States Most Vulnerable to Identity Theft & Fraud
In recent years, many Americans’ personal information has become compromised by big data breaches. In 2019 alone, prominent companies like WhatsApp, Quest Diagnostics, Microsoft, ASUS and Capital One have fallen victim to cybercriminals. According to the Identity Theft Resource Center’s most recent Data Breach Report, between January 1, 2005 and August 31, 2019, there have been 10,818 breaches. That accounts for over 1.6 billion records compromised.
The federal government and various businesses in recent years have taken more aggressive measures to build up our defenses. One big concern is not just hacking on the individual level, but cyberattacks by foreign governments to gain leverage. The United States recently signed a new cybersecurity agreement at the U.N., which condemns cyberattacks on civilian targets. Despite this, criminal strategies continue to evolve and grow in sophistication, keeping consumers vulnerable to identity theft and fraud.
But some Americans are more susceptible than others to such crimes. In order to determine who is most likely to be exposed to and affected by identity theft and fraud, WalletHub compared the 50 states and the District of Columbia across 15 key metrics. Our data set ranges from identity-theft complaints per capita to average loss amount due to fraud. Read on for our findings, tips for protecting your personal information and a full description of our methodology.
States With the Most Identity Theft & Fraud
‘Identity Theft’ Rank
|1||District of Columbia||70.30||6||5||1|
*No. 1 = Most Vulnerable
- Emphasize Email Security: It’s obviously important to use strong passwords for all financial accounts, but you may not realize how essential it is to focus on email. Your primary email address will likely serve as your username and means of resetting your password on other websites. If it’s vulnerable, all of your other accounts will be, too. As a result, make sure to use an especially secure password and establish two-step verification for this account.
- Sign Up for Credit Monitoring: Credit monitoring is the best way to keep tabs on your credit report. It provides peace of mind in the form of alerts about important changes to your file, including potential signs of identity theft. WalletHub offers free monitoring of your TransUnion credit report.
- Leverage Account Alerts & Update Contact Info: Setting up online management for all of your financial accounts (e.g., credit cards, loans, Social Security), and keeping your phone number, email address and street address up to date will make them harder for identity thieves to hijack. Establishing alerts for changes to your contact info and other suspicious account activity will serve as a safeguard.
- Use Common Sense Online: Don’t open emails you don’t recognize. Don’t download files from untrustworthy sources. Don’t send account numbers and passwords via email or messenger applications. And don’t enter financial or personal information into websites that lack the “https” prefix in their URLs.
For more tips and information, check out WalletHub’s Identity Theft Guide.
Ask the Experts
As a cyber-oriented culture, it’s natural to wonder whether and how our daily habits assist hackers in stealing our personal information. We consulted a panel of experts for answers to such questions and advice on how to safeguard our data against cybercriminals. Click on the experts’ profiles to read their bios and thoughts on the following key questions:
- What can individuals do to guard against identity theft?
- How should consumers choose among third-party providers offering services to protect their identity and personal data?
- Should victims of identity theft be able to change their Social Security number? How can we make this number more difficult to steal and use (e.g., add more digits)?
- Is the recent expansion of social media facilitating identity thefts?
- Should the federal government intervene to establish a clear process for victims of identity theft looking to clear their name?
- What measures can authorities undertake in order to avoid cases like the recent Equifax leaks? Should credit bureaus be tested for security breaches by authorities on a regular basis? If so, would the Consumer Financial Protection Bureau play a larger role in regulation and enforcement of bureaus?
In order to determine where American consumers are most vulnerable to identity theft and fraud, WalletHub compared the 50 states and the District of Columbia across three key dimensions: 1) Identity Theft, 2) Fraud and 3) Policy.
We evaluated those dimensions using 15 key metrics, which are listed below with their corresponding weights. Each metric was graded on a 100-point scale, with a score of 100 representing the most vulnerable.
