2022's States Most Vulnerable to Identity Theft & Fraud

In recent years, many Americans’ personal information has become compromised by big data breaches. In 2022, the average data breach in the U.S. cost $9.44 million and took 277 days to identify and contain. Several big companies and organizations were impacted, including Microsoft, Cash App and the Red Cross.

Each new year brings new strategies taken by identity thieves and fraudsters, but older schemes, such as tech support scams and fake IRS calls, still abound. Some Americans are more susceptible than others to such crimes, though. In order to determine who is most likely to be exposed to and affected by identity theft and fraud, WalletHub compared the 50 states and the District of Columbia across 14 key metrics. Our data set ranges from identity-theft complaints per capita to the average loss amount due to fraud.

Quick Tips for Avoiding Identity Theft & Fraud

  • Emphasize Email Security: It’s obviously important to use strong passwords for all financial accounts, but you may not realize how essential it is to focus on email. Your primary email address will likely serve as your username and means of resetting your password on other websites. If it’s vulnerable, all of your other accounts will be, too. As a result, make sure to use an especially secure password and establish two-step verification for this account.

  • Sign up for Credit Monitoring: Credit monitoring is the best way to keep tabs on your credit report. It provides peace of mind in the form of alerts about important changes to your file, including potential signs of identity theft. WalletHub offers free monitoring of your TransUnion credit report.

  • Leverage Account Alerts & Update Contact Info: Setting up online management for all of your financial accounts (e.g., credit cards, loans, Social Security), and keeping your phone number, email address and street address up to date will make them harder for identity thieves to hijack. Establishing alerts for changes to your contact info and other suspicious account activity will serve as a safeguard.

  • Use Common Sense Online: Don’t open emails you don’t recognize. Don’t download files from untrustworthy sources. Don’t send account numbers and passwords via email or messenger applications. And don’t enter financial or personal information into websites that lack the “https” prefix in their URLs.

Ask the Experts

As an internet-oriented culture, it’s natural to wonder whether and how our daily habits assist hackers in stealing our personal information. We consulted a panel of experts for answers to such questions and advice on how to safeguard our data against cybercriminals. Click on the experts’ profiles to read their bios and thoughts on the following key questions:

  1. What can individuals do to guard against identity theft?

  2. Should victims of identity theft be able to change their Social Security number? How can we make this number more difficult to steal and use (e.g., add more digits)?

  3. What are some common scams and fraud attempts people should be vigilant about?

  4. Is the expansion of social media facilitating more identity thefts?

  5. Should the Federal government intervene to establish a clear process for victims of identity theft looking to clear their name?

Katina Michael

Professor, School for the Future of Innovation in Society and Professor, School of Computing and Augmented Intelligence – Arizona State University

What can individuals do to guard against identity theft?

Ensure they have all of their digital devices, and when they are not that they are securely stored, even at home.

Ensure that their wallet never leaves their sight, and do not travel with identity cards that are not required locally. In particular, certain cards or tokens are used to prove one’s identity inclusive of their social security card, driver’s license, birth certificate, and passport.

In fact, these are the high-value physical credentials that are required when you open a bank account or request a new mobile phone number. And certain proofs of identity are stacked in a layered way. You do not want to be storing these valuable pieces of identity in digital form or sending them through email in an unencrypted manner. You just never know who is on the other side and has administrator access to information.

A lot of government platforms today are also electronic, so ensuring that your username and password are difficult to guess and are different from other online apps you use, and not written on the front page of your hardcopy diary, is also paramount.

Should victims of identity theft be able to change their social security number? How can we make this number more difficult to steal and use (e.g., more digits, etc.)?

Social security numbers in some countries are difficult to change. There are horror stories that have been reported, even of people who have been given “duplicate numbers” and have later found themselves living in the same state or even city, which then has become problematic. This particular example is a historical problem more than an identity theft problem. But more recently, having your identity stolen, in terms of your social security number, is a nightmare scenario. Identity thieves can apply for credit, receive it, and then go on a binge with your good name and credit history, and then you are left to fend for unpaid bills and prove that the person who made the claim was not you. Something very difficult to do with online purchases where “card not present” fraud is still prevalent. The first people catch wind of this theft is when they begin to get phone calls from creditors, or they are in person at a store, and their credit card does not work! The SSA’s help page warns citizens not to give out their SSN willingly and to keep that information private, and to always double-check if it is a requirement to share it with a third party. They suggest you do not share it.

