Identity theft prevention comes down to three jobs: make new credit harder to open, keep intruders out of accounts you already use, and look for misuse in records that credit reports may not show. Freeze your credit with Equifax, Experian, and TransUnion; protect your email and financial accounts with unique passwords and multifactor authentication; and check your credit, bank, tax, and medical records.

If fraud has already happened, a freeze is only a containment step. Contact the affected company, report the theft to the FTC, and dispute each fraudulent account through the appropriate process.

This checklist is for U.S. consumers. The response changes depending on whether the problem involves new credit, an existing bank account, taxes, health care, benefits, employment, or a data breach.

Start with these steps

Use the checklist below before moving to the more specific guidance:

Signs that someone may be using your identity

An account in your name that you don't recognize is an obvious warning sign, but identity theft can surface elsewhere:

Credit reports are useful, but they don't show everything. The FTC notes that not all creditors report to the nationwide credit bureaus. A clean report therefore doesn't rule out fraud involving a bank account, tax return, medical record, employment claim, or government benefit account.

Credit freeze or fraud alert?

Both tools are free, but they serve different purposes. The FTC's credit freeze and fraud alert guidance provides the current setup information.

Tool What it does When it helps most Limitation
Credit freeze Restricts prospective creditors from accessing your credit report Preventing many new-credit applications You must place it with each bureau and lift or remove it when a legitimate creditor needs access
Initial fraud alert Tells businesses to take additional steps to verify your identity When you suspect identity theft or want an extra warning It doesn't prevent a lender from approving an application
Extended fraud alert Gives longer-term alert protection to qualifying identity-theft victims After documented identity theft The bureaus may require an FTC identity theft report, police report, or other documentation

A freeze with one bureau doesn't freeze your reports at the other two. Place it separately with Equifax, Experian, and TransUnion. It remains in place until you ask the bureaus to remove it, although you can request a temporary lift when you need to apply for credit.

A fraud alert can be placed with one bureau; that bureau generally sends it to the other two. An initial alert lasts one year and can be renewed. People with evidence of identity theft can ask the FTC and the bureaus whether they qualify for an extended alert and which documents are required.

For preventing new accounts, a freeze is usually the stronger tool. Neither option stops someone from taking over an existing account, using stolen debit or credit-card information, filing a tax return, or misusing medical information.

Protect the accounts and information you already have

Secure email, financial accounts, and devices

Start with email because it can be used to reset other passwords. Use a long, unique password and turn on multifactor authentication. An authenticator app or security key may be preferable to text-message codes when the service offers those options, but any available multifactor protection is safer than a password alone.

A password manager can create and store a different password for each important account. Check the account's recovery email address, phone number, forwarding rules, logged-in devices, and recent sign-in activity. Remove anything you don't recognize.

For a message that claims to be from a bank, retailer, government agency, or delivery company:

  1. Don't click its link or call the number in the message.
  2. Open the company's official app or type its known web address yourself.
  3. Use the number on your statement, card, or official website to contact support.
  4. Never give an unsolicited caller your password, one-time code, or full account number.

Keep your phone, computer, browser, and security software updated. A password entered on a suspicious site should be changed immediately from a trusted device. Change it anywhere else you reused it, too.

Limit exposure of your Social Security number

A business may have a legitimate reason to request your Social Security number. You can still ask why it needs the number, how it will protect it, how long it will retain it, and whether another identifier will work.

Don't carry your Social Security card unless you need it. Avoid sending tax forms, identity documents, or other sensitive records through an unsecured email account. Be cautious with online forms that ask for a full Social Security number, birth date, driver's license number, or a copy of an identity document.

Store identity, tax, insurance, and medical records in a secure place. Cross-cut shred documents you no longer need instead of putting them intact in the trash.

Monitor more than your credit report

Set alerts for account logins, purchases, transfers, password changes, and new payees. Reviewing a statement is still worthwhile even when an alert doesn't arrive.

Check these records as well:

A commercial monitoring service may be convenient, but it doesn't replace a credit freeze, direct account alerts, or checking your statements. A dark-web notification also doesn't prove that a particular account has been misused.

