Identity Theft Statistics and Fraud Losses: What FTC Consumer Sentinel Data Shows

A laptop and phone showing sample account security screens beside a passport, a card, and an identity protection checklist

Identity theft is often discussed together with fraud, scams, phishing, cybercrime, and account takeover.

Those categories overlap, but they are not identical.

That distinction matters because statistics can become misleading when reports from different systems are added together as though they measure the same event.

A stolen identity may be used to open a credit account.

A fraud victim may send money to an impersonator without having an identity stolen.

A phishing email may fail before any financial loss occurs.

A ransomware incident may affect an organization rather than an individual consumer.

Useful identity theft statistics preserve those definitions.

The latest Federal Trade Commission data show that reported consumer fraud losses reached record levels in 2025, while identity theft remained a major part of the FTC's Consumer Sentinel reporting system.

Key Takeaways

The points below summarize the latest identity theft statistics and the fraud figures reported alongside them.

Identity Theft Statistics at a Glance

The table gathers the headline identity theft statistics from the FTC's June 2026 release on imposter scams and its fiscal 2025 annual performance report. These are fraud-loss and report totals. The sources checked for this page do not give a separate 2025 count of identity theft reports, so none is shown.

MetricLatest Verified FigurePeriod
Total reported fraud lossesAbout $16B2025
Imposter scam losses$3.5B2025
Business impersonator lossesNearly $1B2025
Government impersonator lossesAbout $920M2025
Consumer Sentinel reports addedMore than 9.2MFY2025
Law enforcement users with CSN accessNearly 2,400FY2025

Reported Fraud Losses Reached About $16 Billion

The FTC said consumers reported losing approximately $16 billion to fraud in 2025.

That was the highest amount on record.

Reported losses increased about 25% from 2024.

This is one of the clearest indicators that the economic cost of consumer fraud is rising.

However, it should not be mislabeled as an identity-theft loss figure.

The $16 billion total covers multiple fraud categories.

That distinction protects the analysis from exaggeration.

Imposter Scams Cost Consumers $3.5 Billion

Imposter scams generated $3.5 billion in reported losses in 2025.

The FTC said nearly one in three fraud reports involved impersonation.

These scams can involve criminals pretending to be banks, government agencies, businesses, family members, technical-support staff, law enforcement, or other trusted parties.

Impersonation is powerful because the scam does not necessarily require sophisticated hacking.

It requires the victim to believe the communication.

Bank Impersonation Is Especially Costly

The FTC said business impersonation scams generated nearly $1 billion in reported losses in 2025.

Within that category, bank impersonators produced the highest reported losses.

This is an important financial-security signal.

Consumers may trust a message that appears to come from their bank because financial institutions legitimately contact customers about suspicious activity.

Scammers exploit that expectation.

The victim may be instructed to transfer money, reveal a security code, install remote-access software, move funds to a “safe” account, or provide login credentials.

The scam turns trust into a payment mechanism.

Government Impersonation Losses Reached About $920 Million

The FTC reported approximately $920 million in government-impersonation losses during 2025.

That increased from about $789 million in 2024.

Government impersonation often uses fear.

Victims may be told they owe taxes, face arrest, have immigration problems, or must make an urgent payment.

The requested payment method can itself be a warning sign.

Legitimate government agencies generally do not demand immediate payment through cryptocurrency, gift cards, or unusual money-transfer methods.

Identity Theft Is Different From Imposter Fraud

Identity theft generally involves someone using another person's identifying information without permission.

Examples include using stolen information to open a credit card, obtain a loan, access an existing bank account, claim government benefits, file a fraudulent tax return, or create accounts in the victim's name.

Imposter fraud may involve pretending to be someone trustworthy without stealing the victim's identity.

The categories can overlap.

A scammer can impersonate a bank employee and then steal enough information to take over the victim's account.

That event may involve both fraud and identity theft.

The FTC Consumer Sentinel Network Is Broader Than Identity Theft

The FTC's Consumer Sentinel Network is a database used by law enforcement.

