All articles
Identity Protection2026-08-24 9 min read

12 Early Warning Signs of Identity Theft (and What to Do in the First 24 Hours)

Spot identity theft before it becomes expensive: the earliest signals, the exact first-day response, and the free tools that freeze the damage.

Identity theft rarely announces itself with a dramatic event. It starts with a small anomaly — a verification code you didn't request, a letter for an account you never opened — weeks before the financial damage lands. Catching it at that stage is the difference between an afternoon of phone calls and a year of disputes.

The 12 early signals

  • Two-factor codes or password-reset emails you did not trigger.
  • A sudden drop in your credit score with no matching activity.
  • Mail stops arriving — a classic sign of a fraudulent change-of-address.
  • Small unexplained charges (thieves test cards with tiny amounts first).
  • Debt collectors calling about accounts you don't recognise.
  • A tax filing rejected because a return was already submitted under your number.
  • Medical bills or explanation-of-benefits statements for care you never received.
  • A new credit inquiry or account on your credit report.
  • Your bank or a service says your email or phone was changed.
  • Login alerts from unfamiliar devices or countries.
  • Friends receive messages from an account that isn't yours anymore.
  • Your name and address appearing on a new people-search profile you never created.

The first 24 hours

  • Freeze your credit at all three US bureaus — free, instant, and reversible. Outside the US, use the equivalent national credit reference agency.
  • Change the password on your primary email first, then on financial accounts; enable a passkey or hardware key.
  • Report to IdentityTheft.gov (US) or Action Fraud (UK) to generate an official recovery plan and affidavit.
  • Call each affected institution's fraud line and ask for written confirmation of the dispute.
  • Request your free credit reports and read every line for accounts and addresses you don't recognise.
  • Document everything — dates, names, reference numbers. Disputes are won on paperwork.

Cut the fuel supply

Most account-takeover attacks start with data that is publicly purchasable: your address history, relatives' names, old phone numbers, and answers to security questions — all standard fields on people-search profiles. Reducing that exposure is prevention, not cleanup. A MyTrace.fyi audit shows exactly which of those fields is public right now and gives you the removal route for each.

Sources & official references

Keep reading

See what the internet knows about you

Run a free privacy scan and turn every exposed record into a ready-to-send removal request.