Skip to content

Identity Monitoring

Identity monitoring is a paid service that watches non-credit databases for your personal information and tells you when it appears. It is the Federal Trade Commission's name for the product usually sold as dark web monitoring, and the FTC also publishes what it will not catch.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • It is one of four consumer products the FTC distinguishes, alongside credit monitoring, identity recovery services and identity theft insurance.
  • What vendors market as dark web monitoring is one item on the FTC's list of what identity monitoring may alert you to, not a separate product.
  • The difference from credit monitoring is which database is watched. Credit monitoring watches your credit file; this watches everything else.
  • The FTC also publishes a list of six things most of these services will not alert you to, and five of the six are government-benefit claims.
  • You may already have it. The FTC notes these services may come through a bank, credit union, card provider, employer benefits program or insurer.

Definition

Identity monitoring is a service that checks databases outside the credit reporting system for new or inaccurate information associated with you, and notifies you when it finds some. The Federal Trade Commission describes it as companies that "check databases that collect different types of information to see if they contain new or inaccurate information about you, including things that might not show up on your credit report."

It is worth naming carefully, because the phrase most people search for is not the name of the product. The FTC groups consumer identity products into four categories: credit monitoring, identity monitoring, identity recovery services and identity theft insurance. Dark web monitoring is not a fifth category. It is one item on the FTC's list of what an identity monitoring service may alert you to, described there as information showing up "on websites that identity thieves use to trade stolen information." A subscription sold on the strength of dark web scanning is an identity monitoring subscription with one of its features in the advertisement.

The distinction from credit monitoring is which file is being watched. Credit monitoring watches your credit report and reports changes to it, and our page on it sets out what those changes are and the one case where federal law requires the service free. Identity monitoring looks in other places: public records, application databases, marketing and telecommunications records, social media, and the marketplaces where stolen data is traded. Neither prevents anything. Both report events that have already happened.

Advanced Explanation

What it actually watches, in the FTC's own list. Identity monitoring services may tell you when your information shows up in a change of address request; in court or arrest records; in orders for new utility, cable or wireless services; in an application for a payday loan; in a request to cash a check; on social media; and on websites that identity thieves use to trade stolen information.

That list rewards reading twice, because it explains the product's real value and its real limit at once. Several of those events are genuinely early: a change of address request, a utility account and a payday loan application are all things someone does with your identity before they get anywhere near your credit file, and a credit report would not show any of them. So identity monitoring covers a category of harm credit monitoring structurally cannot. Equally, every item on the list is a detection after the fact. Nothing on it is prevented by the service noticing it.

The second list is the one worth reading before buying. The FTC also publishes what these services will miss: "Most identity monitoring services won't alert you if someone uses your information to file a tax return and collect your refund, get Medicare benefits, get Medicaid benefits, get welfare benefits, claim Social Security benefits, or claim unemployment benefits."

Five of those six are claims on government benefits and the sixth is a fraudulent tax return. Those are among the frauds a person is least likely to discover on their own, because nothing about them shows up in a household's ordinary paperwork until a return is rejected or a benefit fails to arrive. A household deciding whether to pay for this should know that the harms it is most afraid of, someone else collecting its refund or its benefits, sit largely outside what the FTC says the product covers.

A structural blind spot the FTC's lists do not address either way. The service looks for "new or inaccurate information about you", which presupposes that the information is filed under you. A fabricated identity built on a real Social Security number but a different name and date of birth is, by construction, a different person in the records. Whether any given service surfaces that is a question for the vendor rather than something the FTC's guidance answers, and it is worth asking directly if that is the risk you are buying against. Our page on synthetic identity fraud explains why that case is so hard to see.

What it is not, since the four products are routinely bundled and routinely confused. It is not identity recovery, which the FTC describes as access to counselors or case managers who help write letters to creditors, place a freeze and work through documents. It is not identity theft insurance, which reimburses the cost of cleaning up rather than the money taken, and which has its own page here. And it is not a credit freeze, which is the only one of these that actually prevents rather than detects, is free, and does not expire on its own.

The first question is whether you are already paying for it. The FTC notes that you might pay a company for one or get it "through your bank or credit union, credit card provider, employer's benefits program, or insurance company", and free monitoring is usually offered with a breach notice. A subscription bought in response to a breach notice frequently duplicates one the same household already holds.

Used in a Sentence

“The identity monitoring service flagged a payday loan application in her name three weeks before anything appeared on her credit report.”

How It Works

The service works by subscription to data rather than by watching you.

