Every school registration form your family fills out this month asks for the same sensitive line: your child’s Social Security number. Add in sports league sign-ups, dentist intake forms, and after-school program paperwork. It is easy to see why child identity theft spikes hard in the final weeks of July and through August every year. This update covers what changed in 2026. That includes two major school data breaches, a set of new state and federal rules, and a checklist for the weeks ahead.

Last Updated: July 2026

This guide is written for two audiences dealing with the same problem from different angles. Parents handling registration paperwork right now want to know what to do differently this year. HR and benefits teams heading into open enrollment planning want to understand why dependent identity coverage keeps coming up. Both threads run through this update.

Why Back to School Is Prime Season for Child Identity Theft

Children make ideal identity theft targets for one simple reason. They have no credit history to contaminate. A stolen adult identity gets flagged the moment a fraudulent charge hits an existing account. A child’s Social Security number can sit unused for years. That gives a thief a clean slate to build on. The U.S. Federal Trade Commission has reported a 40 percent surge in child identity theft between 2021 and 2024. Roughly one in fifty children falls victim each year.

Recent research puts numbers on how the damage plays out. About 66 percent of child identity theft cases involve misuse of the child’s Social Security number specifically. The average case costs a family around $2,303 to resolve. The detection gap is the real problem. Nobody checks a child’s credit file, so fraud can run undetected for years. Often the first red flag comes from a lender, a landlord, or a college financial aid office.

Back-to-school season concentrates the risk because it concentrates the paperwork. Registration forms, emergency contact cards, sports physicals, and school photo order forms all ask for a child’s full legal name and birth date. Many still ask for a Social Security number. That paperwork often passes through several hands before it reaches a locked file. Every one of those touchpoints is a chance for the data to end up somewhere it shouldn’t.

The School Breaches Making 2026 a Bigger Risk Year

Two large-scale breaches now sit behind this year’s guidance. Families should understand both.

The PowerSchool breach, disclosed in December 2024, remains the largest confirmed breach of U.S. K-12 student data on record. A single compromised support credential gave an attacker access to records for roughly 62 million students and 9.5 million teachers. The exposed data included Social Security numbers and health information tied to individualized education plans. Fewer than a quarter of affected students had a Social Security number stored in the exposed system. For those who did, the exposure was direct and severe.

In May 2026, Instructure, the company behind the widely used Canvas learning platform, confirmed a separate major incident. The extortion group ShinyHunters claimed responsibility and put the total as high as 275 million user records across nearly 9,000 schools worldwide. Instructure has not confirmed that number, and it spans Canvas’s full global user base, K-12 students through college students and instructors, not U.S. children specifically. Even at a smaller confirmed scope, the breach still hit U.S. districts directly. Several, including schools within New York City’s public system, confirmed impact and had to rotate credentials and reissue guidance to families mid-semester.

These incidents connect to a broader pattern. The Identity Theft Resource Center’s 2026 Trends in Identity Report found that 25.6 percent of identity crime victims now manage two or more concurrent incidents, up from 23.5 percent the year before. Identity theft increasingly compounds rather than resolving on its own. That matters even more for a child victim who may not learn about an incident until years later. Synthetic identity fraud makes the pattern worse. It combines a real Social Security number with fabricated personal details to build a new credit file from scratch. It now accounts for roughly 20 percent of all fraud losses tracked by TransUnion, making it the third-largest fraud category behind scams and account takeovers. Children’s Social Security numbers remain the preferred raw material for this scheme.

New 2026 Rules for Schools and Vendors Handling Your Child’s Data

Three regulatory changes took effect in 2026. Each affects how quickly a school or its vendors must tell you if your child’s data was exposed.

California’s SB 446 replaced the old “reasonable time” notification standard with a hard 30-day deadline. That clock starts when a business discovers or is informed of a breach. Businesses that notify 500 or more California residents must also report to the state Attorney General within 15 days. Oklahoma’s SB 626 marks that state’s first breach-notification update since 2008. It broadens the definition of personal information to include government-issued ID numbers and biometric data. It also requires Attorney General notification for any breach affecting 500 or more residents.

At the federal level, an updated COPPA rule took effect in April 2026. It tightens consent requirements and breach-notification expectations specifically for data belonging to children under 13. Together, these changes push schools and vendors toward faster, clearer disclosure. A faster notification requirement only starts the clock after a breach has already happened, though. None of these laws stop a child’s data from being exposed in the first place. That is exactly why ongoing monitoring matters more than a one-time breach notice.

