24 Jul Protect Your Identity – 14 Cybersecurity Tips
Your Social Security number, mother’s maiden name, hometown, and elementary school are almost certainly for sale somewhere on the internet right now. Data breaches at banks, retailers, healthcare providers, and government agencies have exposed this information for nearly every American at least once, and often several times over.
You can’t undo that. What you can do is assume this information is public, then make it hard enough for a thief to actually use that information to open an account, file a fraudulent tax return, or take over your phone number that they give up and move on to an easier target. Most identity theft is a numbers game: criminals go after whoever has the fewest protections in place.
The list below covers fourteen steps. None takes more than fifteen minutes, and most are free. I’ll admit to you that these are aggressive steps that will make it more difficult for you to get credit for yourself in the future as well. Find the line between increasing the pain-in-the-butt factor in your life and protecting your credit that works for you.
- Get an IRS Identity Protection PIN
- This is a six-digit number the IRS requires on your return in addition to your Social Security number. Without it, a thief who has your SSN still cannot file a fraudulent return in your name and collect your refund, which is one of the most common forms of tax-related identity theft.
- Apply for the PIN at the link below. It’s good for the calendar year, so you’ll need a new one each year. Learn more and apply here.
- Share the PIN only with your tax preparer, and only once your return is ready to file. Tell your preparer not to store the PIN or your bank account and routing numbers in their software before or after filing, since a breach at their office would then expose that information too.
- If you’ve already filed this year, you can wait until January. Better yet, get the PIN now so you don’t forget, then log back in each January for that year’s new one.
- Freeze Your Credit
- A credit freeze blocks lenders from pulling your credit report, which means a thief with your SSN and other details still cannot open a new credit card, auto loan, or line of credit in your name. It doesn’t affect your existing accounts or your credit score, and you can lift it temporarily any time you need to apply for credit yourself.
- You need to freeze at all three bureaus separately, since a lender can pull from any one of them: Equifax, Experian, and TransUnion. More info: https://www.sfchronicle.com/personal-finance/article/freeze-credit-prevent-identity-theft-20011780.php
- Freeze Your ChexSystems Account
- ChexSystems is what banks check before opening a checking or savings account, similar to how lenders check credit bureaus before issuing credit. Freezing it prevents someone from opening a new bank account in your name, even though it’s a separate system from the three credit bureaus above and easy to overlook.
- Place a ChexSystems Security Freeze. To register: https://chexsystems.eto.fiscloudservices.com/#/registration, then use the Security Freeze link at the top of the page.
- Enable Two-Factor Authentication
- Two-factor authentication means a password alone isn’t enough to log in; you also need a code from your phone or an app. This stops a thief who has guessed or stolen your password from actually getting into the account.
- Where the option exists, use an authenticator app such as Authy rather than text messages, since text messages can be intercepted if your phone number is hijacked (see item 6). Email is the most important account to lock down. If someone gets into your email, they can reset the passwords on your bank, brokerage, and credit card accounts from there, so email is effectively the front door to your entire financial life.
- Add Security to Your Schwab Accounts
- Standard login credentials aren’t enough protection for a brokerage account holding significant assets. A verbal password adds a spoken code word that Schwab requires before discussing your account or making changes over the phone, which stops a thief who has your basic identifying details from calling in and impersonating you.
- Call Schwab Alliance at 800-515-2157 and ask them to add a verbal password to all of your accounts. Also ask them to disable the “Your Voice is Your Password” feature, since voice authentication can potentially be spoofed with AI-generated audio. If you’re still using text messaging for two-factor authentication, ask Schwab Alliance for help switching to the Symantec VIP authentication app for the reason described in item 4.
- Lock Down Your Cell Phone
- “SIM swapping” is when a thief convinces your carrier to transfer your phone number to a device they control. Once they have your number, they can intercept text-message verification codes and reset passwords on your other accounts. A port protection code (also called a PIN or passcode) is a password your carrier must ask for before making any changes to your account, which blocks this attack.
- Contact your cellphone provider directly to set this up. Many require this, and you may already have one.
- Check Your Bank and Credit Card Transactions Mid-Month
- Fraudulent charges are usually easiest to reverse in the first few days after they happen. Waiting for your monthly statement can mean two or three weeks pass before you even notice a problem, which narrows your window to dispute it.
