SeniorSenseGuide

For me or a parent

Identity Theft: First Steps to Contain the Damage

A practical sequence for closing affected accounts, securing email and passwords, protecting credit, documenting the theft, and using the FTC recovery process.

Last reviewed: August 11, 2026Educational guidance — not individualized legal, tax, medical, or financial advice
Start here

Make a short list of the accounts, documents, and personal information involved. Separate confirmed misuse from information that may only have been exposed. Bank or card fraud, a stolen Social Security number, a hijacked email account, a new credit account, tax fraud, and medical identity theft require overlapping but not identical responses.

ACCOUNT SECURITY SWEEP

Secure the accounts that can unlock everything else

Work from a trusted device. Start with email and the mobile-phone account because thieves can use them to reset passwords and intercept codes. Then protect money, benefits, health coverage, and the devices themselves.

AccountCheck nowLock it downWarning sign
EmailRecent sign-ins, recovery email and phone, forwarding rules, filters, sent mail, and deleted mail.Use a new unique password, sign out unfamiliar sessions, remove unknown recovery details and forwarding rules, and turn on multi-factor authentication.Password-reset messages you did not request, missing mail, unfamiliar forwarding, or a recovery address you do not recognize.
Mobile-phone carrierWhether your number, SIM, device, authorized users, or account email changed.Add or change the carrier-account PIN or password. Ask what extra protection the carrier offers against number transfers or SIM changes.Phone suddenly loses service, an unexpected SIM activation notice arrives, or account codes stop reaching you.
Banking, cards, and investmentsTransactions, linked accounts, payees, contact details, authorized users, devices, alerts, and recent profile changes.Report fraud, replace exposed credentials or cards, use unique passwords and stronger authentication, and enable transaction and profile-change alerts.Small test charges, a new payee, changed contact information, missing statements, or an unfamiliar linked account.
Social Security benefitsSign in through SSA.gov and review personal information, earnings, benefit details, address, and direct deposit for changes you did not make.Secure the sign-in account and contact Social Security through an official channel about suspicious changes. Ask whether an eServices or direct-deposit block fits the situation.An unfamiliar benefit application, changed deposit information, an incorrect address, or earnings that are not yours.
Medicare and health coverageMedicare claims, plan notices, Explanation of Benefits statements, prescriptions, providers, and equipment you did not receive.Secure the Medicare.gov and plan accounts, report unfamiliar claims to the provider or plan, and report suspected Medicare fraud through Medicare's official channels.Unknown services, supplies, prescriptions, providers, or a plan enrollment you did not authorize.
Computer, tablet, and phoneRemote-access programs, unknown apps or browser extensions, security warnings, account profiles, and software updates.Disconnect an active remote session, update security software and the operating system, run a security scan, and remove access the scan or a trusted technician identifies as unsafe.Unexpected remote control, pop-ups demanding a call, disabled security tools, or a new administrator profile.

Use addresses, apps, statements, cards, and phone numbers you already know are genuine. Do not follow an unexpected caller's security instructions or move money to a new account because someone says it is safer.

01

Identify what was exposed or misused

Make a short list of the accounts, documents, and personal information involved. Separate confirmed misuse from information that may only have been exposed. Bank or card fraud, a stolen Social Security number, a hijacked email account, a new credit account, tax fraud, and medical identity theft require overlapping but not identical responses.

02

Contact the companies where fraud happened

Use a trusted phone number, app, statement, or website to contact the bank, card issuer, lender, insurer, merchant, or other company. Close or freeze affected accounts when appropriate, dispute fraudulent transactions or accounts, and ask what written documentation the company needs. Change account passwords, PINs, and security questions that may have been compromised.

03

Secure email and turn on multi-factor authentication

Start with the email account used for password resets and financial notices. From a trusted device, change the password, review forwarding rules and recovery information, sign out unfamiliar sessions, and turn on multi-factor authentication. Then secure other important accounts, especially banking, investment, phone, tax, and benefits accounts.

04

Place a fraud alert or credit freeze

A fraud alert tells businesses to verify identity before opening new credit. Contacting one of the three nationwide credit bureaus for a fraud alert requires that bureau to notify the other two. A credit freeze is stronger: it restricts access to the credit file and must be placed separately with Equifax, Experian, and TransUnion. Fraud alerts and freezes are free, and a freeze does not affect a credit score.

05

Use IdentityTheft.gov for the report and recovery plan

Report the identity theft at IdentityTheft.gov. The FTC process creates an Identity Theft Report and a personalized recovery plan based on the type of misuse. Save or print the report, letters, and recovery steps. Some companies and credit bureaus may ask for the FTC report or, in some cases, a police report.

06

Review reports and statements until the problem is actually closed

Check credit reports, bank and card statements, medical explanations of benefits, benefit accounts, and mail for unfamiliar activity. Dispute fraudulent credit-report items and keep copies of letters, confirmations, case numbers, and dates. Continue monitoring after the first accounts are closed because identity theft can surface in more than one place.

PRIMARY SOURCES

Where this guidance comes from

Rule-sensitive guides prioritize government and other primary sources. Links open the official source in a new tab.

NEXT ACTION

What do you want to do next?