How to Respond to Suspected Identity Theft
Identity theft can be unsettling because the warning signs are not always obvious. An unfamiliar transaction, unexpected account notification, strange credit activity, or message from a financial institution may indicate that someone has obtained and used personal information without permission.
The most important response is to act methodically rather than panic.
When identity theft is suspected, the immediate priorities are to secure affected accounts, document suspicious activity, contact the relevant organizations, review financial and digital accounts, and watch for additional misuse. The exact steps depend on what information may have been compromised and which accounts are affected.
Understanding how personal information is exposed and how identity-related attacks work can also make it easier to respond effectively.
What Counts as Suspected Identity Theft?
Identity theft generally involves someone using another person's identifying or account information without authorization for fraudulent or otherwise unauthorized purposes.
Potentially compromised information can include:
- Full names
- Addresses
- Phone numbers
- Email addresses
- Government-issued identification details
- Bank account information
- Payment card information
- Login credentials
- Tax or employment information
- Insurance information
- Account recovery details
Not every suspicious event means identity theft has occurred. A legitimate company may send an unfamiliar notification because of a routine security check, a merchant may use a different billing name, or an account may contain a transaction that someone in the household made.
The goal is to investigate unusual activity without ignoring genuine warning signs.
Common Warning Signs of Identity Theft
Identity theft can reveal itself in several ways.
Possible warning signs include:
- Unrecognized financial transactions
- Unexpected withdrawals
- New accounts that you did not open
- Password-reset messages you did not request
- Notifications about changes to account information
- Unexpected authentication codes
- Bills for unfamiliar services
- Missing mail or financial statements
- Debt collection notices involving unfamiliar accounts
- Unfamiliar login alerts
- Changes to account recovery information
- Notifications about applications you did not submit
One isolated event may have an innocent explanation, but multiple unexplained events deserve closer attention.
First Step: Stay Calm and Verify the Warning
A suspicious message can itself be part of a scam.
For example, someone might receive a text claiming that an account has been compromised and asking the recipient to click a link immediately.
Do not automatically trust the message simply because it claims to be from a bank, government agency, technology company, or other familiar organization.
Instead:
- Do not click suspicious links.
- Do not provide passwords or authentication codes.
- Open the organization's official website or app independently.
- Contact the organization through a trusted channel.
- Check whether the alleged activity actually occurred.
This distinction matters because attackers sometimes use fake identity-theft warnings to obtain even more information.
Secure the Most Important Accounts First
If unauthorized access is suspected, prioritize accounts that could be used to compromise other accounts.
These may include:
- Primary email
- Banking accounts
- Payment services
- Mobile carrier accounts
- Password-management accounts
- Government or tax-related accounts
- Cloud storage
- Social media accounts
The primary email account deserves particular attention because it may be used to reset passwords for other services.
If an attacker controls an email account, they may potentially receive password-reset messages and other sensitive notifications.
Change Compromised Passwords
If a password may have been exposed, change it promptly.
Use a new, unique password rather than simply modifying the old one.
Avoid using the same password across multiple services. If one service experiences a breach and the same password is used elsewhere, attackers may attempt those credentials against other accounts.
Prioritize accounts containing sensitive information or accounts capable of resetting other credentials.
Turn On Multi-Factor Authentication
Multi-factor authentication adds another verification step beyond a password.
Depending on the service, the second factor might involve:
- An authenticator application
- A hardware security key
- A text message
- A biometric method
- Another approved authentication mechanism
Where supported, stronger authentication methods can make unauthorized account access more difficult even when a password has been compromised.
The broader principles of protecting accounts and controlling access are covered in The Complete Guide to Identity and Access Security.
Review Account Recovery Settings
Attackers who gain access to an account may attempt to change recovery information.
Check:
- Recovery email addresses
- Recovery phone numbers
- Trusted devices
- Authentication methods
- Active sessions
- Backup codes
- Authorized applications
Remove unfamiliar recovery methods or sessions where appropriate.
If an account has already been taken over, use the service's official account-recovery process rather than relying on links received through suspicious messages.
Contact the Affected Financial Institution
If financial information may have been compromised, contact the relevant bank, card issuer, payment provider, or financial institution through an official channel.
Explain what happened and identify the suspicious activity.
Depending on the situation, the institution may recommend actions such as:
- Blocking or replacing a payment card
- Changing account credentials
- Reviewing recent transactions
- Placing additional security controls on an account
- Opening a fraud investigation
- Monitoring the account for additional suspicious activity
Keep records of communications, including dates, reference numbers, and the names or departments of organizations contacted.
