A credit card you never applied for arrives. Or a collections notice for an account you have never heard of. Or a lender declines you and the reason turns out to be four recent applications you did not make.
Almost everything written about identity theft is about prevention, which is no longer relevant to you. What matters now is sequence — doing the right things in the right order, because some steps unlock others and doing them backwards costs weeks.
What changed in 2026
- Credit freezes stayed free and got faster. Placing and lifting a freeze at all major bureaus is free by law and now typically takes minutes online rather than days.
- Synthetic identity fraud grew. Fraud combining real details with fabricated ones is harder to detect and harder to unwind, because the resulting identity is not quite yours.
- AI-assisted impersonation raised the stakes. Voice cloning made phone-based account takeover more effective, which means recovery increasingly involves accounts secured by verification that no longer verifies much.
- Recovery processes stayed slow. The tooling improved; the dispute timelines set by law did not.
The first 48 hours, in order
1. Freeze your credit at all major bureaus. Do this before anything else. A freeze stops new credit being opened in your name, which stops the bleeding while you deal with what already happened. It is free, reversible, and does not affect your existing accounts or your score. Do all three major bureaus — freezing one accomplishes little, since a lender may check any of them. Credit freeze vs lock covers the distinction, and for this purpose you want the statutory freeze.
2. File the official identity theft report. In the US this is the FTC report at IdentityTheft.gov, which produces a recovery plan and an affidavit. This document is what activates your statutory rights — the ability to demand fraudulent accounts be blocked, to get free reports, and to require records from creditors. Almost every subsequent conversation will ask for it, so having it first saves repeating yourself.
3. Report to local police if you need it. Some creditors require a police report alongside the federal one. Bring the FTC affidavit and any documentation.
4. Contact the fraud department of each affected company. Not general customer service — the fraud department, which has different authority and different scripts. State that you are reporting identity theft, reference your report, and ask them to close the fraudulent account and confirm in writing.
5. Change credentials on anything reused. If a breach is the likely source, any account sharing that password is exposed. A password manager makes this an hour's work rather than a weekend's — see the best password managers.
Document everything
This is the part that determines whether recovery takes weeks or months, and it is the part most people do badly under stress.
Keep a running log: date, time, company, the name of the person you spoke to, what was agreed, and the reference number. Every call. Disputes get reopened, records get lost, and a company will tell you six weeks later that you never called. Your log is the answer.
Follow up every phone call in writing. Email or letter, restating what was agreed. Phone calls evaporate; written records do not. Where a dispute is formal, send it by a method that produces proof of delivery.
Never send original documents. Copies only, always.
Keep everything. Even after resolution. Fraudulent accounts have a way of resurfacing when a debt is sold to a collections agency that never got the memo.
After the first week
| Task |
Timing |
Why |
| Review full credit reports |
Immediately, then quarterly |
Find accounts you missed |
| Dispute each fraudulent item |
As found |
Written, with your report attached |
| Add a fraud alert |
Alongside the freeze |
Extra verification on applications |
| Check non-credit accounts |
Week one |
Utilities, mobile, medical, tax |
| Watch for collections |
Ongoing, 12+ months |
Sold debt reappears |
| Consider an IRS PIN |
Before tax season |
Blocks fraudulent returns |
Two categories get missed consistently. Medical identity theft — treatment received in your name — corrupts your medical records, which is a safety issue as much as a financial one, and it does not appear on a credit report. And tax identity theft, where someone files a return to claim your refund, only surfaces when your own filing is rejected.
Also check accounts that do not report to credit bureaus at all: mobile carriers, utilities, and streaming services. Fraud there is invisible to credit monitoring.
Common mistakes
- Contacting creditors before filing the report. You will be asked for it and have to start over.
- Freezing one bureau. Lenders may check any of them.
- Relying on phone calls. No record, no leverage.
- Not checking non-credit accounts. A whole category of fraud that credit monitoring never sees.
- Stopping once the accounts are closed. Sold debt resurfaces months later.
- Paying for recovery help first. The statutory process is free; buy help if it stalls, not before.
- Reusing the compromised password anywhere. Guarantees a second incident.
FAQ
How long does recovery take?
Straightforward cases with good documentation often resolve in weeks. Complex ones — several accounts, collections involvement, synthetic identity — can take many months. Documentation quality is the biggest factor you control.
Will this hurt my credit score permanently?
Fraudulent accounts should be removed once blocked, and the associated damage goes with them. Persistence is what makes that happen; items sometimes reappear when debt changes hands, which is why you keep monitoring after it feels resolved.
Should I buy identity theft protection?
It mostly automates monitoring and offers help with paperwork. Useful to some people, and none of it is a prerequisite — freezes and the statutory process are free and more effective than monitoring, which by definition tells you after the fact. See the best identity theft protection if you want it anyway.
How did they get my information?
Frequently a data breach, and frequently unknowable. Reducing your exposure going forward is worth doing regardless — data broker opt-out covers removing the aggregated profiles that make impersonation easier.
Where to go next
For the freeze mechanics, read credit freeze vs lock. For hardening accounts afterwards, passkeys vs 2FA and the best password managers, and for the impersonation attacks that increasingly accompany this, deepfake scam protection.
This is general information, not legal advice. Procedures and statutory rights differ by country; the specific steps above describe the US process.