Skip to content
Support

Significance of Identity Theft

General information about the risks posed by data theft, tips for proactive protection and your rights of access and erasure under GDPR.

As well as using omniac, you should follow the five rules below:

  • Use a unique and strong password for every account.
  • Activate two-factor authentication (2FA) for all your accounts.
  • Delete old accounts that you no longer need (data minimisation).
  • Always make sure your mobile phone and PC have the latest updates.
  • Never click links in e-mails from unknown senders.

Act immediately to limit the damage:

  • Lock: inform your bank straight away and have them lock affected cards or accounts.
  • Change: change the access credentials for all your important accounts.
  • Report: report the incident to An Garda Síochána and inform the people close to you so that no one is tricked by messages from the scammer.
  • Get help: you can find details about who to contact if you are the victim of cyber attacks on the website of An Garda Síochána.

Omniac can help you identify such incidents in good time so you can respond to them faster.

If you are using omniac, you do not need to perform any searches yourself: we send you a warning automatically as soon as we have verified that your data is included in this leak. Note: sometimes, data only appears on criminal forums after some time. We will contact you as soon as it has been found.

If you suddenly find that you can no longer log in to an account, criminals may well have changed your password. Act quickly:

  • Change your e-mail account password immediately. Anyone who has control over this account can reset all your other passwords.
  • Use the “Forgotten password” function for the affected service.
  • Inform your payment provider (for instance, your PayPal or credit card provider) if payment data was being stored there, and report the incident to An Garda Síochána if you have any suspicions.

This usually occurs due to data leaks at large companies (such as social networks or hotels), through hacker attacks or by unknowingly clicking harmful links. Once stolen, your data records are sold on illegal marketplaces, often for just a few dollars. Buyers then use this data to break into your accounts or commit fraud in your name.

You often will not notice the theft until it is too late. Criminals do not just take your data and resell it; they also use it for targeted fraud (social engineering), in order to access your money or conclude contracts in your name. The financial and emotional damage can be immense.

If your data has been exposed due a company data leak, the UK GDPR gives you significant rights for gaining back control. Follow the two steps below to secure yourself:

  1. Find out the details (right of access): what exactly has happened? Before having everything deleted, you should know which exact data has been stolen. This is the only way to respond in a targeted manner (for instance, by blocking a specific credit card). The company is legally obligated to disclose this information about the data to you free of charge.

  2. Deletion: the “right to be forgotten” You can demand for the company to irrevocably delete all your data. Particularly after a security incident, this is a useful way to ensure that no more of your data is being held there insecurely. Only the data stipulated in the legislation is excluded (data for invoicing, for example). You can find a helpful letter template here.