Everything else on this site deals with data taken from you: breached, scraped, compiled, resold. This guide is about the remainder, the data nobody had to steal because you published it, and it matters because fraud rarely runs on breach data alone. It runs on the merge: the stolen half from the breach, the volunteered half from you.
The identity kit you assemble in public
Recall what identity verification actually asks: full name, date of birth, address history, mother's maiden name, first pet, first school. Now audit where those answers already live. The birthday: posted annually, with the year deducible from a graduation post. The maiden name: in the family tree visible through a parent's profile. The first pet and first school: answered cheerfully in one of those viral "get to know you" quizzes, which are, functionally, security-question harvesters, whatever their authors intended. None of this is breached data. It is published data, and brokers and fraudsters merge it with breach data to pass the checks that a password alone would not.
The forms that did not need the truth
The second leak is habit: forms ask, so people answer. A pharmacy loyalty program wants a birth date. A Wi-Fi portal wants a phone number. A newsletter wants your full name. Here is the reframe that changes the habit: outside of government, banking, medical, and employment contexts, almost nobody verifies, and almost nobody needs the truth. The loyalty card works with a different birthday. The portal works with a throwaway email. Every field you fill honestly is a row in a database you do not control, waiting for that company's breach to hand it to the merge.
- Real birth date only where legally required: government, bank, medical, employer. Everywhere else, a fixed fake one you reuse.
- Security questions get invented answers, stored in your password manager like passwords. "First pet: K7-harbor-lamp" phishes very badly.
- Email aliases for signups, so one address is not the join key across every database.
- Before submitting any form: "what happens if I leave this blank or lie?" Usually, nothing.
The resume and the announcement
Two special cases worth naming. Resumes on public job boards routinely carry a home address, birth date, and full history: exactly the dossier a fraudster wants, formatted for their convenience. Post the skills, keep the address and dates offline until a real conversation starts. And life announcements, the new house, the new job, the trip: each is honest joy and also timing data. Post the trip after you are home. The burglar and the fraudster both prefer schedules.
None of this asks you to live less publicly. It asks you to stop answering questions nobody actually asked with the truth nobody actually needed. What is already out there, though, is out there: the volunteered half can be tightened from today, but the breached half already exists, and knowing exactly what it contains is where every defense on this site starts.
You control what you share from today. The rest is already out there.
See exactly which known breaches contain your email and what was taken, so you know which half of your identity kit is already circulating.
Run the Free Breach Scan →