A new viral security alert is spreading on Facebook, once again based on a foundation of truth: IDENTITY THEFT, but providing distorted information about the precautions to take and how to defend oneself. IDENTITY THEFT is a criminal offense that has existed long before the Internet and before Facebook. In the worst-case scenario, it is used to obtain loans in someone else's name, who will then go through a judicial ordeal to prove their innocence.
How to tell if your identity has been stolen?
In the case of Facebook, it couldn't be simpler: if you search for your name and find another profile in your name, with your data and your photos, unless you created it yourself, it is a true identity theft. Similarly, if you read comments in your name that you did not author.
It is more difficult to discover identity theft for fraudulent purposes; in this case, pay attention to:
- Unusual or unexpected withdrawals from your bank account;
- Receiving invoices for products or services you do not possess;
- Problems with credit cards.
Now, do not rush to open the first attachment that arrives with a suspicious email talking about a bank transaction you know nothing about; it is more likely to be ransomware. Simply keep an eye on your bank accounts and credit cards.
How to defend yourself?
Regarding Facebook, it is very simple: as soon as you notice that someone is using your name and photo, just report it to Facebook, and within a few minutes, the profile will be closed. If it reappears, before repeating the process, you should make a copy of the profile page; a screenshot is not enough as it does not provide temporal proof and authenticity. For this purpose, use HASHBOT: https://www.hashbot.com/ and file a report with the Postal Police.
Use only the reporting feature; do not engage in discussions with the person who stole your identity, and do not start warning your contacts. It is pointless, and especially if it is a Troll, they will find your reaction amusing.
For identity theft for fraudulent purposes:
- Be careful with your sensitive data; do not easily provide copies of your documents, for example. Especially if you enter your credit card details, ensure that the connection is protected by SSL (https://); even if it is a website of a company you know, the normal connection (http://) does not protect against potential data interception.
- Do not provide your access passwords and be careful where you enter them: a tactic used by hackers (phishing) is to send a fake email from your bank inviting you to confirm a transaction or reset your password by clicking on a link that opens a page that looks exactly like that of your financial institution. In this case, pay attention to the page address and especially that it is protected by the SSL protocol, meaning it is an https:// address and that something similar to a padlock appears in the browser.
- Keep an eye on your bank accounts and credit cards: personally, I prefer services that provide an alert for every access to my profile (regardless of whether an operation is performed or not) through communication via email or SMS, which, combined with a strong password, make it difficult for any potential wrongdoer to access without our knowledge.