A scenario worth planning for
Maria checks her bank app on a Tuesday and finds two accounts she never opened. She spends the next hour on the phone with her bank, a credit bureau, and the FTC’s identity theft site. By Thursday, a collector calls about one of those accounts. Maria explains what happened, but she cannot remember which bureau she called first, what day she filed her FTC report, or the confirmation number the bank gave her. The collector’s file shows no record of a dispute at all.
Identity theft recovery usually is not one phone call. It is a sequence of official reports, alerts, and letters spread across days or weeks, each one handled by a different company or agency. The single biggest reason recovery drags on is not the theft itself — it is a missing paper trail. This guide uses two official U.S. government resources, IdentityTheft.gov and the Federal Trade Commission’s (FTC) consumer identity theft hub, to show what to record, when, and why it holds up later.
Why a written record matters more than any single phone call
Under federal guidance published by the FTC, several of the strongest legal protections available to identity theft victims only work if the victim can show what was reported and when. An extended fraud alert that blocks marketing offers and lasts seven years, for example, requires a completed identity theft report — not just a phone call to a bank. A credit bureau asked to block fraudulent information from a credit report needs a written request tied to that same report. None of this depends on memory. It depends on dates, names, and confirmation numbers written down as they happen.
This is not legal advice about a specific case. It is a way to organize the official steps IdentityTheft.gov and the FTC already recommend, so the record exists before anyone asks for it.
Before you start: the two accounts you need
Two things anchor the entire record.
- An IdentityTheft.gov account. Filing a report at IdentityTheft.gov and creating a free account lets a person save, print, and update a personal recovery plan over time. Without an account, the FTC’s guidance advises printing and saving the report immediately, since it will not be stored for later retrieval the same way.
- One dedicated place to log everything else. A notebook, a single document, or a simple spreadsheet works. The format matters less than using one place, consistently, from the first phone call onward.
Setting up your log in the next 10 minutes
Before any calls are made, the log itself should exist. This takes three steps:
- Open one blank document, notebook page, or spreadsheet and label it with the date the identity theft was discovered.
- Create five columns or sections: date, who was contacted, what was requested or reported, confirmation received, and follow-up needed.
- Make the first entry right now: the date and time the problem was discovered, and how (a bank alert, a denied application, a collection call, or something else).
Every call, letter, and report that follows gets its own line, added at the time it happens rather than reconstructed later.
Stage 1: The first 24 hours — capture, don’t just act
The official first steps, per IdentityTheft.gov and the FTC, are to contact the companies where fraud occurred, place a fraud alert with one credit bureau, and file a report at IdentityTheft.gov. Each of those steps produces something worth recording immediately, before it is forgotten.
- Company contact: Business name, phone number, date and time called, the name of the representative (if given), and any reference or case number for the fraud claim.
- Fraud alert: Which of the three nationwide credit bureaus (Equifax, Experian, or TransUnion) was contacted. Placing a fraud alert with one bureau requires that bureau to notify the other two, so only one call is needed — but the record should still note which bureau and the date, since an initial fraud alert lasts one year.
- IdentityTheft.gov report: The date filed, whether an account was created, and — critically — a saved or printed copy of the report itself. This report is the document that unlocks stronger protections later, including the extended fraud alert and blocked entries on a credit report.
Where this becomes urgent: if a stolen Social Security number, driver’s license, or passport number is involved, note that separately and immediately — replacing government-issued IDs has its own contacts (the Social Security Administration, a state motor vehicle agency, or the U.S. State Department for passports) and its own timeline, and delays compound.
Stage 2: Building the credit-side record
The FTC distinguishes two protections that are easy to confuse, and the record should reflect which one was chosen and why.
- Fraud alert (initial): Free, lasts one year, requires contacting only one bureau, and requires businesses to verify identity before opening new credit — it does not block access to a credit report.
- Extended fraud alert: Free, lasts seven years, also removes a person from prescreened credit offer lists for five years — but requires a completed identity theft report to activate.
- Credit freeze: Free, lasts until removed, and is the strongest option — it blocks new accounts from being opened at all, including by the account holder, until the freeze is lifted. A freeze must be placed separately with each of the three bureaus.
For each one placed, the record should show: which bureau, which protection, the date, and any PIN or confirmation number provided to lift it later. A credit freeze is only useful if the confirmation details needed to lift it are saved somewhere retrievable — losing that information is one of the most common reasons people abandon a freeze instead of managing it.
The FTC also recommends ordering free credit reports (available through AnnualCreditReport.com, the official site authorized under federal law) and reviewing every account and inquiry listed. Any unfamiliar item goes into the record as its own line: which bureau’s report it appeared on, the account or company name, and the date it was found.
