And How to Actually Protect Yourself
I found the idea for this article in a genuinely unlikely place, visiting a site called ScamAdviser, of all things, checking some sites trust score. Sitting right there in ScamAdviser’s own ad slots: a $89 device that supposedly replaces your air conditioner, and a “credit hack” promising an 800+ score in 30 days. A site whose entire purpose is warning people about scams was running ads for the exact same category of claim it exists to flag. That’s not irony, that’s just how much of this ecosystem actually works, the line between “the site warning you” and “the site selling you the same pitch” is thinner than it looks.
Short version: the “credit hack” ad type is usually selling something called a CPN, a fake or stolen number marketed as a legal fresh start, and using one is a federal crime, not a shortcut. Identity theft itself is getting harder to spot because scammers now use AI to clone voices and faces convincingly. The single strongest, completely free defense against both is a credit freeze at all three bureaus, not a paid monitoring subscription.
The Credit Repair Scam You’re Most Likely to Actually See: CPNs
If you’ve seen an ad promising to erase bad credit and hand you a fresh 800+ score in 30 days, there’s a good chance it’s selling a CPN, a “Credit Privacy Number.” It’s marketed as a legal alternative to your Social Security number, something you can use on credit applications instead of your real SSN to hide bankruptcy, collections, or a thin credit history.
Here’s the problem: CPNs aren’t real. They’re not issued by the government, not recognized by any federal agency, and using one on a credit application is a federal crime, specifically, making false statements on a loan or credit application, and in many cases identity theft itself. The Department of Justice has pursued sentences of 15 to 30 years for identity theft crimes tied to schemes like this.
Worse, the number itself is frequently a stolen Social Security number, sometimes belonging to children, the elderly, or incarcerated individuals, people whose SSNs sit unused long enough that fraud goes undetected. If you buy and use one, you’re not just risking your own legal exposure, you may be using someone else’s stolen identity without realizing it.
Red flags that you’re being sold a CPN, whether or not the seller uses that exact term: a company promises to hide bankruptcy or collections and give you a “clean slate.” They tell you a new number will “protect your identity.” They ask you to use a different mailing address or phone number on applications. They promise a specific score, like 700+ or 800+, within a specific short timeframe. They require payment before doing anything, sometimes thousands of dollars for a number the government issues for free (because it doesn’t issue CPNs at all, that’s the whole scam).
If you’re already working with a credit repair company and any of this sounds familiar, walk away. I’ve covered the broader category of credit repair scams, including legitimate versus predatory companies, in Credit Repair Scams, this CPN pattern specifically is one of the most dangerous versions of that broader problem because it can turn a credit problem into a federal criminal one.
How Identity Theft Actually Happens
CPN scams are one specific, active path into identity theft, but they’re far from the only one. The broader ways your information ends up in the wrong hands:
Data breaches. Companies you’ve done business with, banks, retailers, healthcare providers, get hacked, and your information sits in a leaked database. You often won’t know this happened until you get a notification letter, sometimes months later.
Phishing. Fake emails or texts designed to look like they’re from your bank, the IRS, or a delivery company, built to get you to click a link and enter your login credentials or personal information directly.
Mail and physical theft. Stolen mail, a lost wallet, or a discarded document with your SSN or account numbers still on it. Less common than digital theft now, but still a real vector, especially for older family members.
Public Wi-Fi and unsecured connections. Logging into a bank account or entering personal information on public Wi-Fi without a secure connection can expose that data to anyone else on the same network.
Someone you know. Uncomfortable to say, but real: family identity theft, where a relative uses a child’s or another family member’s SSN, is common enough that it has its own specific recovery process through the FTC.
The New Threat: AI-Powered Scams
This is the part of identity theft that’s changed the most, and fastest, and it’s worth taking seriously rather than treating as science fiction.
The FBI’s Internet Crime Complaint Center created its first-ever AI-related crime category in 2025, logging over 22,000 complaints and roughly $893 million in losses in that category alone. The FTC has recorded a 1,200% increase in deepfake-related complaints between 2023 and 2025. And according to McAfee’s voice-cloning research, just three seconds of audio, a voicemail greeting, a social media video, a work call, is enough to clone a voice with a convincing match, and 70% of people say they’re not confident they could tell a cloned voice from a real one.
