Learn
Identity theft: when someone becomes you
Your identity documents and logins are the keys to your money — and someone who collects enough of them can simply be you: running up charges, taking over accounts, applying for credit in your name. After years of large data breaches, the safer starting assumption is that some of your details are already out there. This page covers what identity theft looks like, what a breach letter from a company actually means, the everyday locks that make stolen details less useful, and the first moves if it happens to you.
What identity theft looks like
Identity theft happens when someone uses your personal information to pretend to be you — Moneysmart's definition, word for word. The value isn't the documents themselves; it's what they unlock. With enough of your details a stranger can get into your bank and government accounts — Centrelink, Medicare, myGov — run up charges, and even move assets: Moneysmart notes rising reports of shares being transferred or sold without the owner ever knowing.
The close cousin is the account takeover — a scammer getting control of an account you already hold, described on Scamwatch's account and identity takeover page. Once in, they can read your personal information, change your passwords and lock you out of your own system. The ways in are mundane: hacking a device, malware riding on a dodgy download, someone posing as tech support to get remote access — or phone porting, where a scammer moves your mobile number onto their own SIM so your security codes arrive on their phone instead of yours.
Because the theft happens quietly, the tell is usually a ripple somewhere else in your life. Moneysmart's warning signs are worth memorising as a pattern: money moves you didn't make, mail that stops arriving or arrives about products you never asked for, contact about services you don't recognise. Scamwatch adds the takeover versions — suddenly being unable to log in to an account, a payment you were expecting that never lands, a phone that unexpectedly loses service. None of these proves identity theft on its own; any of them is a reason to look harder, immediately.
Data breaches: when a company loses your details
Most people don't hand their details to a thief — a company they trusted does it for them. A data breach, in the OAIC's definition, happens when personal information is accessed, disclosed without authorisation or is lost. That's the privacy regulator's deliberately wide net: a hacked database and a misplaced file are both breaches, because either way, details that were supposed to stay locked up no longer are.
Australia runs a Notifiable Data Breaches scheme, and its shape is simple: you must be told if a data breach is likely to cause you serious harm. So a breach letter or email isn't a courtesy — it's an obligation being discharged, and it means someone has already judged the risk to you as real rather than theoretical. Treat the letter as a fire alarm, not a formality: read exactly which of your details were exposed, because that tells you which doors now need new locks.
What a notification does not mean is that you've already been robbed. Exposed details are keys copied, not money taken — the harm arrives later, if at all, when someone tries to use them. That's why the OAIC's advice runs in two directions at once: act quickly on the practical side, and mind the human side too. Its breach support page says plainly that if a data breach causes you distress, reach out to family, friends or a support service — and it lists counselling services alongside the identity-recovery ones.
Locking the doors
If some of your details are already loose, the job is to make them less useful. The first two locks guard your logins. A strong, unique password for every account matters because scammers, per Scamwatch, actively exploit weak passwords — and Moneysmart points to the Australian Cyber Security Centre's tips on building a strong password or passphrase, a string of words that's long for a computer but easy for you. The second lock is multi-factor authentication, which in Moneysmart's words adds a second check when you log in — a code from a text message or an app — so a stolen password on its own stops being enough.
The next set guards the raw material. Be stingy with identity documents and personal details: Moneysmart's prevention list runs from shredding documents and securing your mail to being careful what you share on social media, keeping security software current, treating public computers with caution and not clicking hyperlinks in messages — and Scamwatch adds avoiding public wi-fi for sensitive transactions. Every detail you don't scatter is one a thief has to work harder to collect. Moneysmart's online safety hub gathers the wider set — spotting scams, scam websites, safe online shopping — and its standing instruction is to report every scam you meet to Scamwatch.
The last lock is a tripwire. Your credit report — the file lenders check when you apply to borrow — is where identity theft often surfaces first, because a loan taken out in your name lands there. Moneysmart's advice is to find out how to get a free copy and check it for debts, loans or credit applications you don't recognise; if you suspect fraud, you can request a temporary ban on your report, which jams new credit applications while you sort things out. How the report and the scores built from it work is its own topic — Credit scores walks through it.
If it happens: the first moves
Speed is the whole game, because every hour of access is more damage. The first call is to your bank and card providers: Scamwatch's report-a-scam page puts it as an instruction — contact your bank or credit card provider now and tell them to stop any transactions. Moneysmart's version is the same move: contact your financial institutions and have accounts blocked. Then change your passwords, starting with anything the thief may have touched and anywhere those passwords were reused.
Then get help that does this every day. Moneysmart, the OAIC's breach support page and Scamwatch all point to IDCARE, a free identity recovery support service, on 1800 595 160 — it helps you build a plan for reclaiming your identity rather than leaving you to improvise one. If a government identity is caught up in it — your Centrelink, Medicare or myGov details — Moneysmart and Scamwatch both direct you to the Services Australia Scams and Identity Theft Helpdesk on 1800 941 126.
Finally, report it — twice, for two different reasons. Report the crime through ReportCyber at cyber.gov.au, which Scamwatch describes as making a police report for cybercrime. And report the scam to Scamwatch, which uses reports to have scam websites, ads and contact details taken down and to warn the community about what's circulating. Then keep watch: monitor your statements, and check your credit report for applications you don't recognise — with that temporary ban available if fraud shows up.
Sourced, not generated. The claims on this page trace to ASIC's Moneysmart identity-theft and online-safety guidance, the OAIC's data-breach pages and Scamwatch's account-takeover and report-a-scam pages, not to a model. The page is deliberately figure-light: no loss statistic, harm threshold or ban duration is printed — the linked sources carry the current detail.
The sources behind the facts. The definition of identity theft, the warning signs, the prevention list (passwords, multi-factor authentication, shredding, mail, credit report checks and the temporary ban) and the response steps follow Moneysmart's identity theft page, with its online safety hub as the wider index; the definition of a data breach and the tell-you-if-serious-harm-is-likely shape of the Notifiable Data Breaches scheme follow the OAIC, with the support services from its breach-support page; how takeovers work, phone porting, the takeover warning signs and the bank-first response follow Scamwatch. IDCARE and the Services Australia helpdesk are named, with their phone numbers, exactly as those pages print them.
The explorer illustrates, it doesn't assert. The scenario checklists reorder the same sourced first moves for four common situations, in structural terms only — the explorer computes nothing, stores nothing, and is labelled as an illustrative learning guide on screen. In a real incident, follow the official pages and services it points to.
As at July 2026. The guidance linked from this page was checked when it was written.
Education, not advice. This page explains how identity theft works — it isn't a substitute for the official reporting channels or for professional help. If your identity is misused, the services above exist precisely for that: your bank, IDCARE on 1800 595 160, ReportCyber for the police report and Scamwatch for the warning to everyone else.