All posts
Detection GuideSeptember 21, 2026·9 min read

Someone Can Open a Bank Account in Your Name With a Photo. Here Is How to Check.

Think you found an AI video?

Paste the URL and let the Ledger community verify it. Free.

Check a video

Quick answer: A credit freeze at Equifax, Experian and TransUnion does not stop someone opening a checking account in your name. Banks screen deposit accounts through ChexSystems and Early Warning Services instead. Freeze ChexSystems directly, request your Early Warning report, and report any fraudulent account at IdentityTheft.gov.

Most identity-theft advice ends at the credit freeze. Freeze the three bureaus, the advice goes, and nobody can open anything in your name.

That is true for credit. It is not true for a bank account.

When a bank decides whether to let you open a checking account, it usually does not start with your credit report. It checks a deposit-account screening report, and the two that matter are ChexSystems and Early Warning Services. Freezing Equifax, Experian and TransUnion leaves both of them wide open.

This gap has always existed. It matters more now because the front door got easier to walk through. Israeli police recently alleged that one 20-year-old opened accounts in more than 60 people's names by animating ID photos bought from leaked databases and running software through the online signup flow. Roughly 120 people filed complaints. None of them knew.

Three freezes, two gaps

The standard credit freeze covers Equifax, Experian and TransUnion. Banks opening deposit accounts commonly check ChexSystems or Early Warning Services, neither of which is covered by a credit freeze.

Source: ChexSystems security freeze information and Early Warning consumer information

1. Freeze the Report Banks Actually Check

ChexSystems is a consumer reporting agency for deposit accounts. Banks query it to see whether you have a history of overdrafts, unpaid balances or suspected fraud before they let you open a checking or savings account.

A ChexSystems security freeze, in the company's own words, "prohibits a consumer reporting agency from releasing any information in your consumer file without your expressed authorization." A bank that cannot pull the file generally will not open the account.

Place it three ways:

  • Online through the ChexSystems consumer portal
  • By phone at 800.887.7652
  • By mail to Chex Systems, Inc., Attn: Security Freeze Department, PO Box 583399, Minneapolis, MN 55458

Do this even if your credit is already frozen. The two systems do not talk to each other. A credit freeze does not freeze your ChexSystems file, and a ChexSystems freeze does not freeze your credit.

2. Request Your Early Warning Report

Early Warning Services is the other screening network banks use, owned by a consortium of large US banks and best known to consumers as the company behind Zelle.

Early Warning does not offer the same standardized freeze the credit bureaus do. What it does offer is access: you can request your consumer file, and the company states it will never charge a fee to obtain a file disclosure, to investigate disputed information, or to remove inaccurate information from your file. Request the report through Early Warning's consumer information page.

Read it for accounts you do not recognize. That is the point of the exercise. If an account appears that you did not open, it becomes the evidence trail for everything in step four.

Because there is no freeze to place here, ask what protective measures are available for your situation when you contact them. Options differ depending on whether you are already a confirmed identity-theft victim.

3. Check What Is Already Open

Freezing stops the next account. It does nothing about one opened last month.

Pull your ChexSystems report. The same consumer portal that places the freeze gives you the file. Look for inquiries from banks you have never dealt with. An inquiry means someone tried.

Pull all three credit reports. Fraudulent deposit accounts often come with a credit card issued against them, which does show up on credit. AnnualCreditReport.com is the federally authorized source and it is free.

Check the IRS and the Social Security Administration. Accounts opened in your name get used to receive money, and that money gets reported. A tax transcript showing income you did not earn is a strong signal that someone has been operating as you.

The victims in the Israeli case did not find out from their banks. They found out from police. Do not assume a fraudulent account announces itself.

4. Report It Through the Channel That Generates Paperwork

If you find something, the order matters, because banks want documentation and one channel produces it.

Start at IdentityTheft.gov. The FTC's site walks you through a report and generates an Identity Theft Report plus a personal recovery plan. That report is what banks and credit bureaus ask for, and improvising your own letter slows everything down.