Stage 3: Disputing fraudulent accounts and charges — the paper that carries weight
IdentityTheft.gov provides sample letters for disputing fraudulent accounts, removing fraudulent charges, notifying credit bureaus, and responding to debt collectors. Each letter sent should generate a record entry with four fields:
- Recipient (the business, bureau, or collector)
- Date sent and method (mail, fax, online portal)
- What was requested (account closure, charge removal, blocking of fraudulent information)
- Response received, and the date it arrived
Under federal guidance, a business notified of identity theft should provide written confirmation that the disputed account or charge is not the victim’s responsibility. If that confirmation never arrives, the dated record of the original request is what supports a follow-up call or a complaint to a regulator.
Stage 4: The police report — when it fits into the record
A police report is not always required, but IdentityTheft.gov notes it can matter in specific situations: when a business insists on one before closing an account, when the identity thief’s actions could be confused with the victim’s own conduct, or when local law enforcement is willing to investigate. If one is filed, the record should include the police department, the report number, the date filed, and the name of the officer taking the report, along with a copy of the report itself if issued.
Decision path: what your situation adds to the record
The core log stays the same, but certain situations add specific lines worth tracking from the start.
- If a Social Security number, driver’s license, or passport was exposed, then add separate entries for contacting the Social Security Administration, the state motor vehicle agency, or the State Department, since each has its own process and timeline.
- If you want the strongest protection against new accounts being opened, then choose a credit freeze over a fraud alert, and log the confirmation number or PIN each bureau provides — it will be needed to lift the freeze later.
- If you want protection to last longer than one year without repeated renewal, then use your completed IdentityTheft.gov report to request the extended, seven-year fraud alert instead of the standard one-year alert.
- If a business does not send written confirmation of a dispute within a reasonable time, then the dated record of the original letter or call is what supports a follow-up request or a complaint about the delay.
Putting it together: a simple action-record template
The categories above translate into one running log. Each entry can use the same five columns, whether tracked on paper or in a spreadsheet:
- Date
- Who was contacted (company, bureau, agency, or officer)
- What was requested or reported
- Confirmation received (number, name, or written document)
- Follow-up needed and by when
Keeping this log current as each step happens — not reconstructed afterward — is what separates a record that resolves a dispute quickly from a memory that cannot be verified.
Where this record does its job
A complete, dated record becomes useful in several recurring situations: a collector calling about a debt already reported as fraudulent, a credit bureau requesting proof before blocking an entry, a business asking when a fraud report was filed, or simply confirming, months later, which protections are still active and which have expired (an initial fraud alert, for example, needs renewing after one year if the extended version was not activated).
What this guide does not cover
This page explains how to organize official identity theft recovery steps into a dated record — it does not replace the step-by-step recovery process itself, evaluate a specific dispute, or provide legal advice about an individual’s situation. State laws on credit freezes, reporting deadlines, and consumer protections can vary, and some situations — including tax-related identity theft, medical identity theft, or cases involving a minor — follow different procedures than the general steps described here. A licensed attorney in the relevant state can advise on a specific dispute, a business’s failure to respond, or a suspected FCRA (Fair Credit Reporting Act) violation.
Frequently asked questions
Do I need a lawyer to recover from identity theft?
Not for most cases. The official process — reporting to IdentityTheft.gov, placing fraud alerts or a credit freeze, and disputing fraudulent accounts — is designed to be handled directly by the person affected. A licensed attorney becomes useful if a business refuses to correct an error, a credit bureau will not honor a dispute, or the situation involves potential violations of consumer protection law.
How long should I keep this record?
An extended fraud alert lasts seven years and a credit freeze lasts until removed, so keeping the record at least that long — and definitely until every disputed account is confirmed closed or corrected in writing — is reasonable.
What if a company won’t confirm my dispute in writing?
The dated record of the original request (how it was sent, and when) is what supports escalating the issue, including filing a complaint with the FTC or, where relevant, consulting a licensed attorney about next steps.
Does filing an IdentityTheft.gov report replace a police report?
No. They serve different purposes. An IdentityTheft.gov report is the document that unlocks certain credit protections and dispute rights; a police report may still be required by a specific business or relevant in specific circumstances, such as suspected criminal conduct tied to the theft.
Is there a cost to placing a fraud alert or credit freeze?
No. Under federal law, initial fraud alerts, extended fraud alerts, and credit freezes are free at all three nationwide credit bureaus. Any request for payment to place one of these protections is a reason to stop and verify who you’re dealing with.
Related reading on LegalHelpOnline
- Identity Theft: Legal Steps, Police Reports, FTC Filing, Credit Freezes, and Your Rights — the full step-by-step sequence this action-record template is built to track.
- Online Scam Legal Remedies: Report, Document, Recovery — documentation guidance for scam losses that don’t involve stolen identity.
- Consumer Rights — the full category of consumer protection guides on this site.
This article provides general legal information for educational purposes only. It is not legal advice and does not create an attorney-client relationship. Laws and procedures vary by state and change over time; consult a licensed attorney in your jurisdiction for advice about a specific situation. For emergencies or suspected ongoing crimes, contact local law enforcement directly.
By LegalHelpOnline.org Legal Research & Editorial Team. Last updated: September 10, 2026.