What this looks like in practice: a call that sounds exactly like a family member in distress, urgently asking for money to be wired or sent via gift cards. A voicemail that sounds like your bank’s fraud department, walking you through “verifying” your account details. A video call where the person’s face and voice both seem right, because both were generated to seem right.
The defense here isn’t more vigilance, you genuinely cannot always tell by ear or by eye anymore. The defense is a process that doesn’t depend on trusting what you’re hearing or seeing in the moment:
Set up a family safe phrase. A word or short phrase only your actual family knows, something a scammer scraping social media couldn’t guess. If a call claims to be a relative in an emergency, ask for the phrase before doing anything else.
Hang up and call back on a number you already have. Never call back a number given to you during the suspicious call itself, even if caller ID looks right, caller ID can be spoofed. Use the number already saved in your phone or from official websites/documents.
Build in a mandatory pause. No legitimate emergency requires you to wire money, buy gift cards, or send crypto in the next five minutes. That urgency is the manipulation, not a real constraint. A 30-second pause to call someone else and verify stops the overwhelming majority of these.
Credit Freeze vs. Credit Lock: What Actually Protects You
This is the single most effective, and most underused, free defense against identity theft, and it’s worth understanding the real difference between the two options you’ll see offered.
A credit freeze is free, federally mandated, and the strongest legal protection available. Under federal law (the Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018), all three major bureaus, Equifax, Experian, and TransUnion, must let you freeze your credit report for free, and once frozen, lenders cannot access your report to open a new account in your name. A thief with your stolen SSN literally cannot open new credit if your reports are frozen, because whoever they’re applying with can’t pull your file.
A credit lock is a convenience feature, not a legal right. Locks do something similar, restrict access to your report, but they’re governed by each bureau’s own terms of service, not federal law, and they’re often bundled into a paid monitoring subscription. Equifax’s Lock & Alert is free. Experian’s lock, by contrast, requires their paid IdentityWorks membership, up to roughly $25 a month, for a protection that’s functionally similar to what a freeze already gives you for free.
The practical recommendation most security researchers land on: freeze first, since it’s free and legally backed, and only consider a paid lock if you specifically want the convenience of an app toggle and you’re already paying for that bureau’s other services anyway. Don’t pay monthly for something the law already gives you at no cost.
One detail most guides skip: freezing only Equifax, Experian, and TransUnion isn’t complete coverage. Two smaller bureaus, Innovis and NCTUE, are used by some specialty lenders and utility companies and are worth freezing too for full protection.
To freeze your credit, you’ll need to set up a free account with each bureau individually, there’s no single site that freezes all of them at once. It typically takes effect within a day, and if you need to apply for real credit later, temporarily lifting it takes just a few minutes online.
One thing worth learning from my own mistake here: don’t wait until you’re actually filling out paperwork to unfreeze. I found this out the hard way buying a car last year. My credit was frozen, and by the time the dealer got around to running my application, they’d already been turned down by their first lender and moved on to a second, then a third, then a fourth bank before anyone thought to check whether the freeze was the actual problem.
Here’s what made that worse than it needed to be: normally, multiple auto loan inquiries within a short window, usually 14 to 45 days depending on the scoring model, get bundled together and only count as one hit to your score. That’s built in specifically so you can rate-shop without being punished for it. But when a freeze forces those applications to trickle out over several days instead of happening close together, that bundling protection can break down, and you can end up eating a separate inquiry for every single lender instead of one combined hit. That’s exactly what happened to me, four inquiries, a real (if small) ding to my score, for something that should have been a non-event.
The fix: if you know a big purchase, a car, a mortgage, is coming, unfreeze proactively before you walk into the dealership or start the loan process, not after something’s already gone sideways.
Warning Signs You’ve Already Been Targeted
A few signals worth taking seriously rather than dismissing:
An unexpected fraud alert or hard inquiry notification you didn’t request. A bill or collections notice for an account you never opened. A sudden, unexplained drop in your credit score. Mail that stops arriving as expected (a sign someone may have filed a change of address in your name). A data breach notification letter naming a company you’ve done business with. Calls or texts from collectors about debts that aren’t yours.
Any one of these is worth checking on immediately, not waiting to see if it happens again.
Is Paid Monitoring Worth It?
Services like LifeLock and Aura get marketed heavily, and it’s worth being honest about what they actually do versus what a free credit freeze already does.
