Connect with us

Technology

Is your Social Security number at risk? Signs someone might be stealing it

Published

on

Is your Social Security number at risk? Signs someone might be stealing it

With most of your life attached to these nine numbers, your Social Security number (SSN) is incredibly important to keep safe. That’s why it is crucial to pay attention to signs that your SSN may have been compromised. While preventing the misuse of your SSN is paramount, there are action steps you can take if it does fall into the wrong hands.

I’M GIVING AWAY A $500 GIFT CARD FOR THE HOLIDAYS

Enter the giveaway by signing up for my free newsletter.

There are steps you can take if your Social Security number falls into the wrong hands. (Kurt “CyberGuy” Knutsson)

Top signs someone might be using your Social Security number

Are you concerned that your Social Security number may have gotten into the wrong hands? Check below to see if you are experiencing any of these signs:

Advertisement

1) Changes to your credit report and score

Americans are granted free credit reports every 12 months from the three major consumer reporting companies. Regularly culling through these reports can help you spot potential fraud, which might signal that your Social Security number has been compromised. Any hard inquiries you didn’t request on your credit report are a strong indicator that someone tried to open a credit card or another line of credit with your SSN.

2) Changes to your Social Security statement

While most people know they should check their credit report and scores, you can see your Social Security statement by creating an account on the official Social Security Administration website. Because only one account can be created per SSN, it is safer if you claim it so that no one else can by piecing together your personal information (along with your SSN) to claim it fraudulently. Make sure it is connected to a secure email account that you check frequently. This account also provides up-to-date data on earnings and benefit distributions so you can see if anything is “off.”

You can see your Social Security statement by creating an account on the official Social Security Administration website. (Kurt “CyberGuy” Knutsson)

BEWARE OF THIS SOCIAL SECURITY SCAM BY CROOKS TRYING TO TRICK YOU

3) Strange or new mailings or calls from debt collectors and junk mailers

While it might seem natural to toss a pile of “junk” mailers or ignore calls from random debt collectors or advertisers, it may be an indicator that someone has gotten a hold of your Social Security number and has begun opening accounts under your number. It’s important to make note of the patterns and follow up with these collectors should it become more and more apparent that your SSN might have been misused. Oftentimes, consumers start getting more credit offers when new credit cards are opened. Additionally, if you start receiving bills under someone else’s name at your address, it might be time to follow up with these notices.

Advertisement

4) New notices from the IRS or other governmental agencies

If you start receiving notices about your Social Security number being used to file someone else’s taxes or inappropriately use your health insurance, it is definitely a sign that someone may have compromised your SSN. While receiving a notice from the IRS or Medicare can feel scary, it is imperative that you reach out to the corresponding agency to notify them of the fraudulent activity so that you can stop further damage.

Beware of new notices from the IRS or other governmental agencies. (Kurt “CyberGuy” Knutsson)

Top ways to keep your Social Security number safe

1) Sign up for a Social Security account

Go to the official Social Security Administration website to create an account, if you haven’t already.

2) Hide/keep safe your Social Security number card

Put your Social Security number card in a very safe place, such as a safe, bank safe or a filing cabinet that can be locked. Because it is used so frequently, those nine digits are worth memorizing. If your wallet is lost or stolen, and you keep your SSN card in there, it will be messier than losing just money or your ID. Don’t carry your Social Security card in your wallet or purse.

3) Go online

Skip jotting down your Social Security number on in-person forms. When your SSN is jotted down on paper, it is hard to control how the information gets used or disposed of. If you can submit forms online, you can skip the risk of having your SSN getting into the wrong hands. If you mail in forms that denote your SSN, you risk having that piece of mail stolen or lost.

Advertisement

4) Opt out of inputting SSN

Even though your SSN is requested on some forms, it is not always necessary. If a future employer is requesting your SSN, double-check why they need it. They would most likely need it to run a background check, which you should know about anyway. Additionally, some establishments allow you to provide the last four digits of your SSN until you are finalizing a screening process, etc.

5) Combat child identity theft

Open accounts for your children’s Social Security numbers because you want to claim them for them early and be able to monitor any movement related to their SSN.

6) Secure documents

Some records that contain your Social Security number are important to keep on hand, such as income tax filings. If they are kept digitally, encrypt and or password-protect the document or folder, especially if it is uploaded to the cloud. Keep offline documents with SSNs in a safe or shred instead of throwing them away.