Tax identity theft and the IRS IP PIN

Tax identity theft may become visible through an IRS notice about a return you didn't file, income you don't recognize, or a refund problem. An electronic return can also be rejected because someone already used your identifying information.

An IRS Identity Protection PIN helps prevent another person from filing a federal tax return with your information. The Taxpayer Advocate Service's IP PIN guidance explains the application process and what to expect.

Keep these points in mind:

You don't have to wait for a tax-related identity theft incident to check whether you're eligible to opt in. Review the current IRS instructions before applying.

When an IRS notice arrives, follow the instructions on that notice and use IRS.gov rather than a phone number or link supplied in an unexpected message. Don't send identity documents or file forms to an unverified address.

Medical identity theft

Medical identity theft occurs when someone uses information such as your name, Social Security number, insurance number, or Medicare number to obtain care or submit a claim without your authorization. It can lead to incorrect bills and records and may interfere with future care.

The HHS Office of Inspector General's medical identity theft guidance recommends protecting personal information, checking medical bills and statements, and reporting questionable charges or fraud.

When you find a problem:

  1. Contact the provider's billing or compliance department and the health insurer's fraud department.
  2. Request an itemized bill and copies of the medical records connected with the service.
  3. List each incorrect diagnosis, treatment, prescription, claim, or patient detail in writing.
  4. Ask the provider to correct the record and confirm the correction or disputed entry in writing.
  5. If the provider says the information is accurate, ask how to add your written disagreement to the record. The Identity Theft Resource Center's medical-record guidance describes this process.
  6. For questionable Medicare or other government health-program claims, use the reporting instructions from HHS OIG.

A corrected medical record may not automatically remove a fraudulent insurance claim, bill, or collection account. Ask each organization to address the part it controls.

Breaches involving health apps or connected devices

Some health apps, connected devices, and similar businesses fall under the FTC's Health Breach Notification Rule. The rule's July 2024 amendments clarified that makers of certain health apps and connected products can be covered.

For a covered breach, affected U.S. residents must be notified without unreasonable delay and no later than 60 calendar days after the breach is discovered. The deadline for notifying the FTC can differ when fewer than 500 people are affected, and media notice may apply in some situations.

That notification rule controls a company's notice obligations. It doesn't guarantee that an account will be restored, a fraudulent bill will be canceled, or a medical record will be corrected. Read the breach notice, change any reused passwords, enable multifactor authentication, and consider a credit freeze if financial or Social Security information may be involved.

Children, older adults, veterans, and service members

Children

A child may have no legitimate reason for a credit file. Ask each bureau about its child-credit-freeze process and keep the confirmation documents. The FTC's credit-freeze guidance includes information about freezing a child's credit.

Check school, medical, insurance, and benefit paperwork before providing a child's Social Security number. A collection notice or unfamiliar credit record in a child's name should be treated as a possible identity theft issue. Keep every notice and envelope.

Older adults

Review financial statements and benefit notices with an older family member only with that person's permission. Where available, use delegated access or another formal account tool instead of taking over the person's password.

Callers who claim to represent a bank, government agency, insurer, or family member and demand immediate payment or a verification code deserve particular caution. End the call and use a trusted number to call back.

Veterans and service members

Protect the email and financial accounts connected to benefits, employment, and military services. Don't give a caller your portal password or one-time code, even if the caller says an account update is urgent. Go directly to the relevant official website or use a phone number from an existing statement or official correspondence.

Service members who are deployed can ask the credit bureaus about an active-duty alert. Veterans and other consumers can still use the standard freeze, fraud alert, monitoring, and dispute processes.

How to recover from identity theft

The order below works for many cases, but an account that is actively being drained or an email account that is compromised needs immediate attention.

1. Stop the immediate loss

Contact the bank, card issuer, payment service, lender, phone company, or other affected business through a trusted app, statement, or official website. Ask the organization to secure the account, stop unauthorized activity, replace compromised credentials or cards, and tell you which documents it needs.

