Skip to main content
18 August 2026

Identity Theft: The Cyber Risk Most People Underestimate

By Johannes Troppmann, Chief Information Security Officer & Data Protetcion Officer at SPIE Switzerland

Identity Theft The Cyber Risk Most People Underestimate

A few weeks ago, I was speaking with a colleague about cybercrime. Like many people, the colleague assumed that hackers mainly target large organizations, exploiting technical vulnerabilities and breaking into systems.

The reality is often much simpler.

Today, cybercriminals frequently focus less on technology and more on people. They are not necessarily trying to hack a firewall. They are trying to gain access to an identity.

As Chief Information Security Officer of SPIE Switzerland and 20+ years Consulting experiance, I regularly see how a stolen password, a compromised email account or a carefully crafted phishing message can have far greater consequences than many people expect. Identity theft has become one of the most common starting points for fraud, data breaches and cyber incidents, both in our professional and private lives.

And the trend is growing.

In Switzerland, more than 5,000 cases of digitally enabled identity misuse were recorded in 2025 (Swiss Federal Statistical Office, Police Crime Statistics 2025). In 2026 about 8000 cases in 2023 about 470 cases. And these are only the know and reported cases, the real number is huge. 

Yet despite these numbers, identity theft is still often perceived as somebody else's problem.

Your Identity Is More Valuable Than You Think

When most people hear the term "identity theft", they think about a stolen passport or credit card.

Cybercriminals think differently.

To them, an identity is a collection of valuable information: an email address, a password, a mobile phone number, social media profiles, business contacts and online accounts. Combined together, these details can be used to impersonate someone, access systems or launch convincing fraud attempts.

What makes the situation particularly concerning is the amount of personal information already available online. According to the CRIF Cyber Observatory, more than 7.5 billion records were identified on criminal marketplaces and in the dark web, with over 94% containing combinations of email addresses and passwords (CRIF Cyber Observatory 2024). 

Most victims are unaware that their information is circulating until damage has already occurred.

The Real Target Is Often Trust

One of the biggest misconceptions about cybersecurity is that attacks are primarily technical.

In reality, many successful attacks exploit trust rather than technology.

An employee receives an email that appears to come from Microsoft.

A manager receives a message that seems to originate from a colleague.

A finance team member receives what looks like a legitimate request from a supplier.

These situations happen every day.

Current cyber threat reports in Switzerland continue to show that phishing, credential theft and online fraud remain among the most common types of cyber incidents (Swiss Federal Office for Cybersecurity, Cyber Threat Landscape Switzerland)

The objective is almost always the same: obtain credentials, access information or convince somebody to perform an action they would not normally perform.

This is why I often say that cybersecurity is not primarily a technology challenge. It is a human challenge.

Why Businesses Should Care

Identity theft does not only affect private individuals.

When an employee's account is compromised, the consequences can quickly extend beyond a single person. Depending on the role and level of access involved, attackers may gain access to confidential information, internal systems or sensitive customer data.

The resulting impact can range from financial losses and operational disruption to regulatory investigations and reputational damage.

What concerns me most is that these incidents often begin with something seemingly harmless: a reused password, a successful phishing email or a lack of awareness.

Many organizations invest heavily in technology, which is absolutely necessary. However, technology alone is not enough. Security tools cannot completely prevent an individual from trusting the wrong email or disclosing information to the wrong person.

The Good News: Prevention Is Not Impossible

Unlike many cybersecurity challenges, protecting against identity theft does not always require complex solutions.

In my experience, a few basic practices dramatically reduce risk:

  • Use unique passwords for every service.
  • Store passwords in a trusted password manager.
  • Enable multi-factor authentication wherever possible.
  • Be cautious with unexpected requests, especially those involving urgency or sensitive information.
  • Verify unusual communications through a second channel.
  • Invest in awareness and employee education.

These measures may sound simple, but they remain among the most effective defenses available.

A Question Worth Asking

If somebody obtained one of your passwords today, how much of your professional or private life could they access?

For many people, the answer is uncomfortable.

That is precisely why identity theft has become such an attractive business model for cybercriminals. Stolen identities can be reused, sold, combined with other information and exploited long after the initial compromise.

The good news is that awareness remains one of the strongest defenses. People who understand the risks are more likely to recognize suspicious behavior, challenge unusual requests and report incidents early.

Final Thoughts

Twenty years ago, criminals stole wallets.

Today, they steal identities.

In an increasingly connected world, our digital identities have become some of our most valuable assets. Protecting them is no longer only an IT responsibility. It is a shared responsibility for organizations, employees and individuals alike.

At SPIE Switzerland, we believe that effective cybersecurity is not about creating fear. It is about helping people understand risks, make informed decisions and build a security culture where technology, processes and human awareness work together.

Because in the end, the strongest defense against identity theft is not a security tool.

It is an informed and vigilant person.

 

Find out more about our cybersecurity services

Share

SPIE ICS
Blog
Cybersecurity