plan that walks you through each step," track your progress, and "print pre-filled letters and forms to send to credit bureaus, businesses, and debt collectors." If your number has not been used yet, the FTC directs you to IdentityTheft.gov/databreach instead. Our guide on how to report identity theft walks through the report and what it unlocks.
4. Get an IRS Identity Protection PIN
Neither a credit freeze nor most monitoring services stop someone from filing a tax return with your number. The IRS Identity Protection PIN (IP PIN) is built for exactly that. The IRS says an IP PIN "is a six-digit number that prevents someone else from filing a tax return using your Social Security number (SSN) or individual taxpayer identification number (ITIN)."
- Who can get one: "Anyone who has an SSN or individual taxpayer identification number (ITIN) and is able to verify his/her identity," according to the IRS. Parents and legal guardians can request one for dependents.
- How: The IRS says the fastest way is through your IRS online account. If you cannot set up an account, the IRS page reviewed August 4, 2026 lists Form 15227 for filers whose adjusted gross income on the last filed return is below $84,000 (individuals) or $168,000 (married filing jointly), or an in-person appointment at a Taxpayer Assistance Center.
- What to know: "An IP PIN is valid for one calendar year," and a new one is generated each year. A missing or wrong IP PIN causes "the rejection of your e-filed return or a delay of your paper return until it can be verified." And "The IRS will never ask for your IP PIN," so a call or text asking for it is a scam.
If you think someone has already filed using your number, see our guide to tax identity theft.
5. Secure your Social Security record
The Social Security Administration (SSA) says opening a my Social Security account "helps secure your personal information and prevents identity thieves from fraudulently opening an account in your name. If anyone tries to change your address or direct deposit without your permission, you'll get an alert right away."
The SSA also says it "will never ask for sensitive or personal information through social media, email, or text message." If the scammer pretended to be from Social Security, the SSA says to report it to its Office of the Inspector General at oig.ssa.gov/report. Our guide to government impersonation scams covers those calls.
Can you get a new Social Security number? Only in limited situations. The SSA says it can assign a different number in a short list of cases, including for "a victim of identity theft, who has attempted to fix problems resulting from the misuse but continues to be disadvantaged by using the original number," and where there is "a situation of harassment, abuse or life endangerment." To ask, the SSA says to contact your local Social Security office for an in-person appointment.
A scammer has my bank login or bank account number
This is where the money is, so call your bank's fraud line first, using the number on your card, your statement or the bank's official app. Tell them your login or account details were taken in a scam, ask them to check for transfers, new payees and changed contact details, and ask what protections they can put on the account. Then change your online banking password, and the password anywhere you reused it.
The FTC lists draining your bank account among the things identity thieves do with stolen financial information. Two federal rules matter if money has already moved.
A transfer the scammer makes with information you were tricked into sharing is unauthorized. Regulation E defines an unauthorized electronic fund transfer as one "initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit" (12 C.F.R. § 1005.2(m)). In its official Regulation E FAQ (updated June 4, 2021), the CFPB answered the scam question directly:
"when a consumer is fraudulently induced into sharing account access information with a third party, and a third party uses that information to make an EFT from the consumer's account, the transfer is an unauthorized EFT under Regulation E."
The CFPB's examples include a fake bank representative "tricking the consumer into providing their account login information, texted account confirmation code, debit card number, or other information that could be used to initiate an EFT out of the consumer's account."
Your carelessness cannot be used to raise your liability. The official commentary says: "Negligence by the consumer cannot be used as the basis for imposing greater liability than is permissible under Regulation E" (comment 6(b)-2). The CFPB's FAQ adds that a bank cannot make you contact the merchant before it starts investigating.
Report fast, and always within 60 days of the statement. For an unauthorized transfer made without a card, code or other "access device," the commentary says the $50 and $500 liability tiers "do not apply," and gives this example of an electronic debit made "by means other than the consumer's access device": "if the consumer notifies the institution within 60 days of the transmittal of the periodic statement that shows the unauthorized transfer, the consumer has no liability" (comment 6(b)(3)-2). Miss that window and you can be liable for later transfers. If the scammer used an "access device," which the Regulation E commentary says includes debit cards, PINs and "other means that may be used by a consumer to initiate" a transfer, shorter limits also apply: your liability is capped at $50 only if you tell the bank within two business days after learning of the loss or theft, and can reach $500 after that (12 C.F.R. § 1005.6(b)(1) and (2)). The bank's investigation duties (generally 10 business days, or up to 45 days with a provisional credit to your account within 10 business days) are in 12 C.F.R. § 1005.11(c).
