As Seen On

Recognized By
Why You Can Be Falsely Accused of Identity Theft in Arizona
An accusation is not a conviction. Arizona’s identity theft law, A.R.S. 13-2008, requires the state to prove you knowingly took or used someone else’s personal identifying information without their consent and with the intent to obtain or use their identity for an unlawful purpose or to cause them a loss — a class 4 felony. Mistaken identity, having actual permission to use a card or account, a shared household or business account, or simply lacking the fraudulent intent the statute demands are all real, provable defenses. Bank records, IP logs, device data, and store surveillance frequently show it was not you at all — but only if that evidence is pulled and analyzed before it disappears.
Few accusations feel as disorienting as being blamed for identity theft. You did not open the account, you did not make the charge, or you had every right to use the card — and yet a detective, a bank fraud department, or a Maricopa County grand jury is treating you like the person who did it. Arizona takes identity crimes seriously: taking the identity of another person or entity under A.R.S. 13-2008 is a class 4 felony on its own, and it escalates fast from there.
This article is written specifically for people who believe they have been wrongly accused — not a general overview of identity theft law. It covers mistaken identity, authorized-use disputes, the intent element that decides almost every case, how banks and prosecutors actually build these cases, and how digital forensics can show it was not you. If your accusation involves broader financial fraud allegations, see our Scottsdale white collar crimes lawyer page, and if you have already received a letter from a prosecutor’s office, read our guide on what a target letter in a fraud investigation means.
Identity theft charges get filed on far less certainty than people assume. A bank, a merchant, or an officer sees a suspicious transaction tied to your name, your address, your device, or your account — and the paperwork starts before anyone has confirmed who was actually behind the keyboard. Common ways innocent people end up accused include:
- Someone else — a family member, roommate, ex-partner, or a stranger who obtained your data in a breach — used your name, Social Security number, or account without your knowledge.
- A merchant or card issuer flags a transaction and reports the account holder of record, without ever confirming who actually made the purchase.
- A shared household computer, Wi-Fi network, or IP address ties a fraudulent transaction to your home even though someone else in the house used the device.
- A relative or employee had a card issued in your name — an authorized user or a joint account — and routine, permitted use gets treated as unauthorized after the fact.
- Records mix up two people with similar names, addresses, or dates of birth.
- You were the original victim of the identity theft, and the person who actually stole your information is now pointing back at you to shift the blame.
None of these situations, standing alone, prove the crime Arizona actually has to establish. The law does not punish being present near a fraudulent transaction — it punishes knowingly acting without consent and with the intent to defraud or cause loss.
What the State Must Prove Under A.R.S. 13-2008
Identity theft in Arizona is defined by A.R.S. 13-2008. The statute makes it a crime to knowingly take, purchase, manufacture, record, possess, or use any personal identifying information of another person or entity, without the consent of that person or entity, with the intent to obtain or use the other person’s or entity’s identity for any unlawful purpose, or to cause loss to the person or entity. A first-time violation is a class 4 felony.
Break that into the elements the state must prove, because each one is a place to fight:
- Knowingly — not accidentally, not carelessly, and not through someone else’s independent act you had no part in.
- Personal identifying information — a name, Social Security number, date of birth, account number, PIN, or similar identifier belonging to someone else.
- Without consent — the true owner of the identity did not authorize what you did with it.
- Intent to obtain or use the identity for an unlawful purpose, or to cause loss — the fraudulent-purpose element, and the one most often missing in a falsely-accused case.
If you did not know the information belonged to someone else, if you had actual consent, or if you never intended to defraud anyone or cause a loss, the state’s case has a hole in it — no matter how suspicious the transaction looks on a bank statement.
Aggravated Identity Theft and Trafficking: A.R.S. 13-2009 and 13-2010
Two related statutes raise the stakes further. A.R.S. 13-2009, aggravated identity theft, is charged as a class 3 felony when the state alleges you took or used the identifying information of three or more people or entities, caused a single victim an economic loss of $1,000 or more, or acted with the intent to obtain employment using someone else’s identity. A.R.S. 13-2010, trafficking in the identity of another, is a class 2 felony — the most serious of the three — and applies to someone who knowingly sells, transfers, or transmits another person’s or entity’s identifying information without consent, for an unlawful purpose or to cause loss.
