Technology
Why physical ID theft is harder to fix than credit card fraud
NEWYou can now listen to Fox News articles!
It started with a voicemail from a Hertz rental car location in Miami, Florida. A 57-year-old woman in Los Alamitos, California, was asked when she planned to return a Mercedes-Benz she had never rented. A thief had stolen her driver’s license, replaced the photo with their own and used it to rent the vehicle. The same identity was used to open a credit card account, book airline tickets and reserve hotel stays. By the time she learned what happened, the fraud involved businesses in multiple states.
Clearing her name required police reports in two jurisdictions, written disputes with the credit card issuer and repeated contact with the rental company and hotels. Her accounts were frozen while she submitted notarized copies of her identification and signed fraud affidavits. The process lasted more than a week. She reported losing $78,500 and spent nearly 10 days dealing with the fallout from one stolen ID.
Credit card fraud is usually limited to a single account number. Physical ID theft gives someone the ability to act as you in the real world. As a result, the cleanup process is longer, more intrusive and often tied to your legal record.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
5 MYTHS ABOUT IDENTITY THEFT THAT PUT YOUR DATA AT RISK
A stolen driver’s license can allow someone to rent cars, open accounts and sign contracts in your name. (Photo by Silas Stein/picture alliance via Getty Images)
How credit card fraud recovery works
Under the Fair Credit Billing Act, you report unauthorized charges to the card issuer within 60 days of the statement date. Federal law limits your liability to $50, and most major issuers waive that entirely. The bank cancels the compromised card number, issues a replacement and removes the disputed charges after an investigation. You may need to confirm transactions and sign a fraud affidavit. The account number changes. Your name, driver’s license and Social Security number stay the same. In most cases, fraud is resolved within one or two billing cycles. That structure gives consumers clarity. There is one issuer, one investigation and one account to correct.
Why physical ID theft recovery is more complicated
Physical ID theft creates problems that go far beyond one financial account. When someone uses your driver’s license, they step into your legal identity. Start with reporting requirements. Most states require you to file a police report before the DMV will issue a replacement linked to fraud. That report number becomes part of your official record. If the misuse happened in another state, you may need to file a second report there.
Next, understand what replacing the card actually does. A new physical card does not erase prior activity. Rental contracts, utility accounts, hotel stays, or police interactions tied to the stolen license still carry your name and license number. Fixing those records takes work. You must contact each business directly and submit documentation. No central agency reverses everything at once. Each company sets its own rules and timeline.
The stakes can rise quickly. For example, if someone abandons a rental car or commits a crime using your stolen ID, law enforcement databases may record your name. At that point, the situation shifts from financial inconvenience to legal exposure.
HOW TO PROTECT A LOVED ONE’S IDENTITY AFTER DEATH
Police reports and formal disputes are often required before businesses will remove fraudulent records. (Kurt “Cyberguy” Knutsson)
How to prove physical ID theft was not yours
With credit card fraud, the issuer investigates the charge. With physical ID theft, businesses and agencies often require you to prove that you did not authorize the activity. That process usually starts at IdentityTheft.gov. The FTC generates an Identity Theft Report, which serves as an official statement of fraud. Most banks, collection agencies and rental companies will not proceed without it.
You may also need:
- A local police report
- A copy of your driver’s license
- A notarized identity affidavit
- Proof of residence tied to the date of the fraud
When thieves open fraudulent accounts in your name, dispute each one separately. Act quickly. Send a written response within 30 days of the first collection notice to protect your rights under federal law. Fraud that appears on your credit report requires another step. Contact Equifax, Experian and TransUnion individually and submit formal disputes with supporting documentation. The credit bureaus then have up to 30 days to complete their investigations. No central agency manages these corrections for you. Instead, every company sets its own documentation rules and timeline. Therefore, you must track deadlines, follow up consistently and keep detailed records of every communication.
You cannot simply replace your driver’s license number after identity theft
When a credit card number is stolen, the bank issues a new one. When a driver’s license is stolen, the number usually remains the same. In California, if your driver’s license is lost or stolen, you can request a replacement card through the DMV online system or at a field office. The official process gets you a new physical card. No new license number is automatically assigned when the card is stolen.
If there is identity misuse tied to the license number, the DMV fraud review process allows you to submit documentation, including police reports, to support an identity theft claim before they take further action. A Social Security number is even harder to change. The Social Security Administration approves new numbers only in cases involving continued harm. Applicants must provide extensive documentation and appear in person.
A stolen physical ID, such as your license, includes:
- Full legal name
- Date of birth
- Address
- Driver’s license number
- Signature
That information is sufficient for in-person identity checks, rental contracts, certain loan applications and travel-related transactions.
