Four-step order for responding to identity theft, shown beside household documents and a handwritten record of calls

What to Do First If Your Identity Is Stolen: The Order That Matters

This is recoverable, and there is an official free service built for exactly this. What matters now is doing a few things in the right order instead of everything at once.

Written for readers in the United States.

The first ten minutes

Before you make a single call, sit down and get two things: somewhere to write, and if possible another person in the room. Not for comfort - for accuracy. People working alone under stress cancel the wrong card, miss the charge that mattered, and forget who they spoke to.

Write the date at the top of a page. Everything you do from here goes on it.

Step 1 - Call the companies where you know fraud occurred

Start where money is moving. The FTC’s instruction is direct: “Call the fraud department. Explain that someone stole your identity.” Then “Ask them to close or freeze the accounts.”

While you are in each call, change that account’s login, password and PIN - the FTC folds this into the same step: “Change logins, passwords and PINS for your accounts.”

One priority the official wording does not spell out: do your email first. Email is the reset mechanism for everything else you own. Closing one card while a thief still has your inbox is bailing with the tap running.

Step 2 - Place a fraud alert and get your credit reports

This protects what has not been touched yet.

The alert is one call. “Contact one of the three credit bureaus. That company must tell the other two.” It asks businesses to verify you before opening new credit in your name.

Get your reports at annualcreditreport.com and read them properly. Every account and transaction you do not recognise goes on your page. That list is your evidence.

A freeze is stronger and may be worth adding - you place it at all three yourself. Which fits your situation is covered in Fraud Alert vs Credit Freeze: Which One Should You Use?

Step 3 - Report it at IdentityTheft.gov

Free, and the step that turns a bad day into a managed process.

The FTC calls it “the federal government’s one-stop resource to help people report and recover from identity theft.” Reporting there does two jobs at once. It creates your FTC Identity Theft Report - “an official report to law enforcement” - and it builds “a free personal recovery plan with next steps” that will “print pre-filled letters and forms to send to credit bureaus, businesses, and debt collectors.”

Give it detail. The plan is only as good as what you tell it.

Then find your kind

Here is what almost every guide leaves out. “Identity theft” covers several different problems, and after the three steps above they stop overlapping. The correct next move depends on what is actually happening to you.

A tax return filed in your name. IRS Form 14039 is the mechanism - but only sometimes. The IRS is specific: “Only victims of tax-related identity theft should submit the Form 14039.” And if the IRS has already written asking you to verify your identity - letters 5071C, 4883C or 5747C - then “there is no need to file a Form 14039.” Follow the letter instead. Filing the form anyway is a common wasted step.

Medical treatment or claims on your record. Do not start with the credit bureaus; this does not live there. The FTC’s first action is documentary: “Get your medical records. Contact each doctor, clinic, hospital, pharmacy, laboratory, and health insurance company.” Its print guide puts the insurer first, because the explanation-of-benefits statements are where you will see treatment you never had.

Separately - and this is a right worth knowing rather than an FTC recommendation - HIPAA entitles you to ask a provider for an accounting of disclosures of your health information. HHS states that “Individuals have a right to receive, upon request, an accounting of disclosures of protected health information.” That is HHS’s rule, not FTC advice, and it can show you where your records travelled.

An arrest, citation or charge in your name. This is the case the standard advice actively misdirects, because here a police report is the problem, not the fix. The FTC’s route is to “contact the law enforcement agency that arrested the thief”, file a report about the impersonation, give them your fingerprints, photograph and identifying documents, and ask them to compare your details against the impostor’s. Then, crucially: “Ask the law enforcement agency to give you a ‘clearance letter’ or ‘certificate of release'” - and “Keep the ‘clearance letter’ or ‘certificate of release’ with you at all times.” We should be straight about the sourcing on this one. That procedure appears in an FTC print publication and, as far as we could find, on no live FTC web page. It is the only official consumer procedure for criminal identity theft we could locate, and the terms “clearance letter” and “certificate of release” are the FTC’s own, not invented.

An unemployment claim you did not file. This one is not in the FTC’s recovery plan at all - you would never find it working from FTC material alone. The Department of Labor’s first step is “Report unemployment identity fraud to the state where it occurred,” through that state’s workforce agency; DOL publishes the state-by-state directory. Two further points from DOL: “When you file your income taxes, ONLY include income you actually received” - do not report benefits you never got, and do not wait for a corrected form before filing. And fraud from after March 2020 can also be reported to the Justice Department’s National Center for Disaster Fraud.

Someone working on your Social Security number. Wages you never earned end up on your record. SSA’s instruction is to “Review the earnings posted to your record on your Social Security Statement and report any inconsistencies to us.” The IRS may send a CP01E notice about it, and an Identity Protection PIN is worth getting.

