Daily prevention habits
Identity theft prevention is mostly a matter of reducing the number of places your personal information sits unprotected. A few habits account for most of the risk reduction available to an individual consumer.
- Secure your mail. Use a locking mailbox where possible, retrieve mail promptly, and arrange a hold with Canada Post when travelling. Stolen mail remains one of the simplest ways criminals collect pre-approved credit offers and account statements.
- Shred before discarding. Cross-cut shred any document showing an account number, SIN, date of birth or signature — including expired cards and old statements — rather than placing it in household recycling.
- Use strong, unique passwords with a password manager. Reusing a password across sites means one breach exposes every account that shares it. A password manager makes unique, long passwords practical without needing to memorize them.
- Enable multi-factor authentication on banking, email and any account that offers it. A stolen password alone should not be enough to grant access.
- Limit disclosure of your Social Insurance Number. Very few organizations are legally entitled to it — mainly employers, the CRA and financial institutions for tax-reporting purposes. Ask why it is needed before providing it, and decline if the justification is unclear.
- Review statements monthly and reconcile every transaction, no matter how small. Small unauthorized test charges often precede larger fraudulent activity.
- Pull your free credit report annually from both Equifax Canada and TransUnion Canada, and check for accounts or inquiries you do not recognize.
2
Bureaus to check annually (Equifax, TransUnion)
0
Organizations besides CRA, employers & lenders entitled to your SIN
12-24 mo
Recommended monitoring window after any compromise
Spotting phishing, smishing & vishing
Phishing (email), smishing (text message) and vishing (voice call) attacks all rely on urgency and impersonation to get you to act before you think. The delivery channel changes, but the red flags are consistent.
- Unexpected urgency — "your account will be suspended in 24 hours," "you must confirm payment immediately," or a demand to act before you can verify independently.
- A request to click a link or call a number provided in the message itself, rather than one you look up independently on an official statement or website.
- A request for a password, full credit card number, SIN, or a one-time verification code — legitimate organizations will not ask you to read a two-factor code back to them.
- Generic greetings, subtle spelling or formatting errors, or a sender address that looks close to but not exactly the real domain.
- Requests for payment by gift card, cryptocurrency or e-transfer to an unfamiliar individual — these payment methods are essentially untraceable and are almost never used by legitimate creditors or government agencies.
When in doubt, hang up and call back
End the call or ignore the message, then contact the organization directly using the number on your card, statement or their official website. A legitimate caller will not object to you verifying independently.
Legitimate vs. fraudulent contact
The table below summarizes the signals that most reliably distinguish a genuine contact from a fraudulent one.
| Signal | Legitimate contact | Fraudulent contact |
|---|---|---|
| Payment methods requested | Cheque, pre-authorized debit, credit card, e-transfer to a verified business account | Gift cards, cryptocurrency, wire transfer, e-transfer to a personal name |
| Information requested | Confirms account details you provide; asks for partial identifiers to verify you | Asks you to state your full SIN, full card number, password or 2FA code |
| Tone and pacing | Willing to send written confirmation; comfortable with you calling back | High pressure, threats of arrest or immediate suspension, discourages verification |
| Written documentation | Provides an account number, agency name and licence details on request | Refuses to provide anything in writing or send a callback number |
| Contact channel | Matches the number or domain on your statement or the agency's public registration | Spoofed number, lookalike domain, or unofficial messaging app |
What a legitimate collection agency will ask
A licensed Ontario collection agency, including FDR Asset Group, will identify itself by name, confirm the original creditor and balance, and provide validation of the debt in writing if you request it. It will never ask you to pay by gift card or cryptocurrency, threaten arrest, or demand your full SIN or online banking password over the phone.
If a caller claiming to represent a collection agency cannot provide their agency name, licence information or a callback number, treat the contact as suspicious and verify independently before providing any information or making a payment. If you have questions about a file connected to FDR Asset Group specifically, contact us directly to confirm its legitimacy before responding to any other inquiry.
Full identity restoration protocol
If a compromise has already occurred, restoration follows a fairly consistent sequence over the following weeks and months.
- Place alerts with both bureaus. File a fraud alert (consumer statement) with Equifax Canada and TransUnion Canada, and request a current copy of each file.
- Dispute inaccurate items in writing. For any account or inquiry you did not authorize, submit a written dispute to the bureau along with your police report number and supporting documentation, and request written confirmation of the outcome.
- Open a fraud investigation with each affected creditor. Provide the signed identity theft affidavit or statutory declaration each creditor requires, and ask for written confirmation once the account has been corrected or closed.
- Continue monitoring for 12 to 24 months. Fraudulent use of stolen information often resurfaces months after the initial incident. Re-check your bureau files periodically and renew fraud alerts before they expire.
- Update credentials broadly. Change passwords on any account that shared a compromised password, and enable multi-factor authentication wherever it was missing.
A restored file does not close the loop instantly
Expect the full restoration process to take weeks rather than days. Keep your written incident log current throughout, and if an account connected to FDR Asset Group is affected, reach out so we can flag the file appropriately while your dispute is investigated. Once resolved, we can also discuss payment options for any legitimate balance that remains.