These rules protect money a scammer took. If the scammer talked you into sending the money yourself, the Regulation E definition, written for transfers "initiated by a person other than the consumer," generally does not fit as written. Our guides to getting money back after a scam and to what to do when the bank refuses a scam refund cover both situations and the full deadlines.
A scammer has my credit or debit card number
Credit card. Call the issuer using the number on the back of the card, report the charges and ask for a new card number. Under Regulation Z, your liability for unauthorized use of a credit card "shall not exceed the lesser of $50 or the amount of money, property, labor, or services obtained by the unauthorized use before notification to the card issuer" (12 C.F.R. § 1026.12(b)(1)(ii)). The regulation defines unauthorized use as use "by a person, other than the cardholder, who does not have actual, implied, or apparent authority for such use, and from which the cardholder receives no benefit" (§ 1026.12(b)(1)(i)). You can notify the issuer "in person, by telephone, or in writing" (§ 1026.12(b)(3)). The official commentary adds that when someone uses your card number by phone or online without the card itself, "no liability may be imposed on the cardholder" (comment 12(b)(2)(iii)-3).
Debit card. Call your bank now and ask it to block the card and issue a new one. The CFPB lists a "debit card number" among the information that, when a scammer tricks you into sharing it and then uses it, produces an unauthorized transfer under Regulation E. Exactly which Regulation E liability tier applies when a scammer has only the card number and you still hold the card is not something the CFPB's FAQ addresses, so do not wait to find out: report it the same day you discover it.
If you paid a scammer with your card for something that never arrived, that is a different problem (a billing dispute rather than stolen card details). The money-back guide explains the dispute process and its deadline.
I gave a scammer a one-time code
A one-time code is often the last thing standing between a scammer and your account. The FTC explains that a scammer who controls your texts can "log in to your accounts that use text messages as a form of multi-factor authentication" because "they'll get a text message with the verification code they need to log in." A code you read out to a caller does the same job.
What to do:
- Contact the company the code came from right away, using a number or website you know is real, and say the code was stolen.
- Change the account password and check for new payees, transfers and changed contact details.
- Consider stronger sign-in. The FTC warns that "text message verification may not stop a SIM card swap. If you're concerned about SIM card swapping, use an authentication app or a security key."
If the code was for your bank and money has moved, the CFPB example quoted above, a "texted account confirmation code," applies. Our guide to phishing, smishing and vishing covers the fake fraud-alert calls that usually ask for these codes.
A scammer has my phone number: SIM swaps and port-outs
A scammer who merely knows your phone number can call or text you. The bigger danger is a scammer taking control of the number. In a SIM swap, the FTC says, a scammer tells your carrier your phone was lost or damaged and asks it to activate a new SIM card on a phone the scammer owns. "If your provider believes the bogus story and activates the new SIM card," the FTC says, the scammer, not you, gets all your text messages, calls and data on the new phone. In a port-out, the number is moved to a different carrier instead.

The FTC lists what follows: the scammer "could open new cellular accounts in your name or buy new phones using your information," and "Armed with your log in credentials, the scammer could log in to your bank account and steal your money, or take over your email or social media accounts."
Warning signs. Your phone suddenly has no service, texts or calls, or you get an unexpected notice that your SIM card was activated on a new device.
What to do if it happens, per the FTC (in a consumer alert from October 2019):
- "Contact your cellular service provider immediately to take back control of your phone number."
- After you regain the number, change your account passwords.
- Check your credit card, bank and other financial accounts for unauthorized charges or changes, and report any you find.
- If you think a scammer also has your Social Security, credit card or bank account number, go to IdentityTheft.gov.
How to make it harder. The FTC suggests you "Set up a PIN or password on your cellular account," limit the personal information you post online, and use an authentication app or security key instead of text codes on sensitive accounts.
What the law requires of your carrier today
Some protections are in force now; the newer SIM-swap rules are not.
- In force: Under 47 C.F.R. § 64.2010(a), carriers "must properly authenticate a customer prior to disclosing" customer account and calling information (called CPNI). Under § 64.2010(f)(1), carriers "must notify customers immediately whenever a password, customer response to a back-up means of authentication for lost or forgotten password, online account, or address of record is created or changed." If you get such a notice and did not make the change, call your carrier.
- Adopted but not yet required: On November 15, 2023, the FCC adopted an order (FCC 23-95) aimed at SIM-swap and port-out fraud. It requires carriers to use secure methods to authenticate a customer before a SIM change or a port-out (for SIM changes, methods that do not rely on readily available biographical information, account information, recent payment information or call detail information), and it says: "We require wireless providers to offer all customers, at no cost, the option to lock or freeze their account to stop SIM changes." In July 2024, the FCC's Wireline Competition Bureau (DA 24-649) waived compliance with the order's rules until the parts that need federal paperwork approval take effect. In the eCFR as of September 1, 2026, the codified rules (47 C.F.R. § 64.2010(h) for SIM changes and § 52.37 for port-outs) both still say compliance "will not be required until this paragraph is removed or contains a compliance date," and several of the adopted paragraphs appear only as "[Reserved]."
