In short

Use verified channels to contain compromised accounts and replace credentials, create an FTC Identity Theft Report at IdentityTheft.gov, review all three credit reports, and place freezes or fraud alerts according to the risk. Preserve every case number, submission, response, and deadline for each separate dispute.

Last updated: 2026-09-20

Identity theft is not one event. It can appear as card transactions, an unfamiliar loan, a transferred phone number, a tax return filed first by someone else, or medical records for care the victim never received. Recovery cannot be reduced to changing a password. Existing losses require disputes, new-account risk calls for prevention, and errors in separate systems must be corrected separately.

A manageable response has five stages: contain the active compromise, create an official record, prevent new accounts, correct each affected record, and monitor for recurrence. Preserve evidence at every stage rather than relying on a representative’s statement that the matter is handled.

The first hour: regain control from a trusted device

For suspicious bank, card, or phone activity, use an official app already installed, the number printed on a card, or a domain typed directly into the browser. Do not call a number inside the suspicious alert; the warning itself may be phishing.

Prioritize these actions:

  • lock or close payment cards and accounts already being misused;
  • remove unknown devices, sessions, payees, and transfer instructions;
  • replace email, financial, and mobile-carrier passwords;
  • enable multifactor authentication and generate new recovery codes;
  • add port-out or SIM-change protection to the mobile account;
  • preserve transaction, login, and contact records.

If email was compromised first, recover it before resetting other accounts because their recovery links may go there. When malware is possible, use another trusted device to replace credentials and update and scan the original device before returning to it.

Tell each financial institution which activity was unauthorized and request a case number and interim instructions. Notice rights and deadlines differ among account types. Do not wait until every fact is known: report the confirmed facts promptly and supplement the case through the institution’s approved channel.

Create the FTC Identity Theft Report the same day

Submitting the facts through IdentityTheft.gov produces an FTC Identity Theft Report and a personal recovery plan. The report helps establish to businesses and credit reporting companies that identity theft occurred. Type the .gov address yourself. The CFPB warns that impostors also pretend to represent the FTC or law enforcement.

Separate confirmed facts from matters still being investigated. Record unfamiliar creditors, transaction dates, amounts, how the issue was discovered, and institutions already contacted. Do not upload unrelated records or send Social Security numbers and identification through ordinary email.

An IdentityTheft.gov account can retain and update the plan. The FTC page warns that a person proceeding without an account needs to print or save the report and plan before leaving. Store the PDF in an encrypted location and retain a separate offline copy.

Some situations may also justify or require a local police report—for example, a creditor specifically requests it, physical identification was stolen, criminal impersonation occurred, or another agency needs an incident record. Bring the FTC report, government identification, address proof, and available evidence, then request the report number or a copy.

A credit freeze and a fraud alert are not the same switch

A security freeze restricts prospective new creditors from accessing the credit file, reducing the opportunity to open new credit in the victim’s name. The CFPB says placing and removing a freeze is free and the freeze itself does not affect credit scores. The consumer must separately contact Equifax, Experian, and TransUnion; freezing one file does not freeze the other two.

A freeze does not stop misuse of an existing account and does not necessarily stop employment, tenant-screening, insurance, or other access outside a new-credit decision. Continue monitoring banks, mobile service, medical records, and government accounts. When applying for a mortgage, rental, or new phone service, the consumer may need to lift the freeze at the reporting company used by that business. Preserve each login, PIN, and lift confirmation.

An initial fraud alert tells businesses reviewing the report to take identity-verification steps before extending new credit. The FTC currently describes it as free and generally lasting one year. Contacting one nationwide credit reporting company should cause that company to notify the other two. It allows ordinary report access more readily than a freeze but does not block access.

An identity-theft victim with a qualifying report may request an extended fraud alert, which the FTC recovery guide says lasts seven years. The choice depends on upcoming applications and the threat. For confirmed theft and no immediate need for new credit, three freezes often provide the more direct barrier.

Turn the three credit reports into a case inventory

The FTC directs consumers to AnnualCreditReport.com for reports from Equifax, Experian, and TransUnion. Avoid look-alike domains promoted in search ads and do not rely only on the summary inside a credit-score app. The three reports may contain different accounts and inquiries.

On each report, mark unknown accounts, hard inquiries, addresses, name variations, employers, late payments, and collections. Assign a number to every problem and record the report date and page. Then divide the items into:

  1. unauthorized transactions on a real existing account;
  2. an entirely fraudulent account opened by an impostor;
  3. inaccurate identity or public-record information.

The categories identify the recipient. Transaction disputes go to the account institution. Fraudulent accounts require both the originating business and the reporting companies. Identity-field errors follow the reporting company’s correction process. One bank cannot repair every other database.

