Identity theft rarely announces itself with a dramatic event. It starts with a small anomaly — a verification code you didn't request, a letter for an account you never opened — weeks before the financial damage lands. Catching it at that stage is the difference between an afternoon of phone calls and a year of disputes.
The 12 early signals
- Two-factor codes or password-reset emails you did not trigger.
- A sudden drop in your credit score with no matching activity.
- Mail stops arriving — a classic sign of a fraudulent change-of-address.
- Small unexplained charges (thieves test cards with tiny amounts first).
- Debt collectors calling about accounts you don't recognise.
- A tax filing rejected because a return was already submitted under your number.
- Medical bills or explanation-of-benefits statements for care you never received.
- A new credit inquiry or account on your credit report.
- Your bank or a service says your email or phone was changed.
- Login alerts from unfamiliar devices or countries.
- Friends receive messages from an account that isn't yours anymore.
- Your name and address appearing on a new people-search profile you never created.
The first 24 hours
- Freeze your credit at all three US bureaus — free, instant, and reversible. Outside the US, use the equivalent national credit reference agency.
- Change the password on your primary email first, then on financial accounts; enable a passkey or hardware key.
- Report to IdentityTheft.gov (US) or Action Fraud (UK) to generate an official recovery plan and affidavit.
- Call each affected institution's fraud line and ask for written confirmation of the dispute.
- Request your free credit reports and read every line for accounts and addresses you don't recognise.
- Document everything — dates, names, reference numbers. Disputes are won on paperwork.
Cut the fuel supply
Most account-takeover attacks start with data that is publicly purchasable: your address history, relatives' names, old phone numbers, and answers to security questions — all standard fields on people-search profiles. Reducing that exposure is prevention, not cleanup. A MyTrace.fyi audit shows exactly which of those fields is public right now and gives you the removal route for each.