- Log on to your banks’ websites or apps mid-month to review recent transactions rather than waiting for the statement to arrive.
- Pro Tip: Choose one “money day” each month and make that the day you log in to review your various bank accounts and statements.
- Turn Off Listening Features on Your Devices
- Voice assistants like Siri and Echo are designed to listen for an awake word, but they’ve been known to activate and record unintentionally. Assume they’re listening at all times. https://www.cnet.com/home/security/amazon-is-canceling-this-alexa-privacy-feature-on-march-28-should-you-worry/
- On iPhones, an orange dot at the top of the screen means an app is currently using your microphone. Close the app if you’re not using it.
- Check If Your Data Has Been Exposed
- “Have I Been Pwned” is a free tool that checks whether your email address appeared in a known data breach, and if so, which company and what kind of information (passwords, addresses, etc.) was exposed.
- Check every email address you use. Change passwords on any sites that were breached, and change similar passwords elsewhere too, since reused passwords are one of the most common ways a single breach snowballs into multiple compromised accounts. https://haveibeenpwned.com/
- Back Up Your Data in Three Places
- The standard rule of thumb is three copies of your data, on two different types of storage, with one copy off-site. This protects you not just from theft but from ransomware, hardware failure, fire, or flood. It’s a project to set up, but worth it given what’s at stake if you lose everything with no backup.
- This article is from a backup company; it has many competitors, so you have plenty of choices, including iCloud and OneDrive. https://www.backblaze.com/blog/the-3-2-1-backup-strategy/?utm_source=chatgpt.com
- Opt Out of Data Broker Sites
- People-search and data broker sites (Spokeo, Whitepages, BeenVerified, MyLife, and similar) compile your name, address, age, relatives, and property records from public sources and sell them to anyone who pays, including scammers building a profile to impersonate you or target you with a convincing phishing attempt. Removing your listings closes off that source.
- New listings tend to reappear as these sites re-scrape public records, so this is worth repeating at least once a year rather than treating it as a one-time task.
- California Residents: Use the DROP Platform
- Opting out of data broker sites individually can mean contacting dozens of companies separately. Starting August 1, 2026, California’s Delete Request and Opt-out Platform (DROP) at privacy.ca.gov/drop lets you submit a single request that instructs all data brokers registered in the state to delete your personal information at once.
- Set Up a My Social Security Account
- If you never create an online Social Security account, that leaves the door open for a thief to create one in your name first and potentially redirect your benefits. Setting up your own account at ssa.gov closes that gap and also lets you monitor your earnings record for errors or fraudulent activity.
- Watch for Mail Theft
- Stolen mail is a common source of new account fraud, since checks, new credit cards, and tax documents all contain enough information to open accounts or commit fraud. USPS Informed Delivery (informeddelivery.usps.com) emails you scanned images of your mail before it’s delivered each day, so you know what to expect and can quickly notice if something goes missing.
Information is provided for informational purposes only and should not be relied upon in any manner as professional advice, or an endorsement of any practices, products, or services. There can be no guarantees or assurances that the views expressed here will be applicable for any particular facts or circumstances and should not be relied upon in any manner. You should consult your own advisers as to legal, business, tax, and other related matters concerning any investment.
The commentary in this post (including any related blog, podcasts, videos, and social media) reflects the personal opinions, viewpoints, and analyses of Angela Wright, an Investment Adviser Representative of Gemmer Asset Management LLC (“GAM”) and should not be regarded as the views of GAM, or a description of advisory services provided by GAM or performance returns of any GAM client. References to securities or market-related performance data are for illustrative purposes only and do not constitute an investment recommendation or offer to provide investment advisory services. Charts and graphs provided within are for informational purposes solely and should not be relied upon when making any investment decision. Past performance is not indicative of future results. The content speaks only as of the date indicated. Any projections, estimates, forecasts, targets, prospects, and/or opinions expressed in these materials are subject to change without notice and may differ or be contrary to opinions expressed by others.
The information presented herein may contain links to third party websites with which we have no affiliation. A link to any third-party website does not mean that we endorse it, or the quality or accuracy of the information presented on it.