So, as of October 2026, a free SIM lock or port-out lock is something to ask your carrier for, not something federal rules yet require it to give you. The FTC's advice still applies: set up a PIN or password on your cellular account, and "Check your provider's website for information on how to do this."
A scammer has my email password
Treat your email as urgent. The FTC explains that someone who hacks your email "could request a password reset link for any of your other accounts, get the password reset link from your inbox, change your password, and lock you out of the account." The FTC's steps:
- If you can still log in: "Create a new, strong password for the account that was compromised. (If you use the same password on another account, change it there, too.)" Then "Turn on two-factor authentication on the account."
- If you are locked out: use the provider's official account recovery process. The FTC's guide "How To Get Back Into Your Hacked Account" links to recovery instructions for popular services.
Once you are back in, check your account recovery information. The FTC says: "Make sure the recovery email addresses and phone numbers listed are ones you entered and have access to."
A scammer had remote access to my computer or phone
If you let a "tech support" caller or a fake bank employee connect to your device, they may have seen what you typed or opened while connected. The FTC says to:

- "Update your security software to make sure you have the latest protections."
- "Run a scan and delete anything it identifies as a problem."
- "Change your passwords and turn on two-factor authentication to protect your accounts."
The FTC adds that if you need help removing malware, you can get tech support from the manufacturer or a company you know and trust. If you logged in to your bank while the scammer was connected, call the bank: the CFPB lists "a third party using phishing or other methods to gain access to a consumer's computer and observe the consumer entering account login information" as a situation where resulting transfers are unauthorized under Regulation E. Our guide to tech support and fake invoice scams covers these scams in depth.
A scammer has a photo of my driver's license or ID
A photo of your license or ID card bundles your name, address, date of birth and an ID number in one image. Federal law treats a driver's license or government ID number as a "means of identification" (18 U.S.C. § 1028(d)(7)), the same category as a Social Security number.
We were not able to verify an official, ID-specific recovery procedure for this guide, and state licensing agencies handle replacement and fraud reports differently. What the federal steps above already give you:
- A credit freeze at all three bureaus blocks new credit opened with your stolen identity.
- A fraud alert asks lenders to verify that it is really you.
- IdentityTheft.gov is the place to report if the information is used.
If you sent the photo to a scammer posing as an employer, landlord or lender, freeze your credit the same day.
A scammer has my address and date of birth
These details are rarely secret, but they are pieces a thief uses to pass identity checks. The FTC warns that an identity thief could find your personal information online "and use it to answer the security questions required to verify your identity and log in to your accounts." Federal law lists a "date of birth" as a means of identification (18 U.S.C. § 1028(d)(7)).
Practical defenses:
- Freeze your credit. The FTC says a freeze is "even more important if your Social Security number or other information is exposed."
- Add a PIN or password to accounts that offer one, including your mobile carrier. For carriers, federal rules already bar using "readily available biographical information, or account information" to set up a password or authenticate online access (47 C.F.R. § 64.2010(c) and (e)).
- Watch for warning signs. The FTC says that if you stop getting a bill, "that could be a sign that someone changed your billing address," and that accounts you don't recognize on your credit report could be a sign of identity theft.
When exposed information turns into fraud: your rights
If a scammer actually uses your information, these federal rights come into play.
Block fraudulent information from your credit report. Under 15 U.S.C. § 1681c-2(a), a consumer reporting agency, such as Equifax, Experian or TransUnion, "shall block the reporting of any information in the file of a consumer that the consumer identifies as information that resulted from an alleged identity theft, not later than 4 business days" after it receives four things from you: proof of your identity, a copy of an identity theft report, identification of the information, and a statement that the information does not relate to any transaction by you. The bureau must notify the business that supplied the information (§ 1681c-2(b)). It may decline or rescind a block if it reasonably determines the block was made in error, was based on a material misrepresentation, or if "the consumer obtained possession of goods, services, or money as a result of the blocked transaction" (§ 1681c-2(c)(1)).
Free credit reports. The FTC says the three bureaus "have permanently extended a program that lets you check your credit report from each once a week for free at AnnualCreditReport.com." The FTC also says AnnualCreditReport.com is the only website authorized to fill orders for the free annual reports you are entitled to by law.
