Global information guide

Identity Theft Glossary: Key Terms Explained

A concise glossary of common identity theft and fraud terms with practical context. Learn what each term means and how to use the definitions to assess risk and respond if your information is exposed.

Local context: Credit reporting, consumer rights, record-retention periods, score displays, lending decisions, products, taxes, and consumer protections vary by country and provider. This content is general information, not legal, financial, tax, debt, credit, insurance, investment, or personalised advice. Check the process and terms that apply where you live.

Core definitions you should know

Identity theft refers to the act of taking another person’s personal information—such as name, date of birth, account numbers, or identification details—with the intent to impersonate or misuse that identity. Identity fraud describes the criminal use of that stolen information to obtain money, goods, services, or benefits in the victim’s name. Related terms include data breach (unauthorised access or disclosure of sensitive data), phishing (fraudulent communications designed to trick people into revealing information), and account takeover (unauthorised control of an existing account).

This section also covers less obvious concepts such as synthetic identity, where fragments of real and fabricated data are combined to form a new identity used in fraud, and social engineering, which describes manipulative tactics used to extract information. Understanding these distinctions helps when reading reports, reviewing account notices, and communicating with service providers or advisors. The glossary focuses on clear, practical meanings rather than technical or jurisdiction-specific terminology.

How criminals obtain and misuse data

Fraudsters obtain personal information in many ways. Common sources include data breaches at organisations, phishing and smishing (fraud via email or text), malware and credential-stealing tools, physical theft of documents or cards, and illicit markets where stolen data is bought and sold. Some attackers use skimming devices or intercept mail and parcels; others create convincing impersonations by collecting small details from social media and public records.

Knowing these channels helps you prioritise protections. For example, reducing unnecessary sharing of personal details online, treating unsolicited messages with caution, and keeping paper records secure can lower exposure. The glossary explains technical terms such as encryption, tokenisation, and the so-called dark web in accessible language so you can better evaluate alerts, news reports, and service notifications without needing specialist knowledge.

Practical steps to respond and reduce risk

If you suspect your identity has been misused, start by documenting what you observed: unusual account activity, unexpected bills or notices, or communications about accounts you did not open. Secure or freeze affected accounts where possible, change passwords and enable multi-factor authentication on critical accounts, and contact organisations that hold the compromised accounts to report irregularities. Keep careful notes of dates, names, and reference numbers for future follow-up.

Longer-term actions can include monitoring your credit and account statements, considering a fraud alert or account freeze where those options exist, and seeking guidance from consumer assistance services or legal advisors as needed. Processes and timelines vary by provider and location, so expect to follow up periodically and retain copies of all communications. Use the glossary to translate any unfamiliar terms you encounter during recovery so you can make informed choices about next steps.

A practical next step

Review the glossary to familiarise yourself with key terms, then consider compiling a personal checklist of accounts and documents to monitor and protect.