Home / Learn / Privacy / Identity Theft Prevention
Identity Theft Prevention: The Complete Guide to Protecting Your Identity and Recovering From Fraud
A complete guide to identity-theft prevention, credit freezes, fraud alerts, warning signs, account protection, recovery steps, and appropriate privacy tools.
To reduce identity-theft risk:
- Use a unique password for every important account.
- Turn on multi-factor authentication.
- Protect your primary email and phone recovery channels.
- Freeze your credit when appropriate.
- Review credit reports and financial statements.
- Verify unexpected requests independently.
- Limit public sharing of birth dates, addresses, family details, travel plans, and identification documents.
- Keep devices, apps, browsers, and routers updated.
- Secure physical documents, mail, wallets, and discarded records.
- Use temporary contact information only for low-risk situations that do not require future recovery.
- Respond immediately to unknown accounts, charges, tax notices, medical bills, benefit claims, or account changes.
- In the United States, report identity theft at IdentityTheft.gov to receive an FTC Identity Theft Report and personalized recovery plan.
In this guide
- Key Takeaways
- What Is Identity Theft?
- Identity Theft, Fraud, and Account Takeover
- How Identity Thieves Get Personal Information
- The Main Types of Identity Theft
- Financial Identity Theft
- Tax Identity Theft
- Medical Identity Theft
- Employment Identity Theft
- Government-Benefit Identity Theft
- Child Identity Theft
- Criminal Identity Theft
- Synthetic Identity Fraud
- Account Identity Theft
- Identity Cloning and Impersonation
- Protect Your Social Security Number and Government Identifiers
- Freeze Your Credit When Appropriate
- Understand Fraud Alerts
- Credit Freeze vs Fraud Alert
- Review Credit Reports
- Monitor Financial Accounts
- Protect Your Primary Email Account
- Protect Your Phone Number
- Use Unique Passwords and a Password Manager
- Turn On Multi-Factor Authentication
- Protect Recovery Methods
- Secure Devices
- Keep Software Updated
- Recognize Phishing
- Protect Yourself From Impersonation Scams
- Limit Social Media Exposure
- Protect Physical Mail and Documents
- Protect Documents and Images Online
- Use Temporary Sharing Tools Carefully
- Use Fictional Test Data Responsibly
- Understand Your Public IP Address
- Protect Yourself When Shopping Online
- Protect Medical Information
- Protect Tax Information
- Protect Children From Identity Theft
- Protect Older Adults
- Protect Identity at Work
- Respond to a Lost Wallet
- Respond to a Lost Phone or Computer
- Respond to a Data Breach
- Warning Signs of Identity Theft
- What To Do Immediately if Identity Theft Happens
- Your Rights After Identity Theft
- Correct Fraudulent Credit Information
- Close Fraudulent Accounts and Remove Charges
- Special Forms of Identity Theft
- Identity-Theft Prevention by Risk Level
- FreeTempTools Identity-Protection Toolkit
- Create an Identity Protection Plan Before a Crisis
- Protect Against SIM Swapping and Phone Account Takeover
- Protect Against Check Fraud and Mail-Based Identity Theft
- Protect Against New Utility, Telecom, and Rental Accounts
- Protect Against Unemployment and Benefits Identity Theft
- Protect Against Medical Identity Theft in Greater Detail
- Protect Against Tax Identity Theft in Greater Detail
- Protect Against Business Identity Theft
- Protect Deceased Family Members' Identities
- Identity Theft Prevention for People With Public Profiles
- Identity Theft Prevention for Survivors of Stalking or Abuse
- Decide Which Identity Protection Service You Need
- Build a Household Identity-Theft Response Plan
- Identity-Theft Scenario Guide
- Identity Theft Prevention Checklist
- Common Identity-Theft Prevention Mistakes
- Final Recommendations
- Continue Learning
- Frequently asked questions
- Authoritative references
Identity theft happens when someone uses personal or financial information without permission. The stolen information may be used to open accounts, make purchases, access existing services, file taxes, claim benefits, obtain medical care, apply for employment, impersonate the victim, or commit other fraud.
Preventing identity theft is not about keeping every detail secret or avoiding the internet. It is about reducing unnecessary exposure, protecting high-value accounts, recognizing warning signs, monitoring important records, and responding quickly when information is lost, stolen, breached, or misused.
No single tool can prevent every form of identity theft. A credit freeze can make new-account fraud more difficult, but it does not stop misuse of an existing credit card. Multi-factor authentication can help protect an online account, but it does not prevent someone from using a stolen Social Security number to file a fraudulent tax return. Temporary email can reduce exposure of a permanent inbox, but it is inappropriate for accounts that require reliable recovery.
This FreeTempTools Learning Center guide explains how identity theft occurs, how to lower your risk, which warning signs deserve attention, how credit freezes and fraud alerts differ, and what to do if someone uses your identity. It also explains how privacy tools can support appropriate short-term activities without creating new recovery risks.
Key Takeaways
- Identity theft includes more than credit-card fraud.
- Thieves may misuse financial, tax, medical, employment, government-benefit, child, or account information.
- A credit freeze can make it harder to open new credit accounts in your name.
- A fraud alert tells businesses to verify identity before issuing new credit but does not block access to the credit report.
- Password reuse allows one breach to threaten many accounts.
- Your email account is often the recovery key to your digital identity.
- Temporary email and temporary-sharing tools reduce exposure only when used for appropriate, disposable activities.
- Temporary contact information should never be used for banking, healthcare, government, taxes, employment, or critical recovery.
- Monitoring helps identify misuse, but prevention also requires account security and data minimization.
- IdentityTheft.gov is the U.S. federal government's central identity-theft reporting and recovery resource.
- Victims have rights involving fraud alerts, credit reports, blocking fraudulent information, disputes, records, and debt collection.