Bank and card protections. Regulation E and Regulation Z, described above, limit what you can lose from unauthorized transfers and charges, provided you report on time.
Report the scam. The FTC's reporting routes:
- Identity theft: IdentityTheft.gov (English) or RobodeIdentidad.gov (Spanish). For another language, the FTC says to "call 877-438-4338 and press 3 to report in your preferred language."
- The scam itself: ReportFraud.ftc.gov. The FTC says it uses reports to "build cases against scammers" and "spot trends." It does not resolve individual reports.
Our where to report a scam guide lists the right agency for each kind of scam.
Do you need a paid identity monitoring service?
Monitoring services are often the first thing advertised after a scare. The FTC's guidance is a useful way to decide, because it lays out both what these services do and what they miss. The FTC notes you might pay a company directly or get a service through your bank or credit union, credit card provider, employer's benefits program or insurance company.
What credit monitoring does. According to the FTC, credit monitoring services "keep an eye on your credit report and let you know if anything suspicious pops up" and "usually charge a monthly or annual fee." The FTC says they usually alert you when a company checks your credit, a new loan or credit card account appears, a creditor reports a late payment, or your personal information changes. They may watch one, two or all three bureaus.
What credit monitoring misses. The FTC says credit monitoring services won't alert you when:
- "someone withdraws money from your bank account"
- "someone uses your Social Security number to file a tax return and collect your refund"
What identity monitoring adds, and misses. The FTC says identity monitoring services check other databases and may alert you when your information shows up in a change of address request, court or arrest records, orders for new utility, cable or wireless services, payday loan applications, check-cashing requests, social media, or "on websites that identity thieves use to trade stolen information." But "Most identity monitoring services won't alert you if someone uses your information to" file a tax return and collect your refund, get Medicare, Medicaid or welfare benefits, or claim Social Security or unemployment benefits.
Insurance and recovery help. The FTC says identity theft insurance may cover out-of-pocket recovery costs such as copying, postage, notarizing, lost wages and legal fees, but "generally won't reimburse you for money scammers stole or financial loss from the theft." Of recovery services, the FTC says you "might be able to do some of the services they offer on your own for little or no cost."
The bottom line. Monitoring tells you about some problems after they start. A credit freeze prevents new credit from being opened; your bank's fraud line and Regulation E handle money taken from your account; the IRS IP PIN blocks tax refund fraud; and the FTC reminds you that "you can monitor your credit by getting your free credit reports." Those steps are free, and they come first. If you are considering a paid service, the FTC suggests asking which bureaus it monitors, how often it checks for changes, and what you will be charged.
Related guides
- I got scammed: what to do, how to get money back and where to report
- Phishing, smishing and vishing: what to do if you clicked
- How to get money back after a scam
- Identity theft laws
- Synthetic identity theft
- What to do after a data breach
- Elder fraud
- Free privacy action plan tool
- Mail Theft and Check Washing
Last updated: October 2, 2026.
This article provides general legal information about US federal law as verified on October 2, 2026. It is not legal advice. For your specific situation, contact your bank, card issuer or carrier, the agency named above, or a lawyer licensed in your state.
Frequently Asked Questions
What can a scammer do with my Social Security number?
The FTC says identity thieves use stolen information to get new credit cards in your name, open phone, electricity or gas accounts, steal your tax refund, get a job or medical care, and even pretend to be you if they are arrested. Freeze your credit at all three bureaus and get an IRS Identity Protection PIN.
Is a credit freeze really free?
Yes. Under 15 U.S.C. § 1681c-1(i), the nationwide credit bureaus must place and remove a security freeze free of charge, within 1 business day of a phone or online request to place it and within 1 hour of a phone or online request to lift it. You have to contact Equifax, Experian and TransUnion separately.
Does a credit freeze stop a scammer from using my bank account or credit card?
No. A freeze restricts a bureau from releasing your credit report, so it is aimed at new credit accounts. It does nothing about charges on a card or transfers out of an account you already have; for those, call the bank or card issuer.
I gave a scammer my bank login or a verification code. Will the bank refund me?
If the scammer then moved money out of your account, the CFPB says that transfer is an unauthorized electronic fund transfer under Regulation E, so the bank must investigate when you report it. Report it right away and within 60 days of the statement showing it; the outcome of any investigation is up to the bank and the facts.
What is a SIM swap?
A scammer convinces your mobile carrier to move your phone number to a SIM card on a phone the scammer controls, so the scammer gets your calls, texts and verification codes. Call your carrier immediately to take your number back, then change your passwords.
Is my phone carrier required by law to lock my account against SIM swaps?