These enhanced charges still require the same knowing, non-consensual, fraudulent-intent framework as the base offense — they simply raise the number of alleged victims, the dollar loss, or the nature of the conduct. A prosecutor who charges aggravated identity theft or trafficking based on a shared household account, a misattributed IP address, or a case of mistaken identity has not actually proven any more than the base charge requires — they have only raised what is at stake for you.
How Arizona’s Identity Theft Statutes Are Classified
A.R.S. 13-2008 · 13-2009 · 13-2010
What If It Wasn’t Me? Mistaken Identity in Identity Theft Cases
“It wasn’t me” is one of the most common — and most provable — defenses to an identity theft accusation, because so much of the evidence in these cases points to an account, a device, or an address rather than to an actual person. A few patterns come up again and again.
Stolen information used by someone else
If your identity was genuinely stolen — through a data breach, a lost wallet, a phishing scam, or a scammer who targeted you directly — the person who actually committed the fraud may never be identified, and investigators sometimes default to treating the named account holder as the suspect. Being the original victim of identity theft does not make you the offender.
Shared devices, Wi-Fi, and IP addresses
An IP address identifies a router, not a person. A shared household network, a family computer, a workplace terminal, or unsecured Wi-Fi can put a fraudulent login or purchase at your address while the actual person responsible was a roommate, a guest, a family member, or someone who accessed the network without your knowledge.
Similar names, addresses, or records mixed up
Data-entry errors, similar names, shared addresses at an apartment complex, or clerical mistakes at a bank or credit bureau can attach someone else’s fraudulent activity to your file. These cases are often resolved once the underlying records are pulled and compared side by side.
I Had Permission to Use the Card or Account — Does That Matter?
Yes — consent is a core element the state must disprove, not something you have to prove after the fact. A.R.S. 13-2008 only applies when personal identifying information is used without the consent of the person or entity it belongs to. If you had actual permission, even informal or unwritten, that goes directly at the heart of the state’s case.
Family and household accounts
Parents who let a child use a card, spouses with a shared account, or adult children helping an aging parent with finances are common, lawful arrangements — not identity theft. Disputes often arise later, after a relationship breaks down or a family member changes their story about what was actually agreed to.
Authorized users and shared business accounts
Being added as an authorized user on a credit card, or having access to a shared business or corporate account, is a form of consent. Prosecutors sometimes overlook the difference between exceeding the scope of permission (a civil or workplace dispute) and never having any consent at all (a crime).
Permission that was withdrawn or disputed later
Consent given at the time of the transaction does not disappear because the relationship later soured, the account holder later regretted the arrangement, or a family dispute turned into a police report. What matters is whether you reasonably believed you had permission when you acted.
No Intent to Defraud: Why Intent Decides the Case
Every version of Arizona’s identity theft law requires intent — to obtain or use someone else’s identity for an unlawful purpose, or to cause them a loss. That is very different from simply using information incorrectly, making a billing mistake, misunderstanding whose account something was, or acting on a genuine (even if wrong) belief that you were authorized. Confusion is not fraud. A misunderstanding about whose card, whose login, or whose information was involved is not the same as knowingly and intentionally stealing someone’s identity. Prosecutors have to prove the fraudulent-purpose element beyond a reasonable doubt — and in a genuinely false accusation, that proof usually is not there.
How Are Card and Account Fraud Cases Actually Built?
Understanding how these cases come together helps explain where they fall apart. Banks, card networks, and merchants typically build a fraud referral — and prosecutors build a charging decision — from a combination of:
- Bank and card-issuer records obtained by subpoena: account applications, statements, chargeback and fraud-affidavit paperwork, and the account holder of record.
- Merchant records: point-of-sale logs, register receipts, and in-store or online order details tied to a transaction.
- Surveillance footage from the store, ATM, or gas station where a card was physically used.
- Signature and identification comparisons made at the point of sale or later by a document examiner.
- Device and IP data showing which device, browser, or network was used to open an account, log in, or complete an online purchase.
- Victim statements from the person whose identity was allegedly used, describing what they did and did not authorize.
Notice what that list frequently does not include: direct proof of who was physically present, who typed the password, or who benefited from the transaction. That is exactly the gap a defense investigation targets.