Review Recent Transactions Carefully
Do not look only for large unauthorized transactions.
Small unfamiliar transactions can also be important because criminals may test whether an account or payment method is active before attempting larger transactions.
Review:
- Bank statements
- Credit card activity
- Payment applications
- Digital wallets
- Online shopping accounts
- Subscription services
Pay attention to transactions you do not recognize and investigate them through the relevant provider.
Check for Unauthorized New Accounts
Identity theft can involve the opening of accounts using someone else's information.
Depending on the country and financial system involved, consumers may have access to credit reports or other financial records that can help identify unfamiliar accounts or inquiries.
Look for:
- Accounts you did not open
- Credit applications you did not submit
- Unfamiliar lenders
- Unexpected inquiries
- Incorrect personal information
If an unfamiliar account appears, contact the relevant institution using verified contact information and report the suspected fraud.
Consider Additional Fraud Protections
Some financial systems provide mechanisms designed to make it more difficult for someone to open new accounts using stolen personal information.
Depending on where you live, these may include:
- Fraud alerts
- Credit freezes or locks
- Identity-monitoring services
- Additional verification requirements
The availability, procedures, and legal effects of these measures vary by jurisdiction.
If you believe your identity information has been compromised, investigate the protections available through the relevant financial and consumer-protection authorities in your country.
Preserve Evidence
Documentation can become extremely valuable when investigating identity theft.
Keep copies or records of:
- Suspicious emails
- Text messages
- Transaction records
- Account notifications
- Unauthorized account information
- Relevant screenshots
- Dates and times of incidents
- Case or reference numbers
- Communications with financial institutions
Do not alter or delete suspicious messages before documenting them if they may be useful as evidence.
However, avoid interacting with suspicious senders simply to collect more information.
Be Careful With Suspicious Messages
Once someone suspects identity theft, they may receive additional messages claiming to offer assistance.
Some criminals deliberately target people who have already experienced fraud.
A fraudulent message might claim:
- Your bank account is under attack.
- Your identity has been stolen.
- Your computer has been compromised.
- Your government account requires verification.
- Your refund is waiting.
- Your identity needs to be confirmed immediately.
The message may then request passwords, payment information, identification documents, or authentication codes.
Verify unexpected requests independently.
Understand How Personal Information Gets Exposed
Identity theft often begins with information that has been exposed somewhere else.
Personal information can be collected through legitimate business processes, online accounts, applications, purchases, websites, mobile applications, and other interactions.
It can also be exposed through data breaches, phishing attacks, insecure accounts, lost devices, or social engineering.
Understanding How Personal Data Is Collected and Used can help explain why seemingly ordinary pieces of information can become valuable when combined.
Check Your Email for Signs of Account Takeover
Email accounts deserve special attention after suspected identity theft.
Look for:
- Password-reset notifications
- Login alerts
- Security-setting changes
- Unfamiliar forwarding rules
- Unexpected sent messages
- New recovery addresses
- Unknown connected applications
An attacker who has accessed an email account may attempt to hide evidence or use the account to compromise other services.
Review the account's security settings carefully and sign out unfamiliar sessions where appropriate.
Secure Your Mobile Phone Account
A mobile phone number can be connected to banking, email, social media, and other accounts.
If an attacker gains control of a mobile account, they may potentially interfere with authentication and account recovery.
Contact your mobile carrier if you suspect unauthorized changes to your account.
Ask about available security measures and review whether any unexpected changes have been made to the account.
Review Connected Applications
Online accounts frequently allow third-party applications and services to connect to them.
After a security incident, review connected applications and remove anything unfamiliar or unnecessary.
Pay particular attention to applications that have access to:
- Contacts
- Cloud files
- Financial information
- Social media accounts
- Personal data
Reducing unnecessary third-party access can limit the number of pathways into an account.
Secure Your Devices
Identity theft can sometimes involve compromised computers or smartphones.
Make sure devices are:
- Updated
- Protected with a screen lock
- Running supported operating systems
- Protected by appropriate security software
- Configured with strong account credentials
If you believe a device itself has been compromised, avoid entering additional sensitive information on it until the situation has been assessed.
The broader principles of maintaining secure digital habits are covered in Staying Safe in the Digital World.
Watch for Follow-Up Fraud
Identity theft may not be a single event.
Once criminals obtain personal information, they may attempt additional scams using details they already know.
For example, an attacker who knows someone's name and bank may create a more convincing impersonation attempt.
This can make follow-up scams especially difficult to recognize.
