
In Bitwarden’s 2025 World Password Day survey, 72% of Gen Z respondents admitted to reusing passwords across more than one site, despite most people being perfectly aware that reusing passwords is risky (Bitwarden).
Separately, a Cyber Readiness Institute survey of 1,403 small and medium-sized businesses found that 54% did not use MFA, while 55% were not very aware of MFA and its security benefits. Neither of these numbers reflects ignorance. They reflect knowing better and doing it anyway, which is a different problem than not knowing at all, and it’s the actual subject of this article.
Our myths article covered false beliefs, things freelancers think are true about identity theft protection but aren’t. This one covers the opposite gap: things freelancers already know they should do, and skip anyway, usually because the payoff feels abstract and the friction is immediate. Here are the specific behavioral mistakes that show up most often in freelance work, and why each one is more costly than it feels in the moment.
Table of Contents
Mistake: Reusing Passwords Across Client Portals and Payment Platforms
Freelancers accumulate logins fast, a new client portal here, a new invoicing tool there, a payment platform account for every marketplace you work through. Reusing one password across several of these isn’t laziness so much as fatigue: creating and remembering a dozen unique passwords feels disproportionate to the risk each account seems to carry.
The math doesn’t work that way, though, a breach at the least important platform you use becomes the key to the most important one the moment the password is shared between them. A password manager removes the actual friction (you don’t have to remember anything), which is the only fix that survives contact with how tired you actually are at the end of a work day.
Mistake: Skipping MFA Because “I’ll Set It Up Later”
Multi-factor authentication is one of the most practical ways to strengthen account security, and many services offer it at no additional cost, and it’s also one of the most commonly deferred. The Cyber Readiness Institute’s finding that more than half of small businesses haven’t adopted it isn’t a knowledge gap, MFA is well-publicized at this point, it’s a friction gap.
It takes two extra minutes during setup, and there’s no visible cost to skipping it until the day it would have mattered. Prioritize it on exactly two things first if you do nothing else: your email (since it resets everything else) and whatever payment platform actually moves your income.
Mistake: Sending SSN, EIN, or Banking Details Over Plain Email
Email feels secure because it’s private and familiar, but ordinary email should not automatically be treated as a secure channel for highly sensitive information. Email can use transport encryption such as TLS, but protecting the message itself and the data stored in mailboxes requires additional controls.
Freelancers send this kind of information over email constantly, completing a W-9, confirming direct deposit details, because it’s the path of least resistance in the moment a client asks. A secure client portal, a password-protected document, or simply requesting a phone call to confirm sensitive numbers instead of typing them into an email thread closes this gap without adding real friction to a legitimate business relationship.
Mistake: Not Verifying New Clients Before Sharing Sensitive Information
This is different from the myth of assuming platforms verify clients for you, this is the behavioral version: freelancers who know they should verify a new client independently, and skip it anyway because the project is time-sensitive, the client seems responsive and professional, or asking feels like it risks the relationship before it’s even started. Before sharing sensitive information, independently verify that the client or business is legitimate.
Check the company’s official website and contact information, and use a separate communication channel when something feels unusual. A five-minute check, an independent search of the company, a request for a quick video call- it’s the step that gets cut first under any real time pressure (Consumer Advice).
Mistake: Mixing Personal and Business Finances
Running client payments through a personal bank account, or paying business expenses from the same account you use for groceries, doesn’t cause identity theft directly, but it makes it dramatically harder to notice when something’s wrong.
A personal account with mixed transaction types buries an unfamiliar charge or a misdirected payment among dozens of unrelated ones, while a dedicated business account makes anomalies visible almost immediately because there’s nothing else competing for your attention in that statement. Separating the two is as much a detection strategy as it is good bookkeeping.
Mistake: Never Touching the Privacy Settings on Your Freelance Platform Profile
Freelance platforms can expose more professional information than you realize, depending on your profile and visibility settings. For example, Upwork allows freelancers to control whether their profiles are public, visible only to logged-in users, or private. Public profiles can also appear in search-engine results.
The result is often more personal and professional detail publicly visible than necessary, which feeds directly into the social-engineering risk covered in our guide on how freelancers get identity theft. A scammer who can reference real details about your work may be able to make a phishing message appear more credible, and that detail is often sitting in public view simply because nobody went back to check.
Mistake: Not Requesting Access Revocation When a Contract Ends
When a project ends, access to client systems should be removed rather than left active indefinitely. Because the freelancer often can’t revoke the client’s permissions themselves, asking the client to confirm that access has been removed is a simple offboarding step.