Then contact the bank holding the fraudulent account. Ask for the fraud department, not general customer service. Request that the account be closed as fraudulent and ask for written confirmation.

Then dispute with the reporting agency. ChexSystems and Early Warning both run disputes under the Fair Credit Reporting Act. The fraudulent account has to come off your file, or it will follow you the next time you legitimately open an account.

File a police report. Some banks require one. It also creates a record if the account was used for anything worse than a credit line.

What a Freeze Does Not Cover

Freezes are worth placing and they are not a force field. Three things they leave untouched, so you know where the remaining exposure sits.

Accounts you already have. A freeze governs new applications. It does nothing about someone taking over an existing account with a stolen password or an intercepted verification code. That is a different attack with a different defense: unique passwords and an authenticator app rather than text-message codes.

Payments out of accounts you control. Zelle, wires and card charges run on accounts already open in your name. A ChexSystems freeze has no bearing on them.

Institutions that skip the check. Not every lender or fintech pulls the report you froze. Freezing ChexSystems, Early Warning and the three credit bureaus covers the common paths, not every one.

None of that argues against freezing. It argues for knowing what the freeze bought you, so a fraudulent charge next year does not read as proof the freeze failed.

Triage the Next Breach Notice by What Leaked

Breach notifications arrive constantly and they all read the same. They are not the same, and the sorting rule is simple: ask what an attacker can do with the specific field that leaked.

Email address or phone number. Expect more phishing aimed at you. Annoying, recoverable.

Password. Change it, and change it anywhere you reused it. The reuse is the real exposure.

Social Security number. This is the classic credit-fraud input. Freeze credit, and now freeze ChexSystems too.

A scan or photograph of a government ID. Treat this as the serious one. It is the input the Israeli case ran on, it is the hardest field to reissue, and it is the only one on this list that you cannot change at all. A leaked license photo is permanent in a way a leaked password is not.

That last category is the one most notification letters bury and most readers skim. When it appears, place the freezes the same week rather than filing the letter.

Why the Photo Changed the Math

None of the steps above are new. What changed is how little an attacker now needs from you.

The old version of this crime required your physical documents or enough personal detail to talk past a human. The new version, as investigators described the Israeli case, needs a photograph of your ID from a breach at a company you signed up with years ago and forgot. AI supplies the rest: the selfie, the movement in the verification video, the persistence to sit through the signup flow.

That is why a breach notification mentioning a scan of your license or passport deserves a different response than one mentioning your email address. An email address gets you spam. An ID photo is animation input, and unlike a password you cannot change it. The document check on the other side is not reliably catching the result either: a generated passport image cleared a crypto exchange's verification for about 15 dollars, documented by Margen, a detector-evaluation company run by Ledger's founder.

It is also why the liveness checks in these flows are worth less than they look. Asking a face to move proves the face moved. Understanding what a deepfake actually is makes clear why that is a weak test, and the same reasoning applies whether the target is a bank or a video call with you on it.

Think you found an AI video?

Paste the URL and let the Ledger community verify it. Free.

Check a video

The Short Version

Freeze ChexSystems today. It takes a few minutes, it costs nothing, and it closes the specific hole that a credit freeze leaves open. Request your Early Warning file while you are at it, so you know what is already there.

Then treat future breach notices by what leaked. A password is an inconvenience. A photograph of your government ID is a durable asset in somebody else's hands, and the tooling to use it got cheap this year.

If something is already open in your name, IdentityTheft.gov is the first stop, not the last resort. The paperwork it produces is what every other institution will ask you for.

[APP-DOWNLOAD]

Related Posts

Ledger App

Train your eye. Verify what you find.

Swipe real and AI-generated video clips to sharpen your detection instinct. Then paste any suspicious URL and see what the community has already flagged.

Train Your Eye
AI-generated video flagged in Ledger
AI Detected
Real video verified in Ledger
Not AI