Not yet. The FCC adopted rules in 2023 that would require free account locks, but under the eCFR as of September 1, 2026, compliance is not required until a compliance date is published. The FTC suggests setting up a PIN or password on your cellular account; ask your carrier what account protections it offers.
Can I get a new Social Security number after a scam?
Only in limited situations. The Social Security Administration says it can assign a different number to an identity theft victim who has tried to fix the problems caused by the misuse but is still disadvantaged by using the original number, and in cases of harassment, abuse or life endangerment, among a few other listed situations. You request one in person at a local Social Security office.
Should I pay for identity theft protection?
That is your call, but the FTC notes these services usually charge a monthly or annual fee, that credit monitoring will not flag bank withdrawals or tax refund fraud, and that identity theft insurance generally will not reimburse money scammers stole. The freeze, fraud alert, free weekly credit reports and IP PIN cost nothing.
Updates
Independently fact-checked against the cited primary sources
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
United States Code Title 15
§ 1681c–1Identity theft prevention; fraud alerts and active duty alertsIn forcecited in 5 of our articles
(a) One-call fraud alerts (1) Initial alerts Upon the direct request of a consumer, or an individual acting on behalf of or as a personal representative of a consumer, who asserts in good faith a suspicion that the consumer has been or is about to become a victim of fraud or related crime, including identity theft, a consumer reporting agency described in section 1681a(p) of this title that maintains a file on the consumer and has received appropriate proof of the identity of the requester shall— (A) include a fraud alert in the file of that consumer, and also provide that alert along with any credit score generated in using that file, for a period of not less than 1 year, beginning on the date of such request, unless the consumer or such representative requests that such fraud alert be removed before the end of such period, and the agency has received appropriate proof of the identity of the requester for such purpose; and (B) refer the information regarding the fraud alert under this paragraph to each of the other consumer reporting agencies described in section 1681a(p) of this title, in accordance with procedures developed under section 1681s(f) of this title.
Official text (excerpt) · last checked 2026-09-16 · Read the full text in our law library · Verify at uscode.house.gov
Also relied on in: Child Identity Theft: Warning Signs, Credit Checks, and the Minor Freeze Right, Credit Freeze vs. Fraud Alert: What is the Difference, How to Freeze Your Credit After a Data Breach (Free)
§ 1681c–2Block of information resulting from identity theftIn forcecited in 2 of our articles
Except as otherwise provided in this section, a consumer reporting agency shall block the reporting of any information in the file of a consumer that the consumer identifies as information that resulted from an alleged identity theft, not later than 4 business days after the date of receipt by such agency of— appropriate proof of the identity of the consumer; a copy of an identity theft report; the identification of such information by the consumer; and a statement by the consumer that the information is not information relating to any transaction by the consumer. A consumer reporting agency shall promptly notify the furnisher of information identified by the consumer under subsection (a)— that the information may be a result of identity theft; that an identity theft report has been filed; that a block has been requested under this section; and of the effective dates of the block.
Official text (excerpt) · last checked 2026-09-02 · Read the full text in our law library · Verify at uscode.house.gov
Also relied on in: How to Report Identity Theft: FTC Report and Next Steps
United States Code Title 18
§ 1028Fraud and related activity in connection with identification documents, authentication features, and informationIn forcecited in 22 of our articles
Whoever, in a circumstance described in subsection (c) of this section— knowingly and without lawful authority produces an identification document, authentication feature, or a false identification document; knowingly transfers an identification document, authentication feature, or a false identification document knowing that such document or feature was stolen or produced without lawful authority; knowingly possesses with intent to use unlawfully or transfer unlawfully five or more identification documents (other than those issued lawfully for the use of the possessor), authentication features, or false identification documents; knowingly possesses an identification document (other than one issued lawfully for the use of the possessor), authentication feature, or a false identification document, with the intent such document or feature be used to defraud the United States; knowingly produces, transfers, or possesses a document-making implement or authentication feature with the intent such document-making implement or authentication feature will be used in the production of a false identification document or another document-making implement or authentication feature which will…
Official text (excerpt) · last checked 2026-09-16 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 1,360 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):United States v. Christensen (2016) affirmed Section 1028(a)(7) identity-theft convictions after the CFAA predicates were set aside, holding intent to violate California Penal Code 502 was a valid alternative predicate. United States v. Campa (2008) upheld a 1028(a)(3) conviction on constructive possession of counterfeit documents.