Credit monitoring alerts can help you detect identity misuse before it spreads across multiple accounts. (Kurt “CyberGuy” Knutsson)
Why ongoing identity protection matters
There is no single agency that tracks misuse of your driver’s license across rental companies, lenders, collection agencies and law enforcement systems. That burden falls on you.
Identity theft services monitor your identity across all three credit bureaus and alert you to new credit inquiries, account openings and changes to your credit file. If fraud appears, you are assigned a dedicated U.S.-based case manager who helps:
- File disputes with Equifax, Experian and TransUnion
- Prepare and submit FTC Identity Theft Reports
- Contact creditors and collection agencies
- Track documentation deadlines and responses
- Assist with reimbursement claims when eligible
Plans can include identity theft insurance of up to $1 million per adult to cover eligible expenses such as lost wages, legal fees and document replacement costs related to identity theft recovery.
No service can prevent every misuse of a stolen ID. But when the issue involves police reports, credit bureaus, tax agencies and collection accounts, having structured support can make all the difference.
The California woman in this case was not enrolled in an identity theft protection service. Some businesses may reverse fraudulent charges, but it is unclear whether she recovered the full $78,500.
See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Kurt’s key takeaways
Credit card fraud follows a defined path. You report the charge, the issuer investigates and your account number changes. In most cases, the disruption ends there. Physical ID theft moves differently. It spreads across rental companies, hotels, credit bureaus and sometimes law enforcement databases. Instead of one dispute, you may face several. Instead of replacing a number, you must protect a permanent identity marker tied to your name. That shift matters. A stolen driver’s license carries your legal identity into the real world. Therefore, recovery demands documentation, patience and persistence. Each business sets its own rules. Each agency runs its own timeline. You coordinate the process. The lesson is clear. Protecting your financial accounts is critical. However, protecting your physical identification may be even more important. Once someone uses it in person, the cleanup becomes personal, procedural and time-consuming. Layered monitoring, early alerts and fast reporting reduce long-term damage. The faster you respond, the more control you keep.
Have you ever dealt with physical ID theft, and did the recovery process take longer than you expected? Let us know your thoughts by writing to us at Cyberguy.com
Sign up for my FREE CyberGuy ReportGet my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Technology
YouTube will let you ask AI to make a custom video feed
YouTube is launching a new AI feature that creates a personalized video feed based on descriptions of what you want to watch. In its announcement, YouTube says custom content feeds can be built around your specific interests, moods, or favorite topics, which you can then pin to the top of your YouTube homepage — making it easy to jump back into the feed.
This feature is currently rolling out with English language support to YouTube users in the US who are signed-in on the YouTube mobile app or desktop. To access it, click on the “Your custom feed” tab at the top of the YouTube homepage and enter a prompt description into the AI text box. For example, you can ask the YouTube AI to “help me unwind with guided meditations under 10 minutes,” or for “deep-dive tech podcasts about AI,” and then receive a curated feed based on your request.
It’s similar to other AI-powered feed customization features we’ve seen from other platforms, including Spotify’s prompted playlists. Instagram also gave users more control over their Reels feed algorithm in December, though that uses topic lists rather than descriptive prompts.
YouTube says that prompts can be edited at any time to “generate a brand new space” by selecting the text box at the top of your custom feed. To see the “Your custom feed” tab, YouTube says you need to ensure your search and watch history are enabled in your account settings. If the AI messes up your feed request, you can also report the issue to YouTube by clicking the 3-dot menu on the feature tab and selecting “Something wrong?” to leave feedback.
Technology
Are bank text codes enough to protect you?
NEWYou can now listen to Fox News articles!
Bank security can feel confusing because every account seems to handle it differently. One bank sends a text. Another sends an email. Another asks you to approve a login inside its app. So when someone says, “Use stronger two-factor authentication,” it is fair to wonder what that actually means.
Kyra from West Plains, Missouri, reached out to us asking:
I watched your podcast video where you talked about two-factor authentication and getting codes by email from your bank and other accounts. My accounts seem to do that automatically, as far as I know. Is that enough, or do I need to contact my bank to make sure it’s set up correctly
Kyra, this is a great question because a lot of people are in the same boat. They see a code pop up and assume they are fully protected. The truth is a little more complicated. Text or email codes are better than having only a password.
Text and email codes, however, are not always the strongest options. Scammers have found ways to steal codes, trick people into sharing them or take control of a phone number through a SIM swap scam. Once scammers control your number, they may receive the text codes needed to get into accounts that use SMS-based multi-factor authentication.
