You just saw something that stopped you cold. A credit alert for a card you never opened. A charge you don't recognize. A letter about an account that isn't yours. A call from "your bank's fraud department."
Here's the first thing to know: the order of your next few actions matters more than their speed. Most people do roughly the right things in the wrong sequence — and that mistake costs days of cleanup later. This is the correct order, with the reasoning attached, so you can move fast without guessing.
This step exists because one of the most common identity-theft scams is a fake identity-theft alert. Fraudsters call, text, and email pretending to be your bank's fraud team, the IRS, or a government agency — manufacturing the emergency so you'll "verify" your information or move money to a "safe account."
If the alert checks out — or you've found concrete evidence yourself — keep going. The next five actions are the hour.
Start where the fire is. Call the company where the fraud actually occurred — the bank with the bogus charge, the card issuer with the unfamiliar account, the retailer with the hijacked profile.
If money is actively moving — a wire, a transfer, a drained account — say so immediately and ask about recalling it. Banks can sometimes claw back transfers if notified within hours.
Whatever the thief did first, the next move in their playbook is opening more credit in your name. A credit freeze closes that door at all three bureaus:
Freezes are free under federal law, take effect quickly, and don't touch your credit score or existing accounts. Do all three — fraudsters don't limit themselves to the bureau you froze. If you genuinely can't complete three freezes right now, place a fraud alert with any one bureau as a stopgap, then upgrade to full freezes tonight.
Your primary email account can reset the password on nearly everything else you own. If a thief has your identity details, assume your email is a target.
If you find evidence someone was actually in your email, broaden this step to your other critical accounts: banking, cloud storage, phone carrier.
Go to IdentityTheft.gov — the FTC's identity theft site — and report what happened. It generates a personal recovery plan, produces an FTC Identity Theft Report (the document banks and bureaus will ask for during disputes), and creates the official timestamp showing when you discovered and reported the theft.
Add a police report on top if: you know who did it, the thief used your name in an encounter with law enforcement, or a creditor specifically requires one. Otherwise the FTC report carries most disputes.
Open a note, an email draft to yourself, or a folder, and capture while it's fresh:
Then — genuinely — stop. The first hour's job is containment, and it's done. What remains is a days-and-weeks process that doesn't benefit from panic tonight.
Nothing in the first hour required a paid product — worth noticing, because the first hour is when these products are marketed hardest.
Where they genuinely help is the after: monitoring services watch for new accounts, dark-web exposure, and misuse across more places than you can reasonably check by hand. After a real fraud event, that visibility and support has legitimate value.
But they sit on top of the structural work you just did — the freezes, the locked-down email, the documentation. They don't replace any of it.
Tomorrow, work the FTC recovery plan from Action 4. This week, finish the rest of the foundation — recovery settings on your other accounts, a PIN on your mobile carrier account, two-factor authentication everywhere that matters.
You handled the hard hour. The rest is just follow-through.
Once things are stabilized, here's how to catch this earlier next time.
See Identity Protection Options →