- Fast, documented action can reduce long-term damage.
What Is Identity Theft?
Identity theft occurs when someone uses another person's personal or financial information without permission.
The information might include:
- Name
- Address
- Date of birth
- Social Security number
- Taxpayer identification number
- Driver's license
- Passport
- Bank account details
- Credit-card information
- Health-insurance information
- Medical identifiers
- Email account
- Phone number
- Passwords
- Authentication codes
- Employment records
- Government-benefit information
- Children's identifying information
- Biometric information
Identity theft is the misuse of identity information. A data breach or lost wallet creates exposure, but identity theft occurs when the information is actually used without permission.
That distinction matters because the response differs:
- Information exposed but not yet misused: secure accounts, freeze credit when appropriate, and monitor.
- Information already misused: stop the fraud, report identity theft, dispute fraudulent records, and follow a recovery plan.
Identity Theft, Fraud, and Account Takeover
The terms overlap but are not identical.
| Term | Meaning | Example |
|---|---|---|
| Identity theft | Personal information is used without permission | Someone opens a loan using your Social Security number |
| Payment fraud | A payment method is used without authorization | An unknown charge appears on a card |
| Account takeover | Someone gains control of an existing account | An attacker changes your email password and recovery details |
| New-account fraud | A new service is opened in your name | A credit card or phone account appears on your report |
| Impersonation | Someone pretends to be you | A scammer contacts relatives using your identity |
| Data breach | Information is exposed or stolen from an organization | Customer records are copied from a compromised database |
A person may experience several forms at once. For example, an email account takeover can help an attacker reset a bank password, impersonate the victim, and hide security notices.
How Identity Thieves Get Personal Information
Identity information can be obtained through digital and physical methods.
Data Breaches
Organizations may lose customer, employee, patient, student, or account records through hacking, insider misuse, configuration errors, stolen devices, or third-party incidents.
Exposed information can include:
- Email addresses
- Password hashes
- Social Security numbers
- Payment data
- Medical records
- Addresses
- Phone numbers
- Security questions
- Employment data
Phishing and Social Engineering
Scammers impersonate banks, government agencies, employers, delivery services, relatives, technical support, or familiar companies.
They may ask for:
- Passwords
- Authentication codes
- Account numbers
- Social Security numbers
- Payment
- Remote access
- Identity documents
Password Reuse
Attackers use credentials from one breach on other services. This is known as credential stuffing.
Mail Theft
Stolen mail may contain:
- Checks
- Credit offers
- Statements
- Tax documents
- Medical information
- Account numbers
- Replacement cards
Lost or Stolen Wallets and Devices
Wallets, phones, laptops, and storage devices can expose identity information and account sessions.
Public Records and Social Media
Public information can help answer security questions, locate relatives, build convincing scams, or combine identities across databases.
Malicious Software
Malware can steal passwords, capture keystrokes, access files, hijack sessions, or monitor communications.
Data Brokers and Marketing Lists
Data brokers compile information from public records, purchases, applications, websites, apps, and other companies.
Insider Misuse
Employees, contractors, family members, caregivers, or acquaintances may misuse access.
Trash and Discarded Documents
Unshredded financial, medical, tax, employment, and identification records can expose sensitive information.
The Main Types of Identity Theft
Financial Identity Theft
Someone uses financial or identity information to:
- Open credit accounts
- Take loans
- Access bank accounts
- Make purchases
- Change billing details
- Create utility or phone accounts
Tax Identity Theft
Someone uses a taxpayer's information to file a fraudulent return, claim a refund, or report income from an employer the victim does not recognize.
Warning signs may include an IRS notice about:
- More than one return
- A return already filed
- Income from an unknown employer
- An account the taxpayer did not create
Medical Identity Theft
Someone uses another person's information to receive care, obtain prescriptions, submit insurance claims, or create medical bills.
This can affect:
- Medical records
- Insurance benefits
- Billing
- Treatment history
- Credit reports
- Future care
Employment Identity Theft
Someone uses another person's identity to obtain employment. The victim may discover unknown income, employer records, tax notices, or benefit problems.
Government-Benefit Identity Theft
Someone uses stolen information to claim:
- Unemployment benefits
- Social services
- Disability benefits
- Disaster assistance
- Other government programs
Child Identity Theft
A child's information may be used to open credit, obtain services, or create records long before the child applies for credit.
Criminal Identity Theft
Someone gives another person's identity to law enforcement or uses it during a criminal act.
Synthetic Identity Fraud
A fraudster combines real and invented information to create a new identity. A real Social Security number may be paired with a different name or birth date.
Account Identity Theft
Someone gains control of email, social, shopping, financial, cloud, or communications accounts.
Identity Cloning and Impersonation
Someone uses another person's identity over time for relationships, housing, employment, scams, or other activity.
Each form requires a tailored response. Credit monitoring alone will not detect every category.
Protect Your Social Security Number and Government Identifiers
Do not carry a Social Security card unless it is required for a specific task.
Before providing a Social Security number, ask:
- Why is it needed?
- Is it legally required?
- How will it be protected?
- Can another identifier be used?
- How long will it be retained?
- Who will receive it?
Avoid sending government identifiers through ordinary email or text.
Store passports, licenses, tax documents, and identification records securely.
When disposing of paper copies, use appropriate shredding or secure destruction.
When sharing a copy, remove information the recipient does not need and mark the copy when appropriate, such as noting the purpose and date.
Freeze Your Credit When Appropriate
A credit freeze limits access to a credit report. Because lenders generally need to review a report before opening new credit, a freeze can make new-account fraud more difficult.
According to FTC guidance:
- Anyone can place a freeze.
- It is free to place and lift.
- It does not affect the credit score.
- It remains until lifted or removed.
- A freeze must be placed with each of the three nationwide credit bureaus.
