You are here: I think my identity was stolenIdentity Theft: What to Do in the First 24 Hours
I think my identity was stolen

Identity Theft: What to Do in the First 24 Hours

If fraud is active, stop the account damage first, then create the records and credit controls that make the next days easier.

Identity Theft: What to Do in the First 24 Hours — editorial illustration
By Simone Baptiste · Consumer Identity & Security Writer · Published 2026-09-02 · Updated 2026-09-07
This guide summarizes official consumer and security sources. It is not individualized legal advice, and state-specific breach, court, medical, or regulatory duties can require professional review.

If you discovered identity theft today, the first goal is not to complete every possible form. It is to stop the part that can still move. Call the fraud department of the bank, card issuer, lender, merchant, telecom provider, or other company where you know misuse occurred. Ask what they can freeze, restrict, close, replace, or reverse right now, and write down the case number. Then protect new-account access with a fraud alert or credit freeze, create an IdentityTheft.gov report, and secure the email account that can reset your other logins. That order keeps the first day focused on containment instead of paperwork for its own sake.

The first hour is about accounts that can still lose money

A credit bureau cannot stop a thief who already controls an existing debit card, bank login, or shopping account. Go directly to the company that is seeing the unauthorized activity and use its fraud channel rather than ordinary customer service when one exists. Identify the transactions or account you did not authorize, ask whether a temporary restriction is safer than immediately closing the account, and ask how recurring payments or direct deposits will be handled if numbers change. Do not rely on a promise that “the account is flagged.” Save the secure message, email, letter, or case reference showing what the institution actually did.

If the compromised account is your primary email, treat it as urgent even when no money has moved yet. Email is commonly the recovery path for banks, shopping accounts, cloud storage, tax portals, and social media. Change a reused password from a device you trust, sign out unknown sessions, remove unfamiliar forwarding rules and recovery addresses, and turn on a phishing-resistant factor where the service supports it. A recovered bank account can be taken again if the attacker still owns the mailbox used to reset it.

Fraud alert and freeze solve different first-day problems

An initial fraud alert is fast because you contact one of the three nationwide credit bureaus and that bureau must notify the other two. FTC guidance says the initial alert lasts one year. A security freeze is stronger for preventing access to your credit file for many new-credit decisions, but you place it separately with Equifax, Experian, and TransUnion. A freeze is free and remains until you lift or remove it. Neither tool erases an account that already exists, so use them as barriers to additional new-account fraud while you separately correct fraudulent tradelines or charges.

Do not confuse a bureau “lock” product with the federal security-freeze right. Locks are product features governed by the bureau’s terms; freezes are the statutory control described by the FTC and CFPB. During an active incident, write down which control you placed at each bureau and the date. That small record prevents the common situation in which a person remembers “locking credit somewhere” but cannot tell which files are actually frozen.

Create the FTC record after you can state the facts cleanly

IdentityTheft.gov can create an FTC Identity Theft Report and a recovery plan. Enter facts you know: which account was opened or used, what information was misused, and what dates or amounts are supported by records. Avoid turning guesses into facts just to make the report feel complete. The report can later support consumer-report blocking and requests for records connected to fraudulent transactions or applications, so consistency matters. Save a local PDF or copy, the report number, and the date you filed it. If you later learn something new, document the new fact rather than silently changing your chronology.

NowContact the organization where fraud is actively occurring; restrict or close the affected account and preserve the case reference.
Next 30–60 minutesSecure the primary email account and any reused credentials; remove unknown recovery methods and sessions before changing lower-priority logins.
Same dayPlace a fraud alert or freezes based on the risk of new-account fraud; remember that freezes must be placed with all three nationwide bureaus separately.
After the facts are organizedFile at IdentityTheft.gov and save the Identity Theft Report and recovery plan for disputes, record requests, and follow-up.
Before bedReview the most relevant credit report, bank activity, carrier account, and mail changes; calendar the next check instead of repeatedly refreshing everything.

Pull reports to find scope, not to create panic

Use AnnualCreditReport.com, the federally authorized site, to review the three nationwide credit files. Look for accounts, hard inquiries, addresses, employers, or personal details you do not recognize, but do not label every stale address as fraud. Record suspicious items by bureau, creditor, partial account number, and date first seen. If the incident involves bank-account opening, utilities, telecom service, or employment screening, specialty consumer reports may matter later; they do not all need to be ordered in the first hour unless the evidence points there.

The useful distinction is between evidence and possibility. A fraudulent card application is evidence. A data breach notice saying your SSN was exposed is a reason to protect yourself, but it is not proof that every account has been compromised. Expand the response when a report, notice, transaction, or login history gives you a reason. That keeps the first day finite and makes later disputes easier to explain.

Police reports are situational, not a universal first step

IdentityTheft.gov is the federal starting point for most consumer recovery. A local police report can still be valuable when a creditor or government agency requests one, when physical documents or mail were stolen, when criminal records are involved, or when local law requires an additional report for a specific remedy. Bring the FTC report, identification, and copies of the evidence rather than asking an officer to reconstruct the incident from memory. Ask how to obtain a copy or report number, because a reference you cannot retrieve is much less useful during a later dispute.

If the incident has already branched into several account types, use {{BACKLINK_1}} for account-specific recovery paths instead of forcing every bank, card, email, or breach problem into one generic checklist.

End day one with a controlled queue

You do not need to “finish identity theft” in 24 hours. A good end state is narrower: active fraud is contained where possible; your primary recovery accounts are secured; new-credit access has the controls you chose; the FTC report exists; the suspicious items are listed; and each unresolved issue has an owner and next date. Keep a simple log with organization, channel, case number, action promised, and deadline. That converts an emotional emergency into a sequence of verifiable tasks while leaving room for tax, medical, child, criminal, or other specialized identity-theft paths if evidence points there.

Questions specific to Identity Theft: What to Do in the First 24 Hours

Should I freeze my credit before calling my bank?

If money is moving or an existing account is being used, call that institution first because a credit freeze does not stop transactions on an already-open account. A freeze is still worth placing promptly to reduce new-credit exposure, but it addresses a different risk.

Do I need all three credit reports on the first day?

You should review the reports that can reveal the scope of new-account fraud, and AnnualCreditReport.com is the authorized route. If the situation is still unfolding, containment can come first; you can document the remaining report review as a next task rather than delaying an urgent bank or email recovery.

Is an FTC Identity Theft Report the same as a police report?

No. The FTC report is created through IdentityTheft.gov. A police report is a separate local law-enforcement record. Some processes may use one or both, so follow the instructions of the creditor, agency, or state remedy you are using.

When can I stop checking everything constantly?

Once active misuse is contained and you have freezes or alerts, a documented recovery plan, and scheduled follow-up, move from constant checking to a calendar. Continue monitoring the accounts and records implicated by the incident rather than repeatedly checking unrelated systems.

References used for this guide