Cyber Risk Compendium

Identity theft

BSI ID: G 0.36

Identity theft involves an attacker assuming a false identity, i.e. using information about another person to act on their behalf. Data such as date of birth, address, credit card or account numbers are used to register with an Internet service provider at someone else's expense or to enrich themselves in other ways.

Identity theft often leads directly or indirectly to damage to reputation, but also causes a great deal of time and effort to investigate the causes and avert negative consequences for those affected. Some forms of identity fraud are also referred to as masquerading. Identity theft occurs particularly frequently where identity checks are handled carelessly, especially when expensive services are based on them. A person who has been deceived about the identity of their communication partner can easily be tricked into revealing sensitive information.

Examples:

  • With various email providers and auction platforms on the Internet, it was initially sufficient to come up with a fictitious name and back it up with a suitable address from the telephone directory in order to register. Initially, attackers were also able to register under recognisably fictitious names, such as those of comic book characters. When stricter plausibility tests were introduced, the names, addresses and account numbers of real people were also used for this purpose. Those affected only found out about this when the first payment requests arrived.

  • Email sender addresses are easy to fake. Users are repeatedly tricked into believing that an email comes from a trusted communication partner. Similar attacks are possible by manipulating the caller ID for voice calls or the sender ID for faxes.

  • An attacker can use a masquerade to try to tap into an existing connection without having to authenticate themselves, as this step has already been completed by the original communication participants.

ย