What to Do If Your Identity Is Stolen: The First 48 Hours

hacker

Last updated: July 2026. The government contacts and consumer rights below reflect current U.S. federal law and official FTC guidance — but always confirm details at the official sites linked, since procedures can change.

If it’s happening right now, do these five things in order

If you’ve just discovered fraudulent charges, an account you didn’t open, or a data-breach notice with your Social Security number involved, here is the response sequence — everything else in this article can wait:

  1. Call the companies where fraud occurred. Contact the fraud department of each bank, card issuer, or lender involved. Ask them to close or freeze the affected accounts and change your logins. Federal law sharply limits your liability for unauthorized charges when reported promptly — speed matters.
  2. Report to the FTC at IdentityTheft.gov (or 1-877-438-4338). This does two things: it generates an official FTC Identity Theft Report, which is your legal proof of the crime, and it builds you a personalized recovery plan with pre-filled dispute letters. This report is the key that unlocks most of the remedies below.
  3. Place a fraud alert with one credit bureau. Contact any one of Equifax, Experian, or TransUnion — by law, the one you contact must notify the other two. A standard fraud alert is free, lasts one year, is renewable, and requires businesses to verify your identity before opening new credit. With an FTC Identity Theft Report, you can get an extended alert lasting seven years.
  4. Freeze your credit at all three bureaus. A security freeze blocks new-account fraud almost entirely by preventing lenders from pulling your file. Under federal law, freezes are free to place, lift, and remove at all three bureaus, and freezing does not affect your credit score. You must contact each bureau individually for freezes (unlike alerts). This is the single most effective step on this page.
  5. Pull your credit reports and dispute everything fraudulent. Get your reports from AnnualCreditReport.com — the only federally authorized free source. Dispute fraudulent accounts with both the credit bureau and the business involved; with your FTC report attached, bureaus are required to block information resulting from identity theft.

Situational additions: file a local police report if you know the thief, the theft involved in-person crime, or a creditor demands one. For tax identity theft (a return filed in your name), respond via IRS guidance and file Form 14039. For a stolen Social Security number, also consider the IRS Identity Protection PIN — a free six-digit code, available to all taxpayers, that prevents anyone else from filing a return with your SSN.

How identity theft actually happens

Knowing the entry points tells you what’s worth defending:

  • Data breaches — the dominant source. Your information leaks from companies you trusted, through no action of your own, then gets sold and reused. This is why freezes beat vigilance: you can’t prevent someone else’s breach.
  • Phishing and smishing — fake emails and texts impersonating banks, delivery services, or the government to harvest logins. Modern versions are polished; the tell is the ask (credentials, codes, urgency), not the grammar.
  • Social engineering calls — “your account is compromised, read me the code we just texted you.” No legitimate institution asks for one-time codes. Ever.
  • SIM swapping — attackers hijack your phone number to intercept SMS codes, then reset your accounts. This is why app-based two-factor authentication beats text-message codes.
  • Card skimmers, mail theft, and dumpster diving — the analog classics still work, particularly against tax documents and pre-approved credit offers.

The warning signs people miss

Unfamiliar charges are obvious. The subtler flags: bills or statements that stop arriving (address changed by a thief), collection calls for debts you don’t recognize, denial of credit despite good history, a tax refund that never comes or an IRS notice about income from an employer you’ve never heard of, medical bills for care you didn’t receive, and two-factor codes arriving that you didn’t request — that last one means someone has your password right now.

Prevention: the short list that actually works

  • Keep your credit frozen by default. Since freezes are free and can be lifted online in minutes when you genuinely need new credit, the modern best practice is: frozen always, thawed briefly, refrozen. Consider freezing your children’s credit too — child identity theft often runs undetected for years precisely because no one checks a child’s file.
  • Unique passwords via a password manager, and app-based 2FA (or hardware keys) on email and financial accounts first — your email account is the master key to everything else.
  • Check your credit reports regularly — free at AnnualCreditReport.com — and actually read your card and bank statements.
  • Get an IRS IP PIN if your SSN has ever been exposed in a breach (statistically, it probably has).
  • Treat every unsolicited contact as hostile until proven otherwise: hang up and call back on the number printed on your card or the official website. The IRS initiates contact by mail, not by phone demanding gift cards.
  • Shred documents with financial data and opt out of prescreened credit offers at the official site, OptOutPrescreen.com.

Do you need a paid identity-protection service?

Honest answer: the highest-impact protections — credit freezes, fraud alerts, free annual reports, the IRS IP PIN, strong 2FA — cost nothing. Paid monitoring services primarily offer convenience (aggregated alerts, dark-web notifications) and insurance/restoration help after the fact; they cannot prevent a breach or a fraudulent account the way a freeze does. If you do shop for one, compare on: whether it monitors all three bureaus, what the identity-restoration service actually does versus what you could do yourself with IdentityTheft.gov, the real terms of any insurance, and the renewal price rather than the teaser price. A paid service is a reasonable convenience for people who won’t do the free steps — but do the free steps first.

The bottom line

You cannot prevent your data from leaking — that decision belongs to every company that has ever stored it. What you control is whether leaked data is usable: a frozen credit file, app-based 2FA, an IP PIN, and prompt statement review turn a catastrophic identity theft into a nuisance. And if you’re in the middle of one right now: companies first, IdentityTheft.gov second, fraud alert third, freeze fourth, disputes fifth. It’s recoverable. Millions of people have walked this exact path back.

This article is for general informational purposes and reflects U.S. federal consumer protections. For your specific situation, rely on the official resources linked above.

Related articles

Hi, I am KEN!

Welcome to my blog! My mission is to take you on a journey of financial independence.

Passive Income Ideas