← Back to Blog

A Crypto Scammer Has My Personal Information — What Should I Do?

Identity risk matrix

You gave a crypto scam platform your ID, your SSN, your bank account details, your email login — or all of the above. The money loss is bad enough. But now you're worried about what else they can do with that information. That concern is well-founded, and acting on it quickly matters.

Act Within 48 Hours

The window to prevent identity fraud from personal data exposure is narrow. Freeze your credit, change your passwords, and file with IdentityTheft.gov before finishing this article. The steps below tell you exactly what to do and why.

Bottom Line

Crypto scammers monetize personal data in three primary ways: selling it, using it for account takeovers, and attempting to re-victimize you with fake recovery offers. The most time-sensitive risk is account takeover on your financial accounts and crypto wallets. Freeze your credit, rotate all passwords, enable two-factor authentication on everything financial, and report to IdentityTheft.gov within the next 48 hours.

What Data They Likely Have

The specific exposure depends on how the scam operated. Most crypto scam platforms collect data at multiple points in the interaction:

  • KYC verification — Government-issued ID photos (front and back), selfies, date of birth, address. Scam exchanges require this to appear legitimate.
  • Account registration — Email address, phone number, username, password (or the password you reused from elsewhere).
  • Bank linkage or wire details — Routing number, account number, bank name. Required to fund the fake account.
  • Investment communications — Your financial situation, investment goals, risk tolerance, how much you told them you had. Used for targeted re-scamming.
  • Remote access sessions — If a scammer had remote control of your computer, the exposure is significantly broader. See the remote access crypto theft guide for the full scope of what they can extract.

Risk Level by Data Type

Government ID + Selfie Critical

Used for synthetic identity fraud and KYC bypass at exchanges. Can open financial accounts, crypto exchange accounts, and credit lines in your name.

Social Security Number Critical

Enables new credit account fraud, fraudulent tax filing, and medical identity theft. Freeze credit at all three bureaus immediately.

Email Login Credentials Critical

Email access enables password resets on every account linked to that address — bank, exchange, everything. Change your email password immediately and enable 2FA.

Bank Account Numbers High

Enables ACH pull fraud (unauthorized withdrawals). Alert your bank, review recent transactions, and consider requesting new account numbers.

Phone Number High

Enables SIM swap attacks — porting your number to steal SMS-based two-factor authentication codes. Contact your carrier and add a SIM lock PIN.

Name, Address, DOB Medium

Enables targeted phishing and used to answer security questions. Insufficient on its own for most fraud without additional data, but lowers the bar.

What Scammers Do With Your Data

Sell it on dark web markets. Scam operations frequently package and sell victim data in bulk. Your information may be purchased by other fraud operators who don't know the original context. This extends the threat beyond the original scammer.

Account takeover on your existing accounts. If they have your email password or you reused a password, they'll attempt access to your bank, other crypto exchanges, Amazon, PayPal — anywhere that stores payment methods. This is the most immediate risk after email credential exposure.

Open new fraudulent accounts in your name. With ID photos and SSN, they can attempt to open bank accounts, credit cards, or crypto exchange accounts using your identity. The purpose is usually money laundering — moving stolen funds through accounts in your name to obscure the trail.

File fraudulent tax returns. SSN plus basic personal data is enough to file a fraudulent tax return and claim your refund before you do. File your taxes early if it's tax season, or file an IRS Form 14039 Identity Theft Affidavit proactively.

Re-contact you with a recovery scam. This is extremely common. The original scam operation — or a data buyer — will contact you claiming to be a "crypto recovery service" that can get your money back, for an upfront fee. They know exactly how much you lost and the name of the platform. See our guide on fake crypto recovery services for how this works and how to identify it.

Immediate Steps — Next 48 Hours

1

Change your email password immediately

Your email is the master key to all other accounts. Change the password to something unique, enable two-factor authentication using an authenticator app (not SMS), and review your email's "connected apps" or "third-party access" settings and revoke anything unrecognized. Check your sent folder and filters for unauthorized activity.

2

Freeze your credit at all three bureaus

Go to Equifax.com, Experian.com, and TransUnion.com and place a security freeze on each. It's free, done online, and takes about 10 minutes each. A credit freeze prevents anyone — including you, until you lift it — from opening new credit in your name. This is the most effective protection against new account fraud.

3

Add a SIM lock to your phone number

Call your carrier and add a SIM lock PIN that must be provided before your number can be ported or transferred. Prevents SIM swap attacks that steal your SMS-based 2FA codes. Do this before setting up SMS-based 2FA on any new accounts — then switch to app-based authenticators wherever possible.

4

Alert your bank and flag the account

Call your bank's fraud line and notify them that your account information was exposed in a fraud incident. Ask them to flag your account for unusual activity, review recent transactions for unauthorized ACH pulls, and advise on whether new account numbers are warranted given the exposure.

5

Rotate passwords on all financial accounts

Change passwords on every financial account — bank, brokerage, any remaining crypto exchange — to unique passwords you have not used anywhere else. Use a password manager to generate and store them. Enable app-based two-factor authentication on all of them.

6

File at IdentityTheft.gov

The FTC's IdentityTheft.gov walks you through a personalized recovery plan based on the type of data exposed. It generates pre-filled letters for credit bureaus, dispute letters for fraudulent accounts, and creates your official identity theft report. Takes about 20 minutes and is the official starting point for identity fraud documentation.

