The essentials
- Secure your email account first — it is the master key that resets everything else.
- Freeze your credit with the bureaus (in the US: Equifax, Experian, TransUnion — free). A freeze blocks new accounts; a fraud alert only asks lenders to be careful.
- Move your most important accounts to unique passwords and app-based two-factor or passkeys: email, banking, and your phone carrier first.
- Ask your mobile carrier for a SIM-swap / port-out lock — hijacking your number defeats SMS codes.
- Keep a dated log of every discovery, call, and case number. It becomes your dispute file.
Identity theft rarely announces itself. It surfaces as a small unfamiliar charge, a letter about an account you never opened, or a password that suddenly fails. Underneath is usually stolen data from a breach you had no part in — this is not something you caused.
Recovery is a sequence, not a scramble. The order below exists because each step protects the ones after it.
Do this now
- Take back your email. Change the password to something unique, enable app-based two-factor authentication or a passkey, and check recovery addresses, forwarding rules, and connected apps for anything you don't recognize.
- Freeze your credit. Place a freeze with each credit bureau so no new account can be opened in your name. It is free, it does not affect your score, and you can lift it temporarily whenever you need credit.
- Call banks and card issuers. Report fraudulent charges, request replacement cards with new numbers, and dispute anything you did not authorize. Ask each institution for its fraud case number.
- Lock your phone number. Set a port-out PIN or SIM-lock with your carrier. Attackers hijack numbers precisely to intercept the SMS codes protecting your other accounts.
- File the official reports. In the US, identitytheft.gov generates a recovery plan and an FTC report many institutions require for disputes; elsewhere, file with your national fraud service or police. Keep copies of everything.
- Watch the long tail. Review credit reports and statements for the next twelve months. If the theft traces back to a company breach — especially your employer — professional investigation may be warranted.
What not to do
- Do not reuse your old password pattern with a number changed — attackers try variations first.
- Do not ignore small charges; criminals test with small amounts before striking.
- Do not pay "credit repair" services promising instant deletion of fraud — the official dispute process is free.
- Do not throw away fraud letters, envelopes, or notices — they are evidence with dates.
- Do not trust callers claiming to be your bank's fraud department. Hang up and call the number on your card.
Preserve the evidence
Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:
- Your dated log of discoveries, calls, and case numbers.
- Statements and screenshots showing each fraudulent charge or account.
- Credit reports from each bureau, saved as files.
- Police, FTC, or national fraud-service reports.
- Any phishing emails or texts you suspect started it, kept unforwarded.
Keep a clear head
Identity theft is a drip-feed stressor: it resurfaces in letters and statements for months, and the feeling of violation is real and normal. Contain the anxiety the way you contain the fraud — schedule two or three fixed times a week to work the list and check accounts, instead of checking constantly.
Keep a short script by the phone for fraud-department calls: what happened, when you found it, your case numbers. Turning each call into a routine removes most of its sting.
Questions victims ask
What is the difference between a credit freeze and a fraud alert?
A freeze blocks lenders from pulling your file, so new accounts cannot be opened until you lift it. A fraud alert merely asks lenders to verify your identity. If you are an active victim, freeze.
How did they get my information? I'm careful.
Most identity theft starts with large data breaches, not victim mistakes. Your details were likely bought in bulk. Care reduces risk; it cannot eliminate exposure created by companies that held your data.
How long does recovery take?
Containment — freezes, resets, disputes — is usually days. Cleanup of records and follow-on fraud attempts can surface for months, which is why the log and periodic checks matter more than any single call.