For unauthorized debit-card purchases, checking-account withdrawals, electronic transfers, or payment-app transactions, contact the financial institution immediately. The applicable rules and deadlines can differ by payment method. A credit-report dispute won't reverse a bank transfer.

An email account compromise comes first because it can expose password resets for other accounts. Change the email password from a trusted device, remove unknown recovery methods and forwarding rules, sign out other sessions, and then reset connected accounts.

2. File an FTC identity theft report

Report the theft at IdentityTheft.gov. Save the report and recovery plan. They can help organize the response and may provide documentation that a business or credit bureau requests.

You don't need to know every affected account before starting. Add details as you find them.

3. Freeze your credit and review all three reports

Place a freeze separately with Equifax, Experian, and TransUnion. If you use a fraud alert instead, place it with one bureau and check that it appears with the others.

Request reports through the FTC's free credit report information or the federal consumer guidance at USA.gov. Save a copy of each report. Mark every unfamiliar account, inquiry, address, and collection entry, including items that look only slightly different from your information.

4. Contact creditors and dispute fraudulent accounts

Call each creditor's fraud department, then follow up in writing or through its secure dispute process. Ask the creditor to investigate, secure or close the account when appropriate, and document it as fraudulent.

Dispute inaccurate information with both the business that supplied it and the credit bureau displaying it. Send copies of the FTC report, a police report if available, account notices, and identification documents only through the secure channel the organization requests. Keep the originals, copies of everything you submit, confirmation numbers, and dates.

A debt collector's notice about an account created through identity theft shouldn't be ignored. Follow the notice's instructions to dispute the debt, and keep proof of delivery or electronic submission. Paying the debt simply to end a collection call may not correct the underlying credit record.

5. Use a police report when it helps document the case

A police report isn't automatically required for every identity theft complaint. It can help document a stolen wallet or identity document, impersonation, or a creditor's request for additional proof.

Bring your FTC report, identification, account records, and a short timeline. Ask for the report number and keep a copy. If the agency won't take the report, record the date, agency, and explanation for your files.

6. Handle tax and medical fraud separately

For tax fraud, follow the IRS notice instructions and use current IRS identity-theft guidance. Request an IP PIN when appropriate and keep copies of your correspondence.

For medical fraud, contact the provider and insurer, request the relevant records, correct inaccurate information, and report suspicious Medicare claims to HHS OIG. A credit freeze doesn't resolve a medical record or insurance-billing problem.

7. Keep the case moving

A simple log can prevent missed follow-ups. Record the date, organization, representative, phone number, case number, documents sent, and promised next step. Check bank and card accounts more often while the case is open, then review credit reports again after disputes or account closures should have been processed.

Mistakes that can delay recovery

Common questions

Is a credit freeze better than a fraud alert?

A freeze provides stronger protection against many new-credit applications because it restricts access to your credit report. A fraud alert asks businesses to take extra verification steps but doesn't block an application. The FTC's guidance explains how to set up either tool.

Does a credit freeze stop all identity theft?

No. It mainly addresses new credit based on your credit report. It doesn't stop account takeover, unauthorized bank or card transactions, tax-filing fraud, medical identity theft, employment fraud, or phishing.

Do I need a police report?

Not always. An FTC identity theft report is the usual starting point for a recovery plan. A creditor, insurer, or credit bureau may request a police report or other documentation, and a police report can be useful when a document was stolen or an account is disputed.

Can I get an IRS IP PIN if I haven't been a victim?

Eligible taxpayers may be able to opt in even without a confirmed identity theft incident. Check the current IP PIN instructions from the Taxpayer Advocate Service and complete identity verification through the IRS.

What should I do about an incorrect medical record?

Request the relevant records, identify the incorrect information in writing, and ask the provider to correct it. If the provider disagrees, ask how to add your written statement of disagreement. Report suspicious Medicare claims to HHS OIG and ask the insurer to address related billing.

Secure your email, request your credit reports, and place a separate freeze with each bureau today. When an unfamiliar account appears, contact the business and start the recovery log rather than waiting for another warning sign.