Credit Freeze vs. Fraud Alert: What's the Difference

Both are free and available from all three bureaus, but they work differently:

A fraud alert tells lenders to take extra steps to verify your identity before opening new accounts in your name. It's on file for one year (or seven years if you file an extended fraud alert with an identity theft report). It's less protective than a freeze — a lender can still open an account if they complete extra verification steps.

A credit freeze (security freeze) completely blocks new credit inquiries. No lender can pull your credit — so no new account can be opened — until you temporarily lift the freeze. This is the stronger protection. You can lift it online in minutes when you legitimately need a hard inquiry. For most crypto scam victims with SSN exposure, a full freeze is the right call.

Tax Filing Alert

If your SSN was exposed and it's near tax season, file your taxes as early as possible. If you believe a fraudulent return may have already been filed, submit IRS Form 14039 (Identity Theft Affidavit) to flag your SSN with the IRS. The IRS also offers an Identity Protection PIN program that requires a separate 6-digit PIN to file any return using your SSN.

If They Had Remote Access to Your Computer

Remote access is the most serious data exposure scenario. When a scammer controlled your screen, they could have silently extracted:

  • Saved passwords from your browser (Chrome, Firefox, Safari all store these)
  • Cryptocurrency wallet files and seed phrases — these cannot be changed, only moved
  • Documents, tax returns, ID scans stored in Downloads or Desktop folders
  • Autofill data including bank credentials
  • Keyloggers installed to capture ongoing keystrokes after the session ended

The full attack chain and immediate response steps are covered in our guide: I gave someone remote access to my computer and my crypto is gone. If this applies to you, treat that guide as your primary reference — the scope of data exposure requires additional steps beyond what's covered here.

The most critical action if a remote session occurred: assume all crypto wallet seed phrases are compromised and move assets to new wallets immediately before doing anything else. See hardware wallet best practices for how to secure your wallets going forward.

The Second Scam: Recovery Service Outreach

Within days or weeks of a scam, many victims receive unsolicited contact from "crypto recovery specialists," "blockchain investigators," or people claiming to work with law enforcement to recover crypto losses. They know specific details about your loss — the platform name, the amount, sometimes your wallet address.

This is the second scam. Your data was sold or re-used by the same operation. The business model is identical to the first scam: build trust with specific details, request an upfront fee or additional crypto deposit to "unlock" your funds, and disappear.

A legitimate forensic investigator will never cold-contact you out of nowhere. See our full breakdown in someone said they can recover my crypto — is it legit? for exactly how to tell the difference between a real investigator and a re-scam attempt.

Reporting and Documentation

File reports in this order:

  1. IdentityTheft.gov (FTC) — Generates your recovery plan and official identity theft report. Required for extended fraud alerts and some dispute letters.
  2. IC3.gov (FBI) — File an internet crime complaint. Include the scam platform name, any cryptocurrency addresses involved, and the data types that were exposed. Our IC3 complaint guide covers exactly what to include.
  3. Local police report — Required by some financial institutions before opening fraud investigations and useful for the extended fraud alert process.
  4. Your state attorney general — Many states have identity theft units that work these cases separate from federal channels.

For the full picture of reporting options and what each agency actually does with your report, see how to report a crypto scam to the FBI and the first 72 hours after theft.

Keep All Evidence

Screenshot everything before you delete it — the scam platform login, all communications, any wallet addresses you were given, deposit confirmations, withdrawal refusal messages. This documentation supports your fraud reports, any civil legal action, and a blockchain forensic investigation. See gathering transaction evidence for exactly what to preserve.


Frequently Asked Questions

What will a crypto scammer do with my personal information?

They'll sell it, use it for account takeovers, attempt to open fraudulent accounts in your name, or re-contact you with a fake recovery service scam. The most immediate risks are email account takeover and unauthorized new account openings using your ID and SSN.

Should I freeze my credit after a crypto scam exposed my personal information?

Yes, immediately. A credit freeze at all three bureaus — Equifax, Experian, TransUnion — is the most effective protection against fraudulent account openings. It's free, done online in minutes, and doesn't affect your existing credit or accounts.

The scammer has my ID photos — how serious is that?

Very serious. Government ID photos are used for synthetic identity fraud and KYC bypass at crypto exchanges. File at IdentityTheft.gov, freeze your credit, and monitor for new account openings. Consider requesting a new passport if additional identifying data was also exposed.

A scammer gave me remote access to my computer — what data did they get?

Remote access is the worst case. They could have extracted saved passwords, crypto wallet files and seed phrases, stored ID documents, and installed keyloggers. Move any crypto assets to new wallets immediately. Read the full remote access guide for the complete response.

Will the scammer try to contact me again using my information?

Very likely. Your contact info and loss details will be used to approach you with a fake recovery service offer. Any unsolicited contact about recovering your crypto — no matter how specific they are about your case — should be treated as a second scam attempt.

Need Help Documenting Your Case for Reports or Legal Action?

We produce blockchain forensic reports that trace where your funds went on-chain — the documentation needed for IC3 filings, civil litigation, and exchange subpoenas.

Zack Coffing — Wallet Witness

Blockchain forensic investigator specializing in crypto fraud, on-chain tracing, and litigation support. Wallet Witness produces forensic reports for victims, attorneys, and law enforcement worldwide.