Skip to main content
Privacy Education
•10 min read

Identity Theft Statistics 2026: How to Read the Numbers

Source-bounded identity-fraud statistics, FTC consumer-report limitations, breach-response guidance, and the limits of connecting public profiles to fraud.

Rahul Kandoriya
Written byRahul Kandoriya·Last updated August 25, 2026
Identity Theft Statistics 2026: How to Read the Numbers
Identity Theft Statistics 2026: How to Read the Numbers
Coverage scope: The OfflistMe catalog currently records 1,000+data-broker workflows. Paid access lets you select workflows at once; you review and send or submit the generated requests, while provider eligibility and outcomes remain outside OfflistMe's control.

Every year, identity-fraud statistics get cited by security companies and regulators. The figures measure different things, so this page labels survey estimates, consumer reports, and breach disclosures separately rather than treating them as one national total.

These are the 2026 numbers, where they come from, and what they actually tell you about reducing your exposure.

Key Takeaways

Evidence boundary: The FTC Consumer Sentinel Network contains consumer reports and is not a population survey or verified incident census. The FTC Data Book and the cited source for each estimate should be read separately.

  • Javelin's 2026 commercial study estimates that 18 million people experienced traditional identity fraud in 2025, with $27.3 billion in losses; it separately estimates 36 million victims and $38 billion when its scam measure is combined with identity fraud (Javelin 2026 Identity Fraud Study).
  • Javelin reports a 31% increase in new-account-fraud victims in 2025 (4.2 million to 5.4 million) and an 18% increase in account-takeover victims (Javelin 2026 Identity Fraud Study). These are study estimates, not proof that a particular data broker caused an incident.
  • Breach records, victim notices, and survey estimates measure different things. This page does not treat a reported record count as a verified count of unique people.
  • Credit monitoring and a security freeze serve different purposes. A freeze can restrict prospective creditors' access to a credit report, but it is not a universal block on every form of identity theft and does not replace account security.
  • Removing a people-search profile may reduce one publicly available enrichment source, but this page does not claim a measured fraud-reduction rate.

The headline numbers

According to Javelin Strategy & Research's 2026 Identity Fraud Study, its research estimated 18 million victims of traditional identity fraud and $27.3 billion in losses in 2025. Javelin separately estimated $10.7 billion in scam losses affecting 18 million people; its combined identity-fraud-and-scam measure was $38 billion across 36 million victims. These figures come from Javelin's methodology and should not be treated as an FTC census.

The Federal Trade Commission says the Consumer Sentinel Network received 6.5 million consumer reports in 2024. These are reports submitted by consumers and contributing organizations, not verified incidents or a population survey. The FTC publishes the categories and limitations in its 2024 Data Book. Javelin's separate figure is a commercial survey estimate and should not be merged with the FTC report count.

Request Drafting

Tired of dealing with data exposure?

Choose relevant provider workflows, review the generated drafts in your browser, and send or submit each request yourself. Matching, eligibility, and provider requirements still need checking.

Review Removal Options Free for selected workflows · No opt-out profile stored · No card needed

How fraud actually starts

One useful threat model has three stages: data acquisition, profile assembly, and exploitation. It is an explanatory model, not a measured national sequence.

Stage 1: Data acquisition. An attacker may obtain information from breaches, phishing, compromised accounts, public records, commercial databases, or people-search sites. The sources, legality, completeness, and accuracy vary; this page does not claim that a particular broker supplied information in a particular case.

Stage 2: Profile assembly. A breach may expose one set of fields, while a people-search profile may expose combinations of names, addresses, phone numbers, relatives, or other fields. Cross-referencing records can add context, but speed and completeness vary; this page does not publish a universal time estimate.

Stage 3: Exploitation. Using information from one or more sources, an attacker may attempt account takeover, new-account fraud, tax fraud, benefits fraud, or other misuse. The available information does not establish that an attempt will succeed.

Removing a public profile may make one form of profile assembly harder, but it does not eliminate Stage 2 or prevent identity theft by itself.

By fraud type

The Javelin 2026 study breaks down where identity fraud grew and shrank in 2025:

  • *New-account fraud: 5.4 million victims, up 31% from 4.2 million in 2024 in Javelin's study (Javelin 2026 Identity Fraud Study). A security freeze can restrict access to a credit report for many new-credit applications, but it is not a complete identity-theft control.
  • *Account takeover: 6 million victims, up 18% from 5.1 million in 2024 (Javelin 2026 Identity Fraud Study).
  • *Consumer scams: just under $11 billion in losses, down 45% from 2024. Javelin also reported a 17% year-over-year decline in people reporting scam incidents (Javelin 2026 Identity Fraud Study).

These categories can involve identity attributes that also appear in public and commercial records, but this page does not establish that data-broker profiles caused the reported incidents.

In the FTC's 2024 report data, credit-card identity theft was the largest reported identity-theft type. The Consumer Sentinel Data Book publishes the category definitions, state tables, and reporting limitations; a reported category is not a verified national incidence rate.

The data breach pipeline

The Identity Theft Resource Center (ITRC) tracked 3,322 data compromises in 2025, a new record and a 5% increase over 2024's 3,152, according to the ITRC 2025 Annual Data Breach Report. The number of victim notices fell 79% to 278,827,933, which the ITRC attributed to the lack of 2025 mega-breaches. The number of tracked compromises still rose, and 70% (2,324) of breach notices did not include attack information.

