identity.org.au

Guides · Staying safe

How to protect your identity for free

You do not need to spend money to protect your identity. A practical, free checklist: device locks, passkeys, breach alerts, scam resistance, and sharing proofs instead of documents.

Identity.org.au editorial · Last updated 25 September 2026

Most identity protection costs nothing. The tools that matter most — device encryption, passkeys, unique passwords, breach alerts — are built into the phones, browsers and accounts you already have. What you pay for instead is convenience, and much of that convenience can be skipped entirely.

This guide is the free list, in the order that does the most good. Nothing here asks you to buy anything, and nothing asks you to install anything beyond what your own devices already provide.

Lock the device in your hand

Your phone holds your accounts, your messages and your recovery codes. It is the highest-value target in your digital life, and a five-digit habit protects most of it:

  • Set a real screen lock — a long passcode or biometrics, never nothing. Modern phones encrypt their storage as soon as a lock exists, so the lock is also what makes a lost phone unreadable to whoever finds it.
  • Keep the operating system updating. Security patches arrive this way, and skipping them leaves known holes open for anyone who looks.
  • Turn on the built-in location and remote-wipe features. They are free, preinstalled, and the difference between a lost phone and a lost identity.
  • Never leave your phone unlocked in shared spaces, and treat “borrow my phone” requests with the same care you would give your wallet.

The full version of this checklist, with the reasoning behind each item, is the device security checklist — and if a phone is already lost, start at lost or new device.

Make passwords impossible to reuse

Password reuse is the mechanism behind most account takeovers: one breached service hands an attacker the keys to everything else. The fix is free and boring, which is why it works.

  • Use the password manager built into your browser or phone — or any reputable free one — to generate a long, unique password for every account. You remember one phrase; the machine remembers the rest.
  • Protect your primary email account above everything. It is the recovery path for every other account, so it gets the strongest unique password and free multi-factor authentication turned on.
  • Adopt passkeys wherever they are offered. A passkey cannot be phished, reused or guessed, because it never leaves your device in a form a server can lose.
  • Treat “security questions” (first school, first car) as passwords in disguise — answers that are guessable are not secret, so make them long strings only you would type.

Stop documents from circulating

Every copy of your identity document is inventory for someone else's breach. Photos of licences and passports get emailed to strangers, stored in inboxes, and forgotten in systems you have never heard of — until you have. The free defence is subtraction: share less.

  • Ask what is actually needed. Often the fact — “over 18: yes”, “name matches” — satisfies the request without the document ever moving.
  • Resist photographing documents for casual verification. If a service accepts a photo of your licence, that photo now lives in their storage; the strength of their check is not your problem, but the retention is.
  • Never send identity documents to anyone who contacted you first. Legitimate verifiers ask inside a flow you started, not over a message you did not expect — see recognising scams and phishing.
  • Redact what you do not need to show: a document number rarely needs to accompany a proof of age.

A stronger version of this habit exists: prove the threshold instead of showing the document — a zero-knowledge proof answers the yes/no question and reveals nothing else. The wallet is free and open source, and the age proof walkthrough shows what that looks like in practice.

The cheapest protection is the data you never share. Every document you do not send is a copy that cannot leak, be sold, or be subpoenaed from somewhere you forgot existed.

Recognise the approach before it arrives

Most identity theft begins with a conversation, not a hack — someone convincing you to hand over a code, a password or a document. The patterns repeat enough to memorise:

  • Urgency plus authority. “Your account closes today”, “we need verification immediately”. Real institutions tolerate delays; attackers cannot afford them.
  • Any request for a one-time code or password. No legitimate service needs yours — the code is the lock, and asking for it is the tell.
  • Unexpected contact that ends at an unexpected link. Navigate to the service yourself instead of tapping through.
  • Too good, too fast, too friendly. Investment pitches, romance, job offers and parcel fees all converge on the same ask: verify yourself, or pay, now.

The longer version — message-by-message examples and what to do when you have already replied — is in recognising scams and phishing. National scam-reporting services such as Scamwatch publish free, current guidance on the schemes circulating now.

Turn on the free early-warning systems

Detection is the part people skip, because it is quiet and free:

  • Enable login and recovery alerts on your email and banks. The moment an unfamiliar sign-in happens, you want the message — not the discovery weeks later.
  • Use free breach-notification features where your providers offer them, and treat every notified exposure as a prompt to change that password everywhere it was reused.
  • Review account recovery details: make sure the phone number and alternate address on critical accounts are ones you still control.
  • Check your financial statements for activity you did not authorise — the earliest signal of an impersonated identity is usually a small, strange transaction.

If something has already gone wrong

Recovery is the expensive part — but it is also where free, official help exists. Start by changing the credentials the attacker could hold, then work outward from your primary email. Report the incident to the relevant service and to national reporting channels; if documents were exposed, treat every service where those documents were used as needing attention.

The step-by-step version, including what to do in the first hours, is data breach response. If someone is actively using your identity, the support paths in the help centre cover what to do and who to contact.

What the free wallet adds

The Identity Wallet on this site is free and open source, with no subscription and no fee — its contribution to the free list is structural rather than incremental. Documents are presented once during verification instead of circulating forever; services receive answers, never documents; and consent for each disclosure is explicit, expiring and revocable.

Honest status, as always: the wallet is open-source reference infrastructure rolling out with the VirtEngine network, with no app-store listings at this stage. What the code does today is published on the open-source page — no availability claims beyond it.

Quick answers

What is the single most effective free identity protection?

A screen lock with a strong passcode plus unique passwords from a built-in password manager, with multi-factor authentication on your primary email. Together they close the three doors attackers use most: the physical phone, reused passwords, and email-based account recovery.

Do I need to pay for identity protection services?

Not to get the essentials. Device security, unique passwords, passkeys, login alerts and breach notifications are free and built in. Paid services mostly bundle monitoring you can replicate with alerts and periodic checks — worth it for convenience, not required for protection.

Is photographing my identity documents ever safe?

Safer when unavoidable, but the goal is to make it unnecessary. Each photo creates another copy in someone else's system. Where only a fact is needed — age, name, address — share the fact instead; a proof answers the question without the document travelling.