For U.S. consumers, start with a free security freeze at Equifax, Experian, and TransUnion. Then secure your email and financial accounts with unique passwords, multifactor authentication (MFA), and activity alerts. A freeze can help with many new-credit applications, but it won't stop unauthorized use of an existing account, account takeover, or a scam that persuades you to send money.
If you already see an unfamiliar account or transaction, go directly to Identity theft recovery: a practical order of operations.
The five actions to take first
- Freeze all three credit reports. Use the FTC's credit freeze and fraud alert guidance or USAGov's credit-freeze guide. You must request a freeze separately from Equifax, Experian, and TransUnion.
- Secure your primary email account. Email is often the recovery route for other accounts. Give it a unique password, turn on MFA, and check that its recovery phone number and email address are current.
- Turn on MFA for sensitive accounts. An authenticator app or security key is generally stronger than text-message codes. If SMS is the only option, use it rather than relying on a password alone.
- Enable account alerts. Select notifications for new sign-ins, password or contact changes, new payees, transfers, large purchases, and other activity that needs your attention.
- Review credit reports and statements. Follow the FTC's free credit report guidance to reach the authorized free-report service. Check bank, card, mobile, tax, benefits, payment, and medical accounts for activity you didn't initiate.
These measures address different problems. A freeze limits access to a credit report for many new-account decisions; MFA and alerts help protect accounts that already exist; careful verification helps with phishing.
What a credit freeze does and does not do
A security freeze restricts access to your credit report. When a lender uses that report to evaluate a new application, the freeze can make it harder for a thief to open an account in your name. The freeze is free and remains in place until you ask the bureaus to lift it or remove it, subject to permitted exceptions.
A freeze does not:
- Stop unauthorized purchases on an existing card
- Prevent someone from stealing or guessing a password
- Protect a bank, payment, mobile, tax, benefits, or medical account that doesn't use a credit report
- Remove personal information that has already been exposed
- Guarantee that every fraudulent application will be rejected
For broad protection against new-account fraud, freeze all three reports. Credit reports aren't always identical, and a lender may use a bureau whose report you left unfrozen.
How to place or lift a freeze
- Start with the FTC or USAGov instructions. Don't click a freeze link in an unsolicited email, text, search result, or advertisement.
- Complete the official process for Equifax, Experian, and TransUnion.
- Save confirmation emails, account details, and any PIN or login information in a secure place.
- Before applying for a loan, apartment, utility service, or credit card, ask the company which bureau it expects to check.
- Temporarily lift the freeze with that bureau, or remove it if you no longer want the freeze.
According to USAGov's freeze instructions, an online or phone request to place a freeze should be completed within one business day. A mailed request can take up to three business days. An online or phone request to lift a freeze should be completed within one hour. Don't wait until the day of an application if the timing matters.
A credit freeze is different from a commercial credit lock. Read the terms before paying for a lock or monitoring package, and don't assume that either product replaces the free security freeze available from the bureaus.
Fraud alert versus security freeze
A fraud alert puts a warning on your credit reports and asks businesses to take additional steps to verify your identity before extending credit. It doesn't restrict access to your reports in the same way a freeze does.
| Tool | What it helps with | Main limitation |
|---|---|---|
| Security freeze | Restricts access to a credit report for many new-account decisions | You may need to lift it before applying for credit or services |
| Fraud alert | Signals that you may be a fraud victim and encourages identity verification | It doesn't block access to the report |
| Credit monitoring | Notifies you about certain changes or inquiries | Coverage varies, and an alert may arrive after suspicious activity |
You can request a fraud alert from any of the three nationwide credit bureaus. If you seek an extended fraud alert, check the FTC's current documentation requirements. An FTC identity theft report or police report may be required, and renewing the alert can require submitting the report again.
Protect the accounts a freeze can't reach
Use a password manager
Create a different password for every important account. A password manager can generate and store long, random passwords, which removes the need to reuse one across email, banking, shopping, and social media.
Prioritize these accounts:
- Primary email
- Banking and credit-card accounts
- Mobile-carrier account
- Cloud storage
- Tax and government-benefit accounts
- Payment and peer-to-peer transfer apps
Use a long passphrase for the password-manager vault itself. Avoid names, birthdays, addresses, pets, and phrases visible on your social profiles. Store recovery information and backup codes in the manager or in another secure location.
