I agree with colm17. Identity theft could have been likely linked to the customer themselves.
Customers could have avoided getting their credentials being phished (a.k.a. identity theft), if they were to be more weary of what they do.
One such example is phishing sites. If they were to notice anything that seems out of the ordinary in a particular site that looks like the actual one, they shouldn't proceed with providing their information. |