Identity Theft and Account Protection: SEC's 2026 Updated Guidance
Phishing, smishing, and vishing attacks targeting investment accounts are at an all-time high. Based on the SEC's 2026 updated investor alerts, here's how to protect your accounts and what to do if your identity is stolen.
Investment accounts are prime targets for identity thieves because they hold liquid assets that can be quickly transferred. The SEC's 2026 updated investor alerts warn that cybercriminals are using increasingly sophisticated techniques to compromise online brokerage accounts, retirement accounts, and crypto exchange accounts. The SEC's Office of Investor Education and Advocacy has issued specific guidance on protecting investment accounts from phishing, smishing (SMS phishing), and vishing (voice phishing) attacks. These attacks exploit human psychology rather than technical vulnerabilities — they trick you into giving away your credentials rather than hacking through security systems. The most important defense is awareness: knowing how these attacks work and what red flags to look for. Read our comprehensive identity theft guide →
Real-world example: In 2025, a sophisticated smishing campaign targeted Fidelity customers. Victims received an SMS that appeared to come from Fidelity: "Suspicious login detected. Verify your identity immediately: fidelity-secure-verify.com." The fake website looked identical to Fidelity's login page. Victims who entered their username, password, and 2FA code had their accounts drained within minutes. The scammers used the stolen credentials to log in, trade positions, and transfer funds to external accounts. Fidelity reimbursed some victims, but those who delayed reporting lost significant amounts. The campaign affected thousands of customers across multiple brokers. Learn about impersonation scams →
Phishing, Smishing, and Vishing
Phishing (Email)
Phishing emails appear to come from your broker, bank, or crypto exchange. They claim your account has been compromised, a withdrawal is pending, or your account needs verification. The email contains a link to a fake login page that steals your credentials. Red flags include: generic greetings ("Dear valued customer"), urgent language ("your account will be suspended"), misspelled domains (brokerage-secure.com instead of the real domain), and unsolicited attachments. Never click links in emails about your financial accounts. Navigate directly to the website using your bookmarked URL.
Smishing (SMS/Text)
Smishing is phishing via SMS text messages. These have become increasingly common because people trust text messages more than email. Scammers spoof legitimate phone numbers to make the text appear in the same conversation thread as real messages from your broker. The text typically warns of suspicious activity and provides a link to "secure your account." The link leads to a fake login page. Financial institutions never send text messages asking you to click a link to verify your account. If you receive such a text, do not click the link. Forward it to your financial institution's fraud department and delete it.
Vishing (Voice Calls)
Vishing scams use phone calls to trick victims into revealing information. The caller may spoof the financial institution's phone number (caller ID spoofing). They claim to be from the fraud department and say your account has been compromised. They ask for your account number, password, or 2FA code to "verify your identity." In reality, they are using the information you provide to access your account. Sometimes they already have partial information and use the call to obtain the missing pieces. If you receive an unexpected call from your financial institution, hang up and call back using the number on your statement or the official website. Do not use any phone number the caller provides. Learn how scammers impersonate financial institutions →
Mobile Payment Services Fraud: Venmo, CashApp, and Zelle Scams
Peer-to-peer (P2P) payment apps — Venmo, CashApp, Zelle, PayPal, and similar services — have become a major target for scammers. These apps were designed for sending money between friends and family, not for transactions with strangers. The fatal flaw is that payments on these apps are typically instant and irreversible — once you send money, there is no "chargeback" button. Scammers exploit this finality in countless ways. Common P2P payment scams include: a scammer sends you a payment "by accident" and asks you to send it back (the original payment was from a stolen account and will be reversed, leaving you out the money you sent); a scammer sells event tickets, electronics, or other goods but never delivers after receiving payment; a scammer poses as a grandchild in distress needing money immediately; a scammer claims to be a landlord or property manager demanding a deposit; or a scammer offers to buy something from you but sends a fake payment confirmation email. To protect yourself, only use P2P payment apps with people you know and trust in person. For transactions with strangers, use payment methods with buyer/seller protection — credit cards, PayPal Goods and Services, or escrow services. Enable all available security features: require a PIN or biometric to send money, disable automatic acceptance of payments, and set up transaction notifications. If you are scammed via a P2P app, contact the app's support team immediately, report to your bank, file a complaint with the FTC, and report to the FBI's IC3. Be aware that most P2P apps do not offer fraud protection for authorized payments — even if you were tricked into sending the money. Learn about fake online store scams →
Data Breach Response
When a company you do business with suffers a data breach, your personal information may be exposed. Take these steps immediately after a data breach notification. First, determine what information was exposed. If it was your email and password, change your password on that account and any other account that uses the same password. Never reuse passwords across financial accounts. If your Social Security number was exposed, place a fraud alert or credit freeze with all three credit bureaus — Equifax, Experian, and TransUnion. If your financial account numbers were exposed, contact your financial institution to close the compromised accounts and open new ones. Enable two-factor authentication on all financial accounts if you have not already. Monitor your credit reports and account statements closely for at least 12 months following a breach. Consider using identity monitoring services if the breach exposed sensitive information. The SEC recommends that investors sign up for account alerts from their brokerage firms — notifications for logins, withdrawals, and address changes. Learn more about credit freezes →
How to Protect Online Investment Accounts
Strong Passwords
Every financial account should have a unique, complex password that you do not use anywhere else. Use a password manager (Bitwarden, 1Password, LastPass) to generate and store strong passwords. Your email password is especially important — if a scammer gains access to your email, they can reset passwords on your financial accounts. Use the strongest possible password for your email and secure it with 2FA using an authenticator app.
