The First 72 Hours After Identity Theft: A No-Panic Playbook That Actually Works

A rusty padlock securing a chain-link fence, symbolizing identity protection and credit freezes.

Most identity theft guides start with “don’t panic” and then dump a generic checklist that reads like a Wikipedia outline. They assume you have hours to think. You don’t. When your data is already in someone else’s hands, the first three days decide whether you spend six months untangling fraud or six years. This playbook is the order of operations that actually matters, based on what fraud investigators, FTC caseworkers, and the people who clean up after data breaches recommend.

Hour 0–6: Stop the Bleeding

The moment you suspect fraud, you have a narrow window. Treat it like a kitchen fire, not a slow leak.

  • Call your bank and credit card issuers. Use the number on the back of the card, not a Google result. Tell them you suspect fraud and ask for “a fraud alert and account restriction on new transactions.” For the cards most likely hit, request an immediate freeze and replacement with new numbers. Don’t wait until you have a complete list of every compromised account.
  • Place a free fraud alert with one of the three credit bureaus. You only need to call one (Equifax, Experian, or TransUnion). They’re required to notify the other two. A fraud alert lasts one year and is free. An extended fraud victim alert lasts seven years and requires an FTC Identity Theft Report.
  • Change passwords for email and banking first. Email is the master key. If your email is compromised, every password reset in your life becomes theirs. Use a password manager and a fresh 14+ character passphrase you have never used anywhere else.

Hour 6–24: File the Paperwork That Gives You Legal Power

Most people skip this step because it feels bureaucratic. It’s the step that makes every later dispute easier.

  • File a report with the FTC at IdentityTheft.gov. You’ll get an Identity Theft Report with an affidavit number. This is the document debt collectors, banks, and credit bureaus are legally required to honor when you dispute fraudulent accounts. Without it, you’re just complaining. With it, they have to act.
  • File a police report if any account was opened or any physical good was obtained. Local police departments will sometimes refuse, but the FTC report often satisfies most institutions. If a bank demands a police report for a specific account, ask for a supervisor or get the report anyway — many jurisdictions let you file online.
  • Document everything. Screenshot every suspicious transaction, every account you didn’t open, every communication. Save them in one folder. This folder is your evidence locker; you’ll reference it for months.

Day 2: Freeze, Lock, and Disconnect

Now that you have a paper trail, lock down the rest of your attack surface.

  • Freeze your credit at all three bureaus. A freeze is stronger than a fraud alert: nobody (including you) can open new credit without lifting it. Free, reversible, and instant at all three now. This is the single most effective move in identity theft prevention, and most Americans still don’t have it set up.
  • Pull your free credit reports at AnnualCreditReport.com. Mark every line item that isn’t yours. You’re looking for accounts you didn’t open, addresses that aren’t yours, and inquiries from companies you never contacted.
  • Check your ChexSystems report. Banks use this to approve new checking accounts. If a thief opened a fake account in your name, it’ll show up here.
  • Review your health insurance EOBs. Medical identity theft is the silent one. If someone used your insurance to get care, you’ll see provider names you don’t recognize.

Day 3: Close the Open Doors

Most people stop after the freeze and then wonder why phantom accounts keep appearing. The reason: the thief has other vectors you haven’t closed.

  • Remove your phone number from people-search sites. Spokeo, Whitepages, BeenVerified, and the long tail of data brokers feed SIM-swap attempts. Opt out from the top ones. It’s tedious; do it once.
  • Set up a PIN with your wireless carrier. Without one, a convincing phone call can port your number to a new SIM and reset every text-based 2FA you have. Call your carrier, ask for a “port protection PIN,” and store it in your password manager.
  • Forward your mail if you suspect address tampering. USPS will hold your mail and re-route it. The USPS Change of Address system is itself a common fraud vector; if you didn’t initiate one, dispute it immediately.
  • Opt out of pre-screened credit offers. These are the “pre-approved” cards in your mailbox. Opting out at OptOutPrescreen.com stops thieves from filling them out in your name.

What Comes Next (The Long Tail)

Identity theft isn’t a sprint. Most cases take 30 to 180 days to fully resolve. Tax-related identity theft, where someone files a return in your name to steal your refund, can stretch into the next filing season. Keep a written log of every call: date, time, who you spoke with, what they said they’d do, and the reference number. The companies that owe you money will sometimes “lose” your case; the log lets you restart from a stronger position and is often the difference between a successful dispute and a drawn-out fight.

Dispute every fraudulent item in writing. Send dispute letters via certified mail with return receipt. The bureaus and lenders have 30 days to investigate; if they don’t respond in time, the item legally has to come off. Use the FTC’s sample letters as templates, and keep copies of everything you send. Phone disputes often “clear” without a real investigation; certified-mail disputes don’t.

Don’t pay any debt you didn’t incur, even when collection agencies pressure you. Send the debt collector the FTC affidavit and a written dispute. They are legally required to cease collection until they verify the debt isn’t yours. Many victims pay out of exhaustion and regret it for years, because paying can be construed as accepting the debt as legitimate.

The Honest Truth

If you only do three things, do these: file the FTC report, freeze your credit at all three bureaus, and put a port-protection PIN on your phone number. Everything else is damage control. None of this fully prevents identity theft in a world where your data has already leaked from Equifax, T-Mobile, or the next breach you didn’t hear about. But it puts you in the small minority of people who can recover in weeks instead of years, and that matters a lot when the bills start arriving.

Featured image: Diego3336 via Flickr (CC BY 2.0).

Leave a Reply

Your email address will not be published. Required fields are marked *