Identity Theft: What to Do in the First 24 Hours
If fraud is active, stop the account damage first, then create the records and credit controls that make the next days easier.
Contain active misuse, create the right records, and repair the accounts or reports that were actually affected.
If fraud is active, stop the account damage first, then create the records and credit controls that make the next days easier.
The FTC Identity Theft Report is a formal record created through IdentityTheft.gov that can support specific recovery rights and requests.
Read a credit report as an evidence document: separate unknown accounts and inquiries from harmless stale data, then log each suspicious item precisely.
Use the ordinary FCRA dispute process for inaccuracies and the identity-theft block process for qualifying fraudulent information; they have different requirements and timelines.
A police report is most useful when a creditor, agency, court, insurer, or local process needs a law-enforcement record or when the crime has a local component.
When a bank account or card was opened in your name, close the source account, obtain the application record, and correct both banking and credit-report traces.
Recover the account that can reset the others first—usually email—then remove attacker persistence before changing every downstream password.
When mail disappears or an address is changed without permission, secure USPS access, report the postal event, and trace every financial item that may have been diverted.
A SIM swap or fraudulent port moves control of your phone number to an attacker; harden the carrier account and move critical authentication away from SMS.
A stale address, duplicated tradeline, or paid balance reported incorrectly can be a credit-report error without being identity theft.
The year after identity theft is easier to manage with a calendar than with continuous anxiety-driven checking.
A recovery log should capture date, organization, channel, representative, reference number, promise made, deadline, and next action.
Follow the branch that matches tax, medical, child, criminal, employment, bank-account, or breach evidence.
Treat tax identity theft as an IRS-account problem first: follow the rejection or notice instructions, file the real return, and use Form 14039 only when the IRS process calls for it.
Medical identity theft can corrupt bills, insurance claims, and clinical records; recover both the financial record and the health record instead of treating it as ordinary credit fraud.
A child may have no credit file at all; if a file or account exists unexpectedly, close the fraud, freeze the child’s reports, and keep guardian documentation organized.
Synthetic identity fraud can pair a real SSN with invented identity details, so monitoring only your name may miss a file that is being built around your identifier.
If another person used your identity in a police, citation, warrant, or court matter, work with the agency that owns the record and preserve clearance documentation.
If wages or employment verification appear under your SSN, correct the Social Security and tax records and use myE-Verify controls where they fit.
A breach letter matters most for the data types it names; map each exposed identifier to the control that can actually reduce its misuse.
Reduce new-account, account-recovery, tax, phone, and data-exposure risk before an incident forces the decision.
A freeze, fraud alert, and bureau lock are different controls; choose based on whether you need to block access, add verification friction, or use a bureau product.
Freeze Equifax, Experian, and TransUnion as three separate tasks, save access details, and plan how you will temporarily lift a file later.
An IRS IP PIN is a six-digit, one-calendar-year filing credential; get it through the IRS, retrieve the current year’s number, and keep it out of email and text messages.
Free credit monitoring can be worth enrolling in after a breach, but it detects changes after they occur and should not replace free security freezes.
Dark-web monitoring is useful as an exposure alert, but it cannot search every criminal forum, remove leaked data, or prevent fraud by itself.
A password manager eliminates reuse; passkeys remove the shared secret entirely on supported sites. Set recovery before migrating your most important accounts.
Choose MFA by attack resistance: SMS is better than password-only, authenticator codes are stronger, and passkeys or security keys best resist phishing.
Start with sites that expose a home address, phone number, relatives, and age because that combination can help scammers personalize contact.
The three nationwide credit bureaus are only one category of consumer reporting company.
File a legitimate return on the timeline that fits your tax situation; filing early can reduce the window for a fraudulent refund return but does not replace identity controls.
Change the router administrator password, use WPA3 or WPA2 with a strong Wi-Fi passphrase, and apply current firmware before tuning optional features.
A phone can unlock email, banking, password resets, cloud backups, and carrier accounts, so its screen lock is part of identity protection.
Credit freezes, IdentityTheft.gov recovery plans, IRS IP PIN enrollment, and basic credit-report review are available without a paid identity-protection subscription.
Build a realistic baseline for a tiny team, then handle vendors, incidents, breach obligations, and compliance triggers without enterprise theater.
For a team under twenty, account security and recovery discipline usually matter more than buying a large security stack.
A tiny-team incident plan must name people and phone numbers, not only verbs such as contain and recover.
There is no single U.S. state-breach deadline that safely replaces a state-by-state analysis.
Vendor risk starts by mapping what data and systems a contractor can actually reach, then reducing access to the minimum needed for the work.
Compliance frameworks answer different questions: PCI DSS concerns payment-card environments, HIPAA applies to covered health contexts, GLBA and the FTC Safeguards Rule apply to covered financial institutions, and state privacy laws depend on jurisdiction and thresholds.
Classify what happened, stop irreversible payments or account access, and preserve the evidence that matters for the next step.
In 2026, polished language and synthetic voice make appearance less useful; verify the request, destination, and payment or credential demand through a known channel.
Your response depends on what happened after the click: visiting a page, entering credentials, approving MFA, or running a downloaded file require different actions.
Gift cards, wires, crypto, and cash are common scam payment methods because they move value quickly and are difficult to reverse; stop the next payment first.
Long-con investment scams build trust first, then move victims to fake trading platforms; stop sending money and preserve the transaction trail before the scammer disappears.
Protect an older parent through agreed safeguards—alerts, freezes, trusted contacts, and a verification routine—without taking away control by surprise.