
A chief of staff, reviewing statements while the family was abroad, noticed a credit line that no one had opened. A short call to the bank turned up a second surprise: a tax filing submitted in the principal's name, weeks earlier, from an address the family had never used. Nothing had exploded yet. No headline, no drained account. But the ground had shifted quietly under the household, and the question in the room was not "who did this" but "what do we do now, and in what order."
That scenario is illustrative, a composite drawn from patterns we see rather than any specific client. We open with it because the posture it requires is the same one this piece is built around. Steadier, not panicked. At this wealth tier, identity theft rarely stays contained to a single credit file. It cascades across entities, accounts, and people. The instinct to act fast can do as much damage as the fraud itself if it runs ahead of understanding.
This is a recovery-and-remediation playbook. It assumes something has already happened, or that a near miss has surfaced a gap you now need to close. It is not a guide to detecting a breach in the first place.
Who this is for
- Chiefs of staff, family office leads, and executive assistants acting on a principal's behalf
- Principals and spouses navigating an active or suspected incident
- Counsel, advisors, and security leads coordinating a measured response across the household
If you are dealing with active or suspected identity theft, or a recent near miss that revealed exposure you did not know existed, this playbook is written for you.
At a glance
- Identity theft at this tier is structural, not a single credit file. It touches trusts, LLCs, custodians, real estate, and family members.
- The first 72 hours are about containment and documentation, not frantic action.
- Family and staff are part of the perimeter. Remediation that stops at the principal tends to leave the door open.
- Recovery is the moment to build a standing capability, not just to clean up.
Outcomes vary. The goal here is meaningful risk reduction and a calm, documented path forward.
This is not legal, tax, or financial advice. Coordinate with qualified counsel and advisors. Identity theft touches police reports, regulatory processes, credit bureaus, tax authorities, and insurance claims, all of which belong to qualified professionals. This playbook is meant to help you sequence and coordinate a response, not to replace the counsel and specialist advisors who should own the formal steps.
Why identity theft is structurally different at this wealth tier
Most identity theft advice assumes one person, one bank, one address, one credit file to freeze. That advice is not wrong. It is simply built for a life that looks nothing like a principal's.
A high-net-worth household is a network. There are trusts and LLCs, sometimes dozens of entities. There are delegated signatories, custody relationships with banks and brokerages, real estate held across jurisdictions, and family members with their own accounts and exposure. Each of these expands both the attack surface and the remediation footprint. When an identity is compromised, the question is not "which credit file do we freeze" but "which of these many entities and people could this touch, and in what sequence do we address them."
This is why generic high-net-worth identity theft guidance falls short so quickly. Freezing one credit bureau file does little if the fraud is moving through an LLC, a custodian account, or a property title. The complexity that makes these households function is the same complexity that makes remediation a coordination exercise rather than a checklist.
We tend to frame this within a broader Digital Executive Protection program, because identity is not a standalone problem. It sits inside a layered picture that spans digital, financial, household, and physical dimensions. Treating it in isolation tends to leave gaps.
The household and staff as part of the picture
In our experience, the entry point is often not the principal at all. A compromised staff credential, a family member's reused password, or a household member's exposed account frequently serves as the way in. Remediation that focuses only on the principal closes one door while others stay open.
This is why staff and household members belong inside the remediation perimeter from the start. It also underscores why vetting household staff, vendors, and personal assistants matters as a preventive discipline, not just a hiring formality. The people with access are part of the security picture, both as a strength and as an attack surface.
The first 72 hours, sequenced
The temptation in the first hours is to do everything at once. Close accounts, call banks, freeze files. In our experience, that instinct works against you. Calm and documentation beat speed. A proportionate, ordered response protects both the recovery and any later insurance or legal claim. This is the heart of a workable identity theft playbook for executives, and the foundation of sound post-incident recovery.
Step 1 — Confirm scope before acting
Before closing a single account, separate what is confirmed misuse from what is merely suspected. Map which entities, accounts, and people appear affected. Resist the urge to close accounts blindly, because premature closures can destroy evidence, disrupt legitimate transactions, and complicate the paper trail you will need.