Your child’s information. Different first move again: the FTC asks, “Did someone use your child’s information to commit fraud? Call the company where the fraud occurred.” A child’s file also cannot be checked the ordinary way - you have to request a manual search of their Social Security number.

And one you may have read about: “synthetic” identity theft, where pieces of your information are combined with invented details to build a person who does not exist. It is real, and the Federal Reserve defines synthetic identity fraud as “the use of a combination of personally identifiable information (PII) to fabricate a person or entity.” But that definition is written for banks, not victims, and there is no separate consumer procedure for it - no FTC, CFPB or IdentityTheft.gov guidance prescribes one. If this is your situation, the general route is the route. We would rather tell you that than invent a step.

About the police report

You have probably read that you must file one. Current FTC guidance says otherwise, and chasing an unnecessary police report costs you a day you do not have.

The FTC’s position: your Identity Theft Report from IdentityTheft.gov is “sufficient documentation to resolve issues with the credit bureaus and most companies.”

Two situations where you would still want one, both named by the FTC:

“if you have information about a suspect” - you know or strongly suspect who did this, which is common when it is someone close to you; or “a specific company asks for a police report as part of its dispute resolution process.”

Note the FTC’s register throughout: “you’ll want to.” Never “must.”

There is one more place a police report earns its keep: an extended fraud alert, which lasts seven years and requires either an FTC identity theft report or a police report. Either satisfies it.

If you do need one, our walkthrough is How to File a Police Report for Identity Theft - take your FTC report, photo ID and proof of address, and ask for a copy afterwards.

Keep the record going

Who you contacted, when, what was said, any reference number. Save confirmation emails and your IdentityTheft.gov report somewhere you will find them in six months.

This is the step people skip and later regret. Every dispute from here is easier with a date and a reference number, and much harder without one.

How long this takes

There is no official answer, so we are not going to invent one. Federal guidance describes recovery as a process rather than a duration, and cases genuinely differ - a single fraudulent card is not an arrest record in your name.

What shortens it: acting in order, using the official recovery plan instead of improvising, and keeping the record. Anyone quoting you an average recovery time is not quoting the government.

Paid identity-protection services are worth considering later, for ongoing monitoring. They are not what stops the damage today; the steps above are, and they are free. When things are calm, Is Identity Theft Protection Worth It? covers that decision without pressure.

What people ask in the first week

Do I need to file a police report?

Usually not. The FTC says your Identity Theft Report is “sufficient documentation to resolve issues with the credit bureaus and most companies.” File one if you have information about a suspect, if a company requires it, or if you want a seven-year extended fraud alert.

What is the very first call?

The company where money is actually moving - ask them to close or freeze the account. Then change your email password.

The bank has fixed my card. Am I done?

Not necessarily. Ask what kind of theft this was. A closed card does nothing about a tax return, a medical claim, an unemployment benefit or an arrest record in your name, and each of those has its own first move.

Does everything have to go through IdentityTheft.gov?

Start there - the report and plan make everything else easier. But some types need a second destination: the IRS for tax, your state workforce agency for unemployment benefits, the arresting agency for a criminal record.

Affiliate Disclosure

Every step on this page is free. Nesswick earns nothing from the actions recommended here. Current relationship: Nesswick does not currently use affiliate links in this article. Product and service references are included for editorial purposes.

Sources and Methodology

This is an official-documentation guide. No hands-on testing was performed. The sequence and the wording of each step come from current federal guidance, verified 10 September 2026.

Three things worth stating plainly.

We correct the widely repeated claim that a police report is required. Current FTC guidance says the FTC’s own Identity Theft Report is sufficient for the credit bureaus and most companies, and names the two situations where a police report is still wanted. An older, superseded FTC checklist is still findable online and says otherwise; if you encounter advice about combining an “Identity Theft Affidavit” with a police report, that is the document you are reading, and we have not used it.

On the triage section, each type is attributed to the authority that actually publishes the procedure - the IRS for tax, the FTC for medical and criminal, the Department of Labor for unemployment benefits, SSA for earnings records. Two attributions are commonly got wrong and we have been careful with both: the HIPAA accounting-of-disclosures right is HHS’s, not an FTC recommendation for medical identity theft; and the criminal-identity-theft procedure exists in an FTC print publication rather than on a live FTC web page, which we say in the article. For synthetic identity theft there is no consumer procedure to give, and we say that too.

We give no recovery timeline because no federal source publishes one. IdentityTheft.gov’s own pages could not be machine-read, so every description of what it does is quoted from FTC publications rather than from the site.

General information for US readers, not legal or financial advice, with no guarantee of full recovery. If the stress of this is overwhelming, asking someone you trust to sit with you while you work through it is a reasonable thing to do.

Last reviewed and verified: September 10, 2026.

Sources Referenced