TOP MULTI-FACTOR AUTHENTICATION APPS TO PROTECT YOUR ACCOUNTS
Bank customers using text-message security codes may still face risks from SIM swap scams and phishing attacks. Cybersecurity experts recommend stronger login protection when available. (Anna Barclay/Getty Images)
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
What two-factor authentication actually does
Two-factor authentication, also called 2FA or multi-factor authentication, adds another step when you log in. Instead of relying only on your password, the account asks for something else to prove it is really you.
That “something else” might be a code sent by text, a code from an authenticator app, a security key or a prompt inside your bank’s mobile app. Two-factor authentication is one of the best ways to protect your accounts because it adds a second layer beyond your password.
So, Kyra, if your bank already sends you a code, that is a good sign. It means some form of extra protection is turned on. But the next question is whether your bank offers a stronger option.
SIM SWAP SCAM DRAINED FLORIDA WOMAN’S BANK ACCOUNT IN MINUTES
Why text message codes are not the strongest choice
Text message codes are popular because they are easy to use. Most people know how to read a text and type in a code. That convenience comes with risk.
A SIM swap scam happens when a criminal tricks your phone carrier into moving your phone number to a device they control. Once that happens, your calls and texts may go to the scammer instead of you. The American Bankers Association warns that scammers may try to intercept two-factor authentication codes so they can access financial accounts.
Scammers can also call, text or email while pretending to be your bank. They may say there is fraud on your account and ask you to read back a code. That code may actually be the key they need to log in. Scammers often try to trick people into sharing verification codes because they need both the password and the code to break into an account.
BEWARE FAKE CREDIT CARD ACCOUNT RESTRICTION SCAMS
That is why the safest rule is simple: Never share a bank security code with anyone who contacts you. A real bank should not call and ask you to read back a login code.
Why an authenticator app is usually better
When your bank supports it, an authenticator app is usually a stronger choice than text messages. Apps such as Google Authenticator, Microsoft Authenticator, Authy and Duo Mobile generate a changing six-digit code on your phone.
The big advantage is that the code is created inside the app. It usually works even when you do not have cell service. It also does not depend on your phone number, which helps reduce the risk from SIM swap scams.
That said, authenticator apps are not magic. If you type a code into a fake banking website, a scammer may still capture it. One-time password authentication isn’t phishing-resistant. Still, authenticator apps remove some of the biggest weaknesses tied to text-message codes.
NEW PHISHING ATTACK USES REAL-TIME INTERCEPTION TO BYPASS 2FA
Two-factor authentication adds a second layer of protection to online banking accounts, but not all methods offer the same level of security. Authenticator apps and passkeys are generally safer than text codes. (Kyle Ericksen/WWD/Penske Media via Getty Images)
The strongest option, if your bank offers it
Some banks and financial services give you stronger ways to prove it is really you when you log in. Two of the strongest options are hardware security keys and passkeys.
A hardware security key is a small physical device, often shaped like a USB stick, that you plug into your computer or tap against your phone to approve a login.
A passkey lets you sign in using your device, such as your phone or computer, often with Face ID, Touch ID, a fingerprint or a screen lock.
These options are harder for scammers to steal because they are designed to work only with the real website or app. That means a fake banking website usually cannot trick them the same way it can trick someone into typing in a text code.
For most people, the safest order is simple: use a security key or passkey if your bank supports it. If not, use an authenticator app. If text codes are the only option, keep them turned on because they are still better than using only a password.
How to check your bank’s security settings
You may not need to visit a branch. In most cases, you can check this from your bank’s official website or app.
Start from a computer if you can. Go directly to your bank’s official website by typing the web address yourself. Do not click a link from a text or email, even if it looks real.
Then look for a section with a name like:
- Security
- Login & Security
- Privacy & Security
- Two-Factor Authentication
- Multi-Factor Authentication
- 2-Step Verification
Once you are there, look for an option called Authenticator app. Some banks may use different wording, such as authentication app, one-time passcode app, TOTP, security app or third-party authenticator. If you see that option, follow the setup steps. Your bank will usually show a QR code on your computer screen. Open your authenticator app on your phone, tap Add account or the + button, then scan the QR code. The app will generate a six-digit code. Enter that code on your bank’s website to confirm setup.
Do not skip the backup codes
This part matters more than people realize. If your bank gives you backup codes, save them right away. Print them and store them somewhere safe, or place them in a secure password manager. These codes can help you get back into your account if your phone gets lost, damaged or replaced.