The steps the SSA asks you to go through if you believe you are a victim of identity theft are as follows. But for anyone who has ever tried to call the IRS, it is a bit of a scary endeavor. There are often long call-holding times, and it might take weeks for someone to get back to you. If you are not good with online forms or have difficulty conversing with others (for any myriad of reasons), this may be an insurmountable task. Ordering credit reports is pretty straightforward but even then, it all takes time. You are then encouraged to take the evidence and report it to a local police station. The truth of the matter is that local police are overwhelmed by “physical” immediate crimes, and often don’t know how to handle “digital crimes”. It is not easy. Evidence is hard to come by. Although you will be given a fair hearing, while you are filing your case, your life is likely falling apart because you cannot ask for credit, or go on about your business in the same way you did before the identity theft took place. I would really advise immediate action, and receive support from a lawyer, or a specialized service that would be willing to work with you to reinstate your identity and protect it.

“If you think someone is using your Social Security number (SSN), there are several actions you can take.

  • Review the earnings posted to your record on your Social Security Statement and report any inconsistencies to us.

  • Contact the Internal Revenue Service (IRS) at 1-800-908-4490 or visit them online, if you believe someone is using your SSN to work, get your tax refund, or do other abuses involving taxes.

  • Order free credit reports annually from the three major credit bureaus (Equifax, Experian, and TransUnion). Make a single request for all three credit bureau reports at the Annual Credit Report Request Form, (Disclaimer) or by calling 1-877-322-8228.

  • File a report with your local police or the police in the community where the identity theft took place.

  • Report identity theft at the Federal Trade Commission’s Identity Theft webpage.”

What are some common scams and fraud attempts people should be vigilant about?

Phishing attacks are so common today, and sometimes people succumb to them divulging sensitive personal information. By clicking on an email that has not been authenticated as coming from a particular source, and then writing social security numbers, bank account numbers, telephone numbers, driver's licenses, or passport details, one can find themselves on the back foot quickly.

Always be wary of receiving phone calls directly from a “provider”. No matter how sure you are that you are being called by someone that has your best interest at heart, terminate the call, and ring back the provider to make sure that the case in point is legitimate. When you interact online with a provider request the name and reference number of the call. The scam usually begins with: “hi [NAME], we are calling from Social Security Administration, and we would just like to tell you that we are working on fixing a problem with your number and account”. Older people or vulnerable members of the community may be particularly at risk in these kinds of scams.

The SSA state: “Any call, text, or email asking you to pay a fine or debt with retail gift cards, wire transfers, pre-paid debit cards, internet currency, or by mailing cash. Scammers pretend they are from Social Security or another government agency. Caller ID, texts, or documents sent by email may look official, but they are not.”.

Always report scams to a ScamWatch service or your provider. If there is anything suspicious with any of your dealings call to ensure your suspicions are negated.

Ensure you are using an official website and if possible, never give sensitive personal information over the Internet or phone. If there is an important matter you need to deal with, and you know it will be easier to go in person than spend time copious time online trying to achieve the same aim, carve out some time to visit an agency or provider in person. Though we are being dissuaded to do this in most cities and states, and a single in-person office visit will take at least a few hours in most urban centers, it may be worth the wait and peace of mind.

Is the expansion of social media facilitating more identity thefts?

Yes. I have seen people post bank details on social media, their phone numbers, and much more. We have become lax, thinking that social media platforms are “safe” or that certain pieces of information (even our full name) are not sensitive pieces of data. A profile can be created around you, and you may be subject to social engineering attacks without even realizing it. Open-source intelligence (OS-INT) is just that “open source” and this is not something that only intelligence organizations use, but everyday hackers penetrate systems, identities, and much more. We also divulge a lot of answers to “security questions” in the name of reinstating passwords- do not tell any person or platform what your mother’s maiden name was, or even your date of birth if it can be helped. These are the same questions you get when you apply for an electronic passport online and more.

Should the Federal government intervene to establish a clear process for victims of identity theft looking to clear their name?

I am not American, but the SSA website for the greater part unhelpful (see attached). It does not really tell a victim how to recover their identity. It tells a victim of identity theft what they should have done, begin with (second paragraph). We need to do better as government agencies that are in charge of the most important part of one’s identity to communicate how people can recover post a crime. All identity theft is asymmetric and often as a citizenry, we have a false sense of security. Until we are victims of cybercrime we think “everything is ok, what’s the big deal with shopping online, it’s efficient and convenient”. There is a chilling effect however that comes with all of this identity theft, and every day innocent people are falling victim. The latest attacks we have seen in Australia have been in critical infrastructure providers in terms of massive data breaches with coverage of 50% of Australia’s population, like our major telephone operators, private health insurance companies, and leading supermarket chains. There are hotline services that have been set up to help people find out how to better protect themselves post an attack, but for the greater part the messaging to subscribers has been: “we are very sorry that your data has been stolen by hackers, we acknowledge this must be a difficult time for you, but change your password, and let’s hope nothing else happens with your credentials”. That’s one way to look at it, perhaps, as people scramble to change their Medicare cards, passport, and more, but we are talking about very sensitive information. Governments need a better plan of action, and they need to step in to protect their citizenry. There needs to be a clear path forward of “if this happens to you, then this”. People need to be given a clear timeline for an investigation into their personal circumstances, and most of all we need more trained personnel to help victims get through something that might even impact their employment, let alone their livelihoods. But these processes to are subject to cybercrime, and hackers can take advantage of any measures that are put in place to help victims as well.

