Identity Theft Statistics 2026: The Numbers the Industry Doesn't Advertise
Source-bounded identity-fraud statistics, FTC consumer-report limitations, breach-response guidance, and the limits of connecting public profiles to fraud.
Every year, identity-fraud statistics get cited by security companies and regulators. The figures measure different things, so this page labels survey estimates, consumer reports, and breach disclosures separately rather than treating them as one national total.
These are the 2026 numbers, where they come from, and what they actually tell you about reducing your exposure.
Key Takeaways
Evidence boundary: The FTC Consumer Sentinel Network contains consumer reports and is not a population survey or verified incident census. The FTC Data Book and the cited source for each estimate should be read separately.
- 18 million Americans were victims of traditional identity fraud in 2025, with losses holding at $27.3 billion; combined with scams, 36 million victims lost $38 billion (Javelin 2026 Identity Fraud Study).
- New-account fraud jumped 31% in 2025 (4.2 million to 5.4 million victims), and account takeover rose 18%; synthetic identity fraud combines real SSNs with addresses sourced from data broker databases.
- The National Public Data incident shows why breach records and public/commercial records should be analyzed separately; this page does not treat a reported record count as a verified count of unique people.
- Credit monitoring alerts you only after a fraudulent account is opened; a credit freeze prevents new accounts from being opened at all and is free under federal law.
- Removing a people-search profile may reduce one publicly available enrichment source, but this page does not claim a measured fraud-reduction rate.
The headline numbers
18 million Americans were victims of traditional identity fraud in 2025, according to Javelin Strategy & Research's 2026 Identity Fraud Study, with losses holding steady at $27.3 billion. Add consumer scams and the combined toll reaches $38 billion across 36 million victims, down $9 billion and 4 million victims from 2024.
The Federal Trade Commission says the Consumer Sentinel Network received 6.5 million consumer reports in 2024. These are reports submitted by consumers and contributing organizations, not verified incidents or a population survey. The FTC publishes the categories and limitations in its 2024 Data Book. Javelin's separate figure is a commercial survey estimate and should not be merged with the FTC report count.
Tired of dealing with data exposure?
Your personal data is likely on 1009 data brokers. Use OfflistMe to generate pre-filled opt-out emails for all of them in one go.
How fraud actually starts
One useful threat model has three stages: data acquisition, profile assembly, and exploitation. It is an explanatory model, not a measured national sequence.
Stage 1: Data acquisition. Fraudsters collect personal data from two sources, breached databases bought on dark web markets, and data brokers openly aggregated on people-search sites. The dark web portion gets press coverage. The data broker portion is what makes fraud operationally work.
Stage 2: Profile assembly. A breach may expose one set of fields, while a people-search profile may expose combinations of names, addresses, phone numbers, relatives, or other fields. Cross-referencing records can add context, but speed and completeness vary; this page does not publish a universal time estimate.
Stage 3: Exploitation. Armed with a full profile, fraudsters open credit lines, file tax returns, submit unemployment claims, or take over existing accounts using "security questions" that are now public knowledge.
Removing a public profile may make one form of profile assembly harder, but it does not eliminate Stage 2 or prevent identity theft by itself.
By fraud type
The Javelin 2026 study breaks down where identity fraud grew and shrank in 2025:
- *New-account fraud: 5.4 million victims, up 31% from 4.2 million in 2024. This is the category a credit freeze directly prevents.
- *Account takeover: 6 million victims, up 18% from 5.1 million in 2024.
- *Consumer scams: just under $11 billion in losses, down 45% from 2024, the main driver of the overall decline.
These categories can involve identity attributes that also appear in public and commercial records, but this page does not establish that data-broker profiles caused the reported incidents.
In the FTC's report data, credit card fraud has been the single largest identity theft category for years, followed by government benefits, loan, and bank fraud; the state-by-state and age-band tables are published annually in the Consumer Sentinel Data Book, where Florida and Georgia consistently top the per-capita rankings.
The data breach pipeline
The Identity Theft Resource Center (ITRC) tracked 3,322 data compromises in 2025, a new record and a 5% increase over 2024's 3,152, according to the ITRC 2025 Annual Data Breach Report. Victim notices actually fell 79% to about 279 million, because 2025 lacked the mega-breaches of 2024, but the underlying attack volume kept climbing, and 70% of breach notices no longer disclose how the attack happened.
The 2024 mega-breaches whose data still circulates in fraud markets:
- *National Public Data: 2.9 billion records (names, SSNs, addresses, the largest breach ever recorded)
- *Ticketmaster: 560 million records (via the Snowflake credential attacks)
- *Change Healthcare: roughly 190 million medical records
- *AT&T: 73 million customer records
The National Public Data breach is particularly instructive: the company that was breached *was itself a data broker*. It scraped and sold personal data, then failed to secure it, millions of people had no prior relationship with the company and no way to know they were exposed.
Why credit monitoring is not enough
Credit monitoring detects fraud after a new account is opened in your name. By the time an alert fires and you notice it, the credit line is often already spent, the tax refund claimed, or the account sold.
Prevention beats detection here: with new-account fraud up 31% in 2025, a security freeze, which blocks the account from being opened at all, addresses the fastest-growing category directly, while monitoring only tells you it happened.
The data broker angle that doesn't make the headlines
There is no single official national count of all U.S. data brokers. State registries use different definitions and scopes; for example, the California Data Broker Registry and Vermont registry should be treated as jurisdiction-specific records, not added into a national total.