Remember you (usually) only get one SSN in a lifetime, it is important to safeguard that data with your “life.”

7) Remove your personal information from the internet

Removing your personal information from the internet, given the increasing privacy concerns about artificial intelligence, is essential. Data removal services can help protect your Social Security number by systematically erasing your details from websites, thus reducing the risk of identity theft. 

Advertisement

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services here.

8) IRS identity protection PIN (IP PIN)

To further protect your tax returns from identity theft, the IRS offers an identity protection PIN (IP PIN). This is a six-digit number that prevents someone else from filing a tax return using your Social Security number or individual taxpayer identification number. The IP PIN is known only to you and the IRS, adding an extra layer of security to your tax filings.

How to get an IP PIN

  • Online request: The fastest way to receive an IP PIN is to request one through your online account on the IRS website. If you don’t already have an account, you must register to validate your identity.
  • Alternative methods: If you can’t establish an online account, there are other methods, but they take longer. You can file an application or request in-person authentication.

Using your IP PIN

  • Enter the six-digit IP PIN when prompted by your tax software or provide it to your trusted tax professional when filing your return.
  • An IP PIN must be used on all federal tax returns during the year, including prior year returns.
  • Do not reveal your IP PIN to anyone except your tax professional when you are ready to sign and submit your return.

Important information

  • An IP PIN is valid for one calendar year, and a new one is generated each year.
  • If you lose your IP PIN, you can retrieve it online or have it reissued by calling the IRS.

By using an IP PIN, you can significantly reduce the risk of tax-related identity theft and ensure that your tax returns are processed smoothly and securely.

9) Recognizing and reporting a Social Security scam

If there is a problem with a person’s SSN or record, Social Security will typically mail a letter. You can learn more about recognizing Social Security-related scams, including how to report a scam quickly and easily online to Social Security’s Office of the Inspector General, by reading more at www.ssa.gov/scams.

Advertisement

Image of a lock on Social Security cards (Kurt “CyberGuy” Knutsson)

What to do if you think your Social Security number has been compromised?

If you noticed any of the signs listed above that indicate that your Social Security number may have been compromised, below are action steps you can take:

1) Reach out to the Social Security Administration immediately: Call them at 1-800-772-1213 to put an electronic block on your SSN.

2) Contact the three main credit bureaus to freeze your credit: This will prevent anyone, including hackers, from wreaking havoc on your credit. Make sure to report any errors on your credit reports with the credit agencies as well.

3) File a report with the local authorities as well as the Federal Trade Commission.

Advertisement

4) Submit a Social Security fraud report online or call the SSA’s Office of the Inspector General at 1-800-269-0271. They can help investigate any Social Security-related fraud.

5) Use an identity theft protection service: Identity theft companies can monitor personal information like your Social Security number, phone number and email address and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals. 

One of the best parts of using some services is that they might include identity theft insurance of up to $1 million to cover losses and legal fees and a white-glove fraud resolution team where a U.S.-based case manager helps you recover any lossesSee my tips and best picks on how to protect yourself from identity theft.

HOW DATA BROKERS ARE FUELING ELDER FRAUD IN AMERICA

Kurt’s key takeaways

Because your Social Security number has such a significant impact on your life, it is important to pay attention to any signs that it has been compromised and misused. While it may feel overwhelming to see any of these signs that your SSN might be compromised, it’s important to know there are steps you can take to protect yourself moving forward. While paying regularly for fraud protection services may seem like an unnecessary expense when you’re not presently dealing with identity or credit issues, a fraud protection service subscription can help you focus on your present moment instead of worrying about what a criminal might do with your SSN. And if something does happen, you have people in your corner to help you through the process.

Advertisement

What additional steps do you think government agencies should take to enhance the security of Social Security numbers? Let us know by writing us at Cyberguy.com/Contact.

For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.

Ask Kurt a question or let us know what stories you’d like us to cover.

Follow Kurt on his social channels:

Advertisement

Answers to the most asked CyberGuy questions:

New from Kurt:

Copyright 2024 CyberGuy.com. All rights reserved.