Close fraudulent accounts and obtain written results

Contact the fraud department at each business, explain that identity theft created the account, and provide the FTC report and identity documents the business reasonably requires. Ask it to close the account and confirm in writing that the account is not the victim’s, the victim is not liable, and the business has stopped reporting or requested removal of the information.

For an unfamiliar credit account, request relevant application, signature, transaction, and contact records to understand how it was opened. Send copies rather than originals and redact data the recipient does not need. Log the date, representative, case number, and promised completion date for every call.

If identity-theft information remains on a credit report, FTC recovery instructions describe sending the report and identity materials to the reporting companies and requesting a block. Blocking identity-theft data has a different foundation from a generic “this is inaccurate” dispute. Use the official sample letters or portal requirements and preserve upload confirmation or tracked-mail delivery.

Do not throw away a collection notice after telling a caller “this is not mine.” Preserve it, request validation on time, and send the identity-theft documentation to the proper recipient. The debt collection validation guide explains how to maintain that written record.

Four common systems beyond the main credit reports

Bank and checking accounts

An impostor may open a checking account or write stolen checks against an existing one. In addition to contacting the bank, the victim may need a report from a bank-account consumer reporting service such as ChexSystems. Ask the institution to stop affected payments, close a compromised account when appropriate, and document how legitimate direct deposits and automatic payments will move.

Phone and utility service

Fraudulent mobile, television, electric, or water accounts may not first appear in the three main credit files. Contact the provider’s fraud department and follow the FTC plan for obtaining a National Consumer Telecom and Utilities Exchange report when relevant. After a phone-number takeover, recover the number and carrier account before resetting other accounts that rely on text messages.

Tax identity theft

For an unfamiliar tax filing, refund, employer record, or IRS verification notice, respond through IRS.gov or the official notice process. The IRS advises ending contact with the suspected thief, protecting the Online Account, following formal notices, and using an Identity Protection PIN or required affidavit where appropriate. A fraudulent filing does not eliminate the victim’s obligation to file a correct return and pay taxes under IRS instructions.

Medical identity theft

An incorrect diagnosis, medication, or allergy can endanger later care as well as create bills. Review provider portals, health-plan Explanations of Benefits, and prescription records. Request records and corrections in writing and notify the insurer’s fraud department. Correcting a medical collection on a credit file is not a substitute for correcting the underlying clinical record.

A case log keeps recovery from becoming another crisis

Maintain a table with institution, issue, first notice, case number, documents submitted, deadline, next follow-up, and written outcome. Keep evidence folders separate by institution and preserve originals unchanged. Send copies.

After each conversation, write a short factual summary. When representatives disagree, ask for the fraud or dispute group and use the existing case number. Escalate unresolved matters through the institution’s formal written complaint process. A consumer-finance issue may also be appropriate for a CFPB complaint after direct efforts are documented.

New “recovery help” scams often appear during this period. Do not pay a caller who promises instant deletion of every record. Never disclose a one-time code, freeze credential, or IdentityTheft.gov login to an incoming caller. Even when the caller names a real institution, call back through a verified number.

Recovery continues after the first refund

For the following months, review credit reports, bank and card activity, the mobile account, tax records, and health-plan activity. Retain business confirmation letters because removed information can reappear. Enable alerts for logins, new payees, password changes, and large transactions.

Reassess every identifier exposed. A Social Security number cannot be replaced like a password, so a long-term freeze and monitoring may remain valuable. A stolen license, passport, or insurance card follows the issuing agency’s replacement process. For a child whose data is exposed, an authorized adult can request a protected-consumer freeze separately at each nationwide reporting company.

Criminal records, eviction, bankruptcy, major tax issues, and continuing substantial loss may require more than account disputes. Contact the relevant court, government agency, or qualified attorney. The goal is not a single “resolved” email; it is a documented correction in every account, credit, government, and medical system affected by the theft.

Frequently asked questions

What is the difference between a credit freeze and a fraud alert?

A freeze restricts access by new creditors and must be placed separately with all three nationwide reporting companies. An initial fraud alert tells businesses to verify identity before new credit; contact one bureau and it must notify the other two.

Does freezing credit lower a credit score?

The CFPB says a security freeze does not affect credit scores. It generally needs to be lifted temporarily or removed when the consumer applies for new credit.

Is a police report always required before fixing identity theft?

An FTC Identity Theft Report supports many recovery rights. A business, criminal-impersonation matter, or other circumstance may also require a police report; follow the personal plan from IdentityTheft.gov and the receiving institution's instructions.