Identity Theft Protection: Prevention, Credit Freezes and Recovery Steps

The Risk Management guide helps you prepare for financial risks before they grow. If someone is already using your information, move from prevention to recovery: secure affected accounts, create an official report, protect your credit files, and document every action.

What should you do first after identity theft? Contact the fraud or security department for each affected financial account using a verified number or official app. Lock or close the account as directed, change exposed credentials, save evidence, and report the theft at IdentityTheft.gov. The Federal Trade Commission site creates an Identity Theft Report and a recovery plan based on what happened.
If money is missing or an account is being used now: Contact the bank, card issuer, payment provider, or other account provider immediately. Do not rely on a phone number or link in an unexpected message. Use a number on the card, a statement, the official app, or a website you type yourself.

What are the five immediate identity-theft recovery steps?

  1. Secure affected accounts. Contact the provider’s fraud department, lock or close the account when advised, review transactions, remove unfamiliar devices or access, and change the password from a device you trust.
  2. Protect the accounts that control recovery. Secure your primary email and mobile-provider account because they may receive password resets or security codes. Change any reused password on connected accounts and turn on stronger sign-in protection where available.
  3. Report the identity theft. Use IdentityTheft.gov to describe what happened and create an FTC Identity Theft Report and personal recovery plan. Print or save the report and plan if you do not create an account.
  4. Protect and review your credit files. Decide whether to place a fraud alert, security freeze, or both. Review reports for accounts, inquiries, addresses, employers, and collection items you do not recognize.
  5. Build a recovery record. Keep confirmation numbers, letters, screenshots, dates, transaction details, and the names of departments you contacted. Follow the recovery plan until fraudulent accounts and report information are addressed.

If the first warning is a strange login, changed password, missing phone, or unfamiliar message rather than a credit account, use Hacked Now to organize urgent account-security steps. It complements the FTC recovery plan but does not file reports or contact providers for you.

How do you respond to an existing-account takeover?

A credit freeze can limit new-account fraud, but it does not stop someone from using an account that is already open. Treat account takeover as a direct provider problem.

Bank, card, or payment accountContact the fraud department, identify transactions you did not authorize, follow instructions to lock or replace the account, and monitor related accounts.
Email accountChange the password, review recovery email and phone settings, remove unknown sessions and forwarding rules, and secure accounts that use that email for resets.
Mobile accountContact the carrier through a verified channel, ask about unauthorized SIM or account changes, add or replace the account PIN, and review linked financial accounts.
Shopping or social accountRemove unfamiliar sessions, review saved payment methods and messages, change reused passwords elsewhere, and preserve evidence of purchases or communications.

Do not pay a caller who claims to be a government agency or financial institution and says you must move money, withdraw cash, buy gold, or share a security code to protect an account. CFPB warns that scammers impersonate agencies, law enforcement, and financial institutions. Verify the issue independently.

What is the difference between a fraud alert and a credit freeze?

Protection What it does How to place it How long it lasts
Initial fraud alert Tells a business checking your report to take reasonable steps to verify your identity before approving new credit. Contact one of the three nationwide credit reporting companies. That company must notify the other two. One year. You can renew it.
Extended fraud alert Adds stronger verification after identity theft and removes your name from certain prescreened offers for five years. Create an Identity Theft Report, then follow the credit reporting company’s instructions. Seven years, unless you remove it sooner.
Security freeze Restricts access to your credit file, which can help stop a thief from opening new credit accounts in your name. Contact Equifax, Experian, and TransUnion separately. A freeze placed with one does not reach the others. Until you lift it temporarily or remove it.

Federal law makes freezing and unfreezing your credit files free. A freeze does not affect your credit scores. It also does not block every use of a consumer report and does not prevent takeover of an existing account. Use the FTC’s credit bureau contact page rather than a link from an unsolicited message.

Which one should you use? A fraud alert adds identity verification while leaving the file available to creditors. A freeze is a stronger barrier to new credit that requires you to manage each bureau separately. People dealing with identity theft may use both.