Technology

Amazon’s smart shopping cart for Whole Foods gets bigger, lighter, and adds tap-to-pay

Published

on

Amazon’s smart shopping cart for Whole Foods gets bigger, lighter, and adds tap-to-pay

Amazon is launching a revamped version of its smart shopping cart, which it plans to bring to dozens of Whole Foods locations by the end of this year, according to an announcement on Wednesday. The new Dash Cart features a “more responsive” item scanner that’s now located next to the built-in display, along with a new NFC reader that lets you tap to pay with your credit card or phone.

Amazon’s previous Dash Cart design put scanners beneath and in front of the handle, potentially making them harder to spot. It also only let you pay with the credit card attached to your Amazon account.

With the upgraded Dash Cart, you’ll find a new scale alongside the cart’s handle, which Amazon says “works in tandem with on-cart cameras, weight sensors, and deep learning models to ensure accurate pricing for every item.” The upgraded Dash Cart eliminates the large sensors facing inside the cart as well, offering a 40 percent larger capacity and a 25 percent lighter weight.

The Dash Cart shows an interactive map of the store on its display, similar to Instacart’s smart Caper Cart. You can sync your shopping list created with Alexa, too, and see how much you’re spending as you add more items to your cart. The cart uses built-in sensors and computer vision to detect when you’ve removed an item, allowing it to automatically update your total. When you’re done shopping, you can skip the checkout line and leave the store in a designated Dash Cart lane.

Amazon is launching its new Dash Cart as the company shakes up its grocery business, which has tied Whole Foods more closely to the Amazon brand. The company has already brought its new Dash Cart to three Whole Foods stores in McKinney, Texas; Reston, Virginia; and Westford, Massachusetts, along with two Amazon Fresh stores.

Advertisement
Continue Reading

Technology

Fake error popups are spreading malware fast

Published

on

Fake error popups are spreading malware fast

NEWYou can now listen to Fox News articles!

A dangerous cybercrime tool has surfaced in underground forums, making it far easier for attackers to spread malware. 

Instead of relying on hidden downloads, this tool pushes fake error messages that pressure you into fixing problems that never existed. Security researchers say this method is spreading quickly because it feels legitimate. The page looks broken. The warning feels urgent. The fix sounds simple. 

That combination is proving alarmingly effective for cybercriminals.

Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter.

Advertisement

How fake error malware attacks actually work

These attacks begin with a compromised website. When a visitor lands on the page, something looks wrong right away. Text appears broken. Fonts look scrambled. Visual elements seem corrupted. A pop-up then appears claiming the issue can be fixed with a browser update or a missing system font. A button offers to repair the problem instantly. 

Clicking that button copies a command to the clipboard and displays instructions to paste it into PowerShell or a system terminal. That single step launches the infection.

MALICIOUS CHROME EXTENSIONS CAUGHT STEALING SENSITIVE DATA

Fake error popups make a website look broken by scrambling text or fonts to create urgency and panic. (Jens Büttner/picture alliance via Getty Images)

Why this new tool changes the threat landscape

The tool behind these attacks is called ErrTraffic. It automates the entire process and removes the technical barriers that once limited cybercrime operations. For about $800, attackers get a full package with a control panel and scripted payload delivery. Analysts at the Hudson Rock Threat Intelligence Team identified the tool after tracking its promotion on Russian-language forums in early December 2025. 

Advertisement

ErrTraffic works through a simple JavaScript injection. A single line of code connects a hacked site to the attacker’s dashboard. From there, everything adapts automatically. The script detects the operating system and browser. It then displays a customized fake error message in the correct language. The attack works across Windows, Android, macOS and Linux.

MOST PARKED DOMAINS NOW PUSH SCAMS AND MALWARE

The popups often claim a browser update or missing system font is needed to fix the problem. (Daniel Acker/Bloomberg via Getty Images)

Why security software struggles to stop it

Traditional malware defenses look for suspicious downloads or unauthorized installations. ErrTraffic avoids both. Browsers see normal text copying. Security tools see a legitimate system utility being opened manually. Nothing appears out of place. That design allows the attack to slip through protections that would normally stop malware in its tracks.

The success rate is deeply concerning

Data pulled from active ErrTraffic campaigns shows conversion rates approaching 60%. That means more than half of the visitors who see the fake error message follow the instructions and install malware. Once active, the tool can deliver infostealers like Lumma or Vidar on Windows devices. Android targets often receive banking trojans instead. The control panel even includes geographic filtering, with built-in blocks for Russia and neighboring regions to avoid drawing attention from local authorities.