How Digital Forensics Can Clear You
Digital forensics is often the fastest way to show a case of mistaken identity, authorized use, or lack of intent. Depending on the facts, that can include:
- Device attribution — examining which specific phone, computer, or account credentials were actually used, rather than assuming the named account holder was the user.
- Login timestamps and geolocation — showing you were somewhere else, or that the access came from a device you never possessed, at the moment the fraud occurred.
- Metadata and access logs — establishing who created, edited, or submitted an application or transaction, and when.
- Forensic accounting — tracing where the money or goods actually went, and who benefited, which frequently points away from the accused.
- Handwriting and document examination — comparing a signature on an application, receipt, or check against known exemplars to confirm or exclude authorship.
This evidence has to be identified and requested early. Surveillance footage gets overwritten, IP logs age off servers, and bank retention windows close — all reasons to get a defense investigation moving as soon as you know you are under suspicion.
Where Your Identity Theft Case Is Heard
Identity theft, aggravated identity theft, and trafficking under 13-2008, 13-2009, and 13-2010 are all felonies, prosecuted by the Maricopa County Attorney’s Office and heard in Maricopa County Superior Court — regardless of whether you live in Scottsdale, Phoenix, or elsewhere in the county. Scottsdale City Court has no jurisdiction over these felony charges. If you were arrested locally, our guide to what happens after a Scottsdale arrest walks through the first steps.
Some identity theft and account fraud cases — particularly those involving interstate transactions, out-of-state banks, or card networks — can also draw federal attention from the U.S. Attorney’s Office under wire fraud, bank fraud, or federal aggravated identity theft statutes. If you have received a letter from a federal or county prosecutor identifying you as a subject of an investigation, read our guide on what a target letter in a fraud investigation means before you respond to anyone.
What to Do — and Not Do — Right Now
Do
- Write down everything you remember about the account, card, or information at issue — who had access, who had permission, and when.
- Gather anything that documents consent or your version of events: texts, emails, shared-account records, or a rental or business agreement.
- Pull your own bank, phone, and location records for the relevant dates before they age off or become harder to obtain.
- Contact a defense attorney before you speak with a bank investigator, a detective, or a prosecutor.
- Report the true theft to the credit bureaus and file an FTC identity theft report if someone genuinely stole your information.
Do Not
- Do not give a recorded statement or written explanation to a bank fraud department or detective without counsel present.
- Do not assume that having “nothing to hide” means you do not need a lawyer — the intent and consent elements are legal questions, not just factual ones.
- Do not contact the alleged victim directly to try to work it out; let your attorney handle any communication.
- Do not delete texts, emails, or account access logs that could show who actually had permission or access — that can look like consciousness of guilt even when you are innocent.
The Experts We Bring to Identity Theft Cases
A falsely-accused identity theft case is won on the digital and financial trail as much as on the law. We work with the specialists who trace it.
Digital Forensics & Device Attribution Specialists
Which Device Actually Did It
Examine login records, device fingerprints, and access logs to establish which specific phone, computer, or credentials were used — rather than assuming the account holder was the user.
Forensic Accountants
Where the Money Actually Went
Trace transactions, transfers, and account activity to show who actually benefited from the funds or goods — often pointing away from the accused entirely.
Handwriting & Document Examiners
Whose Signature Is It
Compare signatures and handwriting on applications, receipts, and checks against known exemplars to confirm — or exclude — who actually signed.
Cell-Site & IP-Geolocation Analysts
Where You Really Were
Reconstruct cell-site and IP-geolocation data to show your phone or device was somewhere else — or that access came through a network or router you never controlled.
Private Investigators
Finding Who Actually Did It
Track down the actual user of a shared device or account, locate witnesses who can confirm consent, and pull surveillance footage before it is overwritten.
Mitigation Specialists
Protecting Your Record
Build the character and documentary record that supports a dismissal, a diversion resolution, or a favorable outcome when a case cannot be fully resolved before charging.
How Tamou Law Group Defends Identity Theft Accusations
These cases are won by testing the state’s proof of knowledge, consent, and intent — not by arguing the transaction never happened. In the first days we identify what records exist and move to preserve them: bank and merchant subpoena responses, surveillance footage, device and IP logs, and any documentation of consent or authorized use. We look hard at whether the state can actually prove you knew the information belonged to someone else, that you lacked consent, and that you intended to defraud anyone or cause a loss — because in a genuinely false accusation, one or more of those elements is usually missing.