Finally, we determined each state and the District’s weighted average across all metrics to calculate its overall score and used the resulting scores to rank-order our sample.
Identity Theft – Total Points: 47.5
- Identity-Theft Complaints per Capita: Full Weight (~15.83 Points)
- Change in Identity-Theft Complaints per Capita (2018 vs 2017): Full Weight (~15.83 Points)
- Average Loss Amount Due to Online Identity Theft: Full Weight (~15.83 Points)
Note: This metric was calculated using the following formula: Total Loss Amount / Total Number of Online Identity-Theft Complaints.
Fraud – Total Points: 47.5
- Fraud & Other Complaints per Capita: Full Weight (~9.50 Points)
- Change in Fraud & Other Complaints per Capita (2018 vs 2017): Full Weight (~9.50 Points)
- Median Loss Amount Due to Fraud: Full Weight (~9.50 Points)
Note: “Total reported amount paid” is based on the total number of fraud complaints for which the amount paid was reported by the victims. The amount paid ranges from $0 to $999,999.
- Persons Arrested for Fraud per Capita: Full Weight (~9.50 Points)
- E-Commerce Attack Rates: Full Weight (~9.50 Points)
Policy – Total Points: 5.0
- Availability of Security-Freeze Law for Minors’ Credit Reports: Full Weight (~0.71 Points)
Note: This binary metric considers the presence or absence of legislation allowing parents, legal guardians or other representatives of minors to place a security freeze on the minor’s credit report.
- Availability of Identity-Theft Passport Program : Full Weight (~0.71 Points)
Note: This binary metric considers the presence or absence of Identity-Theft Passport programs that help victims of identity theft reclaim their identity. When presented to a law-enforcement agency, an “identity-theft passport” allows a victim to prevent his or her arrest for offenses committed by an identity thief.
- Compliance with REAL ID Act : Full Weight (~0.71 Points)
Note: According to the Department of Homeland Security, the REAL ID Act “establishes minimum security standards for license issuance and production and prohibits Federal agencies from accepting for certain purposes driver’s licenses and identification cards from states not meeting the Act’s minimum standards. The purposes covered by the Act are: accessing Federal facilities, entering nuclear power plants, and, boarding federally regulated commercial aircraft.”
This binary metric considers a state’s compliance, noncompliance or extension of time to comply with the ACT. An extension allows a state to accept driver’s licenses and identification cards issued by that jurisdiction to accept those forms of identification for official purposes, under the condition that the state has provided adequate justification for noncompliance.
- Data Disposal Laws by State : Full Weight (~0.71 Points)
Note: This is a binary metric that measures the presence or absence of data disposal laws in each state. Businesses and government collect personal information and store it in various formats-digital and paper. Several states have enacted laws that require entities to destroy, dispose or otherwise make personal information unreadable or undecipherable.
- Presence of State Laws Addressing "Phishing": Full Weight (~0.71 Points)
Note: This is a binary metric that measures the presence or absence of laws addressing “phishing” in a state. “Phishing” is a cybercrime in which a target is contacted by email, telephone or text message by someone posing as a legitimate institution to lure individuals into providing sensitive data such as personally identifiable information, banking and credit card details, and passwords.
- Presence of State Spyware Laws: Full Weight (~0.71 Points)
Note: This is a binary metric that measures the presence or absence of laws addressing “spyware” in a state. “Spyware” is classified as a type of malware, malicious software designed to gain access to or damage your computer, track your online activities or collect confidential information.
- Presence of Statewide Cybersecurity Task Forces: Full Weight (~0.71 Points)
Note: This is a binary metric that measures the presence or absence of cybersecurity task forces in a state.
Sources: Data used to create this ranking were collected from the Federal Trade Commission, Internet Crime Complaint Center, Federal Bureau of Investigation, Department of Homeland Security, Experian Information Solutions and National Conference of State Legislatures.
Image: alexskopje / Shutterstock.com
Was this article helpful?