Opinions citing this section in our collection:
- Flores-Figueroa v. United States (Supreme Court of the United States 2009, 556 U.S. 646)“…tion documents, authentica tion features, and information.” 18 U. S. C. §1028. The title of another provision (the pro…”
- United States v. George Lloyd Pregent (Court of Appeals for the Fourth Circuit 1999, 190 F.3d 279)“…zed United States identification documents in violation of 18 U.S.C.A. § 1028 (a)(1) (West Supp.1999), knowingly prod…”
- United States v. Lesmarge Valnor (Court of Appeals for the Eleventh Circuit 2006, 451 F.3d 744)✓Valnor charged $400 to $500 a head to have a Florida DMV examiner issue fraudulent driver's licenses; the Eleventh Circuit affirmed a sentence above the advisory range for his Section 1028(f) conspiracy, noting it fell far below Section 1028(b)(1)(A)'s 15-year maximum.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Identity Theft Laws: Federal Rules and State Penalties, Indiana Identity Theft Laws, Phishing, Smishing and Vishing: Spot Them and What to Do If You Clicked
Code of Federal Regulations Title 12
§ 1005.2Definitions.In forcecited in 9 of our articles
Except as otherwise provided in subpart B, for purposes of this part, the following definitions apply: (a)(1) “Access device” means a card, code, or other means of access to a consumer's account, or any combination thereof, that may be used by the consumer to initiate electronic fund transfers. (2) An access device becomes an “accepted access device” when the consumer: (i) Requests and receives, or signs, or uses (or authorizes another to use) the access device to transfer money between accounts or to obtain money, property, or services; (ii) Requests validation of an access device issued on an unsolicited basis; or (iii) Receives an access device in renewal of, or in substitution for, an accepted access device from either the financial institution that initially issued the device or a successor. (b)(1) “Account” means a demand deposit (checking), savings, or other consumer asset account (other than an occasional or incidental credit balance in a credit plan) held directly or indirectly by a financial institution and established primarily for personal, family, or household purposes.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 25 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts apply the § 1005.2 definitions to decide whether an account falls under the EFTA. In Yagoub Mohamed v. Bank of America (2024), the Fourth Circuit held pandemic benefits on a bank-issued prepaid card sat in a government benefit account; Brown v. Stored Value Cards (2020) found 'account' plausibly reached a jail release card.
Opinions citing this section in our collection:
- Danica Brown v. Stored Value Cards, Inc. (Court of Appeals for the Ninth Circuit 2020, 953 F.3d 567)“…ndants note that the regulation implementing section 1693i, 12 C.F.R. § 1005.2, was amended recently to state that “[t…”
- Yagoub Mohamed v. Bank of America, N.A. (Court of Appeals for the Fourth Circuit 2024, 93 F.4th 205)“…tions” further defining “account” are published at 12 C.F.R. § 1005.2(b)(1). Those provisions are contained i…”
- Warner v. Tinder Inc. (District Court, C.D. California 2015, 105 F. Supp. 3d 1083)“…d in advance to recur at substantially regular intervals.” 12 C.F.R. § 1005.2 (k). “Written authorization” from the c…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How to Get Money Back After a Scam: Your Rights by Payment Method, Zelle, Venmo, Cash App and PayPal Scams: Can You Get Money Back?, Tech Support Scams and Fake Invoices: Geek Squad, McAfee, PayPal
§ 1005.6Liability of consumer for unauthorized transfers.In forcecited in 6 of our articles
(a) Conditions for liability. A consumer may be held liable, within the limitations described in paragraph (b) of this section, for an unauthorized electronic fund transfer involving the consumer's account only if the financial institution has provided the disclosures required by § 1005.7(b)(1), (2), and (3). If the unauthorized transfer involved an access device, it must be an accepted access device and the financial institution must have provided a means to identify the consumer to whom it was issued. (b) Limitations on amount of liability. A consumer's liability for an unauthorized electronic fund transfer or a series of related unauthorized transfers shall be determined as follows: (1) Timely notice given. If the consumer notifies the financial institution within two business days after learning of the loss or theft of the access device, the consumer's liability shall not exceed the lesser of $50 or the amount of unauthorized transfers that occur before notice to the financial institution. (2) Timely notice not given.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 7 court opinions in our collectionLatest citing opinion in our collection: 2024
In the courts (editorial summary, independently checked):In Widjaja v. JPMorgan Chase Bank (2021), the Ninth Circuit applied the 60-day rule reflected in § 1005.6(b)(3): late reporters owe later transfers only if the bank shows the delay caused them, but a suing consumer must plead facts they would have occurred anyway. Trang v. JPMorgan Chase Bank (2023) dismissed such claims on that basis.