Methodology

In order to determine where American consumers are most vulnerable to identity theft and fraud, WalletHub compared the 50 states and the District of Columbia across three key dimensions: 1) Identity Theft, 2) Fraud and 3) Policy.

We evaluated those dimensions using 14 key metrics, which are listed below with their corresponding weights. Each metric was graded on a 100-point scale, with a score of 100 representing the most vulnerable.

Finally, we determined each state and the District’s weighted average across all metrics to calculate its overall score and used the resulting scores to rank-order our sample.

Identity Theft – Total Points: 47.5

  • Identity-Theft Complaints per Capita: Full Weight (~15.83 Points)

  • Change in Identity-Theft Complaints per Capita (2021 vs 2020): Full Weight (~15.83 Points)

  • Average Loss Amount Due to Online Identity Theft: Full Weight (~15.83 Points)
    Note: This metric was calculated using the following formula: Total Loss Amount / Total Number of Online Identity-Theft Complaints.

Fraud – Total Points: 47.5

  • Fraud & Other Complaints per Capita: Full Weight (~9.50 Points)

  • Change in Fraud & Other Complaints per Capita (2021 vs 2020): Full Weight (~9.50 Points)

  • Median Loss Amount Due to Fraud: Full Weight (~9.50 Points)
    Note: “Total reported amount paid” is based on the total number of fraud complaints for which the amount paid was reported by the victims. The amount paid ranges from $1 to $999,999.

  • Persons Arrested for Fraud per Capita: Full Weight (~9.50 Points)

  • E-Commerce Attack Rates: Full Weight (~9.50 Points)

Policy – Total Points: 5.0

  • Availability of Security-Freeze Law for Minors’ Credit Reports: Full Weight (~0.83 Points)
    Note: This binary metric considers the presence or absence of legislation allowing parents, legal guardians or other representatives of minors to place a security freeze on the minor’s credit report.

  • Availability of Identity-Theft Passport Program: Full Weight (~0.83 Points)
    Note: This binary metric considers the presence or absence of Identity-Theft Passport programs that help victims of identity theft reclaim their identity. When presented to a law-enforcement agency, an “identity-theft passport” allows a victim to prevent his or her arrest for offenses committed by an identity thief.

  • Data Disposal Laws by State: Full Weight (~0.83 Points)
    Note: This is a binary metric that measures the presence or absence of data disposal laws in each state. Businesses and government collect personal information and store it in various formats-digital and paper. Several states have enacted laws that require entities to destroy, dispose or otherwise make personal information unreadable or undecipherable.

  • Presence of State Laws Addressing "Phishing": Full Weight (~0.83 Points)
    Note: This is a binary metric that measures the presence or absence of laws addressing “phishing” in a state. “Phishing” is a cybercrime in which a target is contacted by email, telephone or text message by someone posing as a legitimate institution to lure individuals into providing sensitive data such as personally identifiable information, banking and credit card details, and passwords.

  • Presence of State Spyware Laws: Full Weight (~0.83 Points)
    Note: This is a binary metric that measures the presence or absence of laws addressing “spyware” in a state. “Spyware” is classified as a type of malware, malicious software designed to gain access to or damage your computer, track your online activities or collect confidential information.

  • Presence of Statewide Cybersecurity Task Forces: Full Weight (~0.83 Points)
    Note: This is a binary metric that measures the presence or absence of cybersecurity task forces in a state.

 
Sources: Data used to create this ranking were collected from the Federal Trade Commission, Internet Crime Complaint Center, Federal Bureau of Investigation, Experian Information Solutions and National Conference of State Legislatures.

Citation: Katina Michael, 6 December 2022, “Ask an Experts” in (eds) Adam McCann, “2022's States Most Vulnerable to Identity Theft & Fraud”, WalletHub, https://wallethub.com/edu/states-where-identity-theft-and-fraud-are-worst/17549#expert=Katina_Michael

Previous
Previous

New York ranked one of the most vulnerable states for identity theft

Next
Next

As Maps Transform, So Must the Ethics of Mapmaking