Confirming scope often means understanding what data is actually exposed. Breach and dark web tracking can help establish whether leaked credentials or personal data are circulating, which shapes both the severity of the incident and the remediation priorities. If the identity theft was triggered by a known breach or a compromised email account, the email data breach executive playbook is the natural companion piece, because email compromise is frequently the upstream event that makes identity theft possible.
Step 2 — Contain access
Once scope is understood, contain the pathways an attacker is using. This typically means rotating credentials on affected and adjacent accounts, securing two-factor authentication, and locking down the mobile carrier to reduce SIM swap and port-out risk. Review recovery emails and recovery phone numbers on critical accounts, because these are often where attackers quietly establish persistence.
Where appropriate, we tend to recommend moving high-value accounts to a hardware security key rather than SMS-based codes, which are more vulnerable to interception. Identity monitoring services also have a role. We reference these as categories rather than brands, because the right configuration depends on the principal's specific accounts and life, not on any single product.
Step 3 — Document everything (the paper trail)
From the first discovery, build a contemporaneous, dated record. What was found, when, by whom. Every call, every reference number, every action taken. This paper trail is not bureaucratic overhead. It shapes both the recovery and any potential insurance claim, and it is far harder to reconstruct after the fact than to build in real time.
Official reporting channels and credit bureaus exist, and they have defined processes. Rather than improvising your way through them, coordinate with counsel on how and when to use them. The sequence matters, and the wrong order can create complications that are difficult to unwind.
Step 4 — Notify the right institutions and counsel
Notification is not a broadcast. Sequence it. Financial institutions and custodians tied to confirmed exposure come first, alongside counsel. Over-notifying, or notifying the wrong parties, can create noise, confusion, and in some cases new exposure. This is another area where deferring to qualified professionals pays off. Counsel and specialist advisors know which notifications are required, which are advisable, and which can wait.
Specific fraud vectors to check
Once immediate containment is underway, work through the specific vectors methodically. This is a triage checklist, and account takeover recovery depends on checking each one rather than assuming the fraud is limited to what you first saw.
SIM swap and port-out fraud
In a SIM swap or port-out attack, the attacker convinces a mobile carrier to move the principal's number to a device they control. Once they hold the number, SMS-based two-factor codes flow to them, defeating a control the principal believed was protecting their accounts. Carrier-level protections, such as a port-out PIN and account locks, reduce this risk. Where possible, moving critical accounts off SMS-based verification lowers it further.
New-account and synthetic identity fraud
New-account fraud opens credit lines or accounts in the principal's name. Synthetic identity fraud is subtler: it blends real data (a genuine Social Security number, say) with fabricated details to create an identity that passes checks but is not quite the principal. Because these can be opened across multiple institutions and tied to different addresses, they cascade across entities in ways that single-file monitoring can miss.
Tax and government-filing fraud
Fraudulent filings in the principal's name, including tax filings, are a recurring vector. The remediation here is procedural and jurisdiction-specific, and it belongs firmly with counsel and qualified tax advisors. We flag it as something to check, not something to self-remediate. The formal channels have particular requirements, and coordination with the right professionals is essential.
Real estate and title fraud
Property holdings introduce their own exposure. Impersonation-driven title fraud and fraudulent property transactions target the very real, very high-value assets that principals hold, sometimes across multiple entities and jurisdictions. Because these transactions often move through wire transfers and involve multiple parties, they intersect with a broader category of risk we cover in wire fraud, business email compromise, and luxury real estate transactions. Checking title status and transaction activity on held property is a prudent part of triage.
Impersonation of the principal to their own staff
One of the most effective vectors requires no account takeover at all. The attacker impersonates the principal to the principal's own staff, instructing a wire, a credential reset, or a document release. The staff member, wanting to be responsive, complies. Increasingly, this impersonation is reinforced by synthetic voice, which is why deepfake fraud targeting executives is a companion concern here. During remediation, it is worth confirming with staff that no such instructions were received or acted upon.