A credit freeze does not:
- Stop fraud on an existing account
- Prevent tax identity theft
- Prevent medical identity theft
- Stop phishing
- Protect an email account
- Prevent every non-credit account from being opened
Temporarily lift the freeze when a legitimate credit check is needed.
Keep access credentials for each bureau secure.
Understand Fraud Alerts
A fraud alert tells businesses to verify identity before opening new credit.
An initial fraud alert:
- Is free
- Lasts one year
- Can be renewed
- Requires contacting only one of the three credit bureaus; that bureau must notify the other two
An extended fraud alert may be available to identity-theft victims and lasts seven years.
A fraud alert does not block access to the credit report. It adds a verification step.
Credit Freeze vs Fraud Alert
| Feature | Credit Freeze | Fraud Alert |
|---|---|---|
| Main effect | Limits access to credit report | Tells businesses to verify identity |
| Cost | Free | Free |
| Who can place it | Anyone | Initial alert for someone who suspects identity theft; extended alert for victims |
| Contact required | All three bureaus | One bureau for an alert |
| Duration | Until lifted or removed | Initial alert: one year; extended alert: seven years |
| Stops use of existing accounts | No | No |
| Affects credit score | No | No |
| Must be lifted for new credit | Usually | No |
| Best use | Strong prevention of new credit accounts | Added verification with continued credit access |
A person may use both.
Review Credit Reports
Credit reports can reveal:
- New accounts
- Unknown debts
- Incorrect addresses
- Unfamiliar employers
- Hard inquiries
- Collections
- Fraudulent balances
IdentityTheft.gov directs U.S. consumers to AnnualCreditReport.com for free reports from Equifax, Experian, and TransUnion.
Review reports carefully.
If an account is unfamiliar:
- Contact the company.
- Ask for details.
- Report identity theft when appropriate.
- Dispute inaccurate information.
- Preserve documentation.
Credit reports do not show every form of identity theft. Medical, tax, benefits, and account takeover may appear elsewhere.
Monitor Financial Accounts
Review:
- Bank accounts
- Credit cards
- Payment apps
- Investment accounts
- Loans
- Digital wallets
- Rewards accounts
Enable alerts for:
- Purchases
- Withdrawals
- Transfers
- Password changes
- New recipients
- Address changes
- New devices
- Login activity
Report unauthorized transactions promptly using the institution's official contact channels.
Do not respond through a suspicious message.
Protect Your Primary Email Account
Email is often the recovery system for other accounts.
Protect it with:
- A unique password
- Multi-factor authentication
- Updated recovery methods
- Secure backup codes
- Session review
- Forwarding-rule review
- Connected-app review
- Minimal public exposure
Reserve your primary email for critical accounts.
Use a secondary permanent address or alias for shopping, travel, social media, newsletters, and routine accounts.
Use temporary email only for disposable, low-risk activities where future recovery is unnecessary.
Put It Into Practice
Related Learning Center guides:
A temporary inbox should never recover a financial, medical, government, tax, employment, or valuable personal account.
Protect the account everything else recovers through
Your primary email is the master key to your other accounts. Keep it off sign-up forms by using a disposable address for anything low-stakes.
Open Temp Mail →Protect Your Phone Number
A phone number may be used for:
- Account recovery
- Authentication
- Customer records
- Marketing
- Identity matching
- Communications
Before sharing it, ask whether long-term contact is necessary.
Protect the mobile carrier account with:
- A unique password
- An account PIN
- Port-out protections
- Current recovery details
- Alerts for account changes
Be cautious with unexpected requests involving SIM cards, carrier accounts, or authentication codes.
Temporary phone numbers remain listed as coming soon on FreeTempTools and should not be linked until they appear in a future sitemap.
Use Unique Passwords and a Password Manager
Every important account should have a unique password.
A password manager can generate, store, and fill long credentials.
Protect the password manager with:
- A strong master credential
- Multi-factor authentication
- Secure recovery
- Updated software
- Trusted devices
Do not save passwords in ordinary notes, email drafts, spreadsheets, or chats.
Do not reuse passwords even when usernames differ.
The FreeTempTools Password Generator remains listed as coming soon. Add it after its route appears in an updated sitemap.
Turn On Multi-Factor Authentication
Multi-factor authentication makes a password alone less useful to an attacker.
Prefer:
- Passkeys
- Hardware security keys
- Authenticator apps
- Trusted-device prompts
Text-message codes may provide improvement over password-only access but can be vulnerable to SIM swapping and social engineering.
Never share an authentication code or approve an unexpected prompt.
A legitimate support representative should not ask for a one-time code to take over your session.
Protect Recovery Methods
Review:
- Recovery email
- Recovery phone
- Backup codes
- Trusted devices
- Passkeys
- Security keys
- Account-recovery contacts
Remove old information.
Do not let important accounts depend on temporary contact methods.
Store recovery codes separately from the account.
Secure Devices
Use:
- Strong screen locks
- Automatic locking
- Encryption
- Device-locate features
- Remote wipe
- Updates
- Secure backups
- Trusted app stores
- Permission review
Hide sensitive lock-screen notifications.
Remove devices from trusted-device lists before selling or disposing of them.
Use the manufacturer's reset or secure-erasure process.
Keep Software Updated
Update:
- Operating systems
- Browsers
- Mobile apps
- Email clients
- Routers
- Password managers
- Document readers
- Security tools
Remove unsupported software and unused extensions.
Updates reduce risk from known vulnerabilities.
Recognize Phishing
Phishing may impersonate:
- Banks
- Government agencies
- Employers
- Delivery companies
- Technology companies
- Relatives
- Executives
- Medical providers
- Schools
- Charities
Warning signs include:
- Urgency
- Threats
- Unexpected invoices
- Requests for codes
- Requests for passwords
- Unfamiliar attachments
- Misspelled domains
- Payment by gift card, cryptocurrency, or wire
- Messages that discourage independent verification
Do not use a message's contact information when the request is suspicious.