Monitoring alerts you after something’s already happened. A freeze prevents it from happening in the first place. That’s the core distinction. Monitoring services watch for new accounts, dark web mentions of your information, and suspicious activity, then notify you, sometimes within minutes, sometimes with a delay depending on the service and plan. A freeze blocks the new account from being opened at all. Both have a place, but they’re not interchangeable, and a lot of marketing blurs that distinction.
Worth knowing before you pay for anything: LifeLock’s cheapest tier, around $9 a month, only monitors one credit bureau, despite the marketing generally implying comprehensive coverage. Getting genuine three-bureau monitoring and the higher insurance amounts advertised usually means their most expensive tier, closer to $35 a month. LifeLock also settled a $100 million FTC complaint in 2015 over deceptive advertising practices, worth knowing as background, not necessarily disqualifying at this point, but worth factoring in.
If you do want paid monitoring on top of a free freeze, look specifically at whether a plan includes all three bureaus from its base tier (Aura does this from its base plan; LifeLock doesn’t), and treat the insurance/reimbursement numbers in the marketing with some skepticism, they typically cover the cost of recovery services and lawyers, not necessarily a direct check for money a thief actually stole.
For most people, the honest answer is: freeze your credit for free at all five bureaus, and skip the monthly subscription unless you specifically want dark web monitoring or you’ve already been a victim once and want the extra layer.
What to Do If It Happens to You
If you suspect you’re already a victim:
Go to IdentityTheft.gov first. This is the FTC’s official recovery site. It walks you through a personalized recovery plan based on exactly what type of theft happened, and generates an official FTC Identity Theft Report you can use with creditors, bureaus, and police.
Place a fraud alert or freeze immediately at all three major bureaus if you haven’t already. A confirmed identity theft victim can request an extended fraud alert that lasts seven years, rather than the standard one-year alert.
Contact the fraud department directly for any account you know was compromised.
File a police report, especially if you know the person responsible or if a creditor requires one to remove fraudulent charges.
Review your credit reports from all three bureaus for any accounts or inquiries you don’t recognize. You’re entitled to free reports through AnnualCreditReport.com.
None of this fixes itself quickly. But acting fast, and following the actual FTC process rather than a random “credit repair” company’s shortcut, is what actually limits the damage.
If you found this after already dealing with a scam attempt targeting your income or job search specifically, the patterns overlap with several other things I’ve covered: Fake Job Offer Red Flags, Money Mule Job Scams, and Fake Compliance Notice Scams all use similar urgency-and-legitimacy tactics to the ones covered here.
Frequently Asked Questions
No. CPNs are not issued or recognized by any government agency, and using one on a credit or loan application is a federal crime, regardless of how it’s marketed to you. Many CPNs are also stolen Social Security numbers.
Freeze first. It’s free at all three major bureaus, federally mandated, and provides stronger legal protection than a lock, which is governed only by each bureau’s own terms of service and is often part of a paid subscription.
Yes. Research from McAfee found 70% of people aren’t confident they could distinguish a cloned voice from a real one, and just a few seconds of audio is enough to generate a convincing clone. The defense isn’t better listening, it’s a verification process like a family safe phrase and calling back on a known number.
It can add value, but it doesn’t replace a free credit freeze. Monitoring alerts you after suspicious activity happens; a freeze prevents new accounts from being opened in the first place. Check exactly what a plan’s cheapest tier actually covers before paying, some budget tiers only monitor one credit bureau despite marketing that implies full coverage.
Go to IdentityTheft.gov, the FTC’s official recovery site. It builds a personalized recovery plan and generates an official report you can use with creditors, credit bureaus, and police, rather than relying on a private company’s process.
Yes, proactively, before you start the application, not after. If a dealer or lender has to pause and wait for you to unfreeze mid-process, your applications can end up spread out over several days instead of happening close together, which can break the rate-shopping protection that normally bundles multiple similar inquiries into a single hit on your score.
Sources
CPN scams, legal consequences, and stolen SSN patterns: Experian, Capital One
FBI IC3 2025 AI crime category and losses: Netarx
FTC deepfake complaint increase and McAfee voice-cloning research: SQ Magazine, Netarx
Credit freeze federal law and Innovis/NCTUE coverage: ScoreNerds, ScoreNerds
LifeLock tier coverage and FTC settlement history: Deepak Gupta
