The Risk That Isn’t on Anyone’s List
Ask Americans what worries them financially and you’ll get a predictable list: inflation, housing costs, a possible recession, medical bills, interest rates. All reasonable concerns. But one of the largest and fastest-growing threats to household wealth almost never makes that list.
In a recent client education webinar we hosted with Prudential, a regional vice president for sales, technology, and advanced planning made the case that identity fraud deserves a seat at that table. His framing: in any given year, there’s roughly a 15% chance the U.S. enters a recession — the thing that dominates headlines and keeps people up at night. Meanwhile, about a third of Americans have already experienced identity theft, more than nine million fall victim each year, and the problem is compounding at about 13% annually. He called it the hidden risk.
Your Social Security number is almost certainly already out there. The 2017 Equifax breach exposed roughly 145 million Americans’ core identifying data. Last year’s National Public Data breach exposed another 272 million people and, by some counts, 2.9 billion Social Security numbers. Between the two, the working assumption should be that your number is in circulation. Individual data points sell for a few dollars on the dark web.
The encouraging part: most of the exposure is behavioral. Only about a quarter of fraud losses stem from criminals using stolen data in ways you can’t control. The other three quarters trace back to things like clicking a suspicious text, responding to a convincing email, or oversharing details on social media that happen to double as password reset answers — a pet’s name, a graduation year, an anniversary date. Two or three of those, and someone effectively has your password.
The presentation organized defenses into three buckets:
Know. Not all fraud is high-tech — mail theft is still a significant vector, so a shredder and a visit to optoutprescreen.com go a long way. Check haveibeenpwned.com to see which of your accounts have already appeared in known breaches. Recognize the current wave of text-message scams (fake unpaid toll notices, fake shipping alerts), and audit which apps on your phone are tracking your location.
Monitor. Be deliberate about what you post publicly. Verify that people you meet online are who they claim to be — money sent voluntarily in a romance scam is generally unrecoverable. Treat urgency as a red flag: the grandchild in trouble overseas, the IRS threatening jail, the FBI on the line. Hang up and call back through a number you looked up yourself. And pull your credit report from annualcreditreport.com, the only federally authorized source.
Do. Passwords need secrecy, complexity, and variety — a reputable password manager solves the variety problem, provided the master password is genuinely strong. Turn on multi-factor authentication everywhere it’s offered, especially on the accounts that unlock everything else: your Apple or Microsoft account, your email, your financial accounts, your cell phone carrier. Consider a credit monitoring or identity theft protection service. Create accounts at ssa.gov and irs.gov so you’d notice if someone else filed on your behalf.
The single most effective step may be freezing your credit. Freezes are free at all three bureaus, and you can schedule a temporary thaw — open the window for 48 hours to finance a car, then let it close automatically. No one can open credit in your name while it’s frozen.
The recommendation the presenter closed on: every household should maintain six online accounts. One at each of the three credit bureaus, one at the Social Security Administration, one at the IRS, and one identity theft monitoring service. Combine that with good password habits and healthy skepticism, and you become a hardened target — which is often enough for a bad actor to move on to someone easier.
There’s no silver bullet here. But there’s a meaningful difference between being a soft target and a hard one, and most of it is within your control.