Open the official site or app independently.
Protect Yourself From Impersonation Scams
Scammers may use information from social media, data breaches, public records, or AI-generated audio and images.
Verify urgent requests through a known channel.
Families and organizations should create verification methods for unusual money or information requests.
Examples include:
- Calling a known number
- Asking a private question
- Using an agreed family phrase
- Requiring a second employee to approve payments
Do not rely only on voice, caller ID, email display name, or profile image.
Limit Social Media Exposure
Avoid publicly sharing:
- Full birth dates
- Home addresses
- Phone numbers
- Travel plans
- Identification documents
- Boarding passes
- School schedules
- Family relationships
- Financial details
- Real-time location
- Answers to security questions
Review profile visibility, tagging, contact synchronization, location access, and old posts.
Friends and relatives can reveal information about you even when your profile is private.
Protect Physical Mail and Documents
Use secure mail collection.
Do not leave sensitive mail unattended.
Consider paperless statements when the online account is strongly protected.
Shred or securely destroy:
- Bank statements
- Tax records no longer needed
- Medical statements
- Credit offers
- Identification copies
- Employment records
- Labels with account information
Do not discard devices or storage media without secure erasure.
Protect Documents and Images Online
Documents can contain:
- Hidden metadata
- Revision history
- Comments
- Tracked changes
- Account numbers
- Signatures
- OCR text
- Identification information
- Embedded attachments
Photos can reveal:
- Location
- Addresses
- Children's information
- Screens
- Documents
- Badges
- Vehicle information
- Device metadata
FreeTempTools provides verified live tools:
These tools support a workflow but do not automatically remove all sensitive data. Review results before saving, signing, or sharing.
Electronic signatures may have legal effect depending on the jurisdiction, transaction, consent, and implementation. FreeTempTools should not guarantee legal validity for every use.
Use Temporary Sharing Tools Carefully
FreeTempTools includes:
Temporary or expiring access can reduce long-term exposure, but it does not prevent a recipient from copying, photographing, downloading, or preserving the content.
Do not use an unverified temporary-sharing workflow for:
- Social Security numbers
- Full payment details
- Medical records
- Government identification
- Recovery codes
- Confidential legal data
- Regulated business records
- Customer databases
Use an approved secure system when required.
Use Fictional Test Data Responsibly
FreeTempTools provides a Fake Name Generator for legitimate activities such as:
- Software testing
- Form validation
- Design mockups
- Demonstrations
- Training examples
- Fictional datasets
Do not use generated data to:
- Impersonate a real person
- Open fraudulent accounts
- Evade identity requirements
- Obtain benefits or credit
- Harass others
- Mislead a business
- Violate laws or terms
Test data should be clearly separated from production and real customer information.
Understand Your Public IP Address
An IP address can reveal the public network endpoint used for a connection and may support approximate location or network identification.
An IP address is only one signal. Websites may also use:
- Cookies
- Account logins
- Browser fingerprints
- Device identifiers
- Payment details
- Location permissions
- Behavior
Changing an IP address does not erase identity or prevent account tracking.
Protect Yourself When Shopping Online
Use:
- Trusted merchants
- Verified domains
- Credit cards or protected payment methods
- Transaction alerts
- Secondary email or aliases
- Secure account passwords
- Multi-factor authentication
- Saved receipts
Avoid:
- Wire transfers
- Gift-card payment
- Cryptocurrency payment for ordinary retail
- Purchases through unexpected messages
- Permanent storage of payment data when unnecessary
HTTPS protects the connection but does not prove that the merchant is honest.
Use a stable email for purchases because refunds, shipping, warranty, and support may be needed later.
Protect Medical Information
Medical identity theft can affect billing, insurance benefits, records, and care.
Review:
- Explanation of benefits
- Provider statements
- Insurance portals
- Prescription history
- Medical bills
- Credit reports for medical collections
Question unfamiliar:
- Providers
- Procedures
- Prescriptions
- Insurance claims
- Diagnoses
- Addresses
Contact the provider and insurer through official channels.
Do not use temporary contact information for healthcare accounts.
Protect Tax Information
Safeguard:
- Tax returns
- W-2 and 1099 forms
- IRS correspondence
- Tax software
- Tax-preparer portals
- Electronic filing PINs
Use a trusted tax preparer and verify communications independently.
The IRS offers an Identity Protection PIN program. Follow current IRS instructions to determine whether it is appropriate.
Respond to tax notices promptly.
Protect Children From Identity Theft
Children may not discover identity misuse until applying for:
- Credit
- Employment
- Financial aid
- Housing
- Utilities
Protect:
- Social Security numbers
- Birth certificates
- School records
- Medical records
- Account credentials
Ask schools and activities why sensitive information is needed and how it is protected.
FTC guidance explains that parents and guardians can place freezes for children under applicable procedures.
Watch for:
- Credit offers addressed to a child
- Collection notices
- Benefit problems
- Tax notices
- Account statements
- Credit-file existence when none is expected
Protect Older Adults
Common scams include:
- Government impersonation
- Tech support
- Romance scams
- Investment fraud
- Prize scams
- Family-emergency scams
- Medical and insurance fraud
Useful protections include:
- Trusted contacts
- Transaction alerts
- Credit freezes
- Multi-factor authentication
- Password managers
- Independent verification
- Call blocking
- Regular account review
Support should preserve autonomy while reducing exposure.
Protect Identity at Work
Employers hold:
- Social Security numbers
- Tax data
- Direct-deposit details
- Health information
- Contact information
- Background records
- Credentials
Employees should use approved systems and report suspicious access.