Turn on MFA and review recovery methods
An authenticator app or security key generally provides stronger protection than SMS. Text messages can be exposed if a criminal takes control of your phone number, but SMS is still better than using only a password when no stronger MFA option is available.
After enabling MFA:
- Save backup codes in your password manager or another secure offline location.
- Review the phones, browsers, and apps currently signed in.
- Remove old devices and third-party apps you no longer use.
- Set alerts for password, email, phone-number, and recovery-detail changes.
- Protect your mobile-carrier account with a separate password and any available account PIN.
- Never read a one-time code to an unsolicited caller or message sender.
Check these settings after a password reset or a suspected compromise. An attacker who controls a recovery email, phone number, forwarding rule, or active session may be able to regain access even after you change the password.
Recognize phishing before sharing information
Phishing messages imitate banks, delivery companies, employers, government agencies, retailers, and family members. They may ask you to confirm your identity, unlock an account, pay an invoice, or share a verification code.
Pause when a message:
- Creates urgent pressure or threatens immediate account closure
- Requests a Social Security number, password, payment, or one-time code
- Uses an unexpected link or phone number
- Insists that you keep the request secret
- Asks you to move money, buy gift cards, install remote-access software, or use cryptocurrency
- Comes from a familiar name but an unexpected address or number
Don't use the link or phone number in the message. Open the official app, type the company's known website yourself, or use a number from a statement or the back of your card. Caller ID, logos, and familiar names can be faked. Verify an unusual request through a separate channel.
If you entered a password on a suspicious site, change it from a trusted device and change it anywhere else you reused it. Sign out other sessions, review recovery details and email-forwarding rules, and check for unauthorized transactions. A legitimate support representative should not need your password, a one-time code, or remote control of your device.
Share less personal information
Identity thieves look for details that can help them impersonate you, answer security questions, or exploit an account-recovery process. Before providing sensitive information, ask why it is needed, how it will be used, and whether a less sensitive identifier will work.
Useful habits include:
- Don't post identification documents, boarding passes, or account details publicly.
- Limit personal details visible on social profiles.
- Use different answers for security questions and store those answers securely.
- Shred documents containing account numbers, medical information, or other personal data.
- Collect mail promptly and put outgoing sensitive documents in a secure postal collection box.
- Avoid entering sensitive information on public or shared computers.
- Keep phones, computers, browsers, and apps updated.
- Review app permissions and delete apps you no longer need.
A company may legitimately request information during an account process, but an unexpected message isn't proof that the request is genuine. Initiate contact yourself before sharing anything.
Monitor credit reports, statements, and alerts
A credit report can show unfamiliar accounts, hard inquiries, collection accounts, addresses, and other changes. Request the report from each bureau because their information may differ. The FTC notes that not all creditors report information to the bureaus, although most nationwide chain-store and bank credit-card accounts, along with loans, are included. A clean credit report therefore doesn't rule out identity theft.
Set a regular reminder to:
- Review every report for accounts and inquiries you don't recognize.
- Check bank and credit-card statements, including small transactions.
- Watch mobile, utility, payment-app, and online-shopping accounts.
- Review tax, government-benefit, and medical notices for activity you didn't initiate.
- Confirm that alerts still go to your current email address or phone.
If you see an unfamiliar account or transaction, contact the company through its official website, app, or a statement. Ask for the fraud department, record the case number and instructions, and use the bureau's dispute process if the account or inquiry appears on your report.
Paid monitoring may put some alerts in one dashboard, but it isn't a substitute for a freeze, MFA, or reviewing your accounts yourself. Check the coverage and terms before subscribing.
What to do after a data breach
A breach notice means information may have been exposed; it doesn't by itself prove that someone has used your identity. Verify the notice independently because scammers also send fake breach messages.
- Find the company's notice through its known website or official app.
- Determine what information was exposed and whether the notice offers monitoring or another form of assistance.
- If a password was exposed, change it and change every other account where you reused it.
- Turn on MFA and review active sessions, recovery details, and forwarding rules.
- If the exposed information includes a Social Security number or other data that could be used to open credit, consider freezing all three reports, especially if you don't expect to apply for credit soon.
- Watch statements, account alerts, and credit reports for changes.
