If you notice signs of misuse
If money or banking access is at risk, contact your bank immediately through its app or a known official number. For an unfamiliar loan, contract or account change, contact the institution named in the notification independently of the message itself.
- Explain what you did not request or authorise, and ask what protection and checks are possible.
- Keep notifications, event times and a record of conversations. Note any case reference you receive.
- If an account has been taken over, follow the recovery steps. For a work account, involve internal IT or security support.
- You can report a cyber incident to FIN-CSIRT. Do not send passwords, PINs or one-time codes. Reporting does not replace contacting the bank or another relevant institution.
What is identity theft?
Identity theft is the use of someone else’s personal or financial information without permission to commit fraud. It may involve opening an account, applying for credit or buying something in another person’s name. Criminals may obtain information through phishing, compromised accounts or trading stolen data.
Which signs should you check?
Look out for unfamiliar transactions, notices about contracts you did not enter into and contact-detail changes you did not request. These signs need investigation; they do not establish how a problem occurred.
A notification can itself be bait: a message about supposed misuse may lead to a fake form. Check through the official app, a website you open yourself or a telephone number you already know.
How can you reduce exposure?
- Use a long, unique password for each account.
- Enable 2FA where available and do not approve unfamiliar sign-ins.
- Before sharing personal information, check who is requesting it and why.
- Review banking and service notifications regularly. Keep devices and security software updated.
Sharing personal information does not automatically mean every account has been taken over. Act according to what was exposed and what the institution confirms; if payment details were exposed, do not wait for evidence of financial loss.
Check your knowledge · 3
of 5
Your turn to choose the next step.
Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.
Questions and explanations are also available without JavaScript.
Without JavaScript, the full bank of 5 questions is shown.
You receive a message about credit you did not apply for. What is the best first step?
Why does this matter? An unexpected notice may indicate real identity misuse or merely be phishing bait. An independent check helps distinguish these possibilities without entering more information into a suspicious form.
-
Open the cancellation button in the message.
The notification itself could be phishing. The cancellation button may lead to a form intended to steal information, even though you are trying to prevent harm.
-
Check the notification with the bank through its official channel.Correct answer
Independent contact lets you investigate without relying on the suspicious message. The bank can check whether such a request exists instead of you judging its truth from the message’s appearance.
-
Delete it because I did not apply.
Deleting without checking could miss actual misuse. If the notice is genuine, this misses an opportunity to dispute an action you did not authorise promptly.
The bank confirms a change you did not request. What do you keep for follow-up?
Why does this matter? Following up misuse requires linking events and earlier reports. Useful records explain what happened, but should not create new exposure by publishing passwords or codes.
-
Only my memory of the conversation.
A written record helps with follow-up checks. Memory can omit a time, an agreed action or a case number that helps the next person locate the matter.
-
My password in a public warning post.
Never publish passwords or include them in a report. Warning others does not require disclosing access details; a public password can enable further misuse.
-
Notifications, event times and any case reference I receive.Correct answer
This record helps track the case without publicly exposing secrets. These details connect reports and institutional responses, reducing the need to reconstruct the whole sequence each time.
You entered banking sign-in details into a suspicious form. What takes priority?
Why does this matter? Access details can be used after you close the form. The absence of an immediately visible transaction therefore does not establish that access is protected.
-
Contact my bank immediately through an official channel.Correct answer
The bank needs to assess protection before the details can be used further. The bank can assess protection for the exposed access before delay allows further misuse.
-
Wait for an unfamiliar transaction.
No visible transaction does not mean the details are safe. Waiting uses possible harm as the trigger for action even though you already know you gave details to an unverified site.
-
Finish the quiz and other lessons first.
Education should not delay urgent protection of banking access. Learning can wait; delaying bank contact does not reduce the exposure of information already disclosed.
A required identity-document copy contains more information than the recipient needs. What do you do?
Why does this matter? Every unnecessary data point increases the impact if the document reaches the wrong person.
-
Verify the request and confirm which data is genuinely required and how to provide it safely.Correct answer
Checking purpose, scope and channel reduces unnecessary exposure.
-
Send the complete document through the first link in the message.
A message link may be false, and the full document may disclose more than necessary.
-
Publish the copy and send a public link.
A public link creates new and uncontrolled exposure.
Unrelated changes begin appearing across several accounts. What should you record?
Why does this matter? A timeline helps connect events and gives each institution precise information.
-
Time, account, type of change, institution contacted and case reference.Correct answer
This record supports follow-up without exposing more secrets.
-
Only the total number of messages.
Message count does not describe what changed or where.
-
All passwords so the institutions can check them.
Passwords should not be shared or included in an incident record.
No registration. Your answers are not sent; the result is just for you.