Businesses should apply:
- Least privilege
- MFA
- Managed devices
- Secure onboarding and offboarding
- Retention rules
- Encryption
- Logging
- Incident response
- Vendor review
- Phishing reporting
- Access reviews
Do not send employee or customer data through personal email or unapproved temporary tools.
Respond to a Lost Wallet
If a wallet is lost or stolen:
- Cancel or lock payment cards.
- Contact banks and issuers.
- Replace identification.
- Review transactions.
- Consider a fraud alert or credit freeze.
- Secure accounts tied to the phone or cards.
- Document what was lost.
- Report theft to local authorities when appropriate.
- Watch for follow-up phishing.
Do not carry unnecessary identification, passwords, PINs, or Social Security cards.
Respond to a Lost Phone or Computer
Use device-locate and remote-lock features.
Then:
- Change critical passwords
- Revoke sessions
- Contact the carrier
- Protect the phone number from porting
- Review authentication apps
- Remove mobile-wallet cards
- Notify the employer if work data is involved
- Monitor accounts
- Document the loss
A screen lock reduces risk but does not eliminate it.
Respond to a Data Breach
When information is exposed:
- Verify the breach notice through the official company site.
- Identify the information affected.
- Change affected passwords.
- Change reused passwords.
- Review MFA and recovery.
- Freeze credit if sensitive identity information was exposed.
- Review credit reports.
- Monitor financial and account activity.
- Watch for targeted phishing.
- Keep the notice and documentation.
IdentityTheft.gov provides a pathway for information that was lost, stolen, or exposed even when misuse is not yet known.
Give out less to begin with
Every form you fill in is data that can leak later. Use a temporary inbox for the sign-ups that do not deserve your real details.
Get a temporary inbox →Warning Signs of Identity Theft
Watch for:
- Accounts you did not open
- Charges you did not make
- Withdrawals you did not authorize
- Bills that stop arriving
- New addresses on accounts
- Credit denial
- Unknown collections
- Tax notices
- Income from an unfamiliar employer
- Medical claims you do not recognize
- Benefit notices
- Unemployment claims
- Utility or phone accounts
- Authentication prompts
- Password resets
- Mail from unfamiliar lenders
- Changes to recovery details
- Contacts receiving messages from an impersonator
One sign may have an innocent explanation. Investigate promptly.
What To Do Immediately if Identity Theft Happens
IdentityTheft.gov recommends beginning with the companies where fraud occurred.
Step 1: Contact Affected Companies
Call the fraud department.
Ask the company to:
- Close or freeze fraudulent accounts
- Stop new charges
- Remove unauthorized transactions
- Preserve records
Change affected logins, passwords, and PINs.
Step 2: Place a Fraud Alert and Review Credit Reports
Contact one nationwide credit bureau to place a one-year fraud alert. That bureau must notify the other two.
Get and review reports from all three bureaus.
Step 3: Report Identity Theft to the FTC
Use IdentityTheft.gov to create an FTC Identity Theft Report and personalized recovery plan.
Save copies.
The report can help prove to businesses that identity theft occurred.
Step 4: Consider a Police Report
A police report may be useful in certain circumstances, especially when required by a company or when criminal impersonation is involved.
Bring:
- FTC Identity Theft Report
- Government ID
- Proof of address
- Evidence of theft
Step 5: Keep Records
Record:
- Dates
- Names
- Phone numbers
- Case numbers
- Letters
- Emails
- Reports
- Supporting documents
Keep copies rather than sending originals.
Your Rights After Identity Theft
IdentityTheft.gov states that victims have rights including the ability to:
- Create an FTC Identity Theft Report
- Place fraud alerts
- Obtain free credit reports
- Request fraudulent information be blocked
- Dispute inaccurate information
- Stop fraudulent debts from being reported
- Obtain records related to the theft
- Limit certain debt-collector contact
The exact process depends on the problem.
Use official instructions and keep documentation.
Correct Fraudulent Credit Information
Contact each bureau reporting incorrect information.
Provide:
- Identity Theft Report
- Proof of identity
- Explanation of fraudulent information
- Supporting documents
Ask that identity-theft information be blocked.
Contact the business that supplied the information.
Request written confirmation.
Close Fraudulent Accounts and Remove Charges
Contact the fraud department of each company.
Explain the theft.
Ask for:
- Closure
- Removal of charges
- Written confirmation
- Copies of application or transaction records when appropriate
Do not pay a fraudulent debt merely because a collector demands immediate payment.
Follow IdentityTheft.gov guidance and understand your rights.
Special Forms of Identity Theft
Tax Identity Theft
Contact the IRS through official instructions and follow current procedures.
Medical Identity Theft
Contact providers and insurers, correct records, and dispute improper bills.
Child Identity Theft
Contact credit bureaus and affected organizations. Follow FTC child-identity guidance.
Employment Identity Theft
Contact the employer, Social Security Administration, IRS, and relevant agencies as appropriate.
Unemployment-Benefit Identity Theft
Notify the employer and state workforce agency, then report at IdentityTheft.gov. FTC guidance published in 2026 emphasizes acting promptly, freezing credit, checking credit reports, and considering an IRS Identity Protection PIN.
Criminal Identity Theft
Contact law enforcement and courts involved. Seek records or clearance documentation needed to separate your identity from the impersonator.
