· Digital Footprint Check · Content Marketing · 13 min read
What to Do After Identity Theft: Identity Theft Recovery
Learn what to do after identity theft strikes. Follow this step-by-step recovery plan to protect your finances, credit, and identity in 2026.

You notice a credit card you never opened, a collection account tied to an address you don’t recognize, or a tax notice for a return you never filed. Then the calls begin. Each institution asks for different documents, each representative gives you a different reference number, and the problem seems to spread faster than you can contain it.
What to do after identity theft is not limited to freezing your credit and filing a report. Those actions matter, but recovery often becomes a long administrative case involving banks, credit bureaus, government agencies, creditors, and sometimes law enforcement. The people who recover most effectively treat the incident like an investigation. They stop active misuse, create an evidence trail, challenge each fraudulent record, and keep escalating when an institution fails to respond.
Immediate Triage to Stop Ongoing Fraud
Start with the accounts showing unauthorized activity. Call each bank, card issuer, lender, payment service, or telecommunications provider through a verified number from its official website or statement. Tell the representative that you’re reporting identity theft and unauthorized activity, ask for the fraud department, and request that the account be locked, restricted, or closed while the institution investigates.
Don’t rely on a single password change. Change credentials for the affected account, your primary email, and any service that reused the same password. Turn on two-factor authentication, sign out other sessions, replace compromised payment methods, and review recent transactions for smaller charges that may have preceded the larger fraud.

Make the first calls count
Use the first hour to contact:
- The affected financial institution. Ask it to stop transactions, secure or close the account, issue new credentials, and explain its dispute process.
- Your primary email provider. An email takeover can let criminals reset banking, shopping, and social accounts.
- The three credit bureaus. Place a fraud alert and begin the process of freezing your credit files.
- Any telecommunications provider involved. A stolen phone number can expose password resets and verification codes.
- Your employer, tax preparer, or relevant government agency. Escalate quickly if the theft involves payroll, taxes, benefits, licenses, or official records.
Before each call, gather the suspicious transaction dates, merchant names, account numbers, screenshots, notification emails, and the date you discovered the activity. During the call, record the representative’s name, department, time, case number, promised action, and deadline. Ask the institution to confirm the next step in writing.
Practical rule: Never end a fraud call with only “we’ll investigate.” Get a reference number and ask exactly how you’ll submit supporting documents.
Review the warning signs that your identity may have been stolen if you’re still determining the scope. If the incident followed a company breach, a structured cloud security after a breach response plan can help you separate exposed credentials from confirmed misuse.
Speed matters because an open account, active email session, or working phone number gives the criminal another route into your life. Your job in the first day isn’t to solve everything. It’s to cut access, preserve evidence, and prevent the next transaction.
Filing Official Reports with FTC and Law Enforcement
Your official report becomes the backbone of every later dispute. File through IdentityTheft.gov, the Federal Trade Commission’s one-stop resource for reporting identity theft and receiving step-by-step recovery instructions. The FTC says the personalized plan may direct you to close fraudulent accounts, remove unauthorized charges, contact the three credit bureaus, consider an extended fraud alert or credit freeze, and check your credit reports regularly. FTC recovery guidance also tells victims to review account and transaction records first, include as many details as possible, and contact the agency at 1-877-438-4338 or use the online portal.
Build a report that another person can use
Don’t write a vague summary such as “someone stole my information.” List each known event:
- Account details: Name the institution, account type, last known digits, and date of suspicious activity.
- Transaction evidence: Record unauthorized charges, applications, withdrawals, addresses, phone numbers, or email accounts.
- Your actions: Note when you contacted each company and what the representative told you.
- Supporting records: Keep statements, alerts, screenshots, emails, letters, and copies of submitted forms.
Download or print the completed FTC Identity Theft Report and save the report number in more than one secure location. The report gives creditors a clear explanation of the identity theft and can support requests to remove fraudulent accounts or charges.
A police report isn’t required for every dispute, but it can become important when a creditor, lender, insurer, employer, or government agency asks for formal law-enforcement documentation. Take your FTC report, photo identification, proof of address, and supporting evidence to your local police department. Request the case number and a copy of the completed report.

If an officer declines to take a report, ask for the refusal and the department’s policy in writing. Stay factual, request a supervisor, and document the interaction. You can still use your FTC report, financial records, and creditor correspondence while pursuing another law-enforcement contact or seeking advice from a consumer attorney.
For a separate issue involving a stolen driver’s license, keep the reporting process distinct and follow the relevant stolen driver’s license guidance. Mixing identity documents, credit disputes, and police records into one unsorted narrative makes later escalation harder.
