Back to Glossary

Entry · Corporate Finance

Identity Theft

Identity theft is the use of another person's personal details, such as a name, date of birth, account number or tax reference, to obtain money, credit or services in their name. It ranges from a single cloned payment card to the complete takeover of someone's financial identity.

Victims often discover it only when a statement, a rejected application or a debt collector reveals activity they never authorised.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

The raw material is personal data, and it reaches criminals through data breaches, phishing messages, stolen post, insider leaks and simple oversharing online. Once assembled, a set of details is enough to open accounts, redirect deliveries, apply for credit or file a fraudulent tax refund.

The stolen identity is often resold several times before it is used. For businesses this is not only a customer problem, it is a direct operating cost.

Firms absorb chargebacks, write off fraudulent credit, pay for investigations and lose customers who blame them for weak controls. Banks, telecoms companies and retailers therefore run identity verification checks that are themselves a meaningful line in the operating budget.

Finance teams treat identity fraud as an expected loss and provide for it in the same way they provide for bad debts. The usual measure is fraud losses as a percentage of transaction value, tracked monthly against a tolerance.

Controls are then sized against that figure, because tighter checks cut losses but also reject genuine customers, and those false declines have their own cost. Two variants cause most of the trouble.

Synthetic identity fraud combines real and invented details to build a credit file that behaves impeccably for months before every available limit is drawn down at once. Account takeover instead uses stolen credentials on an existing account, and is often spotted faster because established spending patterns change abruptly.

Recovery is administrative rather than dramatic: freezing credit files, filing reports, disputing entries and waiting for corrections to work through the system. The time cost frequently exceeds the cash loss, particularly for the self-employed who lose billable hours.

Insurance products cover some of this, but they reimburse costs rather than preventing the disruption.

In practice

Real-world examples.

1

Example

An online electronics retailer notices a cluster of orders shipping to the same forwarding address under different names. Investigation shows stolen identities used to open buy-now-pay-later accounts, and the retailer adds address velocity checks that cut fraudulent orders by two thirds.

2

Example

A mid-sized employer receives a payroll email asking to change an employee's bank details, apparently from that employee. Because the finance team requires a callback to a number held on file rather than the one in the email, the attempt fails before any salary is diverted.

3

Example

A property lawyer verifying a seller's identity spots that the passport details do not match the title register history. The transaction is halted, preventing a fraudulent sale of a house whose real owner lived abroad.

Formula

Calculation

Total Cost of an Identity Theft Incident = Unrecovered Direct Loss + Recovery Time Cost + Protective Costs A self-employed consultant discovers that a fraudster has opened a store card and made $4,200 of purchases in her name. The card issuer accepts the fraud claim and writes off $3,500, but $700 relating to a cash advance is disputed and ultimately not reimbursed. Unrecovered direct loss = $4,200 - $3,500 = $700. She spends 12 hours over three months on calls, statements and disputes. Valuing that at her normal billing rate of $45 an hour gives a recovery time cost of 12 x $45 = $540. She then subscribes to credit monitoring at $15 a month for two years, a protective cost of $15 x 24 = $360. Total cost = $700 + $540 + $360 = $1,600. The headline fraud was $4,200, but the amount she personally bore was $1,600, and more than half of that was time and prevention rather than the theft itself.

Case study

Seen in the real world.

Copperline Telecom is a fictional mobile network used purely to illustrate how identity fraud is managed commercially. Over one quarter it wrote off $1,600,000 of handset contracts opened with stolen identities, against total contract sales of $80,000,000, giving a fraud loss rate of 2%.

The board's first instinct was to tighten checks across the board. Modelling showed that the stricter rules would cut fraud losses to about $600,000 but would also decline roughly 4% of genuine applications, worth an estimated $2,400,000 of lifetime margin. The saving of $1,000,000 was smaller than the business being turned away.

Copperline instead applied the strict checks only to the high-risk segment where most losses were concentrated: same-day upgrades shipped to a new address. In this illustrative account fraud losses fell to about $800,000 while genuine declines rose by well under 1%, showing that fraud control is an optimisation problem rather than a simple matter of saying no more often.

Watch out

Common mistakes.

  • Believing identity theft only affects careless people, when most stolen data comes from breaches at organisations the victim had no control over.
  • Treating fraud losses as an unavoidable cost of doing business without measuring them as a percentage of transaction value, which hides whether the problem is growing.
  • Tightening verification everywhere after an incident, ignoring the larger revenue lost from declining genuine customers.

Questions

People also ask.

What is the first thing a victim should do?

Contact the affected bank or lender immediately, then place a fraud alert or freeze on their credit files so that new applications cannot be opened.

Does a business have to tell customers their data was stolen?

In most jurisdictions yes, notification within a defined period is a legal requirement, and the specific rules and deadlines vary by region.

Is identity theft insurance worth buying?

It mainly reimburses recovery costs and provides case-handling support rather than preventing the theft, so the value depends on how much you would otherwise pay for that help.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.