Identity Theft Not That Frequent, Study Says

SAN DIEGO, Calif. — Despite the barrage of doomsday new stories decrying the perils of identity theft, especially around the holiday season, a new study from fraud detection firm ID Analytics suggests most worries are actually overblown.

So much so, in fact, that ID Analytics co-founder Mike Cook said consumers needn’t always be notified if their personal data is compromised.

The company looked at four recent dangerous security breaches in its study — ones in which thieves uncovered sensitive information like social security numbers and other personal data — that involved roughly a half million consumers.

Although Cook would not reveal the names of the companies studied, he said one of them involved a “top five U.S. bank.”

Despite the frightening amount of potential victims, Cook said only about 1 in 1,000 ended up having their identities stolen.

Interestingly, the ID Analytics study also found that the greater the security breach, the less likely stolen data was used to compromise a person’s identity.

“If you're in a breach of 100, 200 or 250 names, there's a pretty high probability that you're identity is going to be used,” Cook said, comparing stolen information against fraudulent credit applications. “The reason for that is if you look at how long it takes a fraudster to use an identity, they can roughly use 100 to 250 in a year. But as the size of the breach grows, it drops off pretty drastically.”

Cook said the biggest hindrance to identity theft is the simple fact that most stolen credit card numbers are quickly cancelled, preventing any sustained illegal use. He also said that actually stealing someone’s identity is far more difficult than most people suspect, involving the piecing together of a long chain of disconnected data from multiple sources before identity can be fully compromised.

Because of this, the official stance from ID Analytics is that data breaches should not always be publicized, something consumers may not respond well to despite the reportedly small chance of becoming a victim.

“As far as notifications, we think there are certain instances where businesses might want to notify consumers and certain instances where they might not to inform them,” Cook said. “For instance, if they lose data, and they don't know where it is, we think too many notices may not be a good thing. They should probably monitor that and spend dollars on consumers who are actually harmed, rather than spending dollars on 10 million [likely unaffected] consumers.”

Cook’s statement flies in the face of recent moves by Sen. Arlen Specter, R-Penn., and Sen. Patrick Leahy, D-Vt., both of whom are pushing Congress to enact tougher data security and consumer notification standards in the U.S.

The study also comes less than a month after a report from Internet security firm iDefense suggested keylogger programs that record user names, passwords, credit card data and other sensitive information without a user’s knowledge are becoming much more prevalent, growing 65 percent in the last year.

But the ID Analytics study countered that many incidents involving perceived identity theft are harmless, often perpetuated by people the victims know, and do not result in financial hardships or other serious implications.

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

2026 XBIZ Miami Conference Schedule Announced

XBIZ is pleased to announce the release of the full show schedule for XBIZ Miami, set to take place May 11-14 at the Goodtime Hotel in South Beach.

UPDATED: Utah VPN Rule Enforcement Paused in Aylo Lawsuit

Provisions of a new Utah law making adult websites liable if minors in the state circumvent geolocation efforts to bypass age verification, which were set to come into force on Wednesday, have been put on hold until Sept. 3.

JustFor.fans Launches 'JFF Create' iPhone App

JustFor.fans (JFF) has launched its new iPhone creator management app, JFF Create.

ShootXEvents Joins ASACP as Media Sponsor

ShootXEvents has signed on as an in-kind media sponsor for the Association of Sites Advocating Child Protection (ASACP).

Pornhub Unblocks UK Users on iOS Devices, Citing Apple AV Effectiveness

Pornhub parent company Aylo on Tuesday announced that users in the United Kingdom will once again be able to access the popular site if they are using Apple devices and have confirmed their age through Apple’s U.K. age-verification process.

FSC Launches 'Know Your Rights' 1st Amendment Resource Page

The Free Speech Coalition (FSC) has launched "Know Your Rights," a resource page detailing First Amendment protest guidelines.

Utah VPN Rule for Adult Sites Takes Effect This Week

A new law in Utah comes into force Wednesday, making adult websites liable if minors in the state circumvent geolocation efforts to bypass age verification.

UPDATED: Court Approves Class Action in Labor Claims Against VMG

A U.S. district court has granted class certification in a civil lawsuit filed against Vixen Media Group (VMG) by retired performer Kenzie Anne, making it possible for additional performers to join in a class action against the company.

Brazil Invites Public Input on Guidelines for New Digital Law

Brazil’s National Data Protection Authority (ANPD) is soliciting public comments to help improve interpretation and application of the country’s Digital Statute for Children and Adolescents (Digital ECA), which requires adult websites to age-verify users located in Brazil.

X3 Expo Unveils Euro All-Stars for Inaugural Amsterdam Edition

X3 Expo, Hollywood's premier adult entertainment expo, makes its European debut at Passenger Terminal Amsterdam Sept. 11-12, bringing together fans, creators, and industry insiders for the Continent’s largest assembly of adult entertainment stars, alongside a dazzling lineup of attractions spotlighting the cutting edge of modern media and pleasure tech.

Show More