The FTC Identity Theft Report: What It Is and How to Use It
The FTC Identity Theft Report is a formal record created through IdentityTheft.gov that can support specific recovery rights and requests.

The FTC Identity Theft Report is created when you report identity theft through IdentityTheft.gov. It is more than a generic complaint receipt: in the right context it can help support a request to block identity-theft information from a consumer report and a request for transaction or application records connected to fraud. Its value depends on accuracy. State only what you know, save the report number and a copy, and make later letters consistent with the facts you originally reported. The report is a foundation for recovery paperwork; it does not automatically close accounts, erase credit entries, or replace every police or agency report.
What the report actually proves
The report records your statement that identity theft occurred and the details you provided to the FTC. It does not independently prove that every disputed transaction was fraudulent, and it does not tell a bank exactly how to resolve its own investigation. Think of it as a standardized identity-theft record that other processes can rely on. When you send it to a bureau or creditor, pair it with a clear request: identify the item you want blocked, the records you want produced, or the account you say was opened without your authorization. A report without a specific requested action often creates another round of correspondence.
IdentityTheft.gov also provides a recovery plan. Use that plan as a task list, but preserve your own chronology as well. A plan can tell you what category of action comes next; your log should show the account number fragment, date, representative, reference number, deadline, and outcome. Those are the details that become important when several organizations are handling the same incident on different clocks.
Build the report from evidence, not from assumptions
Before submitting, gather the fraudulent statement, credit-report entry, breach notice, collection letter, rejected tax return, or account-opening email that triggered the report. Write down dates exactly as they appear. If you do not know how a thief obtained your SSN, say that you do not know rather than inventing a breach source. If you know an account is unfamiliar but cannot yet see the application, describe it that way. Precision is more useful than certainty you cannot support.
After filing, save the generated report in a durable location. Give the file a date and incident name instead of leaving it in a downloads folder. Keep a second copy of important supporting records. If you later discover a second fraudulent account, add that new evidence to your recovery file and follow the current IdentityTheft.gov instructions for updating or creating the documentation needed for that issue. Avoid rewriting old facts in a way that makes later packets contradict each other.
Where the report can change the credit-report process
A normal accuracy dispute and an identity-theft block are not identical. CFPB guidance explains that a consumer reporting company must block qualifying identity-theft information within four business days after it receives the required package, which includes proof of identity, an identity-theft report, identification of the fraudulent information, and a statement that the information is not related to a transaction by the consumer. That is a specific remedy with specific prerequisites. If you are only disputing a billing error or stale balance, the ordinary dispute process may be the correct tool instead.
For a block request, make the packet easy to audit. Highlight the tradeline or inquiry, state that it resulted from identity theft, include the FTC report, and retain proof of delivery or portal submission. If the bureau asks for missing information, respond to the missing item rather than resending a pile of unrelated documents. The goal is to make the relationship between the report and the item unmistakable.
| Use | What to attach or preserve | What not to assume |
|---|---|---|
| Credit-report identity-theft block | FTC Identity Theft Report, proof of identity, marked report item, written request | That a normal accuracy dispute automatically invokes the identity-theft block rule |
| Fraudulent account records | Report plus the creditor’s required identity documents and a precise description of the application or transaction | That the FTC itself will retrieve the creditor’s records for you |
| Police report support | FTC report, identification, statements, screenshots, mail or account evidence | That every police department uses the same intake process |
| Recovery chronology | A stable copy of the report and dated notes for later discoveries | That the first report must predict facts you had not yet learned |
Record requests can reveal how the fraud happened
Federal law gives identity-theft victims a route to request certain business records relating to transactions or accounts resulting from identity theft. The FTC report can be part of that request. Ask for the actual application, signature records, addresses, phone numbers, device or order information that the company is permitted to provide under the process. Those records can help identify where an account was opened, whether an old address was used, and which other organizations may need notice. Do not expect a creditor’s fraud department to volunteer the records automatically; a recovery decision and a records request are different tasks.
When a police report still matters
Some creditors, motor-vehicle agencies, courts, employers, or state programs may ask for a police report. Physical document theft, mail theft, criminal impersonation, and local records are also situations where law enforcement may have a distinct role. The FTC report does not make that local process unnecessary. Instead, it gives you a concise factual starting point. Bring a copy and supporting documents, ask for the local case number, and keep the officer or agency name if one is provided.
Treat the FTC report as a reusable evidence anchor
The best use of the report is consistent, targeted repetition: the same core facts support different narrowly worded requests. One packet may ask a bureau to block a tradeline; another may ask a card issuer for application records; another may support a police report. Keep the report unchanged, label each outgoing packet, and log the result. When recovery is complete, you should be able to reconstruct why each organization was contacted and what record supported the request without relying on memory.
Questions specific to The FTC Identity Theft Report: What It Is and How to Use It
Can I get an FTC Identity Theft Report without creating an account?
IdentityTheft.gov provides the reporting and recovery workflow. Account features can help you save and return to a plan, but follow the site’s current prompts because the exact workflow can change. Always save the report or confirmation you receive.
Does the FTC Identity Theft Report automatically remove fraudulent credit items?
No. It can support an identity-theft block request, but you still have to identify the fraudulent information and provide the bureau with the required package. The report is evidence for the request, not an automatic deletion command.
Should I change details in the report if I learn something later?
Preserve the original facts and document later discoveries with dates. If IdentityTheft.gov provides a way to update the matter, follow that workflow, but avoid making old and new documents conflict without an explanation.
Why would a creditor need the FTC report if it already closed the account?
Closing the account stops further use, while later tasks may involve correcting consumer reports or obtaining application and transaction records. The same incident can therefore require different documents at different stages.