Also, make sure your bank has your current email address and phone number on file. If your recovery information is old, getting back into your account can become much harder.
If you share access with a spouse or trusted family member, ask your bank how additional users should set up their own secure login. Avoid sharing one password or one authenticator code when the bank offers separate user access.
What to do if your bank only offers text codes
Some banks may not offer a third-party authenticator app, but may let you approve logins inside the bank’s own mobile app. That can be stronger than a text message because the approval happens inside the banking app rather than through your phone number.
AMERICA’S MOST-USED PASSWORD IN 2025 REVEALED
If yours only offers text-message codes, do not turn them off. Text codes are still better than no second layer at all. However, you should ask your bank whether it supports a stronger option. You can call the number on the back of your debit or credit card, use secure messaging inside the bank’s app or visit a branch.
Ask this: “Do you support authenticator apps, passkeys, hardware security keys or app-based login approval for online banking?”
If the answer is no, keep text codes turned on. Then strengthen the parts you can control. Use a strong and unique bank password, and store it in a trusted password manager so you do not have to remember it or reuse it anywhere else. Check out the best expert-reviewed password managers of 2026 at CyberGuy.com.
In addition, ask your mobile carrier to add a port-out PIN, number transfer lock or account security PIN to help reduce SIM swap risk. Also, turn on account alerts for transfers, password changes and new device logins.
HOW SIM SWAPPING LED TO A $1.8M CYBER FRAUD CASE
Security experts warn that scammers can intercept text verification codes or trick customers into sharing them. Customers should never provide login codes to unsolicited callers or texts. (Karl-Josef Hildenbrand/picture alliance via Getty Images)
Should Kyra contact her bank?
Yes, but she probably does not need to walk into a branch unless she prefers in-person help. Kyra should first log in to her bank’s official website or app and check the security settings. If she sees an authenticator app, passkey, security key or app-based approval option, she should consider using it. If she only sees text or email codes, she should keep them turned on and contact the bank to ask whether stronger login options are available.
She should also make sure her bank password is strong and unique, protect her email account with strong two-factor authentication and confirm that her account alerts are turned on.
WORLD PASSWORD DAY: CHECK IF YOUR PASSWORDS ARE SAFE
Kurt’s key takeaways
Kyra’s question gets to the heart of account security. Seeing a code arrive by text or email can feel reassuring. And yes, it is better than relying on a password alone. However, bank accounts deserve the strongest protection your bank offers. If you can move from text codes to an authenticator app, that is a smart upgrade. If your bank supports a passkey or security key, even better. And no matter which method you use, never give a security code to someone who calls, texts or emails you out of the blue.
Have you checked whether your bank still relies on text codes, and would you switch banks if yours refused to offer stronger login protection? Let us know by writing to us at CyberGuy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
All the news about Ferrari’s polarizing Luce EV
Ferrari released the first interior images of the company’s first all-electric supercar, called the Ferrari Luce (“light” in Italian). This is the second time the Italian automaker has teased the Luce (formerly Elettrica) without showing us the actual car, or even a silhouette. But the interior images should suffice given the bold-faced name of the designer: Jony Ive.
Ferrari decided to outsource the work of designing the Luce’s interior to Ive and his partner Marc Newson, who together run the design shop LoveFrom. Ive, obviously, is well known for his work as Apple’s former chief designer, overseeing such iconic products as the iMac, iPhone, iPad, and Apple Watch. Now he’s turning his attention to a vehicle from Ferrari — and perhaps, in the process, giving us an idea of what an Apple car could have looked like, had the tech giant decided to pursue its secretive Project Titan instead of spiking it.
Read Article >
-
Wyoming6 minutes agoProposed Seminoe pumped storage project draws criticisms at Wednesday public meeting
-
Crypto12 minutes agoUS-Iran Escalation Pushes Bitcoin to $72,622 as $870M Long Bets Collapse
-
Fitness24 minutes agoI Spent Years Believing Exercise Wasn’t for Me—Until I Ran My First Half Marathon at 35
-
Movie Reviews36 minutes agoMovie review: ‘Power Ballad’ follows a weak Nick Jonas/Paul Rudd feud – UPI.com
-
World48 minutes ago
Think it’s hot now? The next five years will smash records, UN says
-
News54 minutes agoVideo: They Fought for the Voting Rights Act. Now They’re Fighting Its Unraveling.
-
Business1 hour agoVideo: Ferrari’s Stock Falls After It Unveils Its Latest Car
-
Lifestyle2 hours agoKeke Palmer steals the (fashion) scene in ‘I Love Boosters’ : Pop Culture Happy Hour