Skip to main content
Fraud & Identity Theft Protection

How to Avoid or Recover From Identity Theft

Most identity theft is preventable with a handful of consistent habits, and most of what feels overwhelming after a compromise follows a predictable restoration sequence. This guide covers both: how to reduce your exposure, and how to rebuild if a compromise has already occurred.

Last updated July 20269 min readReviewed by FDR Compliance

Daily prevention habits

Identity theft prevention is mostly a matter of reducing the number of places your personal information sits unprotected. A few habits account for most of the risk reduction available to an individual consumer.

  • Secure your mail. Use a locking mailbox where possible, retrieve mail promptly, and arrange a hold with Canada Post when travelling. Stolen mail remains one of the simplest ways criminals collect pre-approved credit offers and account statements.
  • Shred before discarding. Cross-cut shred any document showing an account number, SIN, date of birth or signature — including expired cards and old statements — rather than placing it in household recycling.
  • Use strong, unique passwords with a password manager. Reusing a password across sites means one breach exposes every account that shares it. A password manager makes unique, long passwords practical without needing to memorize them.
  • Enable multi-factor authentication on banking, email and any account that offers it. A stolen password alone should not be enough to grant access.
  • Limit disclosure of your Social Insurance Number. Very few organizations are legally entitled to it — mainly employers, the CRA and financial institutions for tax-reporting purposes. Ask why it is needed before providing it, and decline if the justification is unclear.
  • Review statements monthly and reconcile every transaction, no matter how small. Small unauthorized test charges often precede larger fraudulent activity.
  • Pull your free credit report annually from both Equifax Canada and TransUnion Canada, and check for accounts or inquiries you do not recognize.

2

Bureaus to check annually (Equifax, TransUnion)

0

Organizations besides CRA, employers & lenders entitled to your SIN

12-24 mo

Recommended monitoring window after any compromise

Spotting phishing, smishing & vishing

Phishing (email), smishing (text message) and vishing (voice call) attacks all rely on urgency and impersonation to get you to act before you think. The delivery channel changes, but the red flags are consistent.

  • Unexpected urgency — "your account will be suspended in 24 hours," "you must confirm payment immediately," or a demand to act before you can verify independently.
  • A request to click a link or call a number provided in the message itself, rather than one you look up independently on an official statement or website.
  • A request for a password, full credit card number, SIN, or a one-time verification code — legitimate organizations will not ask you to read a two-factor code back to them.
  • Generic greetings, subtle spelling or formatting errors, or a sender address that looks close to but not exactly the real domain.
  • Requests for payment by gift card, cryptocurrency or e-transfer to an unfamiliar individual — these payment methods are essentially untraceable and are almost never used by legitimate creditors or government agencies.

When in doubt, hang up and call back

End the call or ignore the message, then contact the organization directly using the number on your card, statement or their official website. A legitimate caller will not object to you verifying independently.

Legitimate vs. fraudulent contact

The table below summarizes the signals that most reliably distinguish a genuine contact from a fraudulent one.

SignalLegitimate contactFraudulent contact
Payment methods requestedCheque, pre-authorized debit, credit card, e-transfer to a verified business accountGift cards, cryptocurrency, wire transfer, e-transfer to a personal name
Information requestedConfirms account details you provide; asks for partial identifiers to verify youAsks you to state your full SIN, full card number, password or 2FA code
Tone and pacingWilling to send written confirmation; comfortable with you calling backHigh pressure, threats of arrest or immediate suspension, discourages verification
Written documentationProvides an account number, agency name and licence details on requestRefuses to provide anything in writing or send a callback number
Contact channelMatches the number or domain on your statement or the agency's public registrationSpoofed number, lookalike domain, or unofficial messaging app

What a legitimate collection agency will ask

A licensed Ontario collection agency, including FDR Asset Group, will identify itself by name, confirm the original creditor and balance, and provide validation of the debt in writing if you request it. It will never ask you to pay by gift card or cryptocurrency, threaten arrest, or demand your full SIN or online banking password over the phone.

If a caller claiming to represent a collection agency cannot provide their agency name, licence information or a callback number, treat the contact as suspicious and verify independently before providing any information or making a payment. If you have questions about a file connected to FDR Asset Group specifically, contact us directly to confirm its legitimacy before responding to any other inquiry.

Full identity restoration protocol

If a compromise has already occurred, restoration follows a fairly consistent sequence over the following weeks and months.

  1. Place alerts with both bureaus. File a fraud alert (consumer statement) with Equifax Canada and TransUnion Canada, and request a current copy of each file.
  2. Dispute inaccurate items in writing. For any account or inquiry you did not authorize, submit a written dispute to the bureau along with your police report number and supporting documentation, and request written confirmation of the outcome.
  3. Open a fraud investigation with each affected creditor. Provide the signed identity theft affidavit or statutory declaration each creditor requires, and ask for written confirmation once the account has been corrected or closed.
  4. Continue monitoring for 12 to 24 months. Fraudulent use of stolen information often resurfaces months after the initial incident. Re-check your bureau files periodically and renew fraud alerts before they expire.
  5. Update credentials broadly. Change passwords on any account that shared a compromised password, and enable multi-factor authentication wherever it was missing.

A restored file does not close the loop instantly

Expect the full restoration process to take weeks rather than days. Keep your written incident log current throughout, and if an account connected to FDR Asset Group is affected, reach out so we can flag the file appropriately while your dispute is investigated. Once resolved, we can also discuss payment options for any legitimate balance that remains.

Frequently asked questions