Phil's List

Connecting Union County

Resources • Events • Ways to Help • Community Updates

Your Information May Already Be on the Dark Web. Here’s What You Can Actually Do.

Every few months, it seems like another company announces a data breach. Names, addresses, passwords, Social Security numbers and other personal information may already be circulating online.

That raises an unsettling question:

If my information is already out there, what can I possibly do about it?

The answer is: quite a lot.

You probably cannot retrieve every copy of information that has already been stolen or sold. And no company can guarantee that it will somehow “erase you from the dark web.”

A more useful goal is to make stolen information much harder for a criminal to use.

Here are some of the most important steps you can take. Most are completely free.

1. Freeze your credit

If you do only one thing after reading this article, consider making it this one.

A credit freeze prevents most lenders from accessing your credit report. Since lenders normally check your credit before opening an account, a thief who has your name, birth date and Social Security number will have a much harder time opening a new credit card or loan in your name.

You need to place a freeze separately with:

  • Equifax
  • Experian
  • TransUnion

According to the Federal Trade Commission, credit freezes are free, they don’t lower your credit score, and they remain in place until you decide to lift them. The FTC’s page includes links to all three credit bureaus.

When you legitimately need new credit—for example, when buying a car—you can temporarily lift the freeze and put it back afterward.

Official information: Federal Trade Commission — Credit Freezes and Fraud Alerts

2. Protect your email account especially well

Your email account deserves stronger protection than almost anything else you use online.

Why?

Think about how many websites have a “Forgot password?” button. If someone controls your email, they may be able to reset passwords to your other accounts.

Use a password that you do not use anywhere else.

Then turn on multifactor authentication (MFA).

When available, a passkey or security key provides particularly strong protection. An authenticator app is another good choice. Text-message verification is still better than having no second factor at all, although stronger methods are preferable when available.

And never approve a login request you didn’t initiate.

3. Stop reusing passwords

One compromised website shouldn’t give a criminal the password to five other accounts.

Every important account should have its own password.

You don’t have to memorize dozens of complicated passwords. A reputable password manager—or the password management system built into your phone or computer—can create and remember them for you. CISA’s password guidance explains how long, random and unique passwords help protect your accounts.

Prioritize:

  • Email
  • Banking and investments
  • Social Security
  • IRS
  • Credit cards
  • Apple, Google or Microsoft accounts
  • Shopping sites that store payment information

4. Turn on alerts for your financial accounts

A credit freeze helps prevent someone from opening new credit in your name.

It doesn’t stop a criminal who manages to gain access to an account you already have.

Check your bank and credit-card apps for alerts such as:

  • Purchases
  • Withdrawals
  • Transfers
  • Password changes
  • New payees
  • Changes to contact information
  • Logins from unfamiliar devices

You may discover fraud much faster from a phone notification than from your monthly statement.

5. Consider getting an IRS Identity Protection PIN

This is a particularly useful free protection that many people don’t know exists.

An IRS Identity Protection PIN (IP PIN) is a six-digit number known to you and the IRS. It helps prevent someone from using your Social Security number to file a fraudulent federal tax return.

The IRS says anyone with a Social Security number or Individual Taxpayer Identification Number who can verify their identity can request one.

The IRS issues a new IP PIN each year.

Official information: IRS — Get an Identity Protection PIN

6. Create and periodically check your Social Security account

The Social Security Administration recommends creating a personal my Social Security account and reviewing your records for suspicious activity.

Check that your earnings history looks correct and, if you’re receiving benefits, pay attention to unexpected changes to your payment or account information.

Social Security also offers additional security blocks in some situations, including protections against unauthorized changes to direct deposit information.

Never trust an unexpected caller, text or email simply because the person claims to be from Social Security.

7. Look at your credit reports

You can review your credit reports from Equifax, Experian and TransUnion free every week through AnnualCreditReport.com.

Look for:

  • Accounts you don’t recognize
  • Addresses that aren’t yours
  • Loans you didn’t request
  • Credit inquiries you don’t recognize

A credit freeze helps prevent future problems. Reviewing your reports helps you discover problems that may already have happened.

8. If identity theft actually happens, use IdentityTheft.gov

Don’t try to figure everything out yourself.

IdentityTheft.gov is the Federal Trade Commission’s official identity-theft recovery site.

Tell it what happened and it can provide a recovery plan based on the type of theft involved.

That’s very different from a commercial company trying to sell you identity-theft protection.

What about getting my information removed from data brokers?

This can still be worthwhile.

People-search websites may display surprisingly detailed information, including your address, age, telephone number, relatives and previous addresses.

The Federal Trade Commission says most people-search sites provide a way to opt out. You can do this yourself for free or pay a service to do it for you.

But understand what you’re accomplishing.

You’re making your information less readily available, not retrieving every copy that has ever existed.

Information can also reappear later, especially when public records change.

So data-broker removal is useful, but it should come after the basic security steps above, not instead of them.

The most important idea

Try not to think:

“How can I make sure nobody has my information?”

In today’s world, that may be impossible.

A better question is:

“If somebody already has some of my information, how can I keep them from using it?”

Freeze your credit. Protect your email. Use different passwords. Turn on multifactor authentication. Watch your financial accounts. Protect your tax and Social Security identities.

You may not be able to put your personal information back in the bottle.

But you can make it considerably less useful to the person who shouldn’t have it.


Helpful official resources

Phil’s List provides informational resources and does not endorse paid identity-protection or data-removal services. Be especially cautious of companies that promise they can completely remove your personal information from the internet or “dark web.”

Comments

Leave a Reply

Discover more from Phil's List

Subscribe now to keep reading and get access to the full archive.

Continue reading