In fiscal 2025, more than 9.2 million fraud, identity theft, financial, and Do Not Call reports were added to the network.

That number should not be quoted as “9.2 million identity-theft cases.”

It includes several categories.

This is an example of why source definitions matter.

Large numbers attract attention.

Accurate labels protect credibility.

Financial Identity Theft Can Take Several Forms

Financial identity theft includes misuse of personal information in financial accounts.

Common patterns include:

New-Account Fraud

The criminal uses stolen identity information to open a new account.

This may include credit cards, loans, deposit accounts, telecom accounts, or other services.

Account Takeover

The criminal gains access to an existing account.

This can happen through stolen credentials, phishing, SIM swapping, malware, credential stuffing, or social engineering.

Payment Fraud

The attacker uses payment-card or bank information to make unauthorized transactions.

Synthetic Identity Fraud

Real and fabricated identity information can be combined to create a new identity profile.

This can be particularly difficult to detect because the victim may not be a single person.

Stolen Credentials Are Only One Part of the Problem

Identity theft discussions often focus on data breaches.

Breaches matter because stolen data can feed future fraud.

But possession of information does not automatically create a successful theft.

Criminals may still need to bypass authentication, persuade customer service, intercept a one-time code, answer security questions, redirect communications, or move money.

This is why security controls must operate at multiple layers.

Social Engineering Can Defeat Technical Security

A bank can use strong encryption and still face fraud if a customer is persuaded to authorize the transaction.

This is the core challenge of social engineering.

The attacker moves the target from passive victim to active participant.

A fake fraud alert might tell the customer that money is at risk.

The scammer then instructs the customer to move the money.

Technically, the legitimate customer initiated the payment.

Economically, the criminal caused the loss.

This complicates both fraud detection and reimbursement.

Payment Speed Changes Fraud Dynamics

Real-time payments improve convenience.

They can also reduce the window for stopping a fraudulent transfer.

Once money moves quickly, recovery may become harder.

That does not make faster payments inherently unsafe.

It means fraud controls must also operate quickly.

The financial system needs: identity verification, behavioral analytics, transaction monitoring, customer warnings, and rapid intervention.

This is one reason consumer financial security increasingly depends on the interaction between banking controls and consumer behavior rather than passwords alone.

Identity Theft Has Direct and Indirect Costs

The direct cost is money lost.

The indirect costs can include time spent resolving accounts, frozen credit, credit-score damage, legal expenses, lost access to funds, emotional stress, and missed financial opportunities.

A person may recover unauthorized charges but still spend months repairing the consequences.

These costs are difficult to measure consistently.

That is another reason loss statistics should not be treated as the entire burden.

Older Adults Can Face Large Losses

Fraud losses often increase with the victim's age even when younger consumers report more incidents in some categories.

Older adults may have larger accumulated savings, retirement accounts, greater home equity, and more accessible cash.

Impersonation scams exploit this.

A small number of high-loss cases can create enormous aggregate losses.

Age-specific statistics should therefore be interpreted using both report counts and median or total loss.

Younger Consumers Face Different Exposure

Younger consumers may have greater exposure to social media scams, online marketplaces, payment apps, cryptocurrency, account takeover, and digital-first identity systems.

The risk profile is different rather than necessarily lower.

A consumer who conducts most financial activity through a smartphone can face rapid cascading damage if email, phone number, and banking credentials are compromised together.

Credit Freezes Are a Powerful Preventive Tool

A credit freeze restricts access to a consumer's credit file.

That can make it harder for criminals to open new credit accounts.

A freeze does not stop every form of identity theft.

It does not prevent: existing-account takeover, tax fraud, medical identity theft, or fraud on accounts that do not require a credit check.

Still, it is one of the strongest preventive tools for new-account credit fraud.

Multi-Factor Authentication Helps, but the Method Matters

Multi-factor authentication makes account takeover harder because a password alone is insufficient.

Not all methods are equally resilient.

SMS codes can be vulnerable to SIM-swapping and social engineering.