Protecting Your Child’s Identity: A Back to School Checklist

Use this list as registration paperwork starts arriving this month.

  • Freeze your child’s credit now, before anything happens. Federal law lets parents or guardians place a free security freeze on a child’s credit file at any of the three bureaus. Doing it before an incident is far easier than doing it after.
  • Ask what a form actually requires before you fill in the SSN field. Many schools accept a state student ID number or leave the field optional. Ask the front office directly instead of assuming the number is mandatory.
  • Ask how the school and its vendors store and encrypt student data. You have a right to ask. A school that cannot answer is worth following up with in writing.
  • Watch the mail for anything addressed to your child. Credit card offers, collection notices, or IRS correspondence in a minor’s name are early warning signs worth acting on right away.
  • Shred anything with your child’s full legal information before you throw it away. Old registration copies and outdated medical forms are common sources of exposure inside the home, not just outside it.
  • Use an identity monitoring service that covers dependents. Real-time alerts and dark web scanning catch misuse far faster than a bank statement review ever will.

What Child Identity Theft Means for HR and Benefits Teams

Every parent filling out school forms this month is also an employee. Many of them are your employees. Open enrollment planning season starts soon. That makes this the right window to revisit how dependent identity coverage gets positioned in your benefits package.

Child identity theft has no age floor. Cases involving children under five are well documented. Because the fraud can go undetected for years, an employee may not discover a problem until well after an enrollment window that could have covered it has closed. That is a real gap, not a hypothetical one. It is worth surfacing directly in open enrollment communications rather than leaving dependent coverage as a line item nobody reads.

There is also a productivity angle HR teams do not always connect to identity theft. The ITRC’s multi-layered incident finding means an employee dealing with a compromised child’s identity is often not dealing with one problem. They are juggling credit bureau calls, school communications, and account cleanup. Much of that happens during work hours, because those offices are only open during work hours. A benefit that includes fully managed recovery support does more than protect the family. It gives that employee somewhere else to route the work.

Frequently Asked Questions

How can I tell if my child is a victim of identity theft?
Watch for credit card offers, collection notices, or IRS correspondence addressed to your child. Also watch for a school or health insurer telling you a Social Security number is already in use. Children should not have a credit file at all, so any credit file existing under their name is itself a red flag.

Can I freeze my child’s credit before anything has gone wrong?
Yes, and this is the single most effective preventive step available. Federal law allows a parent or guardian to place a free security freeze on a child’s credit file at each of the three major bureaus at any time, whether or not a breach has occurred.

Does the PowerSchool or Instructure breach mean my child’s identity was stolen?
Not automatically. Both breaches exposed data for millions of students, but exposure and active fraud are different things. Check with your school district about whether your child’s records were affected. Treat a freeze and ongoing monitoring as the response either way.

What is synthetic identity theft and why does it target children specifically?
Synthetic identity theft combines a real Social Security number with a fabricated name, birth date, and address to build a new credit identity. Children’s numbers are attractive because no existing credit file exists to contradict the fabricated details. That lets a fraudulent identity build credit undetected for years.

Do the new 2026 state breach laws apply to my child’s school?
California’s SB 446 and Oklahoma’s SB 626 apply to businesses and entities handling residents’ data in those states. That includes many school vendors and education technology platforms. Coverage depends on where your family and the vendor are located, so ask your district directly which notification rules apply to your records.

Should I ask my employer about dependent identity theft coverage?
Yes. Many employer identity protection benefits already extend to dependents at no added cost, and most employees never ask. If your workplace offers identity theft protection, confirm whether your children are already covered before assuming you need a separate consumer plan.

What should I do first if I find fraud under my child’s name?
File a report at IdentityTheft.gov and with your local police department. Then contact all three credit bureaus to freeze your child’s file and add a fraud alert. Notify any financial institution involved directly, and keep copies of every report and letter until the fraudulent accounts are fully resolved.

Child identity theft is not a once-a-year problem that back-to-school paperwork simply reminds you about. It is a year-round exposure. It gets worse every time a form asks for a Social Security number, and better every time a family or an employer builds in a layer of active monitoring instead of hoping nothing goes wrong. If you found this guide useful, share it with another parent, or with your HR team before open enrollment planning starts. Learn more about how defend-id protects families and employees with real-time monitoring and fully managed recovery support.

Related Articles

error

Enjoy this blog? Please spread the word :)