Advertisement

What happens after infection?

Once malware is installed, credentials and session data are stolen. Those compromised logins are then used to breach additional websites. Each newly hacked site becomes another delivery vehicle for the same attack. That cycle allows the campaign to grow without direct involvement from the original operator.

FAKE WINDOWS UPDATE PUSHES MALWARE IN NEW CLICKFIX ATTACK

Following the on-screen instructions can quietly trigger malware that steals passwords and personal data. (Kurt Knutsson)

Ways to stay safe from fake error malware

A few smart habits can significantly reduce risk when facing fake error pop-ups and browser-based traps.

1) Never run commands suggested by a website

Legitimate websites never ask you to copy and paste commands into PowerShell or a system terminal. Fake error malware relies on convincing messages that pressure you into doing exactly that. If a page instructs you to run code to fix a problem, close it immediately.

Advertisement

2) Close pages that claim your system is corrupted

Fake error campaigns often use broken text, scrambled fonts or warnings about missing files to grab attention. As a result, these visuals create urgency and trigger fear. In reality, a real system problem never announces itself through a random website, so close the page right away.

3) Install updates only through official system settings

Real browser and operating system updates come from built-in update tools, not pop-ups on websites. If an update is needed, your device will notify you directly through system settings or trusted app stores.

4) Install strong antivirus software on every device

Strong antivirus software can help block malicious scripts, detect infostealers and stop suspicious behavior before damage spreads. This is especially important since fake error malware targets Windows, Android, macOS and Linux systems.

The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.

Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.

Advertisement

5) Use a data removal service to reduce exposure

Stolen credentials fuel the spread of fake error malware. Removing personal information from data broker sites can reduce the impact if login details are compromised and limit how far an attack can spread.

While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.

Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.

Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.

6) Treat font and browser update pop-ups with suspicion

Claims about missing fonts or outdated browsers are a hallmark of these attacks. Modern systems manage fonts automatically, and browsers update themselves. A webpage has no reason to request manual fixes.

Advertisement

If a real update is needed, the operating system will request it directly. A random webpage never should.

Kurt’s key takeaways 

Fake error malware works because it plays on a very human reaction. When something on a screen suddenly looks broken, most people want to fix it fast and move on. That split-second decision is exactly what attackers are counting on. Tools like ErrTraffic show how polished these scams have become. The messages look professional. The instructions feel routine. Nothing about the moment screams danger. But behind the scenes, one click can quietly hand over passwords, banking access and personal data. The good news is that slowing down makes a real difference. Closing a suspicious page and trusting built-in system updates can stop these attacks cold. When it comes to pop-ups claiming your device is broken, walking away is often the smartest fix.

Have you ever seen a pop-up or error message that made you stop and wonder if it was real? Tell us what it looked like and how you handled it by writing to us at Cyberguy.com.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Sign up for my FREE CyberGuy Report 
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter. 

Advertisement

Copyright 2025 CyberGuy.com. All rights reserved.

Continue Reading

Technology

Intel is planning a custom Panther Lake CPU for handheld PCs

Published

on

Intel is planning a custom Panther Lake CPU for handheld PCs

Intel announced yesterday that it’s developing an entire “handheld gaming platform” powered by its new Panther Lake chips, and joining an increasingly competitive field. Qualcomm is hinting about potential Windows gaming handhelds showing up at the Game Developers Conference in March, and AMD’s new Strix Halo chips could lead to more powerful handhelds.

According to IGN and TechCrunch, sources say Intel is going to compete by developing a custom Intel Core G3 “variant or variants” just for handhelds that could outperform the Arc B390 GPU on the chips it just announced. IGN reports that by using the new 18A process, Intel can cut different die slices, and “spec the chips to offer better performance on the GPU where you want it.”

As for concrete details about the gaming platform, we’re going to have to wait. According to Intel’s Dan Rogers yesterday, the company will have “more news to share on that from our hardware and software partners later this year.” The Intel-based MSI Claw saw a marked improvement when it jumped to Lunar Lake, and hopefully the new platform keeps up that positive trend.

Continue Reading

Trending