Our team includes former prosecutors, law enforcement officers, and public defenders who know how the Maricopa County Attorney’s Office evaluates identity theft and fraud referrals from banks and merchants. We work out of offices at 9375 E Shea Blvd, Suite 100 in Scottsdale and 2390 E Camelback Rd, Suite 130 in Phoenix, and can meet with you at either location on short notice. Call 623-321-4699 any time, day or night, or learn more on our Scottsdale criminal defense lawyer page and our Scottsdale white collar crimes lawyer page.
Related Arizona Theft & Property Crime Guides
Awards & Recognition
Our recognition for Phoenix criminal defense defense is independently verified, click any award to confirm it:
- National Trial Lawyers Top 100
- National Trial Lawyers Top 40 Under 40
- Elite Lawyer 2026 – Criminal Defense
- Super Lawyers – Southwest
- National College for DUI Defense (NCDD)
When you are looking for the best Phoenix criminal defense lawyers, these are the independently verified credentials that matter, earned by Founding Attorney Michael Tamou and a full team of attorneys, including former prosecutors, public defenders, and law enforcement.
What Clients Say About Tamou Law
Real Google reviews from clients we have defended across Phoenix and Maricopa County. Every review is from a criminal defense client, never padded with non-legal work.
Frequently Asked Questions
What should I do if I’ve been falsely accused of identity theft in Arizona?
Do not explain the account, card, or transaction to a bank investigator, detective, or prosecutor on your own. Write down what you remember about consent and access, preserve texts, emails, and records that support your version, and contact a defense attorney before you say anything further. Statements meant to clear your name often supply the very facts the state needs.
What if it wasn’t me , can I be charged for identity theft someone else committed?
You can be investigated, but A.R.S. 13-2008 requires the state to prove you knowingly used someone else’s information without consent and with intent to defraud. If a family member, roommate, or stranger used a shared device, network, or stolen data without your knowledge, that is a real defense , and device logs, IP data, and location records can often show it wasn’t you.
I had permission to use the card or account , is that still identity theft?
No. A.R.S. 13-2008 only applies when personal identifying information is used without the consent of the person it belongs to. Family accounts, authorized users, and shared business cards are common lawful arrangements, not identity theft, even if a relationship later sours and someone disputes what was agreed to.
How do prosecutors prove identity theft in Arizona?
They typically rely on bank and card-issuer records obtained by subpoena, merchant point-of-sale logs, surveillance footage, signature comparisons, and device or IP data tied to an account or transaction. That evidence often shows which account or device was used, but not always who was actually behind it , which is where a defense investigation focuses.
Can identity theft charges be a misunderstanding?
Yes. Billing confusion, a genuine belief that you were authorized to use an account, mixed-up records between similarly named people, or a family dispute over a shared card can all look like fraud on paper without meeting the knowing, non-consensual, intent-to-defraud standard the law actually requires.
How do I clear my name after being accused of identity theft?
Move quickly to preserve evidence , bank records, device logs, texts showing consent, and location data , before it becomes harder to obtain. A defense attorney can request records through subpoena, retain digital forensics and forensic accounting experts, and present that evidence to the prosecutor before charges are filed or at the earliest stage of the case.
What is the difference between identity theft and aggravated identity theft in Arizona?
A.R.S. 13-2008, taking the identity of another, is a class 4 felony involving a single victim. A.R.S. 13-2009, aggravated identity theft, is a class 3 felony that applies when three or more victims are alleged, a single victim’s loss reaches $1,000 or more, or the intent was to obtain employment using someone else’s identity. A.R.S. 13-2010, trafficking, is a class 2 felony for selling or transferring someone’s identifying information.
Will my identity theft case be handled in state or federal court?
Most identity theft cases in Maricopa County are prosecuted as state felonies in Maricopa County Superior Court by the County Attorney’s Office. Cases involving interstate transactions, out-of-state banks, or card networks can also draw federal attention under wire fraud, bank fraud, or federal identity theft statutes, sometimes beginning with a target letter from a federal prosecutor.
Two Arizona Offices, One Team
We serve all of Maricopa County and the surrounding area, with free, confidential consultations 24/7 by phone and in-person meetings at either office by appointment.
Case Results Disclaimer: The results described on this page are based on specific facts and circumstances and do not guarantee or predict a similar outcome in any future case. Every case is different. Past results do not guarantee future results. No attorney-client relationship is formed by viewing this page or submitting a contact form until a written fee agreement has been signed. Tamou Law Group, PLLC is licensed to practice law in the State of Arizona. This website is for informational purposes only and does not constitute legal advice.
(function() {
function customizeConsultForm() {
var form = document.querySelector('#consult-form');
if (!form) return false;
var fields = form.querySelectorAll('.gfield');
var emailField = null;
var didWork = false;
fields.forEach(function(field) {
var label = field.querySelector('.gfield_label, label');
if (!label) return;
var labelText = (label.textContent || '').trim().toLowerCase();
if (labelText.indexOf('best way to reply') !== -1 || labelText.indexOf('preferred contact') !== -1) {
field.classList.add('tlg-hide-field');
field.querySelectorAll('input').forEach(function(input) {
input.checked = false;
input.removeAttribute('required');
});
didWork = true;
}
if (labelText.indexOf('email') !== -1) {
emailField = field;
field.classList.add('tlg-email-required');
field.querySelectorAll('input[type="email"], input[type="text"]').forEach(function(input) {
input.setAttribute('required', 'required');
input.setAttribute('aria-required', 'true');
});
didWork = true;
}
});
var gform = form.tagName === 'FORM' ? form : (form.querySelector('form') || form.closest('form'));
if (!gform) gform = document.querySelector('#consult-form form, form[id^="gform_"]');
if (gform && !gform.dataset.tlgSourceBound) {
gform.dataset.tlgSourceBound = '1';
var pageUrl = window.location.href;
var pageTitle = document.title || 'Phoenix White Collar Defense Lawyers';
var pagePath = window.location.pathname;
var sourceTag = '[Source: ' + pageTitle.replace(/\s*[,|].*$/, '') + ' | ' + pagePath + ']';
['source_page', 'page_url', 'lander_url'].forEach(function(name) {
var h = document.createElement('input');
h.type = 'hidden';
h.name = name;
h.value = pageUrl;
gform.appendChild(h);
});
var hp = document.createElement('input');
hp.type = 'hidden';
hp.name = 'source_path';
hp.value = pagePath;
gform.appendChild(hp);
function findMessageField() {
var match = null;
form.querySelectorAll('.gfield').forEach(function(field) {
var label = field.querySelector('.gfield_label, label');
if (!label) return;
var t = (label.textContent || '').trim().toLowerCase();
if (t.indexOf('message') !== -1 || t.indexOf('comment') !== -1 || t.indexOf('detail') !== -1 || t.indexOf('describe') !== -1 || t.indexOf('tell us') !== -1 || t.indexOf('your story') !== -1) {
match = field.querySelector('textarea, input[type="text"]');
}
});
if (!match) match = form.querySelector('textarea');
return match;
}
function prependSource() {
var textarea = findMessageField();
if (textarea && textarea.value.indexOf('[Source:') === -1) {
textarea.value = sourceTag + '\n\n' + (textarea.value || '');
}
}
gform.addEventListener('submit', prependSource, true);
var submitBtns = gform.querySelectorAll('input[type="submit"], button[type="submit"], .gform_button');
submitBtns.forEach(function(btn) {
btn.addEventListener('click', function() {
setTimeout(prependSource, 0);
prependSource();
}, true);
});
}
var submitBtn = form.querySelector('input[type="submit"], button[type="submit"]');
if (submitBtn && emailField && !submitBtn.dataset.tlgBound) {
submitBtn.dataset.tlgBound = '1';
submitBtn.addEventListener('click', function(e) {
var emailInput = emailField.querySelector('input[type="email"], input[type="text"]');
if (emailInput && !emailInput.value.trim()) {
e.preventDefault();
emailInput.focus();
emailInput.style.borderColor = '#c62828';
emailInput.style.boxShadow = '0 0 0 3px rgba(198,40,40,.15)';
}
});
}
return didWork;
}
if (document.readyState === 'loading') {
document.addEventListener('DOMContentLoaded', customizeConsultForm);
} else {
customizeConsultForm();
}
var attempts = 0;
var interval = setInterval(function() {
attempts++;
var done = customizeConsultForm();
if (done || attempts > 10) clearInterval(interval);
}, 500);
})();