Remain cautious about unexpected requests for:
- Passwords
- Authentication codes
- Payment
- Identification documents
- Account verification
- Remote computer access
Be Careful With Authentication Codes
One-time authentication codes should be treated as sensitive information.
A legitimate service may send a code when you are signing in or changing account settings.
If you receive a code that you did not request, do not give it to someone who contacts you asking for it.
An unexpected code may indicate that someone is attempting to access an account or initiate an account-recovery process.
Instead, independently access the relevant service and review its security activity.
Consider Whether Multiple Accounts Are Affected
If the same password or personal information was used across multiple services, one compromised account may not be the only concern.
Create a list of potentially affected accounts and prioritize them based on sensitivity.
For example:
High Priority
- Primary email
- Banking
- Payment services
- Mobile carrier
- Government-related accounts
- Password manager
Medium Priority
- Shopping accounts
- Cloud storage
- Social media
- Subscription services
Lower Priority
- Accounts containing little sensitive information
The exact priority depends on the information each service holds and what an attacker could do with access.
Don't Ignore Physical Documents
Identity protection is not limited to online accounts.
Paper documents can also contain sensitive information.
Examples include:
- Financial statements
- Identification documents
- Tax records
- Medical paperwork
- Insurance documents
- Employment records
Store sensitive documents securely and dispose of unnecessary copies using appropriate methods.
Be Cautious About Sharing Identification Documents
Sometimes a legitimate organization may need identity documents, but unsolicited requests deserve careful scrutiny.
Before providing a copy of an identification document, verify:
- Who is requesting it
- Why it is required
- How it will be transmitted
- How it will be stored
- Whether an alternative verification method exists
Avoid sending sensitive documents through an unfamiliar link or to an unverified contact.
Report Fraud Through Appropriate Channels
Depending on the nature of the incident and your location, identity theft may need to be reported to relevant financial institutions, law enforcement, government agencies, credit-reporting organizations, or other authorities.
Reporting requirements and available resources differ between countries.
When reporting, provide factual information and retain any case or reference number you receive.
This documentation may be useful when disputing fraudulent transactions or accounts later.
Monitor Your Accounts After the Initial Response
Securing an account today does not necessarily mean the situation is finished.
Continue watching for:
- New unfamiliar transactions
- New account notifications
- Password-reset attempts
- Unexpected authentication messages
- Changes to account information
- New communications from financial institutions
- Unfamiliar credit activity
Monitoring is particularly important when sensitive information may have been exposed rather than merely one isolated password.
Avoid Trying to Investigate the Attacker Yourself
It can be tempting to respond to suspected fraud by attempting to identify or confront whoever may be responsible.
That can create additional risks.
Do not:
- Threaten suspected criminals
- Attempt unauthorized access to their accounts
- Download suspicious files to investigate them
- Follow links sent by suspected attackers
- Share additional personal information
- Engage in retaliatory activity
Focus on securing your own accounts, preserving evidence, and reporting the incident through appropriate channels.
Create an Identity Theft Response Checklist
Having a simple checklist can make a stressful situation easier to manage.
Immediate Actions
- Verify the suspicious activity independently.
- Secure affected accounts.
- Change compromised passwords.
- Enable multi-factor authentication.
- Contact affected financial institutions.
- Review recent transactions.
- Preserve relevant evidence.
Follow-Up Actions
- Review credit or financial records where available.
- Check account recovery settings.
- Remove unfamiliar connected applications.
- Secure your mobile account.
- Review other potentially affected accounts.
- Monitor for additional suspicious activity.
- Report fraud through appropriate channels.
Prevention
- Use unique passwords.
- Enable strong authentication.
- Keep devices updated.
- Limit unnecessary data sharing.
- Be cautious with unexpected messages.
- Review account activity regularly.
- Dispose of sensitive documents securely.
Building a Stronger Identity Protection Routine
Responding to suspected identity theft is easier when good security habits already exist.
Regularly reviewing account activity, using unique passwords, enabling multi-factor authentication, limiting unnecessary access, and keeping devices updated can reduce opportunities for unauthorized access.
The broader principles covered in the Identity Theft Protection Guide can also help put these individual practices into a more comprehensive identity-protection framework.
Most importantly, suspicious activity should be treated as a reason to investigate rather than an automatic confirmation that identity theft has occurred. Verify the warning, secure the relevant accounts, document what happened, and continue monitoring for additional signs of misuse.
A measured response can help contain the problem while providing a clearer record of what happened and which accounts or information may have been affected.