Authenticator apps and hardware security keys can offer stronger protection.

Consumers should also avoid approving unexpected login prompts.

A security control is only effective if the user recognizes when not to authorize it.

Password Reuse Expands the Blast Radius

When the same password is used across multiple services, a breach at one company can expose accounts elsewhere.

Credential-stuffing attacks automate this process.

Unique passwords limit the damage.

Password managers can help users maintain strong unique credentials without memorizing each one.

The principle is simple:

one compromised account should not open ten more.

Account Alerts Shorten Detection Time

Fraud is easier to contain when discovered quickly.

Useful alerts include login notifications, payment alerts, password-change alerts, new-payee alerts, large-transfer warnings, and credit-monitoring alerts.

The goal is not merely awareness.

It is shortening the interval between unauthorized activity and response.

What to Do After Identity Theft

Consumers should act quickly.

A practical sequence can include:

  1. contact affected financial institutions;
  2. change compromised passwords;
  3. secure the associated email account;
  4. review credit reports;
  5. place fraud alerts or freezes when appropriate;
  6. report identity theft through IdentityTheft.gov;
  7. preserve evidence;
  8. monitor accounts for follow-on activity.

Different incidents require different steps.

A stolen card number is not the same as a fully compromised identity.

Why Reported Losses Understate the Full Problem

Official statistics rely on reports.

Not every victim reports.

Some people may feel embarrassed, believe the loss is too small, recover funds directly, not know where to report, or never realize their identity was used.

Reported losses therefore measure known reports rather than every fraud event.

This limitation should be visible whenever statistics are quoted.

Fraud Loss Data Should Be Reported With the Word "Reported"

FTC loss figures are based on consumer reports.

That means the correct phrasing is “reported losses.”

This seems minor.

It is statistically important.

The number does not estimate every fraud loss in the United States.

Some victims do not report.

Some reports contain no loss.

Some losses may later be recovered.

Preserving the word “reported” prevents the statistic from implying a completeness it does not have.

Identity Theft Reports Measure Incidents, Not People Perfectly

One person may submit more than one report.

One event can involve multiple accounts.

Different agencies may receive reports about the same underlying incident.

For that reason, report counts are not always equivalent to unique victims.

Researchers should use the exact unit supplied by the source.

If the source says reports, write reports.

If it says victims, write victims.

Financial Institutions Are Both Targets and Defenders

Banks and payment providers face direct fraud losses.

They also act as detection systems.

Their controls can include device fingerprinting, behavioral analytics, transaction scoring, sanctions screening, identity verification, and manual review.

Fraud prevention is therefore a continuous tradeoff.

Controls that are too weak increase losses.

Controls that are too aggressive block legitimate customers.

The economic objective is not zero fraud at any cost.

It is minimizing fraud while maintaining usable financial services.

Artificial Intelligence Can Scale Both Sides

AI can help criminals create convincing text, audio, images, and impersonation scripts.

It can also help financial institutions detect anomalies.

This creates an arms race.

A scammer can personalize outreach more cheaply.

A bank can score transactions more quickly.

The technology does not inherently favor either side.

Outcomes depend on implementation, data quality, controls, and consumer awareness.

Recovery Is Part of Financial Resilience

Prevention receives most attention.

Recovery matters too.

A resilient consumer setup includes backup access to funds, documented financial accounts, secure recovery methods, emergency contact procedures, and knowledge of where to report.

If one account becomes unavailable, the household should still be able to function.

This turns identity protection into a broader financial-planning issue.

Businesses Also Bear Identity-Fraud Costs

Consumers are not the only ones harmed.

Merchants, banks, lenders, and insurers may bear: chargebacks, reimbursement, investigation, customer-service costs, compliance expense, and reputational damage.

Some consumer losses are ultimately absorbed by institutions.

Some are not.

This is why fraud statistics based only on direct consumer losses understate the economic cost across the system.

Financial Losses Can Continue After the First Incident

Identity theft is often treated as a single event.

In practice, stolen information can be reused.