Understanding Fraud Alerts Versus Credit Freezes
A fraud alert and a credit freeze solve different problems. A fraud alert tells lenders to take extra steps to verify your identity before approving new credit. A credit freeze blocks prospective creditors from accessing your credit file until you lift the freeze. If active misuse is already confirmed, I recommend using the freeze as the stronger control and keeping the alert as an additional signal when appropriate.
| Feature | Fraud Alert | Credit Freeze |
|---|---|---|
| Main function | Signals creditors to verify your identity | Blocks new creditors from accessing your file |
| Placement | Contact one bureau, which must notify the other two | Contact Equifax, Experian, and TransUnion separately |
| Standard duration | One year, renewable for free | Remains until you lift or remove it |
| Identity-theft extension | Seven years with qualifying documentation | No routine expiration while maintained |
| Effect on legitimate applications | May add verification steps | You must lift it before a lender can access the file |
| Cost | Free | Free under federal law at the three nationwide bureaus |
The FTC confirms that contacting any one of the three nationwide credit bureaus is enough to place a standard alert because that bureau must notify the other two. An initial alert lasts 90 days, according to the DOJ checklist summarized in identity theft recovery guidance, while the FTC’s consumer explanation describes a standard alert as lasting one year and allowing free renewal. These references describe different alert contexts, so check the exact term and expiration date shown when you place yours.
An extended fraud alert lasts seven years for people who experienced identity theft and filed an FTC identity theft report or police report, as explained by the FTC’s credit freeze and fraud alert guidance. A freeze requires separate action with each bureau. Record the login credentials, PINs, confirmation emails, and removal process for Equifax, Experian, and TransUnion.
A fraud alert asks a lender to pause and verify. A freeze prevents the credit-file access that often precedes a new account.
Don’t confuse a freeze with closing existing accounts. It protects new-credit applications, not a compromised bank login, debit card, tax account, or email inbox. Use the appropriate control for each exposure, then review whether identity theft protection works for your situation without treating any monitoring service as a substitute for direct account security.
Building Your Identity Theft Documentation File
Identity theft recovery fails administratively when victims can’t prove what happened. Create one master case file, preferably in a secure folder with an encrypted digital copy and a paper backup for critical reports. Use a consistent filename format that includes the institution, document type, and date.

Organize evidence for a stranger
A bank investigator or regulator should be able to understand the case without calling you for basic context. Create these folders:
- Identity records: Save proof of identity, address history relevant to the dispute, account ownership records, and copies of identification submitted.
- Fraud evidence: Store the FTC report, police report, credit reports, statements, application records, transaction details, and fraud-alert or freeze confirmations.
- Communications: Keep letters, emails, secure messages, call notes, representative names, confirmation numbers, and delivery receipts.
- Open issues: Maintain a live list of every unresolved account, responsible institution, dispute date, response deadline, and next escalation.
Create a timeline beginning with the first suspicious event, not the day you noticed it. Add dates for every call, dispute, document submission, account closure, credit-report update, and new incident. This timeline helps you identify repeated failures, such as an institution losing the same document or reopening an account after you reported fraud.
Use precise dispute language
Your letters should identify the disputed debt and state why it isn’t yours. Attach copies, not originals, of your FTC report, police report when available, proof of identity, and relevant account records. Send documents through the creditor’s designated dispute channel and use a delivery method that creates proof of receipt.
A concise template can read:
I am disputing account [reference] because it resulted from identity theft and wasn’t opened or used by me. Please investigate, stop collection activity while the dispute is reviewed where applicable, remove the fraudulent information from my records, and provide written confirmation of the result. Attached are my FTC Identity Theft Report, [police report if available], proof of identity, and supporting records.
Keep a second template for a credit bureau:
I dispute the account listed as [account and creditor] because it resulted from identity theft. Please block or correct the information and send written confirmation of the investigation outcome. Attached are my identity-theft documentation and a copy of the relevant credit report page.
Before sending anything, review the identity theft checker as one way to identify exposed accounts or personal information that may belong in your evidence inventory. Don’t upload sensitive documents to an unverified service. Your master file should show what you submitted, when you submitted it, and what the recipient did next.
Managing Long-Term Recovery When Cases Remain Unresolved
The biggest mistake in identity theft advice is treating the first report as the finish line. The Identity Theft Resource Center’s 2026 trends data says only 53% of victims with no financial loss reported a resolution, while just 9% of victims with any financial impact resolved their cases. Those figures, reported in the ITRC trends summary, show why a durable case-management system matters.