This isn’t usually anyone’s fault, it’s not a step built into how most freelance relationships end. Making it a habit to ask “can you confirm my access has been removed?” as a normal part of wrapping up a project closes a gap that otherwise depends entirely on someone else remembering to do it.
Mistake: Delaying Action After Spotting a Genuine Warning Sign
This differs from misreading a sign (which our warning signs guide covers); it is correctly recognising something is wrong and still not acting on it right away, usually because the current project or deadline feels more urgent in the moment.
A fake 1099 sitting unopened for a few weeks, or a client’s report of a strange message getting filed away as “I’ll deal with that later,” both cost real time later, since several of the recovery processes covered in freelance-specific identity theft, particularly anything involving the IRS, move slower the longer they sit unaddressed.
Why Knowing Isn’t the Same as Doing
Every identity theft protection mistake on this list is one most freelancers, if asked directly, would say they know they should avoid. That’s precisely why listing the risk again wouldn’t have helped, what actually closes each of these gaps is reducing the friction of doing the right thing, not repeating the warning. A password manager removes the memory burden.
Asking about access revocation becomes a habit after doing it once or twice. The mistakes that persist tend to be the ones where the safe behavior still feels like extra work relative to the visible, immediate cost of skipping it, which is exactly why they’re worth naming specifically rather than folding into a general “be careful” reminder.
What Fixing Each Mistake Actually Solves, and What It Doesn’t
| Mistake | Fix | What the Fix Doesn’t Solve |
| Password reuse | Password manager generating unique passwords per account | Doesn’t prevent a platform from exposing other personal information in a breach |
| Skipping MFA | Enable app-based MFA on email and payment platforms first | Doesn’t protect your SSN or EIN if those are exposed through a different channel entirely |
| Sending sensitive data over plain email | Use a secure portal, encrypted document, or phone confirmation instead | Doesn’t undo prior information already sent this way in past client relationships |
| Skipping new-client verification | A five-minute independent check before sharing anything sensitive | Doesn’t protect against a platform-side breach that has nothing to do with any individual client |
| Mixing personal and business finances | A dedicated business account for all client payments | Doesn’t prevent fraud, it makes fraud easier to notice, which is still valuable but distinct |
| Ignoring platform privacy settings | A periodic review of what’s publicly visible on your profile | Doesn’t stop a determined attacker who already has other identifying information about you |
| Not requesting access revocation | Ask directly when a project ends | Depends on the client’s cooperation, not fully within your control either way |
| Delaying action on a real warning sign | Treat any Tier 1 sign (fake 1099, EIN misuse) as immediately actionable | Doesn’t undo delays that already happened before the habit changes |
FAQs: Identity Theft Protection Mistakes Freelancers Make
What’s the Most Common Identity Theft Protection Mistake Freelancers Make?
Password reuse is one of the most widespread security mistakes generally, and it can be particularly problematic for freelancers who manage accounts across multiple clients and platforms (Bitwarden).
Why Do Freelancers Skip MFA Even When They Know It Helps?
The reasons vary. In the Cyber Readiness Institute’s survey, 54% of SMBs said they did not use MFA, and among businesses that had not implemented it, 47% said they didn’t understand MFA or didn’t see its value. For freelancers, setup friction can be another reason security tasks get postponed.
Is Mixing Personal and Business Bank Accounts Actually a Security Risk?
Indirectly, yes. It doesn’t cause fraud on its own, but it makes fraud significantly harder to notice, since unfamiliar transactions get lost among a much larger and more varied set of personal spending.
How Is This Different From the Identity Theft Myths Freelancers Believe?
Myths are false beliefs, things freelancers think are true but aren’t. Mistakes are the gap between knowing the right thing to do and actually doing it consistently, which is a separate and arguably more common problem.
What’s the Single Easiest Mistake to Fix First?
Enabling MFA on your email and primary payment platform takes only a few minutes and closes one of the fastest-moving risks (account takeover) with almost no ongoing effort required afterwards.
Bottom Line: Identity Theft Protection Mistakes
The biggest identity theft protection mistakes freelancers make usually aren’t caused by not knowing better. They’re caused by putting security off until it’s convenient. A reused password, skipped MFA setup, overshared profile, or unverified client may seem harmless on its own. Together, they create openings that are much harder to fix after something goes wrong.
The solution isn’t perfect security. It’s consistent habits: use unique passwords, enable MFA, limit sensitive information sharing, verify new clients, separate business finances, and act quickly when something looks wrong. For freelancers, good identity theft protection is less about doing everything and more about consistently doing the important things.
What to Do Next
A lot of these protection mistakes trace back to a single root cause: sharing an SSN when an EIN would have done the job instead. If you haven’t made that switch yet, it’s worth understanding exactly what changes and what doesn’t.