Opinions citing this section in our collection:
- Margaretha Widjaja v. Jpmorgan Chase Bank, N.A. (Court of Appeals for the Ninth Circuit 2021, 21 F.4th 579)“…A ordinarily requires. See 15 U.S.C. §§ 1693f(a), 1693g(a); 12 C.F.R. § 1005.6(b)(3). 1 In June 2019, Widjaja fil…”
- Nelipa v. TD Bank, N.A. (District Court, E.D. New York 2024)“…ed electronic fund transfer[s].” 15 U.S.C. § 1693f(f)(1); 12 C.F.R. § 1005.6. The term “unauthorized electronic fund…”
- Trang v. JPMorgan Chase Bank, N.A. (District Court, D. Oregon 2023)“…rs occurring outside the 60-day period.” Id. at 583 (citing 12 C.F.R. § 1005.6(b)(3); 12 C.F.R. pt. 1005, Supp. I, 6(b…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: I Got Scammed: What to Do, How to Get Money Back, Where to Report, Bank Refused Your Scam Refund? How to Challenge a Fraud Claim Denial
§ 1005.11Procedures for resolving errors.In forcecited in 9 of our articles
(a) Definition of error —(1) Types of transfers or inquiries covered. The term “error” means: (i) An unauthorized electronic fund transfer; (ii) An incorrect electronic fund transfer to or from the consumer's account; (iii) The omission of an electronic fund transfer from a periodic statement; (iv) A computational or bookkeeping error made by the financial institution relating to an electronic fund transfer; (v) The consumer's receipt of an incorrect amount of money from an electronic terminal; (vi) An electronic fund transfer not identified in accordance with § 1005.9 or § 1005.10(a); or (vii) The consumer's request for documentation required by § 1005.9 or § 1005.10(a) or for additional information or clarification concerning an electronic fund transfer, including a request the consumer makes to determine whether an error exists under paragraphs (a)(1)(i) through (vi) of this section. (2) Types of inquiries not covered. The term “error” does not include: (i) A routine inquiry about the consumer's account balance; (ii) A request for information for tax or other recordkeeping purposes; or (iii) A request for duplicate copies of documentation.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 23 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Machinski (District Court, D. Utah 2026)“…entified by the financial institution or the consumer. See 12 C.F.R. § 1005.11. Regulation E provides a closed list of…”
- Sundahl (District Court, S.D. California 2026)“…notice requirements.” Id.; see 15 U.S.C. 20 § 1693f(a); 12 C.F.R. § 1005.11(b).…”
- Hubbard v. Chime Financial, Inc. (District Court, S.D. Ohio 2025)“…had failed to allege “which investigatory obligation under 12 C.F.R. § 1005.11(c) Huntington violated.” Lumbus, 2025 W…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Where to Report a Scam: Which Agency, and Can You Get Money Back?, Can I Sue a Scammer? When a Lawyer Actually Helps After a Scam
§ 1026.12Special credit card provisions.In forcecited in 6 of our articles
(a) Issuance of credit cards. Regardless of the purpose for which a credit card is to be used, including business, commercial, or agricultural use, no credit card shall be issued to any person except: (1) In response to an oral or written request or application for the card; or (2) As a renewal of, or substitute for, an accepted credit card. (b) Liability of cardholder for unauthorized use —(1)(i) Definition of unauthorized use. For purposes of this section, the term “unauthorized use” means the use of a credit card by a person, other than the cardholder, who does not have actual, implied, or apparent authority for such use, and from which the cardholder receives no benefit. (ii) Limitation on amount. The liability of a cardholder for unauthorized use of a credit card shall not exceed the lesser of $50 or the amount of money, property, labor, or services obtained by the unauthorized use before notification to the card issuer under paragraph (b)(3) of this section. (2) Conditions of liability.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 12 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Strubel v. Comenity Bank (Court of Appeals for the Second Circuit 2016, 842 F.3d 181)“…extension of credit.” The official staff interpretation of 12 C.F.R. § 1026.12(c)(1), the portion of Regulation Z impl…”
- William Krieger v. Bank of America NA (Court of Appeals for the Third Circuit 2018, 890 F.3d 429)“…he cardholder previously the “maximum potential liability,” 12 C.F.R. § 1026.12(b)(2)(ii), and a means by which the car…”
- William Lyons v. PNC Bank, N.A. (Court of Appeals for the Fourth Circuit 2024)“…e cardholder held on deposit with the card issuer. 12 C.F.R. § 1026.12(d)(1). 2 In January 200…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Code of Federal Regulations Title 47
§ 64.2010Safeguards on the disclosure of customer proprietary network information.In force
