Skip to content
ScamVictimLawyer

Protect your identity after a scam

The scam involved more than money, and you are worried about your personal details now.

Updated 2026-09-29 · Independent resource. Legal review pending.

What exposure actually looks like

A scam that goes beyond a single payment can leave your personal details, an identification number, bank information, or login credentials, in the hands of someone who may reuse them. This is different from a one-time financial loss and needs its own response.

Not every scam exposes this much. If the scam involved sharing a one-time password, a scanned document, or account login details, treat the exposure seriously even if the direct financial loss was limited.

Working out exactly what was shared, and with whom, is the first step to knowing what to secure.

What to lock down first

Start with anything tied to money: your online banking password, any linked e-wallet, and cards connected to the affected account. Securing your online banking covers this step in more detail if you have not already done it.

Change passwords on your email next, since email is often the recovery point for other accounts. If you reused a password across multiple services, change it everywhere it appears, not just on the account that was directly affected.

If a physical or scanned identity document was shared, this carries a longer-term risk than a single transaction and deserves separate attention.

Where stolen details commonly resurface

Personal information is sometimes reused to open new accounts, apply for credit, or register services in your name, which can happen weeks or months after the original scam. This is why a single password change is not always enough on its own.

Keep an eye on your credit report and any notification services your bank offers for new account activity. If you have not already made a police report about the original scam, doing so also creates a record that can support you if identity misuse surfaces later.

Monitoring for ongoing misuse

Set up alerts where available, for new credit applications, unfamiliar logins, or changes to your registered details. Early detection is usually what limits the damage from identity misuse, more than any single protective step.

If something unfamiliar does appear, treat it as a new incident and report it separately rather than assuming it is connected to something already resolved.

What to do next

Prioritise your bank and email first, then work through any other service where you reused the same password or shared similar details. This order reflects where the most immediate risk usually sits.

If you are unsure what was actually exposed or what deserves attention first, a short conversation can help you work through it methodically.

If you are not sure what information was exposed or what to lock down first, tell us what happened and we will help you prioritise.

Common questions

What details should I be most worried about?

Your identification number, bank account details, and any documents like a scanned identity card or passport carry the most risk, since these can be reused to open accounts or apply for credit in your name. Passwords matter too, especially if reused across services.

Should I change all my passwords, not just the affected account?

Yes, particularly if you reuse passwords across services, since a scammer who accessed one account may try the same details elsewhere. Prioritise your bank, email, and any account linked to payments first.

How would I know if someone is using my identity elsewhere?

Watch for unexpected credit applications, unfamiliar accounts, or notifications about logins you did not make. Checking your credit report periodically and setting up alerts where your bank or service providers offer them helps catch this early.

If you are not sure what information was exposed or what to lock down first, tell us what happened and we will help you prioritise.