How do you review credit reports after identity theft?

Request your reports through AnnualCreditReport.com, the federally authorized source named by CFPB. Checking your own reports does not hurt your credit scores. Review all three because the information can differ.

  • Look for credit cards, loans, utilities, or other accounts you did not open.
  • Review hard inquiries from businesses you do not recognize.
  • Check names, addresses, employers, and phone numbers for unfamiliar entries.
  • Review balances, payment history, and collection accounts for fraudulent activity.
  • Save copies of the reports and mark each item connected to the theft.

Report unfamiliar accounts and transactions to the business involved as well as through your FTC recovery plan. An ordinary credit-report dispute and an identity-theft block are related but not identical processes.

How can you block fraudulent information from a credit report?

CFPB states that an identity-theft victim can ask credit reporting companies to block fraudulent debts and information by sending:

  • an Identity Theft Report created through IdentityTheft.gov,
  • proof of identity, and
  • a letter identifying the fraudulent debts and report information.

IdentityTheft.gov provides sample letters. Use an identity-theft block only for information caused by identity theft. CFPB says a credit reporting company generally must block the fraudulent information within four business days after receiving a complete request, though it may decline or remove a block when the supplied information is incorrect or the debt was not caused by identity theft.

Keep copies of what you send and proof of delivery. If a debt is not related to identity theft but is inaccurate, use the standard credit-report dispute process. If a credit reporting problem is not resolved, CFPB provides a complaint process.

How can you reduce the chance of identity theft?

No prevention step guarantees that your information will stay private. A practical system reduces exposure, makes account takeover harder, and helps you notice suspicious activity sooner.

Use unique passwordsGive important accounts separate passwords so one breach does not expose every account. A password manager can help generate and store them.
Turn on stronger sign-in protectionUse multifactor authentication where available, especially for email, financial, mobile-provider, and cloud accounts.
Verify unexpected requestsDo not share passwords, sign-in codes, or financial details in response to an unexpected call, text, or email. Contact the organization independently.
Watch account activityEnable useful transaction and login alerts, review statements, and investigate unfamiliar activity promptly.
Protect devices and documentsInstall security updates, use screen locks, securely store records containing personal data, and shred sensitive paper before disposal.
Review consumer reportsCheck credit reports periodically and consider a security freeze when you are not actively applying for credit.

What identity-theft records should you keep?

  • FTC Identity Theft Report and recovery plan
  • Police report, if you chose or were asked to file one
  • Fraud-alert and freeze confirmations from each credit reporting company
  • Credit reports with fraudulent entries marked
  • Letters, secure messages, emails, screenshots, and delivery records
  • Dates, departments, representative names, and confirmation numbers
  • Records of fraudulent transactions, accounts, debts, and corrections

Store the record in a secure place and keep it organized by account. Recovery can involve several businesses, so a dated log helps you see what is complete and what still needs follow-up.

Identity-theft protection questions

Where should you report identity theft?

Report it at IdentityTheft.gov, the Federal Trade Commission’s recovery site. It creates an FTC Identity Theft Report and a personal recovery plan based on what happened.

Does a credit freeze stop all identity theft?

No. A freeze can help stop new credit accounts that require access to your credit file, but it does not prevent takeover of existing bank, card, email, mobile, or other accounts.

Do you have to pay to freeze your credit?

No. Federal law makes it free to place, lift, and remove a security freeze with Equifax, Experian, and TransUnion. You must contact each company separately.

Will freezing your credit lower your credit score?

No. CFPB states that a security freeze does not affect your credit scores.

Can fraudulent information be removed from a credit report?

An identity-theft victim can ask credit reporting companies to block fraudulent information by sending an Identity Theft Report, proof of identity, and a letter identifying the fraudulent items. Keep copies and follow the current instructions from IdentityTheft.gov and CFPB.

This article provides general educational information and is not individualized legal, financial, credit, or cybersecurity advice. Procedures and account-provider requirements can vary. Use current instructions from the relevant provider and government agency.