(a) Safeguarding CPNI. Telecommunications carriers must take reasonable measures to discover and protect against attempts to gain unauthorized access to CPNI. Telecommunications carriers must properly authenticate a customer prior to disclosing CPNI based on customer-initiated telephone contact, online account access, or an in-store visit. (b) Telephone access to CPNI. Telecommunications carriers may only disclose call detail information over the telephone, based on customer-initiated telephone contact, if the customer first provides the carrier with a password, as described in paragraph (e) of this section, that is not prompted by the carrier asking for readily available biographical information, or account information. If the customer does not provide a password, the telecommunications carrier may only disclose call detail information by sending it to the customer's address of record, or by calling the customer at the telephone number of record.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 7 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- AT&T v. FCC (Court of Appeals for the Fifth Circuit 2025)“…tect against attempts to gain unauthorized access to CPNI,” 47 C.F.R. § 64.2010(a), and they may use or disclose CPNI o…”
- Sprint Corporation v. FCC (Court of Appeals for the D.C. Circuit 2025)“…to protect CLI from unauthorized access by third parties. 47 C.F.R. § 64.2010(a). This case concerns whether tw…”
- Michael Terpin v. at and T Mobility LLC (Court of Appeals for the Ninth Circuit 2024, 118 F.4th 1102)“…tect against attempts to gain unauthorized access to CPNI.” 47 C.F.R. § 64.2010(a) (emphasis added). Permitting “access…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
§ 52.37Number Portability Requirements for Wireless Providers.In force
(a) Applicability. This section applies to all providers of commercial mobile radio service (CMRS), as defined in 47 CFR 20.3, including resellers of wireless service. (b) Authentication of port-out requests. A CMRS provider shall use secure methods to authenticate a customer that are reasonably designed to confirm the customer's identity before effectuating a port-out request, except to the extent otherwise required by 47 U.S.C. 345 (Safe Connections Act of 2022) or Part 64 Subpart II of this chapter. A CMRS provider shall regularly, but not less than annually, review and, as necessary, update its customer authentication methods to ensure that its authentication methods continue to be secure. (c)-(e) [Reserved] (f) Employee Training. A CMRS provider shall develop and implement training for employees to specifically address fraudulent port-out attempts, complaints, and remediation. Training shall include, at a minimum, how to identify fraudulent requests, how to recognize when a customer may be the victim of fraud, and how to direct potential victims and individuals making potentially fraudulent requests to employees specifically trained to handle such incidents.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- FTC, What To Know About Identity Theft (September 2024)(consumer.ftc.gov).gov
- 15 U.S.C. § 1681c-1, Identity theft prevention; fraud alerts and active duty alerts (security freeze)(law.cornell.edu)
- CFPB, Electronic Fund Transfers FAQs (Regulation E compliance aid)(consumerfinance.gov).gov
- IRS, Get an Identity Protection PIN (page reviewed August 4, 2026)(irs.gov).gov
- FCC, Protecting Consumers from SIM Swap and Port-Out Fraud, Report and Order, FCC 23-95 (adopted November 15, 2023)(docs.fcc.gov).gov
- FTC, What To Do if You Were Scammed (June 2026)(consumer.ftc.gov).gov
- 18 U.S.C. § 1028, Fraud and related activity in connection with identification documents and information(law.cornell.edu)
- 15 U.S.C. § 1681c-2, Block of information resulting from identity theft(law.cornell.edu)
- Electronic Code of Federal Regulations, 12 C.F.R. Part 1005 (Regulation E), §§ 1005.6 and 1005.11 and Supplement I (Official Interpretations)(ecfr.gov).gov
- Electronic Code of Federal Regulations, 12 C.F.R. § 1026.12, Special credit card provisions (Regulation Z)(ecfr.gov).gov
- Electronic Code of Federal Regulations, 47 C.F.R. § 64.2010, Safeguards on the disclosure of customer proprietary network information(ecfr.gov).gov
- FTC, Credit Freezes and Fraud Alerts (August 2025)(consumer.ftc.gov).gov
- CFPB, Consumer reporting companies list: ChexSystems (last modified January 30, 2025)(consumerfinance.gov).gov
- Social Security Administration, Protect Yourself from Social Security Scams(ssa.gov).gov
- Social Security Administration, FAQ: Can I change my Social Security number? (October 7, 2022)(ssa.gov).gov
- FTC Consumer Alert, SIM Swap Scams: How to Protect Yourself (October 23, 2019)(consumer.ftc.gov).gov
- FCC Wireline Competition Bureau, Order DA 24-649 (July 5, 2024), waiving compliance with SIM swap and port-out rules(docs.fcc.gov).gov
- Electronic Code of Federal Regulations, 47 C.F.R. § 52.37, Number portability requirements for wireless providers(ecfr.gov).gov
- FTC, Free Credit Reports (June 2026)(consumer.ftc.gov).gov
- FTC, How To Recover Your Hacked Email or Social Media Account (August 2023)(consumer.ftc.gov).gov