By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Bank’s Investigation Began
The customer service representative immediately froze the new credit card.
She assured me that it could not be activated while they investigated.
Then she asked me another question.
“Have you recently applied for any other loans or credit products?”
My answer was simple.
“No.”
Her response made my heart race.
“You should check your credit history immediately.”
Until that moment, I had never imagined someone could use my identity to apply for financial products.
I Checked My Credit Report
That evening, I requested a copy of my credit report.
I expected everything to be normal.
Instead, I found something terrifying.
There were multiple credit enquiries from banks I had never contacted.
Some had been rejected.
One had been approved.
The approved application was the credit card sitting on my table.
Someone had been trying to borrow money using my identity.
Then I Started Looking Through My Emails
I searched my inbox for messages from banks and financial institutions.
Buried among hundreds of emails, I found several messages I had ignored.
Some were verification emails.
Others confirmed attempts to create online banking accounts.
At the time, I assumed they had been sent by mistake.
Now I realised someone had been testing whether they could access my financial identity.
The Bank Explained What Might Have Happened
The fraud department told me that criminals don’t always need a physical ID to impersonate someone.
If they collect enough personal information, they may attempt to complete online applications by answering security questions or using stolen identity details.
That information can come from many different sources, including data breaches, phishing attacks or other forms of identity theft.
The goal is simple.
Open financial accounts before the real person discovers what’s happening.
I Began Checking Everything
I reviewed all my financial accounts.
Fortunately, my existing bank accounts still appeared secure.
But I noticed something unusual.
Several online accounts had received password reset requests that I had never initiated.
Someone wasn’t just trying to open a credit card.
They were trying to gain access to other parts of my digital life.
The Fraud Team Asked an Important Question
The investigator asked whether I had recently:
- Clicked suspicious links.
- Shared personal information online.
- Uploaded identification documents to unfamiliar websites.
- Responded to unexpected phone calls requesting personal details.
I couldn’t think of anything obvious.
But then I remembered something.
Months earlier, a company I used had announced a data breach affecting customer information.
At the time, I changed my password and moved on.
I never imagined that stolen personal information could later be used to apply for financial products in my name.
The Situation Became More Serious
The fraud team warned me that criminals often don’t stop after opening one account.
If successful, they may continue applying for:
- Additional credit cards.
- Personal loans.
- Mobile phone contracts.
- Buy-now-pay-later accounts.
- Other financial services.
The sooner identity theft is discovered, the easier it is to limit the damage.
I realised the unexpected credit card wasn’t the problem.
It was the warning sign that exposed a much larger threat.
In the final part of this story, I’ll explain how the investigation ended, reveal practical ways to protect yourself from identity theft, and share the lessons I learned after discovering someone had tried to become me.
Continue Reading: The Credit Card That Arrived in My Name—But I Never Applied for It (Part 3)









