The First 60 Minutes After You Think Your Identity Has Been Stolen — Digital Moat
Digital Moat · If This Is Happening Right Now

The First 60 Minutes After You Think Your Identity Has Been Stolen

You just saw something that stopped you cold. A credit alert for a card you never opened. A charge you don't recognize. A letter about an account that isn't yours. A call from "your bank's fraud department."

Here's the first thing to know: the order of your next few actions matters more than their speed. Most people do roughly the right things in the wrong sequence — and that mistake costs days of cleanup later. This is the correct order, with the reasoning attached, so you can move fast without guessing.

First: Confirm It's Real

⏱ 5 minutes

This step exists because one of the most common identity-theft scams is a fake identity-theft alert. Fraudsters call, text, and email pretending to be your bank's fraud team, the IRS, or a government agency — manufacturing the emergency so you'll "verify" your information or move money to a "safe account."

So before anything else
  • If the alert arrived by phone call or text: hang up. Call the institution back using the number on the back of your card or on a statement — never a number the caller gave you, and never a link in the text.
  • If the alert came from an app or website you logged into yourself: that's trustworthy. Proceed.
  • Two rules that settle most cases instantly: no legitimate institution will ever ask you to move money to "protect" it, and none takes payment in gift cards. Either request means scam, full stop.

If the alert checks out — or you've found concrete evidence yourself — keep going. The next five actions are the hour.

1
Contain the Known Damage
⏱ 10 min

Start where the fire is. Call the company where the fraud actually occurred — the bank with the bogus charge, the card issuer with the unfamiliar account, the retailer with the hijacked profile.

  • Ask for the fraud department specifically, not general support
  • Tell them the account or transaction is fraudulent and ask them to freeze or close it
  • Ask them to note the date and time of your report, and write down who you spoke to and any reference number

If money is actively moving — a wire, a transfer, a drained account — say so immediately and ask about recalling it. Banks can sometimes claw back transfers if notified within hours.

2
Freeze Your Credit at All Three Bureaus
⏱ 15 min

Whatever the thief did first, the next move in their playbook is opening more credit in your name. A credit freeze closes that door at all three bureaus:

  • Equifax — equifax.com or 1-800-349-9960
  • Experian — experian.com or 1-888-397-3742
  • TransUnion — transunion.com or 1-800-916-8800

Freezes are free under federal law, take effect quickly, and don't touch your credit score or existing accounts. Do all three — fraudsters don't limit themselves to the bureau you froze. If you genuinely can't complete three freezes right now, place a fraud alert with any one bureau as a stopgap, then upgrade to full freezes tonight.

3
Lock the Master Key
⏱ 10 min

Your primary email account can reset the password on nearly everything else you own. If a thief has your identity details, assume your email is a target.

  • Change your primary email password to something long and unique
  • Check the recovery settings — recovery email, recovery phone, and forwarding rules. Attackers add silent forwarding so they keep reading your mail after you change the password.
  • Turn on two-factor authentication if it isn't already on
  • Then change the password on the account connected to the fraud, and anything sharing that same password elsewhere

If you find evidence someone was actually in your email, broaden this step to your other critical accounts: banking, cloud storage, phone carrier.

4
File the Official Report
⏱ 15 min

Go to IdentityTheft.gov — the FTC's identity theft site — and report what happened. It generates a personal recovery plan, produces an FTC Identity Theft Report (the document banks and bureaus will ask for during disputes), and creates the official timestamp showing when you discovered and reported the theft.

Add a police report on top if: you know who did it, the thief used your name in an encounter with law enforcement, or a creditor specifically requires one. Otherwise the FTC report carries most disputes.

5
Document Everything, Then Stop
⏱ 5 min

Open a note, an email draft to yourself, or a folder, and capture while it's fresh:

  • What you found, and exactly when
  • Every call: institution, person's name, time, reference number
  • Screenshots of fraudulent charges, accounts, or messages
  • Confirmation numbers from the freezes and the FTC report

Then — genuinely — stop. The first hour's job is containment, and it's done. What remains is a days-and-weeks process that doesn't benefit from panic tonight.

What Not to Do in the First Hour
  • Don't pay anyone who contacts you offering to fix it. Legitimate recovery help doesn't cold-call victims.
  • Don't make decisions inside the emotional spike. That includes panic-buying a protection subscription mid-incident.
  • Don't delete anything. Fraudulent emails, fake texts, scam voicemails — they feel toxic, but they're evidence. Screenshot, then archive.
  • Don't post about it publicly yet. Announcing it tells opportunists exactly who's vulnerable to a fake "bank follow-up" call this week.

Where Monitoring Services Fit (and Where They Don't)

Nothing in the first hour required a paid product — worth noticing, because the first hour is when these products are marketed hardest.

Where they genuinely help is the after: monitoring services watch for new accounts, dark-web exposure, and misuse across more places than you can reasonably check by hand. After a real fraud event, that visibility and support has legitimate value.

But they sit on top of the structural work you just did — the freezes, the locked-down email, the documentation. They don't replace any of it.

After the First Hour

Tomorrow, work the FTC recovery plan from Action 4. This week, finish the rest of the foundation — recovery settings on your other accounts, a PIN on your mobile carrier account, two-factor authentication everywhere that matters.

You handled the hard hour. The rest is just follow-through.

Once things are stabilized, here's how to catch this earlier next time.

See Identity Protection Options →