Identity-Theft Prevention by Risk Level
Essential for Everyone
- Unique passwords
- MFA
- Software updates
- Financial alerts
- Secure primary email
- Careful sharing
- Phishing verification
Strong Additional Protection
- Credit freeze
- Password manager
- Account separation
- Credit-report review
- Carrier PIN
- Secure document storage
- Data-broker opt-outs where appropriate
Higher-Risk Situations
People facing stalking, harassment, public exposure, previous identity theft, major breaches, or sensitive occupations may need:
- Security keys
- Dedicated contact information
- Professional privacy support
- Address-confidentiality programs
- Stricter public-record management
- Device hardening
- Legal or law-enforcement assistance
FreeTempTools Identity-Protection Toolkit
FreeTempTools cannot prevent or resolve identity theft by itself. It can support specific privacy and security practices.
| Goal | Verified FreeTempTools resource | Appropriate use |
|---|---|---|
| Keep primary inbox out of a disposable sign-up | Temp Mail | Low-risk, short-term registrations |
| Share an expiring message | Self-Destructing Notes | Non-regulated information suitable for temporary sharing |
| Share temporary text or code | Temporary Pastebin | Disposable, non-sensitive text |
| Transfer a file | P2P File Transfer | Verify recipient and file sensitivity |
| Generate fictional test records | Fake Name Generator | Testing, mockups, and demonstrations |
| Check public network identity | What Is My IP | Awareness of public IP address |
| Scan a document | Document Scanner | Review sensitive content before processing |
| Extract text from an image | Image to Text | Check extracted text before reuse |
| Sign a PDF | Sign PDF | Verify legal and organizational requirements |
| Prepare an image | Image Compressor | Compression does not remove all sensitive details |
| Remove visible background | Background Remover | Review metadata and remaining visible information |
| Create a trusted QR code | QR Code Generator | Test destination before publishing |
Use permanent, strongly protected accounts for important relationships. Use temporary tools only where loss of access would not matter.
Create an Identity Protection Plan Before a Crisis
Recovery is easier when important information is organized before fraud occurs.
Create a secure identity-protection plan containing:
- A list of critical financial institutions
- Official fraud-department contact methods
- The three credit-bureau websites
- IdentityTheft.gov
- Insurance and healthcare contacts
- Mobile carrier information
- Employer or payroll contact
- Tax-preparer and IRS resources
- Device serial numbers
- Important account recovery methods
- Instructions for a trusted family member
Do not store full passwords, authentication codes, Social Security numbers, or complete payment details in an unsecured document.
A password manager's secure notes feature, encrypted storage, or another trusted system may be appropriate.
The plan should explain what to do if:
- A wallet is stolen
- A phone is lost
- Email is compromised
- A new account appears
- A tax notice arrives
- Medical claims are unfamiliar
- A child receives credit-related mail
- An unemployment claim is filed
- An impersonator contacts family members
Review the plan annually.
Protect Against SIM Swapping and Phone Account Takeover
A phone number may be used to receive authentication codes and recover accounts. An attacker who convinces a carrier to transfer the number may intercept calls and messages.
Reduce risk by:
- Creating a carrier-account PIN
- Enabling port-out or number-lock protections
- Using a unique carrier password
- Reviewing account contacts
- Removing old authorized users
- Watching for sudden loss of service
- Preferring authenticator apps, passkeys, or security keys for important accounts
- Contacting the carrier immediately if the number unexpectedly stops working
A sudden service loss can have an innocent explanation, but it may require urgent investigation when combined with password resets or account alerts.
Do not publish carrier-account information or authentication codes.
Protect Against Check Fraud and Mail-Based Identity Theft
Paper checks contain names, addresses, routing numbers, and account numbers.
Safer practices include:
- Use secure electronic payment when appropriate
- Do not leave outgoing checks in an unlocked mailbox
- Use a secure postal collection point
- Collect incoming mail promptly
- Review check images and account activity
- Use fraud alerts offered by the bank
- Store unused checks securely
- Destroy old checks properly
Contact the bank immediately if a check is stolen or altered.
Mail theft can also expose replacement cards, tax forms, medical records, and credit offers. Report persistent delivery problems through official postal channels.
Protect Against New Utility, Telecom, and Rental Accounts
Identity thieves may open accounts that do not immediately appear like ordinary credit-card fraud.
Watch for:
- Utility bills at unknown addresses
- Mobile-phone accounts
- Internet or cable accounts
- Rental applications
- Buy-now-pay-later accounts
- Subscription services
- Storage-unit accounts
Unknown bills, collections, or service notices deserve investigation.
Contact the provider's fraud department and request records related to the application.
A credit freeze may help with some services, but not every provider relies on the same reports or verification process.
Protect Against Unemployment and Benefits Identity Theft
Benefits identity theft may be discovered when:
- An employer receives an unexpected claim
- A state agency sends a notice
- Benefits are unavailable because someone already claimed them
- Tax documents report benefits the victim did not receive
FTC guidance published in 2026 advises unemployment-identity-theft victims to notify the employer, contact the state workforce agency, and report the theft at IdentityTheft.gov.
Additional steps may include:
- Freezing credit
- Reviewing credit reports
- Preserving agency notices
- Monitoring tax records
- Considering an IRS Identity Protection PIN
- Documenting contacts and case numbers
Do not ignore an unexpected benefits letter.
Protect Against Medical Identity Theft in Greater Detail
Medical identity theft can create both financial and health risks.
Review:
- Explanation-of-benefits statements
- Patient portals
- Prescription records
- Provider bills
- Insurance claim history
- Credit reports
- Health-savings accounts
If records contain unfamiliar care:
- Contact the provider's privacy or fraud office.
- Contact the insurer.
- Request copies of relevant records.
- Ask how incorrect information will be corrected.
- Dispute fraudulent bills.
- Monitor for additional claims.
- Follow IdentityTheft.gov's recovery guidance.
Incorrect medical data can affect treatment. Address inaccuracies rather than only disputed charges.
Use stable, protected contact information for healthcare. Temporary email and phone tools are inappropriate for patient portals and insurance recovery.
Protect Against Tax Identity Theft in Greater Detail
Tax identity theft may involve fraudulent returns, refund claims, employment income, or business filings.
