ID Theft Statistics
September 2011 PWC Data and Privacy Report
According to accounting firm PricewaterhouseCoopers (PwC) medical identify theft is the fastest-growing form of identity theft in 2010:
- Affecting 1.42 million Americans
- Costing more than $28 billion
August 2011 Digital Forensic Association The Leaking Vault - 6 years of Data Breaches
The Leaking Vault 2011 presents data gathered from studying 3,765 publicly disclosed data breach incidents, and is the largest study of its kind to date. Information was gleaned from the organizations that track these events, as well as government sources. Data breaches from 33 countries were included, as well as those from the United States.
This study covers incidents from 2005 through 2010, and includes over 806.2 million known records disclosed.
On average, these organizations lost:
- 388,000 records per day
- 15,000 records per hour
- Every single day for the past six years
The estimated cost for these breaches comes to more than $156 billion to the organizations experiencing these incidents. This figure does not include the costs that the organizations downstream or upstream may incur, nor that of the data subject victims.
May 2011 GAO Taxes and ID Theft Report
In 2010 alone, the Internal Revenue Service (IRS) identified over 245,000 identity theft incidents that affected the tax system.
Identity theft harms innocent taxpayers through employment and refund fraud. In refund fraud, an identity thief uses a taxpayer's name and Social Security Number (SSN) to file for a tax refund, which IRS discovers after the legitimate taxpayer files.
In employment fraud, an identity thief uses a taxpayer's name and SSN to obtain a job. When the thief's employer reports income to IRS, the taxpayer appears to have unreported income on his or her return, leading to enforcement action.
The IRS and Taxpayers may not discover refund or employment fraud until after legitimate tax returns are filed.
The number of tax-related identity theft incidents (primarily refund or employment fraud attempts) identified by IRS has grown:
- 51,702 incidents in 2008
- 169,087 incidents in 2009
- 248,357 incidents in 2010
March 2011 FTC Consumer Sentinel Report
Identity Theft
Identity theft was the number one complaint category in the CSN for calendar year 2010 with 19% of the overall complaints.
Government documents/benefits fraud increased 4 percentage points since calendar year 2008; identity theft-related credit card fraud, on the other hand, declined 5 percentage points since calendar year 2008.
- Government documents/benefits fraud (19%)
- Credit card fraud (15%)
- Phone or utilities fraud (14%)
- Employment fraud (11%)
- Bank fraud (10%)
- Loan fraud (4%)
Other types of identity theft categories included:
- Uncertain (10.3%)
- Miscellaneous (8.8 %)
- Internet/Email (1.1 %)
- Evading the Law (1.4%)
- Medical (1.3%)
- Apartment or House Rented (0.7%)
- Insurance (0.3%)
- Child Support (0.2%)
- Bankruptcy (0.1%)
- Magazines (0.2%)
- Property Rental Fraud (0.2%)
- Securities/Other Investments (0.2%)
Forty-two percent of identity theft complainants reported whether they contacted law enforcement. Of those victims, 72% notified a police department. Sixty-two percent indicated a report was taken.
Identity Theft Complaints by Victims' Age:
- 19 years old and under - 8 percent
- 20-29 years old - 24 percent
- 30-39 years old - 21 percent
- 40-49 years old - 19 percent
- 50-59 years old - 15 percent
- 60-69 years old - 8 percent
- 70 years old and over - 5 percent
Top 10 states with the highest per capita rate of reported identity theft complaints include:
- Florida
- Arizona
- California
- Georgia
- Texas
- Nevada
- New Mexico
- New York
- Maryland
- Illinois
March 2011 Ponemon Cost of a Data Breach Study
For the fifth year in a row, data breach costs have continued to rise:
- Data breaches continue to cost organizations more every year.
- The average organizational cost of a data breach in 2010 increased to $7.2 million, up 7 percent from $6.8 million in 2009.
- Total breach costs have grown every year since 2006.
- Data breaches in 2010 cost their companies an average of $214 per compromised record, up $10 (5 percent) from last year.
- 542,214,290 Records Breached
- from 2,711 Data Breaches made public since 2005
- Through October 7, 2011
Public Data Breach Events since 2005 - 2,670 breaches totaling 535,605,215
Public data breach events in 2011 - 392 breaches totaling 23,316,765
Organizational Type for Years 2005 – Sep 3, 2011
- BSO - Businesses - Other - 325 breaches totaling 8 million records (12.1%)
- BSF - Businesses - Financial and Insurance Services - 404 breaches totaling 248 million records (15.1%)
- BSR - Businesses - Retail/Merchant - 276 breaches totaling 116 million records (10.3%)
- EDU - Educational Institutions – 568 breaches totaling 9 million records (21.3%)
- GOV - Government and Military - 495 breaches totaling 132 million records (18.5%)
- MED - Healthcare - Medical Providers - 544 breaches totaling 21 million records (20.4%)
- NGO - Nonprofit Organizations - 58 breaches totaling 1.8 million records (2%)
Type of Breaches for years 2005 – Sep 3, 2011
- Unintended disclosure (DISC) - 480 breaches totaling 16 million (17.9%)
- Hacking or malware (HACK) - 500 breaches totaling 312 million (18.7%)
- Payment Card Fraud (CARD) - 41 breaches totaling 75,000 (1.5%)
- Insider (INSD) - 283 breaches totaling 32 million (10.6%)
- Physical loss (PHYS) - 343 breaches totaling 3 million (12.9%)
- Portable device (PORT) - 759 breaches totaling 160 million (28.4%)
- Stationary device (STAT) - 181 breaches totaling 9 million (6.7%)
- Unknown or other (UNKN) - 83 breaches totaling 3 million (3%)
Types of Breaches for 2011
- Unintended disclosure (DISC) - 55 breaches totaling 4.1 million records (14%)
- Hacking or malware (HACK) - 100 breaches totaling 13.4 million records (25.5%)
- Payment Card Fraud (CARD) - 14 breaches totaling 6,499 records (3.5%)
- Insider (INSD) - 56 breaches totaling 107,500 records (14.3%)
- Physical loss (PHYS) - 57 breaches totaling 15,330 records (14.5%)
- Portable device (PORT) - 70 breaches totaling 3.2 million records (17.9%)
- Stationary device (STAT) - 18 breaches totaling 2.5 million records (4.5%)
- Unknown or other (UNKN) - 22 breaches totaling 13,500 records (5.6%)
Organizational Type in 2011
- BSO - Businesses - Other - 51 breaches totaling 861,000 records (13%)
- BSF - Businesses - Financial and Insurance Services - 41 breaches totaling 566,000 records (10.5%)
- BSR - Businesses - Retail/Merchant - 61 breaches totaling 12 million records (15.6%)
- EDU - Educational Institutions - 47 breaches totaling 389,000 records (12%)
- GOV - Government and Military - 53 breaches totaling 4 million (13.5%)
- MED - Healthcare - Medical Providers - 129 breaches totaling 5.6 million records (33%)
- NGO - Nonprofit Organizations - 5 breaches totaling 828 (1%)