Headline breach figures need a separate audit. A notice may report records, accounts, or affected individuals, and historical or duplicate records can make those units non-comparable. For health-sector incidents, the HHS OCR Breach Portal defines its published list as breaches of unsecured protected health information affecting 500 or more individuals; use the affected organization's notice and the applicable regulator rather than treating a media headline as a verified unique-person total.

Why credit monitoring is not enough

Credit monitoring can alert you to changes that a monitoring provider receives, but it is not necessarily real-time and does not cover every type of identity theft. A security freeze addresses a different point in the process by restricting prospective creditors' access to a credit report.

With new-account fraud estimated to have increased 31% in Javelin's 2025 study (Javelin 2026 Identity Fraud Study), a security freeze is one useful control for many new-credit applications. It does not block every account, transaction, tax filing, benefits claim, or account takeover, so use it alongside passwords, multifactor authentication, and account monitoring.

The data broker angle that doesn't make the headlines

State registries use different definitions and scopes, so this page does not add their totals into a national count. The California Data Broker Registry is a jurisdiction-specific record, not a national total.

This page does not publish a universal price-per-lookup, API-access, reappearance, or removal-success statistic. Broker business models and public-record refresh practices differ, and OfflistMe has not completed a reproducible outcome study. See the removal-effectiveness benchmark methodology.

The right response, in order

Frequently Asked Questions

How common is identity theft in 2025?

Javelin's 2026 study estimates 18 million Americans experienced traditional identity fraud in 2025 (Javelin 2026 Identity Fraud Study), but that is a commercial survey estimate. FTC Consumer Sentinel reports are a separate source with different coverage and should not be combined with it into a single rate.

What is the most common type of identity theft?

Credit card fraud is consistently the largest single category in FTC identity theft reports (FTC Consumer Sentinel Network Data Book 2024). New-account fraud is the fastest-growing, up 31% in 2025 per Javelin, followed by account takeover at 18% growth (Javelin 2026 Identity Fraud Study).

How long does it take to resolve identity theft?

Resolution time depends on the account, institution, type of fraud, documentation, and whether several organizations are involved. Do not rely on a universal hours-or-months estimate.

Do data breaches cause identity theft?

Data breaches and public or commercial records can overlap, but this page does not establish a universal causal chain from a broker profile to identity theft. Opting out may reduce one public enrichment source; it does not remove breach data or eliminate risk.

Is credit monitoring enough to prevent identity theft?

No. Credit monitoring and a security freeze serve different purposes. The FTC explains the available identity-theft response options; do not assume a fixed alert lag for every provider or account.


What the Numbers Mean for Your Personal Risk

The aggregate statistics, 18 million victims, $27.3 billion in losses (Javelin 2026 Identity Fraud Study), are important context, but they obscure the more useful question: what does your personal lifetime risk of identity theft actually look like?

The Javelin estimate should not be converted into a lifetime probability here. Survey estimates, report counts, and adult-population denominators have different scopes, and a constant annual rate assumption would create false precision.

Risk and impact can differ by account usage, exposure, age, resources, and the type of fraud involved. Avoid turning a general demographic pattern into a prediction about an individual; use the affected account, breach notice, and official response guidance to choose controls.


The Data Broker Connection in Identity Theft Cases

Public and commercial profiles can provide context that an attacker may combine with other sources, but this page does not establish a direct causal connection between a named broker and a reported identity-theft incident.

People-search profiles can expose combinations of names, addresses, phone numbers, relatives, or other fields. Whether that information is sufficient for fraud depends on the record, the person, and the attempted activity; a profile is not by itself proof that fraud will occur.

One possible mechanism is profile augmentation: a partial record may be combined with other sources to fill gaps. The result depends on the site, the data, and the attacker; this page does not claim that any named broker enables a particular fraud outcome.

Consumer Reports' 2024 evaluation of people-search removal measured removal outcomes in its test. Treat that result as a study-specific observation, not a universal success rate or fraud-reduction measure. A removed profile may reduce one public source while other copies remain.

Opting out of data brokers does not eliminate identity-theft risk or remove breach records. It may reduce the availability of one public profile, while other records, public sources, and previously copied data may remain.


How to respond after a breach

Breach size, affected fields, and legal notices must be verified from the affected organization or an authoritative regulator. A breach record does not by itself prove identity theft, and a media-reported record count may include duplicate records or historical data.

If you believe your information was exposed, follow the organization's notice and use the appropriate official response channels. For new-account risk, review the Federal Trade Commission's guidance on credit freezes and fraud alerts. A freeze and a monitoring service serve different purposes; neither removes information already copied into other systems.

For health-sector incidents, the HHS OCR Breach Portal is a source for published HIPAA breach records affecting 500 or more individuals. It is not a census of all breaches. For general consumer reports, use the FTC Consumer Sentinel Data Book and preserve its stated reporting limitations.


Start your data broker opt-out → | Read: What to Do After a Data Breach → | Compare data removal services →


How to read identity-theft statistics

Number typeWhat it measuresHow to use it safely
Consumer reportsComplaints submitted to an agencyTreat as reported volume, not a verified victim census
Survey estimatesResponses from a defined sampleCheck the sample, field dates, and fraud definition
Breach disclosuresRecords or accounts reported by an organizationDo not equate records with unique people
Dollar-loss estimatesReported or modeled financial harmCheck whether attempted and completed fraud are combined

Related Guides

Take back your privacy today

Review provider-specific routes, prepare your requests locally, and send or submit each one yourself.

Review Provider Routes

Free to review provider routes · Optional one-time unlock from $9.00 · No subscription