Prevention steps include:
- Protect tax documents
- Use trusted tax software and preparers
- File promptly when practical
- Secure online tax accounts
- Verify tax messages independently
- Avoid emailing complete tax returns
- Use unique passwords and MFA
- Consider an IRS Identity Protection PIN when appropriate
The IRS does not initiate every issue by email or text. Follow current IRS instructions rather than using links in an unexpected message.
If a notice shows unknown income or a return already filed, respond promptly through official channels and report identity theft where appropriate.
Protect Against Business Identity Theft
Business identity theft may involve:
- Fraudulent loans
- Vendor impersonation
- Payroll changes
- Tax filings
- Domain hijacking
- Email compromise
- Unauthorized purchases
- Changes to corporate records
- Fake invoices
- Account takeovers
Small businesses should protect:
- Tax identifiers
- Banking
- Payroll
- Domain registrar
- Email administration
- Accounting systems
- Vendor records
- State registrations
- Government portals
Require independent verification for changes to:
- Payment instructions
- Direct deposit
- Vendor bank details
- Executive requests
- Administrator access
Use separate administrator accounts, MFA, role-based permissions, and documented offboarding.
Temporary FreeTempTools utilities may support low-risk testing or sharing, but they should not own or recover business-critical accounts.
Protect Deceased Family Members' Identities
A deceased person's information may be misused to open accounts, file taxes, obtain benefits, or create records.
Families and estate representatives should:
- Secure identity documents
- Notify relevant financial institutions
- Protect mail
- Follow official procedures for credit bureaus
- Monitor estate accounts
- Preserve death certificates securely
- Avoid publishing unnecessary identifying details
- Contact tax and benefits agencies as appropriate
Obituaries may reveal birth dates, addresses, relatives, and other facts. Share only what is appropriate.
Estate and probate requirements vary, so legal guidance may be needed.
Identity Theft Prevention for People With Public Profiles
Business owners, creators, professionals, public officials, and community leaders may have more information publicly available.
Consider:
- Separate public and private contact information
- Domain privacy settings where lawful and appropriate
- Dedicated business phone and email
- Security keys
- Data-broker opt-outs
- Address-confidentiality programs when eligible
- Family social-media boundaries
- Monitoring for impersonation accounts
- Domain and trademark monitoring
- Strong payment-verification procedures
Public visibility changes the threat model. It does not mean the person must accept unnecessary exposure.
Identity Theft Prevention for Survivors of Stalking or Abuse
People facing stalking, harassment, domestic violence, or targeted abuse may need specialized protections.
Depending on circumstances, consider:
- Address-confidentiality programs
- Separate devices and accounts
- New recovery methods
- Security keys
- Carrier protections
- Location-sharing review
- Family-plan separation
- Account-session review
- Professional safety planning
- Legal and advocacy resources
Do not make abrupt account changes on a device that may be monitored without considering safety.
Temporary contact tools can sometimes reduce exposure, but they are not a substitute for professional safety planning.
Decide Which Identity Protection Service You Need
Commercial identity-protection services may offer:
- Credit monitoring
- Dark-web alerts
- Account alerts
- Recovery assistance
- Insurance
- Public-record monitoring
- Child monitoring
Before paying, ask:
- What records are monitored?
- How quickly are alerts delivered?
- Does the service freeze credit or only provide instructions?
- What recovery help is included?
- What does insurance actually cover?
- Are there deductibles or exclusions?
- Is the same monitoring available for free?
- How is the service itself secured?
- What personal information must you provide?
Monitoring can be useful, but it does not replace freezes, unique passwords, MFA, financial alerts, and careful account management.
Build a Household Identity-Theft Response Plan
Families should agree on how to verify urgent requests.
Create rules such as:
- No money transfer based only on a message
- No sharing authentication codes
- Call a known number
- Use an agreed verification phrase
- Require confirmation from a second family member for unusual requests
- Report lost devices immediately
- Keep official contact details available
Discuss scams without blaming victims. Scammers use urgency, fear, authority, and emotional pressure deliberately.
A calm response plan can prevent a convincing impersonation from becoming a financial loss.
Identity-Theft Scenario Guide
You Receive a Password-Reset Email
Do not use the link if you did not request it.
Open the official account independently, review activity, change the password if needed, and check recovery settings.
Your Phone Suddenly Loses Service
Contact the carrier through another phone. Check for SIM or port activity. Review accounts that use text-message authentication.
A New Credit Card Appears on Your Report
Contact the issuer, place a fraud alert, consider a freeze, and report at IdentityTheft.gov.
You Receive a Medical Bill for Unknown Care
Contact the provider and insurer, request records, dispute the bill, and review other claims.
Your Employer Mentions an Unemployment Claim
Notify the employer, contact the state workforce agency, report at IdentityTheft.gov, and review credit and tax protections.
A Relative Requests Emergency Money
Call a known number, verify with another person, and do not rely on voice or caller ID alone.
Your Wallet Is Missing
Lock cards, contact issuers, document identification, review transactions, and consider credit protections.
A Company Announces a Breach
Determine what data was exposed, change affected passwords, freeze credit when sensitive identifiers were involved, and monitor for phishing.
Identity Theft Prevention Checklist
Accounts
- [ ] Every important account has a unique password.
- [ ] MFA is enabled.
- [ ] Recovery details are current.
- [ ] Old sessions are removed.
- [ ] Connected apps are reviewed.
- [ ] My primary email is protected and minimally exposed.
Credit and Finance
- [ ] I considered a credit freeze.
- [ ] I understand fraud alerts.
- [ ] I review credit reports.
- [ ] Transaction alerts are enabled.
- [ ] Statements are reviewed.
- [ ] Unknown activity is investigated promptly.
Personal Information
- [ ] My Social Security card is not carried routinely.
- [ ] Identification documents are stored securely.