Two-Factor Authentication (2FA) and Multi-Factor Authentication (MFA)
Enable 2FA or MFA on every financial account that offers it. Avoid SMS-based 2FA when possible — SIM swapping attacks can intercept your text messages. Use an authenticator app (Google Authenticator, Authy, Microsoft Authenticator) or a hardware security key (YubiKey). For brokerage and crypto accounts, use a hardware security key for the highest level of protection. MFA makes it significantly harder for scammers to access your accounts even if they have your password. Learn about SIM swap attacks →
Biometric Authentication
Most brokerage and banking apps now support biometric authentication — fingerprint or facial recognition. Biometrics provide a combination of security and convenience. Unlike passwords, biometric data cannot be easily stolen or guessed. Enable biometric login on all financial apps that support it. However, always maintain a strong password as a backup — biometric data can be invalidated by injuries, and devices can be lost or replaced. Biometrics should complement, not replace, other security measures.
SEC's Lost and Stolen Securities Program
The SEC operates a Lost and Stolen Securities Program (LASS) that tracks reports of lost, stolen, or counterfeit securities certificates and provides investigative assistance to law enforcement. Under SEC Rule 17f-1, brokers, dealers, banks, and transfer agents are required to report lost, stolen, or counterfeit securities to the SEC. The LASS database helps prevent fraudulent transfer or sale of stolen securities and assists in recovery efforts. If your physical stock certificates are lost or stolen, report the loss to your broker or transfer agent immediately. They will file a report with the SEC's LASS program. While most securities are now held in electronic (book-entry) form through the Depository Trust Company (DTC), physical certificates still exist and require additional protection. Consider converting physical certificates to book-entry form through your broker to eliminate the risk of loss or theft. Learn more about account protection →
Adding a Trusted Contact to Your Account
FINRA rules require brokerage firms to ask customers if they want to designate a trusted contact person. A trusted contact is someone you authorize your broker to contact if they have concerns about financial exploitation of an older or vulnerable adult, if they suspect fraudulent activity in your account, or if they cannot reach you. The trusted contact does not have authority to make trades or withdraw funds — they are simply a point of contact. Designating a trusted contact is one of the simplest and most effective steps you can take to protect your investment accounts. If a scammer is attempting to liquidate your accounts, the broker can contact your trusted contact to verify the activity. When you open a new brokerage account or update your account information, you will be asked whether you want to designate a trusted contact. Say yes, and choose someone you trust who is financially responsible. Learn about account impersonation scams →
What to Do If You Suspect Identity Theft
If you suspect your identity has been stolen or your investment accounts have been compromised, act immediately. First, contact your broker or financial institution and freeze your accounts. Second, change your passwords and revoke any active sessions. Third, file a report with the FBI's IC3 (ic3.gov) and the FTC (IdentityTheft.gov). Fourth, place a fraud alert or credit freeze with all three credit bureaus. Fifth, review your account statements and credit reports for unauthorized activity. Sixth, file a police report with your local law enforcement. Seventh, contact the SEC's Office of Investor Education and Advocacy for guidance. The SEC recommends keeping detailed records of all communications and transactions related to the incident. The faster you act, the more likely you are to limit your financial liability. Many brokers have fraud protection policies that cover losses if you report the incident promptly.
Related Resources
Identity Theft Protection
Comprehensive guide to preventing and responding to identity theft.
Impersonation Scams
How fraudsters impersonate the SEC, FINRA, and brokers.
Internet & Social Media Scams
How scammers use online platforms to steal identities.
Crypto Asset Scams
Protect your crypto accounts from phishing and theft.
Common Investment Scams
Overview of scams that target investment accounts.
Weekly Digest Newsletter
Get security alerts delivered to your inbox weekly.