A criminal who has a victim's personal data may attempt several forms of fraud over time.

For example, the same information might be used to open a credit account, reset an email password, impersonate the victim with a bank, redirect a phone number, or apply for benefits.

This creates a long tail of monitoring and recovery.

A resolved unauthorized transaction does not necessarily mean the identity risk has ended.

Credit Reports Provide a Separate Detection Layer

Bank alerts can identify activity on existing accounts.

Credit reports can reveal accounts the victim did not know existed.

Consumers can review reports from the major credit bureaus and investigate unfamiliar: accounts, hard inquiries, addresses, or balances.

This matters because new-account identity theft may not touch the victim's current bank account at all.

Detection therefore needs both account monitoring and credit-file monitoring.

SIM Swapping Can Defeat SMS-Based Security

A phone number can become part of an identity attack.

In a SIM-swap attack, a criminal persuades or manipulates a carrier into transferring the victim's number.

The attacker can then receive calls and text messages intended for the victim.

If financial accounts rely on SMS authentication, that can become a pathway to account takeover.

Stronger authentication methods can reduce this risk.

The broader lesson is that a phone number should not be treated as unquestionable proof of identity.

Email Accounts Are High-Value Identity Infrastructure

A compromised email account can allow an attacker to reset passwords across multiple services.

It may also reveal: financial statements, travel records, tax documents, account notifications, and personal relationships.

For many consumers, securing email is therefore as important as securing the bank account itself.

Strong unique passwords, multi-factor authentication, and recovery controls matter.

Fraud Prevention Has an Economic Tradeoff

Financial institutions can stop more fraud by blocking more transactions.

That creates false positives.

A legitimate customer may find their card declined, transfer delayed, or account locked.

Good fraud systems try to minimize both fraud loss and customer friction.

This makes fraud prevention an optimization problem.

The best controls identify unusual activity precisely enough to intervene without making normal banking unusable.

Reported Losses Do Not Capture Prevention Spending

Consumers and institutions spend money to avoid identity theft.

This can include fraud-monitoring systems, credit monitoring, identity-verification tools, security staff, customer-support teams, cybersecurity, and insurance.

Those costs are economically real even when no fraud succeeds.

A complete view of identity-theft economics therefore includes prevention, direct losses, recovery, and operational expense.

Identity Theft Can Affect Access to Credit

A damaged credit file can influence borrowing.

Fraudulent balances or accounts may affect: credit scores, loan approvals, interest rates, apartment applications, and other financial decisions.

Even when fraudulent information is eventually removed, the timing can matter.

A person applying for a mortgage cannot always wait months for a dispute to resolve.

This is one reason early detection has financial value beyond recovering stolen funds.

Final Perspective

Identity theft statistics become more useful when the categories remain clear.

Fraud losses are not the same as identity-theft losses.

Consumer Sentinel reports are not all identity-theft cases.

Phishing attempts are not all successful fraud.

The strongest evidence shows a financial system facing rising losses from impersonation, account abuse, social engineering, and stolen identity data.

For consumers, the practical lesson is equally clear.

Security is no longer one password or one bank alert.

It is a layered process involving identity, devices, communications, accounts, payments, and fast response when something looks wrong.

Frequently Asked Questions

Short answers to the questions readers ask most often about identity theft statistics.

How Much Money Was Lost to Fraud in 2025?

Consumers reported approximately $16 billion in total fraud losses to the FTC in 2025.

How Much Was Lost to Imposter Scams?

Reported imposter-scam losses reached about $3.5 billion in 2025.

Is Fraud the Same as Identity Theft?

No. Fraud is broader. Identity theft specifically involves unauthorized use of another person's identifying information. The categories can overlap.

What Is the Most Costly Impersonation Type?

The FTC said bank impersonators produced the highest reported losses among business impersonation scams in 2025.

What Should I Do If My Identity Is Stolen?

Contact affected institutions, secure your accounts, review credit reports, consider a credit freeze, and use IdentityTheft.gov to create a recovery plan.

Resources