Run the case like an escalation ladder
Set a recurring review date for every open dispute. At each review, compare the institution’s response with your timeline, check whether the fraudulent item still appears, and look for new accounts or addresses. If an institution ignores evidence or refuses to correct an item, escalate in writing to its executive complaints channel, then consider the appropriate regulator, attorney, or consumer advocate.
Don’t send angry messages. Send a complete packet with a short cover letter, an indexed exhibit list, prior reference numbers, and one specific requested outcome. A regulator or attorney can act more efficiently when the record shows exactly what the company received and how it responded.
New fraud months later doesn’t mean the original case was imaginary. It may indicate that another exposed credential, account, address, or government record remains active. Add the new event to the same master file, secure the newly affected account, update your FTC report when appropriate, and notify every institution whose records now overlap.
A structured credit recovery plan for fraud victims can help organize disputes, but no private service can replace direct contact with creditors, credit bureaus, government agencies, or legal counsel. Seek legal advice when a creditor threatens litigation, a collector continues pursuing a documented fraudulent debt, benefits or licenses are affected, or the case creates employment or housing consequences.
Handling Tax Identity Theft and Government Record Fraud
Tax identity theft needs its own track. A criminal may use your Social Security number to file a return, claim a refund, or create a tax record that doesn’t match your legitimate filing. A credit freeze won’t correct an IRS record, so treat the tax authority as a separate case owner.
Start with the IRS identity-theft process and follow its instructions for your circumstances. The IRS tells victims to keep records, obtain an Identity Protection PIN, and use tax-specific forms such as Form 14039 when required. The IP PIN adds an authentication step to tax filing, but it doesn’t erase a fraudulent return or resolve unrelated credit and banking problems.
Recovery can be slow. One independent summary reports that the IRS Identity Theft Victim Assistance process takes an average of 22 months, as cited in the IRS Identity Theft Guide for Individuals. Keep every IRS notice, submitted form, identity-verification record, transcript request, and phone log in a tax-specific folder within your larger case file.
Separate government records from credit disputes
Government-record fraud may affect benefits, professional licenses, driver’s licenses, immigration records, or official correspondence. Contact the agency that owns the record, ask for its identity-theft or fraud unit, and request its exact correction procedure. Agencies often require forms, certified documents, sworn statements, or records that credit bureaus don’t request.
For benefits or licensing issues, document missed payments, rejected applications, suspension notices, and work-related consequences. Ask the agency to place an internal fraud notation and to confirm whether it will notify other departments. Never assume one agency’s correction will propagate to another system.
Treat tax, government, banking, and credit records as separate recovery tracks that share evidence but require different owners.
Long-Term Monitoring and Prevention Strategies
Recovery isn’t complete when a fraudulent account closes. You need a repeatable routine that detects new exposure without turning every day into an investigation. Review bank and card activity, enable available transaction notifications, and inspect your credit reports for unfamiliar accounts, addresses, inquiries, and public-record entries.
Use unique passwords for every important account, store them in a reputable password manager, and protect the manager with a strong master password and two-factor authentication. Secure your email first because attackers can use it to reset other accounts. Review recovery phone numbers, backup email addresses, active sessions, connected applications, and forwarding rules.
Digital Footprint Check can scan 500+ platforms for exposed information across social networks, gaming profiles, breach databases, professional networks, and public records, then provide removal guidance. Use that type of scan to identify old usernames, abandoned accounts, exposed contact details, and data-broker listings that may help an attacker connect separate pieces of your identity. For breach and dark-web alerts, compare services carefully with this guide to dark web monitoring services.
Watch for targeted phishing after a breach or identity-theft report. A message that pressures you to act immediately, comes from an unusual address, includes an unexpected attachment, or asks for information the sender should already have deserves independent verification. Call the organization through a trusted number, not the contact details inside the message.
The same discipline applies to small businesses and contractors handling personal data. If security controls affect eligibility for work, review practical resources on meeting Cyber Essentials for contracts. For individuals, the priority is simpler: protect email, use unique credentials, enable two-factor authentication, maintain credit controls, and keep a case file that remains useful long after the initial panic ends.
Digital Footprint Check helps you identify exposed personal information across 500+ platforms, including social networks, gaming profiles, breach databases, and public records, so you can address risks before they become another fraud event. Visit Digital Footprint Check to run a free scan, review what’s exposed, and turn your identity-theft recovery into an ongoing privacy routine.