A simple severity scoring model
To triage calmly, it helps to score the incident across four dimensions on a scale of 1 to 5, for a total out of 20. This is a prioritization aid, not a verdict, and outcomes vary regardless of the number.
- Financial exposure (1 to 5): How many entities, accounts, and custody relationships appear touched. A single dormant credit line scores low. Movement across trusts, LLCs, and custodians scores high.
- Account and credential exposure (1 to 5): The state of credentials, two-factor authentication, and SIM or port-out risk. Reused passwords and SMS-only verification score higher.
- Household and family exposure (1 to 5): Whether a spouse, children, or staff accounts appear involved. Any confirmed family or staff compromise raises this materially.
- Public and OSINT exposure (1 to 5): Whether leaked address or family data is circulating in a way that enables recurrence. High public discoverability keeps the risk alive even after immediate cleanup.
A score of 4 or 5 suggests the incident is relatively contained and largely one-dimensional. A score of 14 or higher signals a structural incident that touches multiple entities and people, and that will need coordinated remediation and, in our view, a standing capability afterward. The number guides sequence and resourcing. It does not tell you the story is over.
The family and household dimension
Remediation that stops at the principal tends to be incomplete. Family members are frequently the least defended path into an otherwise well-protected household. A spouse's reused password, a child's public social account, a household member's exposed email: any of these can be both the origin of an incident and the route to its recurrence.
For this reason, remediation should extend deliberately to the spouse, the children, and household members' accounts and exposure. This is a core part of VIP family risk protection, which treats the family not as an afterthought but as part of the principal's security perimeter.
Where impersonation extends to a minor, or where the incident shades into harassment, handle it calmly and engage the appropriate professionals. That may mean counsel, law enforcement, or mental health support, depending on the situation. These are moments to bring in qualified help rather than to manage alone.
From reaction to standing capability
An identity theft incident is evidence of a gap, not simply bad luck. That reframing matters, because it changes what recovery is for. The point is not only to clean up the current fraud. It is to reduce the likelihood of recurrence, which is where identity theft recovery becomes durable rather than temporary.
The moment the immediate fire is out is the right moment to establish privacy and threat monitoring and, for many principals, an ongoing monitoring retainer. Monitoring is what turns a one-time cleanup into a standing capability that catches recurrence signals early, when they are cheaper and quieter to address.
Reduce reachability after the fact
The same leaked address and family data that enabled the first incident tend to enable the next one. Reducing reachability is therefore central to preventing recurrence. Data broker and people-search removal is a meaningful, ongoing form of exposure reduction. Complete removal is unrealistic, but meaningful reduction is very realistic, and it changes the risk picture.
If you are unfamiliar with how this ecosystem works, data brokers explained is a useful primer, and the personal OSINT problem for executives explains why open-source exposure is so consequential for high-profile individuals. Reducing what is publicly discoverable makes the principal a poorer target, which is the aim.
The diagnostic step
Once the immediate response is complete, a structured executive privacy audit maps the remaining exposure across the principal, the household, and the entities. Think of it as the diagnostic that turns a reactive scramble into a deliberate program. It answers the question that lingers after any incident: what else is out there that we have not yet seen. For a self-directed starting point, the executive digital footprint audit checklist offers a structured way to begin.
What good looks like
A well-run remediation, in our experience, produces a few consistent deliverables and rhythms.
- A documented incident record. Contemporaneous, dated, and complete, covering discoveries, communications, and actions taken.
- A sequenced remediation checklist. Tied to each affected entity and person, so nothing is assumed and nothing is missed.
- Defined ownership. Clarity on who does what across staff, counsel, custodians, and advisors. Ambiguity about ownership is where remediation stalls.
- A monitoring cadence. Regular checks for recurrence signals across credentials, credit, entities, and public exposure, with a clear escalation path when something surfaces.
All of this is proportionate and calibrated to the principal's life, and handled discreetly. The measure of good work is that the principal's routine barely changes while the exposure quietly comes down.
Common mistakes
- DIY-only remediation without documentation. Fast action with no paper trail complicates both recovery and any insurance claim.
- Ignoring family members and staff. Focusing on the principal alone leaves the most common entry points untouched.
