# What is Identity theft?

> Using someone's personal information to impersonate them, usually for financial gain.

Last reviewed: 2026-09-01

## Identity theft

Category: Attacks

Canonical page: https://moolkey.com/glossary/identity-theft

Identity theft is the use of personal details such as your name, date of birth, address, or government ID number to impersonate you. The goal is often to open credit or access an existing account. A compromised email or financial account can expose much of the information an impersonator needs.

### How password security connects to it

An email account is a dossier. It holds statements, delivery addresses, tax documents, and the reset links for everything else. A single reused password that leaks in an unrelated breach can therefore open a path to a full identity profile, which is why email deserves your strongest password and second factor.

### What to do first if it happens

Regain and secure the email account before anything else because it controls the recovery of other accounts. Then contact affected financial institutions, place a fraud alert or credit freeze where that is available in your country, and document each step. Most remediation processes require a paper trail.

### Sources

- [CISA: Secure Our World](https://www.cisa.gov/secure-our-world): Public guidance for recognizing phishing and protecting high-value accounts.
- [OWASP: Credential Stuffing Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Credential_Stuffing_Prevention_Cheat_Sheet.html): How password reuse is replayed at scale and how services can limit the damage.
- [NIST: Computer Security Resource Center glossary](https://csrc.nist.gov/glossary): Canonical terminology used across US computer security guidance.
