Online identity theft involves someone using your personal details to impersonate you, open an account, place orders or take out a contract. The immediate priorities are to stop ongoing harm, alert the organisations involved, preserve evidence and use the appropriate complaint process. Reducing information exposed through brokers and breaches is a separate, longer-term step.
This guide explains practical routes in France. For official guidance on your circumstances, consult Service-Public, Cybermalveillance.gouv.fr and the CNIL.
Immediate priorities
- Financial risk: contact your bank through a trusted number, such as the number on your card, and ask what needs to be blocked or disputed.
- Evidence: save screenshots, emails, transaction references and case numbers.
- Complaint: contact the police or gendarmerie, or use an official online complaint route if your situation is eligible. Follow Service-Public's guidance and keep the receipt.
- Longer-term protection: secure accounts, enable two-factor authentication, review your footprint and request appropriate removals.
Identity theft or someone with the same name?
| Same-name confusion | Identity theft | |
|---|---|---|
| What happens | A different person shares your name | Someone fraudulently uses your identity |
| Typical response | Clarify the mismatch and review search results | Secure accounts, report fraud and correct records |
| Evidence | A result concerns another person | A fraudulent account, contract, message or transaction uses your details |
A namesake result is not, by itself, identity theft. Read the guide to namesakes online.
If the incident followed a suspicious parcel or bank message, see parcel text scams. For the wider response to a breach, use the seven-day action plan, while handling urgent account or financial risks immediately.
Action checklist
1. Secure your genuine accounts
- Change compromised or reused passwords, beginning with your main email account.
- Enable two-factor authentication where possible.
- Review sessions, recovery addresses and unfamiliar devices.
- Check supported breach records through Have I Been Pwned or our breach-checking guide. No match does not rule out compromise.
- Follow Cybermalveillance's account recovery guidance if an account has been taken over.
2. Contact the organisation involved
- Mobile operator: report a line or SIM opened in your name. Ask how to challenge it and obtain written confirmation of the action taken.
- Bank: report unauthorised transactions, follow its fraud procedure and ask about blocking affected payment methods.
- Online platform: use the official impersonation or account recovery form. The CNIL's guide provides routes for major services.
- Fraudulent credit or debt: seek guidance from the Banque de France, including relevant checks of the FICP and FCC registers.
Keep records of whom you contacted and what they confirmed. Do not send identity documents to an address supplied by a suspected fraudster.
3. Preserve evidence and report
- Keep the original messages and transaction records, plus dated screenshots where useful.
- File a complaint through a police station, gendarmerie or the official route appropriate to the incident. Check Service-Public for current options.
- Use PHAROS to report qualifying unlawful online content. A PHAROS report is not a formal criminal complaint.
- For guidance on fraud, consult the official Info Escroqueries information.
- For improper personal-data processing, consider an access request, a suitable erasure request, and a CNIL complaint where appropriate.
4. Reduce exposed data sources
Once urgent issues are being handled, review information that could make future impersonation easier:
- Run a free scan covering supported public web, broker and breach sources.
- Check matches and request removal from the sources you choose where rights apply.
- Learn how personal data is resold.
This does not establish how the fraudster obtained your details, and it cannot erase stolen copies. It reduces specific sources of ongoing exposure. If comparing paid assistance, read choosing a digital identity protection service.
Prevention afterwards
- Watch for new profiles or repeated exposure, then request removal or follow up with the organisation.
- Remain alert to spam calls and texts after an incident.
- Avoid entering your phone number, address or identity details in unverified forms.
- Keep unique passwords and check account recovery methods periodically.
For a broader approach, see digital footprints and GDPR erasure.
What Data Knight can help with
Data Knight helps review supported sources of exposure and send authorised erasure requests to identified brokers and certain websites.
It does not replace the police, your bank or legal advice. It cannot close a fraudulent phone contract for you, guarantee removal from every source or promise that identity theft will never recur.



