I’ve written about pieces of this before — the OSINT self-audit, the data broker opt-out slog, what actually happens in a SIM swap — but I kept getting the same question after each one: okay, but where do I start, and in what order? Those articles are each a deep dive into one failure mode. This one is the map that ties them together, because identity protection doesn’t work as a pile of unrelated tips. It works as a system with layers, and the layers have a priority order.
Want the technical reference sheet for this stuff too? Subscribe and get the Security Command Reference free — plus one new deep-dive article a week, no daily spam.
Identity Protection Is a System, Not a Single Fix
Every identity-theft prevention list I’ve seen reads like a grab bag: freeze your credit, use a password manager, don’t overshare on social media. All true, all useless as a list, because they don’t tell you which failure actually gets exploited first, or what depends on what. In practice there are four layers, and they fail in a specific order when someone’s actually targeting you rather than opportunistically phishing a random inbox:
- Exposure — what’s publicly findable about you, which is the recon phase for everything else.
- Interception — your phone number and inbox, which is how most account recovery flows get hijacked.
- Authentication — the actual login credentials protecting your accounts.
- Financial backstop — what happens after prevention fails, because something eventually will.
Most people start at the authentication layer because “use a password manager” is the advice that’s repeated most often. That’s backwards. If your exposure layer is wide open, an attacker doesn’t need to crack your password — they’ll use what’s publicly findable about you to answer your security questions, social-engineer your phone carrier, or convince a support rep they’re you. Fix exposure first.

Layer One: What’s Actually Findable About You
Start with an honest audit of what a stranger with ten minutes and a search engine could learn about you. I wrote up the actual process in OSINT for Personal Security — old forum accounts, conference bios, social media metadata, the stuff that feels harmless individually but adds up to a profile. The uncomfortable part isn’t finding your own name. It’s finding your relatives, your daily routine, and your home address sitting on a data broker site in one aggregated listing.
Once you know what’s out there, the next step is actually doing the data broker opt-outs, which is a bigger job than a one-click unsubscribe and a recurring one, not a one-time task — brokers re-scrape and relist. Do this layer first. Everything downstream — phishing, SIM swaps, social engineering — starts with an attacker having something to work with, and this is where most of that something comes from.
Layer Two: The Phone Number Is the Weak Link
Your phone number is both a contact method and, for most services, a password-reset backdoor. That’s the exact mechanism behind a SIM swap attack — convince your carrier to port your number to a new SIM, and every “text us a code” recovery flow on every account you own just handed itself to someone else. The fixes that actually work: a carrier-side PIN or port-freeze, moving two-factor codes off SMS and onto an authenticator app wherever a service allows it, and treating your phone number as something to compartmentalize rather than hand out by default.
That compartmentalization is also the whole premise behind burner phones for operational security — a separate number for the accounts and transactions where you don’t want your primary identity linked, so a compromise of one doesn’t cascade into everything.
Layer Three: Locking Down Authentication
This is the layer everyone starts with, which is fine once the first two are handled. I use a mix of a password manager for anything without hardware-key support and a physical security key for the handful of accounts that matter most — I laid out exactly which and why in passkeys vs. hardware security keys vs. authenticator apps. The short version: passkeys are the right default going forward, a hardware key is the right call for your email and password manager account specifically (since those two are the recovery path for everything else), and SMS-based 2FA is better than nothing but is also exactly the thing Layer Two is about defeating.
What I actually use: A YubiKey hardware security key — one on my keychain, one in a safe as a backup. Worth the $25-50 for email and password manager accounts specifically.
If you haven’t picked a password manager yet, I compared the actual options — not marketing copy — in password managers compared.
Layer Four: Who’s Actually Trying to Trick You
None of the above matters if you hand over a code or a password because someone called pretending to be your bank’s fraud department. Social engineering defense is the layer that’s hardest to automate a fix for, because the attack targets a person, not a system. The practical version: nobody legitimate asks for a 2FA code over the phone, a callback to a number you looked up yourself beats a callback to a number someone gave you, and the urgency in “this has to happen right now” is itself the tell.

Layer Five: The Financial Backstop
Assume prevention eventually fails somewhere, for someone, even if it’s never you directly — a breach at a company that held your data counts. This is why credit freezes and fraud alerts exist as a layer of their own: they don’t stop someone from getting your information, but they stop that information from being usable to open new credit in your name. A freeze with all three bureaus is free, takes about fifteen minutes total, and is the single highest-value-per-minute action on this entire list — I’d do it before anything else if I were starting completely from zero.
A Layer That Cuts Across All of These: Communication Privacy
Where you actually talk — texts, calls, group chats — is metadata and content that can itself become exposure. I compared the real options in encrypted messaging apps: Signal vs. Session vs. Matrix. For most people, Signal is the right default: strong encryption, minimal metadata retention, and enough adoption that you can actually get the people you talk to onto it.
When You Need More Separation: Burner Identities and Physical Exposure
For researchers, journalists, or anyone whose threat model includes someone specifically motivated to find them, the layers above aren’t always enough — sometimes the right move is a fully separate identity for specific activities. I wrote the actual setup process in building a burner. On the physical side, RFID skimming is mostly overhyped for payment cards specifically, but the underlying concern — contactless credentials being readable at a distance — is real enough for building access badges and passports that a blocking sleeve is worth the ten dollars.
For anyone going deeper on identity separation: Extreme Privacy by Michael Bazzell — the most thorough practical reference I’ve found on this specific topic, and the book I point people to after the burner-identity article.
A Practical Priority Order, If You’re Starting From Zero
- Freeze your credit with all three bureaus. Fifteen minutes, free, highest value per minute of effort on this list.
- Run your own OSINT audit and do the top five data broker opt-outs for the brokers that show up first when you search your own name.
- Add a port-freeze or PIN with your mobile carrier to shut down the easiest SIM swap vector.
- Move your email and password manager onto a hardware security key, since those two accounts are the recovery path for everything else.
- Switch primary 2FA from SMS to an authenticator app or passkey everywhere a service supports it.
- Move sensitive conversations to Signal and get the people you talk to most onto it with you.
- Only then consider burner identities or RFID blocking — they’re real tools, but they solve a narrower problem than the first six steps.
Common Mistakes
Doing the authentication layer first and skipping the exposure layer. A hardware security key doesn’t help if an attacker can social-engineer your carrier using information they found on a data broker site in two minutes.
Treating any of this as a one-time project. Data brokers relist you, SIM swap techniques evolve, and a credit freeze doesn’t un-freeze itself — but none of them stay fixed forever without occasional rechecking.
Assuming this only matters if you’re “a target.” Most of the actual damage from identity theft hits people through breaches at companies they’ve never heard of, not because anyone specifically targeted them.
What This Doesn’t Fix
None of this makes you untraceable or unhackable, and that’s not really the goal. The goal is raising the cost of targeting you from “opportunistic and easy” to “requires actual effort and probably moves on to an easier target instead.” A determined, resourced attacker with a specific reason to go after you specifically is a different threat model than what this guide covers — if that’s your situation, start with the burner-identity and OSINT articles above and treat this as the first pass, not the last one.