Children can be victims of identity theft too. Warning signs parents can spot
A child's national ID number and personal data can be misused for years before a family notices. Here is how to reduce the risk and respond in Poland.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 11 September 2026
- READING TIME
- 8 min read
- TOPIC
- Human Security
A child does not apply for a loan, sign a mobile contract or routinely check for liabilities in their name. That is precisely why their data can appeal to an identity thief: nobody expects financial activity, so misuse may remain invisible for a long time.
The theft does not have to begin with a dramatic intrusion. A Polish PESEL number, name, date of birth, address or image of an identity document may leak from an institution, be sent to the wrong recipient or reach a scammer through a form pretending to represent a sports club, competition or activity programme.
Ask before supplying the full set of data
A school, doctor, insurer or trip organiser may need some information about a child. That does not mean every form should receive everything.
Ask:
- why the PESEL number or document copy is required;
- whether another identifier can be used;
- who will have access and how long the information will be retained;
- how it will be deleted when the service ends.
“We have always done it this way” does not explain the need. When information is necessary, submit it through a channel named on the institution’s official site, not in reply to a message from an unfamiliar address.
Paper records need protection too. Do not put copies carrying a PESEL number, old student cards or medical forms in the bin without destroying them. Before selling or giving away a phone, tablet or computer, remove accounts and data according to the manufacturer’s instructions.
The first warning may resemble an innocent mistake
Pay attention to correspondence about a service the family did not order, a payment demand, an overdue bill or an attempt to contact the child about an unknown account. Messages about changed credentials for a service the child supposedly uses are suspicious too.
Do not assume it is simply an addressing error. Contact the sender through a telephone number or address you find independently on its official site. Avoid the contact details in the suspicious letter until you have confirmed that the document itself is genuine.
A notice that data leaked from a company, school or platform is another important signal. It does not mean the identity has already been misused, but it justifies closer attention to correspondence and retaining the notice as evidence.
Do not publish a ready-made digital file on your child
A photograph of a student card on the first day of school, a boarding pass, an award showing a date of birth and a post revealing a precise location can combine into a rich profile. A scammer does not always need one complete document; sometimes they assemble details from several places.
Before posting, cover identifiers, barcodes, the school name and information the audience does not need. Check who can see family albums in the cloud and whether an old shared-folder link still works.
The goal is not to erase a child from the internet. It is to make sure a public post does not become a completed form containing their data.
How to respond in Poland
When you suspect unlawful use of a child’s data, collect evidence: a company’s breach notice, correspondence about an unknown liability, report confirmations and page addresses. Do not answer the scammer or send another document copy for supposed verification.
Poland’s GOV.PL service says a parent, legal guardian or court-appointed guardian can report unauthorised use of a child’s personal data at any municipality office. It can be done in person and, since 1 January 2026, electronically through the e-Delivery system. Evidence making identity theft plausible should accompany the report, such as a company’s letter about a data breach. The process invalidates the identity card if the child has one, after which a new document is required.
At the same time, contact the institution where the unknown account or liability appeared. Use official channels only and record dates, case numbers and the names of support representatives. Report suspected crime to law enforcement.
A conversation with the child is a security control
Children should know that a date of birth, address, document number and one-time codes are not ordinary competition answers. Establish a simple rule: show an adult any form asking for identity information before submitting it.
Do not blame the child if they have already disclosed something. Calm, prompt disclosure offers a better chance of limiting harm than fear of punishment that delays the conversation.
What the sources say and what Breachroad recommends
The US Federal Trade Commission explains how to protect a child from identity theft: ask why data is needed and whether an alternative identifier will work, destroy records securely and watch for unexpected bills or unfamiliar accounts. These principles travel well, although US credit procedures do not apply directly in Poland.
The Polish response path appears in the GOV.PL service for reporting unauthorised use of a child’s or another person’s personal data. Details about eligible representatives, evidence, municipality offices and e-Delivery come from that guidance.
Breachroad recommends treating a breach notice as the start of monitoring, not proof that nothing has happened yet. Keeping the document may later help establish where the information originated.
Our broader guide explains how to protect yourself from identity theft. We help organisations reduce similar risks through cybersecurity training.