- Closing the wrong accounts before scope is confirmed. Premature closures destroy evidence and disrupt legitimate activity.
- Failing to build a paper trail. Reconstructing events after the fact is far harder than recording them in real time.
- Treating the incident as a one-time cleanup. An incident is a signal to build a standing capability, not a chore to finish and forget.
- Over-notifying or notifying the wrong parties. Notification is a sequence, not a broadcast, and getting it wrong can create new exposure.
Illustrative patterns drawn from practice
These are composites, not specific clients. They reflect recurring patterns we observe.
Pattern one: the principal impersonated to their own family office lead during travel
While a principal was traveling internationally, their family office lead received what appeared to be an urgent instruction to authorize a transfer, reinforced by a voicemail that sounded like the principal. The lead paused, sensed something was off in the phrasing, and called a known number to verify. The instruction was fraudulent. Because the team had a verification protocol and paused rather than complied, no funds moved. The remediation that followed was calm and documented: confirming scope, containing the impersonated channels, notifying counsel and the relevant institutions, and, afterward, formalizing out-of-band verification and ongoing monitoring so the next attempt would meet the same friction.
Pattern two: new-account fraud that surfaced a hidden exposure
A chief of staff discovered a credit line opened in a principal's name. Investigation revealed the underlying cause: a years-old data breach had exposed personal details the household did not know were circulating. The immediate fraud was addressed through documented, sequenced remediation. The more important outcome was the diagnostic that followed. A privacy audit mapped the remaining exposure, data broker removal reduced the household's reachability, and a monitoring retainer put recurrence signals on watch. The incident became the reason a standing capability finally existed.
Work with Biscayne Secure
Biscayne Secure was founded in 2020 by former national security professionals who spent decades countering complex, transnational threats. We bring that discipline to private clients: principals, families, and the family offices and chiefs of staff who support them. Our work is quiet exposure reduction, not surveillance theater, and it is calibrated so the principal often barely notices it.
Identity theft remediation is one moment in a longer relationship. Engagements are handled discreetly and treated as a standing capability, calibrated to the principal's life. If you are navigating an active incident, a near miss, or simply the uncomfortable sense that there are gaps you have not had the bandwidth to map, we are glad to help you think it through.
To arrange a confidential consultation, contact us. Conversations are treated with discretion.
Frequently Asked Questions
What should I do first if I suspect the principal's identity has been stolen?
Confirm scope before acting. Separate confirmed misuse from suspicion, map which entities and people appear affected, and begin a dated record of everything you find. Resist the urge to close accounts before you understand what is happening. Then coordinate with counsel on the formal steps.
Can identity theft be fully reversed?
Outcomes vary, and we avoid promising full reversal. In most cases, the realistic goal is meaningful recovery of what was compromised and a substantial reduction in the likelihood of recurrence. Some elements resolve cleanly. Others, particularly where data is already circulating, are better addressed through ongoing exposure reduction than through a single fix.
How is high-net-worth identity theft different from consumer identity theft?
Consumer advice assumes one person, one bank, one address. High-net-worth life involves multiple entities, delegated signatories, custody relationships, real estate, and family members. That structure expands both the attack surface and the remediation footprint, so response becomes a coordination exercise rather than a simple checklist.
Should we involve law enforcement and counsel?
Official channels exist for reporting identity theft, and formal processes involve credit bureaus, regulators, tax authorities, and sometimes law enforcement. These belong to qualified professionals. We tend to recommend engaging counsel early so notifications and reports are sequenced correctly rather than improvised.
How do we protect family members and staff during remediation?
Bring them inside the perimeter from the start. Review and secure spouse, children, and staff accounts, since these are often the least defended paths. If impersonation touches a minor or shades into harassment, handle it calmly and engage counsel and appropriate support.
How do we reduce the chance of it happening again?
Treat the incident as the trigger to build a standing capability. Establish monitoring, reduce public reachability through data broker and people-search removal, and run a structured privacy audit to map remaining exposure across the principal, household, and entities. Recurrence risk falls as discoverability falls.