- [ ] Sensitive mail is collected promptly.
- [ ] Paper records are destroyed securely.
- [ ] Optional form fields are skipped.
- [ ] Public profiles reveal minimal personal information.
Devices
- [ ] Devices use strong screen locks.
- [ ] Software updates automatically.
- [ ] Remote-locate and wipe are configured.
- [ ] Old devices are securely erased.
- [ ] App permissions are reviewed.
- [ ] Router and Wi-Fi passwords are secure.
Monitoring and Recovery
- [ ] I know the warning signs.
- [ ] I know how to reach affected companies.
- [ ] I know where to place a fraud alert or freeze.
- [ ] I know how to access IdentityTheft.gov.
- [ ] I keep records of fraud reports and disputes.
- [ ] Family members understand emergency verification.
Common Identity-Theft Prevention Mistakes
Relying Only on Credit Monitoring
Monitoring may detect some changes but does not prevent all fraud.
Reusing Passwords
One breach can expose many accounts.
Treating Email as Low Risk
Email often controls password recovery.
Ignoring Mail and Medical Statements
Identity theft may appear outside a credit report.
Using Temporary Contact Information for Important Accounts
This can create permanent recovery loss.
Sharing Authentication Codes
Codes are credentials.
Trusting Caller ID
Caller ID can be spoofed.
Posting Full Birth Dates and Family Details
These facts can support impersonation.
Waiting to Respond
Delays can allow additional fraud.
Failing to Document Contacts
Records are essential for disputes and recovery.
Final Recommendations
Identity-theft prevention works best as a system.
Protect critical identifiers. Use unique passwords and MFA. Secure email and phone recovery. Freeze credit where appropriate. Review financial and credit activity. Limit public sharing. Secure physical documents and devices. Verify unexpected requests independently.
Use FreeTempTools for appropriate temporary and privacy-focused workflows, but do not confuse convenience with complete security. Temporary contact information, expiring notes, and disposable sharing are useful only when the relationship and information are genuinely low risk.
If identity theft occurs, act immediately and document every step. In the United States, begin with affected companies and IdentityTheft.gov.
Continue Learning
- Protect Your Personal Information Online
- The Complete Guide to Temporary Email
- How to Avoid Email Spam
- Temporary Email vs Personal Email
Frequently asked questions
What is the best way to prevent identity theft?
Use unique passwords, MFA, a protected primary email, careful data sharing, credit freezes where appropriate, account alerts, and regular review of financial and credit records.
Does a credit freeze prevent identity theft?
It can make new-credit fraud more difficult, but it does not prevent misuse of existing accounts, tax fraud, medical fraud, phishing, or account takeover.
Is a credit freeze free?
Yes. FTC guidance states that placing and lifting a freeze is free.
Does a credit freeze hurt my credit score?
No.
What is the difference between a fraud alert and credit freeze?
A fraud alert tells businesses to verify identity. A freeze limits access to the credit report. A freeze must be placed with all three bureaus; an alert can begin through one.
Should everyone freeze their credit?
Anyone can place a freeze. Whether to do so depends on circumstances and willingness to lift it when legitimate credit access is needed.
Can someone steal my identity with my email address?
An address alone may not be enough for every form of theft, but it can support phishing, account discovery, password resets, data matching, and impersonation.
Should I use temporary email to prevent identity theft?
Temporary email can reduce exposure during low-risk disposable sign-ups. It should not be used for valuable accounts or critical recovery.
What should I do if my Social Security number is exposed?
Review official IdentityTheft.gov guidance, check and freeze credit, monitor accounts, strengthen authentication, and report identity theft if misuse occurs.
How do I know whether someone stole my identity?
Look for unknown accounts, charges, tax notices, employer records, medical claims, benefit applications, collections, or account changes.
What is IdentityTheft.gov?
It is the U.S. federal government's identity-theft reporting and recovery resource. It creates an FTC Identity Theft Report and personalized recovery plan.
Do I need a police report?
Not in every case, but it may be useful or required for certain disputes, criminal impersonation, or company procedures.
Can a child have a credit freeze?
FTC guidance describes procedures for parents and guardians to freeze a child's credit.
Does identity-theft protection insurance prevent fraud?
Insurance may provide certain recovery services or reimbursement according to policy terms. It does not stop information from being stolen or misused.
Can a VPN prevent identity theft?
No. A VPN changes network routing and IP exposure. It does not prevent phishing, password reuse, data breaches, or misuse of identity documents.
Are self-destructing notes safe for Social Security numbers?
They should not be assumed appropriate for highly sensitive identity information. Recipients can preserve content, and tool security models vary.
What should I do first after discovering identity theft?
Contact the affected company, stop the fraud, change credentials, place a fraud alert, review credit reports, and report at IdentityTheft.gov.
How long does identity-theft recovery take?
It varies with the type and extent of fraud. New-account, tax, medical, benefits, and criminal identity theft follow different processes.
Can identity theft happen without affecting my credit report?
Yes. Tax, medical, employment, benefits, account takeover, and criminal identity theft may not appear as a new credit account.
How often should I check credit reports?
IdentityTheft.gov states that U.S. consumers can access free weekly reports through AnnualCreditReport.com. Choose a review schedule that fits your risk and circumstances.
Authoritative references
- IdentityTheft.gov: Report Identity Theft and Get a Recovery Plan
- IdentityTheft.gov: Recovery Steps
- IdentityTheft.gov: What To Do if Information Was Lost, Stolen, or Exposed
- IdentityTheft.gov: Warning Signs of Identity Theft
- IdentityTheft.gov: Know Your Rights
- Federal Trade Commission: Identity Theft
- Federal Trade Commission: Credit Freezes and Fraud Alerts
- CISA: Secure Our World
- Federal Trade Commission: Got a letter about unemployment benefits you didn't file?