  1. You supply identifiers to be watched: a Social Security number, a date of birth, addresses, email addresses, phone numbers, and often card and account numbers.
  2. Those identifiers are matched against the data sources the vendor has access to, which is where the products differ from one another and where the contract, rather than any statute, decides what you get.
  3. A match produces an alert, which tells you an event has occurred.
  4. You act on it, which is the part the subscription does not do. The response to a genuine alert is a freeze, a fraud alert, a call to the institution involved, and where accounts were opened, the identity theft report our page on identity theft describes.

A hypothetical example, and the comparison is the point rather than the amounts. A household is offered identity monitoring at $19.99 a month, which is $239.88 a year (12 x $19.99). Set against that, freezing credit files at each of the three nationwide bureaus is free, does not expire on its own, and prevents new accounts rather than reporting them.

The two do different jobs, so this is not an argument that one replaces the other. It is an argument about sequence. The free control that stops the commonest harm goes first; the paid control that reports other harms after they happen is a second decision, made knowing that the FTC's own list says most such services will not catch a fraudulent tax return or a claim on Medicare, Medicaid, welfare, Social Security or unemployment benefits. If the household's specific fear is one of those six, the $239.88 is not buying protection against it.

Pros and Cons

Pros

  • It reaches events a credit report never shows: a change of address request, utility, cable or wireless orders, a payday loan application, a request to cash a check, court and arrest records, and stolen data appearing in the marketplaces vendors advertise as dark web scanning.
  • Some of those events are genuinely early, occurring before anything reaches a credit file, which is the strongest argument for the product.
  • It requires nothing of the subscriber once configured, which suits a household that will not check anything manually.
  • It may already be available at no extra cost through a bank, credit union, card provider, employer benefits program or insurer, and free monitoring is usually offered with a breach notice.
  • Alerts arrive with enough specificity to act on, which shortens the gap between a fraud starting and a freeze going on.

Cons

  • It detects rather than prevents. Every alert describes something that has already happened.
  • The FTC's own list of what most of these services will not catch runs to six items, five of them government-benefit claims and the sixth a fraudulent tax return, which is much of what people buy the product fearing.
  • What any particular service covers is set by its contract rather than by statute, so two subscriptions at the same price can watch materially different things.
  • A fabricated identity built on your Social Security number under a different name is filed as a different person, and whether a service surfaces that is a question for the vendor.
  • It duplicates protections that are free, in particular the credit freeze, which prevents the harm this product reports.
  • Bundling makes comparison difficult, since monitoring, recovery services and insurance are sold together and the marketing rarely separates them.

People Also Asked

Answers to the most frequently asked questions.

Is dark web monitoring a different product from identity monitoring?
No. The Federal Trade Commission's product taxonomy has four categories: credit monitoring, identity monitoring, identity recovery services and identity theft insurance. What vendors market as dark web monitoring is one item on the FTC's list of what identity monitoring may alert you to, described as your information showing up "on websites that identity thieves use to trade stolen information." It is a feature of the product, not a product.
How is this different from credit monitoring?
They watch different records. Credit monitoring watches your credit file and reports changes to it, such as a new account, an inquiry or a change of address on the file. Identity monitoring looks outside the credit system: public records, application databases, utility and wireless orders, social media and stolen-data marketplaces. The practical consequence is that identity monitoring can surface some misuse before it ever reaches a credit report.
What will it not catch?
The FTC publishes the list. Most identity monitoring services will not alert you if someone uses your information to file a tax return and collect your refund, get Medicare benefits, get Medicaid benefits, get welfare benefits, claim Social Security benefits, or claim unemployment benefits. Five of those six are claims on government benefits, and they include several of the frauds that take longest to discover.
Should I pay for it, or is a credit freeze enough?
They do different jobs and the order matters more than the choice. A credit freeze is free, does not expire on its own, and stops new accounts being opened in your name, which is prevention. Identity monitoring reports events after they occur, including some a credit file would never show. The freeze is the step to take first; whether the subscription earns its cost depends on whether the risks you are worried about are on the FTC's covered list or its excluded one.
A company that lost my data offered me free monitoring. Is it worth taking?
It generally costs nothing to accept, and it is worth knowing what you are accepting. It is monitoring rather than prevention, so it will tell you about misuse rather than stop it, and it may duplicate a service you already have through a bank, card provider, employer or insurer. Taking it does not replace freezing your credit files, which is the step that blocks new accounts, and our page on the data breach covers what else the notice obliges anyone to do.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Federal Trade Commission. "What To Know About Identity Theft."
  2. Federal Trade Commission. "IdentityTheft.gov."
  3. U.S. Code. "15 U.S.C. § 1681c-1 — Identity theft prevention; fraud alerts and active duty alerts."

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor