Oklahoma Criminal Defense

Tulsa Identity Theft Lawyer

Identity theft investigations often begin with records rather than an eyewitness. A bank may report a suspicious account, a lender may flag an application, a person may dispute transactions made in their name, or police may find identifying information on a phone, computer, document, or other device.

Oklahoma's identity theft law now reaches far beyond a stolen Social Security number or credit application. Henson Law Firm represents people accused of identity theft in Tulsa and throughout Northeast Oklahoma, and Rob Henson examines permission, fraudulent intent, digital attribution, account history, device evidence, financial records, and whether the State can actually connect the accused to the conduct alleged.

FREE Initial Consultation

What Is Identity Theft in Oklahoma?

Identity theft is governed by 21 O.S. ยง 1533.1. Oklahoma law covers obtaining, possessing, using, selling, creating, altering, or otherwise dealing with many forms of personal or business identifying information with fraudulent intent.

Covered information can include names, addresses, Social Security numbers, dates of birth, email addresses, telephone numbers, account and card numbers, PINs and security codes, usernames and passwords, peer-to-peer payment information, government identification, biometric information, and other information used to identify a person, business, or company.

Identity Theft Does Not Require a Completed Financial Loss

An identity theft investigation can begin even when no loan was funded, no purchase was completed, and no bank account was emptied. Oklahoma law reaches attempts to obtain money, credit, accounts, merchandise, services, property, or other things of value through fraudulent use of identifying information.

That makes failed transactions important evidence rather than automatic defenses. An unsuccessful credit application, declined transaction, rejected account opening, or interrupted online purchase may still become part of an identity theft prosecution.

Possessing Identifying Information Can Become a Serious Criminal Case

Police do not need to catch someone actively using another person's identity before an investigation begins. Identifying information found on a phone, laptop, notebook, photograph, document, cloud account, email account, or other storage medium can become the basis for a much larger investigation.

The source and purpose of that information still need to be examined. Family members, employees, accountants, business owners, caregivers, landlords, contractors, and other people may lawfully possess personal information belonging to others as part of ordinary relationships or work responsibilities.

Fraudulent Intent Is a Central Issue

Possessing another person's information is not the same as proving identity theft. The State must connect the information to fraudulent intent and the conduct prohibited by Oklahoma law. The surrounding records may show a legitimate business purpose, shared account access, permission, family financial arrangements, employment duties, account recovery information, or another explanation. Rob examines why the information was possessed and what evidence actually shows it was intended for fraudulent use.

Permission Can Completely Change the Facts

Identity theft allegations frequently arise between people who knew each other before police became involved. Spouses, dating partners, relatives, employees, business partners, and caregivers may share passwords, account information, identification documents, payment information, or authority to conduct transactions.

A dispute may arise later when one person claims permission never existed or had already ended. Messages, prior transactions, shared accounts, business practices, powers of attorney, employment duties, and the parties' history may show that the accused had authority the initial police report does not acknowledge.

Family Financial Arrangements Can Become Identity Theft Investigations

A parent may allow an adult child to use account information, spouses may share financial credentials, or one family member may manage bills and online accounts for another. Those arrangements can continue for years without formal written authorization.

A breakup, inheritance dispute, family conflict, or disagreement over money can change how earlier transactions are later described. The defense may need to reconstruct what access was permitted before the relationship deteriorated rather than treating the later accusation as proof that every earlier use was fraudulent.

Workplace Access Can Lead to False or Overstated Accusations

Employees may legitimately handle customer information, payroll records, account numbers, identification documents, passwords, financial records, or application materials. An employer may later accuse an employee of improperly accessing or using that information after a termination, audit, customer complaint, or internal investigation.

Access alone does not prove criminal use. Login records, job duties, access permissions, company policies, shared workstations, account histories, and communications may show that the accused possessed the information because the job required it.

Online Accounts Can Create Difficult Identity Questions

An email address, IP address, username, social-media account, cryptocurrency account, delivery address, or device identifier can point investigators toward a suspect without proving who actually performed the transaction.

Homes and businesses often have shared internet connections and devices. Several people may know the same passwords, use the same computer, receive packages at the same address, or have access to the same online account.

A Phone or Computer Does Not Automatically Identify the User

Police may find identifying information, screenshots, account credentials, photographs of cards or identification, messages, or transaction records on a device associated with the accused. That evidence may be important, but ownership of a device does not answer every question about who created, saved, accessed, or used a particular file or account.

Shared devices, old data, cloud synchronization, forwarded messages, automatic backups, and multiple account users can complicate attribution. The timeline of the data and the way it was created may be as important as the fact that it was found.

Synthetic Identities Are Now Specifically Covered

Oklahoma law now addresses synthetic identities, which can combine real identifying information with invented information or can use fabricated information to create an identity that appears legitimate. These cases may involve false names, dates of birth, addresses, account information, business identities, credit profiles, or combinations of information belonging to different people.

Synthetic identity investigations can become document and data intensive. Credit applications, account-opening records, device information, email accounts, addresses, payment records, and the history of the identity itself may be necessary to determine who created or used it.

False Online Profiles Can Lead to Identity Theft Charges

Creating or using a physical, digital, or online profile that falsely represents a person, business, company, or other entity can create identity theft exposure when it is done with fraudulent intent to obtain money, accounts, property, merchandise, licenses, or another thing of value.

The same concern can arise from using a business logo, telephone number, letterhead, or other identifying mark to create a false appearance of authenticity. The prosecution still has to connect the accused to the false profile or representation and prove the fraudulent purpose behind it.

Identity Theft Using a Phone or Computer Can Add Another Felony Issue

Modern identity theft allegations frequently involve phones, computers, artificial intelligence tools, payment applications, social media, email, skimming devices, or other electronic systems. When an electronic device is used to accomplish identity theft, Oklahoma law can expose the accused to additional computer-crime liability on top of the identity theft charge.

The digital evidence should be examined carefully before assuming that every device-related record proves a separate offense. Investigators still need to establish who used the device, what was done with it, and how the activity connects to the alleged identity theft.

Aggravated Identity Theft Carries Much Greater Punishment

Possession of personal identifying information belonging to five or more victims can result in an aggravated identity theft charge. Oklahoma law also allows fraudulent intent to be presumed from that type of possession unless the evidence rebuts the presumption.

Aggravated identity theft carries a prison sentence of ten (10) to fifteen (15) years. The number of alleged victims and whether the identifying information actually belongs to separate people, businesses, or companies can become major issues in the defense.

A First Identity Theft Conviction Is a Class D1 Felony

For a first identity theft conviction, the offense is a Class D1 felony. The base punishment is up to five (5) years in prison, and if a prison sentence is imposed, at least 20 percent must be served before release from custody. A fine of up to $100,000 may also be imposed, and restitution may be ordered. Qualifying prior convictions can increase the punishment, while a third or subsequent identity theft conviction carries a separate prison range of ten (10) to fifteen (15) years.

Identifying Information Belonging to Minors or Elderly People Receives Special Treatment

Oklahoma's current identity theft law specifically addresses possession of identifying information belonging to minors and elderly people. A minor is defined for this purpose as someone under twenty-one, while an elderly person is someone sixty-two or older. The age of the person whose information was allegedly possessed may become important even when prosecutors are not alleging aggravated identity theft involving five or more victims. Records identifying the actual person connected to the information should be verified rather than assumed from account or database entries.

Identity Theft Is Different From False Personation

False personation generally focuses on assuming another person's identity and then acting in that person's role, such as signing documents, creating legal liability, receiving property intended for that person, or falsely exercising official authority.

Identity theft focuses more heavily on obtaining, possessing, altering, or using identifying information with fraudulent intent. The same investigation can involve both offenses, but a false signature or assumed identity should not automatically be treated as proof of every form of identity theft.

Identity Theft Is Different From Credit or Debit Card Fraud

A disputed card transaction may result in a specific credit or debit card charge rather than identity theft. Card offenses have their own rules covering unauthorized use, card theft, cloned cards, counterfeit cards, and skimming.

Identity theft may become part of the same investigation when prosecutors claim the accused obtained or used broader identifying information to access accounts, open credit, create profiles, or obtain other benefits. The charges should remain separate rather than treating every card allegation as identity theft.

Account Openings and Loan Applications Can Produce Detailed Paper Trails

Banks, lenders, finance companies, credit-card issuers, and online platforms may keep applications, uploaded identification, IP information, telephone numbers, email addresses, timestamps, device records, signatures, and transaction histories.

Those records can be powerful when they reliably identify the person who submitted the application. They can also contain information supplied by someone else, shared addresses, forwarded documents, spoofed contact information, or records tied to a device used by several people.

Delivery Addresses Do Not Necessarily Identify Who Placed an Order

Police may focus on the address where merchandise, cards, identification, or financial documents were delivered. A delivery location can connect the transaction to a place without proving who placed the order or who ultimately received the item.

Apartment complexes, family homes, workplaces, shared mailboxes, package rooms, and addresses used by several people can create attribution problems. Shipping records should be compared with surveillance, account activity, communications, and other evidence rather than treated as conclusive by themselves.

Several Alleged Victims Can Turn One Investigation Into Many Counts

The current law allows separate identifying information and separate methods of obtaining money or property to support multiple offenses. An investigation involving numerous identities, accounts, applications, or transactions can therefore expand quickly into a case containing many felony counts.

The defense should determine whether the records actually represent separate people and separate acts, whether information is duplicated, and whether every alleged transaction can be connected to the accused. A large spreadsheet of names and account numbers should not substitute for transaction-by-transaction proof.

Search Warrants Can Produce Enormous Amounts of Digital Evidence

Identity theft investigations may involve search warrants for phones, computers, cloud accounts, email accounts, financial records, residences, vehicles, or online services. The amount of data recovered can be enormous and can include material unrelated to the alleged offense.

The defense may need to examine what investigators were authorized to search, which accounts or devices were actually connected to the accused, and whether the relevant records establish use, intent, or merely possession. Rob focuses on the evidence tied to the charged conduct instead of assuming that a large digital-data seizure proves a large fraud scheme.

Do Not Delete or Alter Digital Records After Learning About an Investigation

Someone who learns they are being investigated may be tempted to delete accounts, messages, applications, browsing history, photographs, or stored identifying information. Altering or deleting evidence after an investigation begins can create additional problems and can make prosecutors argue that the accused was trying to conceal what happened.

Preserve the information as it exists and speak with a lawyer before taking action involving relevant accounts or devices. Messages, access records, account histories, receipts, and other information that appear unfavorable in isolation may provide important context when reviewed as part of the complete record.

What If Someone Else Used Your Identity and You Were Arrested?

Identity theft sometimes creates a different problem: the person whose information was stolen is arrested or charged for conduct actually committed by someone else. Oklahoma provides a procedure that may allow the criminal records to be expunged when a charge is dismissed because another person used the defendant's name or identification without consent.

Oklahoma also has an Identity Theft Passport Program administered by the Oklahoma State Bureau of Investigation. For someone repeatedly being confused with the person who stole or used their identity, those remedies can help document what happened and reduce the risk of the same false attribution continuing.

Evidence Rob Examines in an Identity Theft Case

Identity theft cases may involve bank records, credit applications, account-opening documents, transaction histories, phone records, emails, text messages, IP records, device data, surveillance footage, shipping records, login histories, business records, photographs of identification, social-media records, payment applications, and search-warrant returns.

Rob compares those records with the State's theory of who possessed or used the information, what permission existed, what benefit was sought, and whether fraudulent intent can actually be proven. Digital records can establish that something happened without necessarily establishing who was responsible for it.

What Should You Do If Police Want to Question You About Identity Theft?

You should decline to answer questions and ask to speak with an attorney. Identity theft cases can involve months or years of transactions, multiple accounts, several devices, and records investigators have already collected before asking for your explanation.