This page does not publish a universal price-per-lookup, API-access, reappearance, or removal-success statistic. Broker business models and public-record refresh practices differ, and OfflistMe has not completed a reproducible outcome study. See the removal-effectiveness benchmark methodology.
The right response, in order
- *Remove yourself from data broker databases. Target people-search sites first: Whitepages, Spokeo, BeenVerified, TruthFinder, Radaris, MyLife. Browse the full data broker directory or use OfflistMe to cover 1000+ brokers in a single pass.
- *Place a security freeze at all three credit bureaus plus ChexSystems. Free under federal law. See our credit freeze guide.
- *Enable two-factor authentication using an authenticator app, not SMS.
- *Check Have I Been Pwned (haveibeenpwned.com) and set up breach alerts.
Frequently Asked Questions
How common is identity theft in 2025?
Javelin's 2026 study estimates 18 million Americans experienced traditional identity fraud in 2025, but that is a commercial survey estimate. FTC Consumer Sentinel reports are a separate source with different coverage and should not be combined with it into a single rate.
What is the most common type of identity theft?
Credit card fraud is consistently the largest single category in FTC identity theft reports. New-account fraud is the fastest-growing, up 31% in 2025 per Javelin, followed by account takeover at 18% growth.
How long does it take to resolve identity theft?
Simple cases (a single fraudulent card) can be resolved in hours; complex cases involving synthetic identities or government benefits fraud can take over 200 hours and more than a year to fully resolve.
Do data breaches cause identity theft?
Data breaches provide raw material but data brokers provide the profile enrichment that makes fraud operationally viable. Opting out of data brokers reduces risk even after a breach has already occurred.
Is credit monitoring enough to prevent identity theft?
No. Credit monitoring and a security freeze serve different purposes. The FTC explains the available identity-theft response options; do not assume a fixed alert lag for every provider or account.
What the Numbers Mean for Your Personal Risk
The aggregate statistics, 18 million victims, $27.3 billion in losses, are important context, but they obscure the more useful question: what does your personal lifetime risk of identity theft actually look like?
The Javelin estimate should not be converted into a lifetime probability here. Survey estimates, report counts, and adult-population denominators have different scopes, and a constant annual rate assumption would create false precision.
The risk profile also differs by life stage. Young adults who are heavily active on financial apps and reuse passwords face the most account takeover attempts; seniors are disproportionately targeted for government benefits and investment fraud, which involve larger sums and longer timelines before discovery; and established credit profiles make middle-aged earners the preferred target for credit card and loan fraud.
The Data Broker Connection in Identity Theft Cases
The role of data brokers in enabling identity theft receives significantly less attention than data breaches, but FTC data and independent research point to a direct and documented connection.
People-search profiles can expose combinations of names, addresses, phone numbers, relatives, or other fields. Whether that information is sufficient for fraud depends on the record, the person, and the attempted activity; a profile is not by itself proof that fraud will occur.
One possible mechanism is profile augmentation: a partial record may be combined with other sources to fill gaps. The result depends on the site, the data, and the attacker; this page does not claim that any named broker enables a particular fraud outcome.
Consumer Reports' 2024 evaluation of people-search removal found that manual opt-outs removed about 70% of profiles within a week, while even the best paid services took months to reach similar coverage. The takeaway for fraud risk: removal works, and the profiles that marketers use are the same ones fraudsters use, so every profile taken down is one less enrichment source.
Opting out of data brokers does not eliminate identity-theft risk or remove breach records. It may reduce the availability of one public profile, while other records, public sources, and previously copied data may remain.
How to respond after a breach
Breach size, affected fields, and legal notices must be verified from the affected organization or an authoritative regulator. A breach record does not by itself prove identity theft, and a media-reported record count may include duplicate records or historical data.
If you believe your information was exposed, follow the organization's notice and use the appropriate official response channels. For new-account risk, review the Federal Trade Commission's guidance on credit freezes and fraud alerts. A freeze and a monitoring service serve different purposes; neither removes information already copied into other systems.
For health-sector incidents, the HHS OCR Breach Portal is a source for published HIPAA breach records affecting 500 or more individuals. It is not a census of all breaches. For general consumer reports, use the FTC Consumer Sentinel Data Book and preserve its stated reporting limitations.
Start your data broker opt-out → | Read: What to Do After a Data Breach → | Compare data removal services →
How to read identity-theft statistics
| Number type | What it measures | How to use it safely |
|---|---|---|
| Consumer reports | Complaints submitted to an agency | Treat as reported volume, not a verified victim census |
| Survey estimates | Responses from a defined sample | Check the sample, field dates, and fraud definition |
| Breach disclosures | Records or accounts reported by an organization | Do not equate records with unique people |
| Dollar-loss estimates | Reported or modeled financial harm | Check whether attempted and completed fraud are combined |
Related Guides
- What is a Data Broker? (Complete Guide): Comprehensive foundational guide on data broker networks and legal opt-out mechanisms.
Understand your privacy rights
Every removal request cites a specific statute. These plain-English explainers show what each law covers and how enforcement actually works.
Related Data Broker Removal Guides
Take back your privacy today
Remove your personal information from data brokers and platforms in seconds.
Remove Your Personal Data Now100% Free for top brokers · One-time unlock from $9.00 · No subscription
