Identity events spread across systems. Contain the account or record first, then preserve evidence and correct downstream records.

Do this first

Use an alert for added verification; use a freeze for stronger new-credit control.

Use a known device or contact path. Do not paste passwords, recovery codes, identity numbers, or confidential records into an online checker.

Separate the signal from the story.

A surprising event is a reason to verify, not proof of a specific cause. Record what you observed, when it happened, and which account, device, record, or person is affected. Then confirm through a channel you already trust.

Prevention and recovery work best when the connected identity controls are reviewed together. Continue with Credit freeze guide, Identity theft recovery plan, and Types of identity theft.

Good security decisions preserve options.

Start with reversible containment. Keep evidence. Avoid making a rushed change that destroys logs or locks you out of recovery.

Three questions before you act

  • What exactly changed?Distinguish a message about an event from evidence inside the real account or system.
  • What can this access unlock?Prioritize email, phone, finance, administrator access, and recovery channels.
  • Can I verify independently?Use a saved number, official app, typed address, or accountable person—not details supplied by the alert.

Move from containment to confidence.

The sequence below is deliberately broad enough to stay useful as interfaces change. Provider-specific buttons move; the security objective does not.

  1. 01

    Secure primary email, phone, and financial access

    Start with the highest-impact access or data in scope and avoid using a link from an unexpected message.

  2. 02

    Record dates, notices, case numbers, and screenshots

    Use dates, case numbers, screenshots, owners, and decisions so another person can follow what happened.

  3. 03

    Block new abuse with freezes, alerts, or account controls

    Choose the smallest effective control, confirm it took effect, and protect its recovery path.

  4. 04

    Report to the relevant institution and official channel

    Use the provider or authority appropriate to the affected account, record, jurisdiction, or workplace.

  5. 05

    Re-check statements and records until corrections hold

    Schedule a follow-up. Many problems reappear through unchanged recovery details, connected apps, or stale copies.

Turn warning signs into specific checks.

SignalWhat it may meanSafer next step
Unexpected account or address changePossible account takeoverUse a known channel; lock and document
New inquiry or accountNew-account identity fraudFreeze files and dispute promptly
Missing mail or phone serviceMail theft or SIM changeContact provider from another device
Source discipline

For live incidents, verify steps with the affected provider and the relevant government or regulatory authority. Product screens, laws, reporting routes, and eligibility can change by place and time.

What people ask next.

Does monitoring prevent identity theft?+

No. Monitoring can shorten detection time; preventive controls such as unique credentials, strong authentication, and credit freezes address different parts of the risk.

Should I wait for proof before acting?+

No. Use proportionate, reversible containment when a credible warning appears, and keep records of what you changed.

When should I get professional help?+

Escalate when safety is at risk, money or regulated data is involved, an attacker may still have access, legal deadlines apply, business operations are affected, or you cannot confidently preserve evidence and recover.