Do not try to reconstruct complicated account activity from memory or guess about who used a device, password, address, or account. Preserve the relevant records and let Rob examine the accusation before deciding whether any information should be provided through counsel.

Frequently Asked Questions About Oklahoma Identity Theft

Is identity theft a felony in Oklahoma?

Yes. Under Oklahoma's current identity theft framework, a first conviction is a Class D1 felony with a base punishment of up to five (5) years in prison. Aggravated identity theft and a third or subsequent identity theft conviction carry substantially higher punishment, including a prison range of ten (10) to fifteen (15) years. A fine of up to $100,000 and restitution may also apply.

Can I be charged just for possessing someone else's identifying information?

Possession can result in criminal exposure when the State claims the information was possessed willfully and with fraudulent intent. The context matters because many people legitimately possess identifying information belonging to family members, employees, customers, clients, tenants, patients, or business contacts. The defense will need to establish why the information was present and what it was actually used for. Possession in the course of legitimate work or an authorized relationship presents a different factual situation from possession connected to fraudulent applications or transactions.

What is aggravated identity theft in Oklahoma?

Aggravated identity theft involves possession of identifying information belonging to five or more victims. The offense carries ten (10) to fifteen (15) years in prison. The number of alleged victims should be verified carefully. Duplicate information, records belonging to the same person, misidentified account holders, or information possessed with consent can materially affect that analysis.

What if I had permission to use the information?

Permission can be an important defense issue when the accusation involves information shared between spouses, family members, business partners, employees, or other people with an existing relationship. Messages, prior transactions, shared accounts, employment duties, powers of attorney, and the parties' history may show what access was authorized. A later dispute does not automatically prove that the earlier possession or use was fraudulent.

Can an IP address or phone prove I committed identity theft?

Not by itself. An IP address can identify an internet connection and a phone may contain relevant records, but neither automatically proves who performed a particular transaction. Shared networks, shared devices, multiple users, cloud accounts, forwarded information, and saved credentials can complicate attribution. The State still needs evidence connecting the accused to the conduct charged.

Can using a family member's credit card become identity theft?

It can, depending on what information was used, whether there was permission, and what prosecutors claim the accused intended to obtain. The same conduct may also be investigated as a credit or debit card offense rather than identity theft. Family access can be informal and longstanding. Messages, prior authorized transactions, shared PINs, account history, and the relationship between the people involved may become important in determining whether the use was fraudulent.

Can identity theft charges involve businesses or fake identities?

Yes. Oklahoma's current law reaches identifying information involving businesses and companies and also addresses fake or false identities created from combinations of real and invented information. Those cases may involve business accounts, payment systems, logos, digital profiles, online platforms, credit applications, or fabricated identities. The records used to create and operate the identity may become central to determining who was responsible.

What should I do if a detective calls about identity theft?

You should decline to answer questions and ask to speak with an attorney. The detective may already have account records, applications, digital evidence, transaction histories, and statements from alleged victims that you have not reviewed. Preserve relevant records and devices rather than deleting or changing information. Rob can evaluate the evidence and the charging theory before deciding whether any information should be provided through counsel.

Talk With a Tulsa Identity Theft Lawyer

Identity theft cases can involve enormous amounts of financial and digital information, but the volume of records does not eliminate the need to prove who acted, what information was used, whether there was permission, and whether the accused acted with fraudulent intent. Those questions become even more important when an investigation involves numerous accounts, multiple alleged victims, synthetic identities, or devices shared by several people.

Henson Law Firm defends people accused of identity theft in Tulsa and throughout Northeast Oklahoma. If you or a family member is under investigation or has already been charged, contact the firm at 918-551-8995 for a FREE initial consultation with Rob Henson.

Honest Advice. Strategic Defense.

Analytics Preferences

Google receives limited cookieless measurements before you choose. Allow analytics cookies for fuller measurement, or choose No Thanks. Your form answers are never included.

Analytics cookies are off unless you allow them.