- Contact the company through an independently verified channel if you see unauthorized activity.
Don't pay a caller who claims to be recovering your information. Don't provide remote access or a one-time code to someone who contacted you first.
Identity theft recovery: a practical order of operations
Act promptly if you find an account, transaction, bill, tax filing, benefit claim, or other activity that you didn't authorize.
- Secure the affected account. Contact the bank, card issuer, lender, provider, or agency through an official channel. Ask how to lock the account, replace credentials or cards, and dispute the activity.
- Protect related accounts. Change reused passwords, secure your email, remove unknown devices, and enable MFA.
- Freeze your credit reports. Place freezes with all three bureaus if you haven't already.
- Create an official identity theft report. The FTC's identity theft reporting guidance directs consumers to IdentityTheft.gov for a federal reporting and recovery route, including checklists and sample letters.
- Notify the businesses involved. Ask what documents they need, where to send them, and when you'll receive confirmation that the account or debt is being investigated.
- Report related scams. Use the FTC's ReportFraud.ftc.gov route for scams and bad business practices. A police report may also be useful or requested, depending on the situation.
- Keep a case file. Save breach notices, statements, emails, screenshots, letters, dates, names, confirmation numbers, and postage records.
- Follow up. Set calendar reminders for promised responses and continue checking accounts after the first issue appears resolved.
Payment protections and deadlines can differ by payment type. A fraudulent credit-card charge, unauthorized debit or electronic transfer, wire, and peer-to-peer payment may follow different procedures. Tell the institution exactly how the transaction occurred and follow its instructions promptly.
Extra steps for children, households, and small businesses
Parents and guardians can use the FTC's freeze guidance for children. A child may not have a conventional credit file, and a bureau may request proof of the child's identity and the adult's authority to act. Follow each bureau's current instructions, keep copies of documents, and don't mail original identity documents unless the official process specifically requires them.
Families can reduce risk by using separate logins, enabling alerts, and agreeing that no one will share a password or verification code by text or phone. A shared password manager can help adults manage household accounts without writing credentials on paper.
Small businesses should separate personal and business finances, use individual employee logins, require MFA for email and financial systems, and limit access to payroll and payment tools. Verify changes to vendor bank details or payment instructions through a known phone number. A short written response plan should identify who contacts the bank, preserves evidence, informs employees, and reports an incident.
Are paid identity protection services necessary?
You can take the core preventive steps without buying a service: freeze your credit, obtain your reports, use MFA, create unique passwords, and turn on financial alerts.
A paid service may be useful if you value consolidated monitoring, restoration assistance, or an insurance benefit. Compare the actual terms rather than the headline coverage amount:
- Which bureaus, accounts, and data sources are monitored?
- Does the plan cover every adult or child you need to protect?
- What counts as a covered loss or reimbursable expense?
- Are attorney, restoration, and fraud-resolution services limited?
- What are the monthly price, renewal terms, and cancellation steps?
- What personal information will the provider collect?
- Can you place a true security freeze separately?
Insurance is a policy benefit with conditions and exclusions. It isn't a promise that fraud won't happen or that every loss will be repaid.
Frequently asked questions
Should I freeze my credit if I haven't seen suspicious activity?
You can. A freeze is free and can remain until you lift or remove it. The tradeoff is that you'll need to temporarily lift it before some applications or services can review your report.
Do I have to freeze all three credit bureaus?
For broad protection against new-account fraud, yes. A freeze at only one bureau doesn't restrict access to reports held by the other two.
Is text-message MFA unsafe?
SMS is more exposed to phone-number takeover than an authenticator app or security key. If SMS is the only MFA option, use it rather than relying on a password alone, then upgrade when possible.
Will a credit freeze stop someone from using my existing card?
No. A freeze primarily addresses access to a credit report for new applications. Use transaction alerts, strong account credentials, and the issuer's fraud process to protect an existing account.
Where should I get free credit reports?
Start with the FTC's free credit report instructions and use the authorized service it identifies. Be cautious with search ads and sites that ask for payment details for a supposedly free report.
What should I do first after discovering identity theft?
Contact the affected institution through an official channel, secure the account, preserve evidence, change reused passwords, and freeze all three credit reports. Then use the FTC's identity theft reporting guidance to create a recovery plan and keep the case number for follow-up.