How to Report Identity Theft to the FTC at IdentityTheft.gov

Last updated October 7, 2026 · 1,292 words · Identity Theft

Identity theft is reported to the Federal Trade Commission at IdentityTheft.gov. Filing there creates an FTC Identity Theft Report, an official record of the fraud, and generates a recovery plan listing the organizations to notify. The report is separate from a police report and from a dispute filed with a credit reporting agency.

This guide is general educational information for U.S. readers. It is not financial advice and does not describe your individual credit file. Figures such as score ranges and timeline estimates are typical examples, not promises.

Key takeaways

Identity theft is reported to the Federal Trade Commission (FTC) at IdentityTheft.gov, the agency's dedicated reporting site. A completed report produces an FTC Identity Theft Report — an official record of the fraud — plus a recovery plan generated from the details entered. The FTC also publishes background material at FTC — Identity theft.

What the FTC actually does with a report

The FTC is a consumer protection and law enforcement agency. It is not a credit bureau, bank, or lender, and it does not delete accounts from credit files or contact creditors on a consumer's behalf. Filing at IdentityTheft.gov does three practical things: it creates a formal record of what happened, it generates the Identity Theft Report that other organizations recognize, and it assembles a recovery plan covering the institutions that typically need to be told.

The Identity Theft Report matters because several rights under the Fair Credit Reporting Act (FCRA, 15 U.S.C. section 1681) are tied to having one. The FCRA was enacted in 1970 and amended by the Fair and Accurate Credit Transactions Act in 2003, which added many of the identity theft provisions in use today. FCRA section 605A covers fraud alerts (15 U.S.C. section 1681c-1) and section 605B covers identity theft report blocking (15 U.S.C. section 1681c-2).

Information the report draws on

The report is built from answers to questions about the fraud, so documents kept nearby shorten the process. Commonly referenced items include:

How the FTC reporting process is structured

  1. Open IdentityTheft.gov and answer the opening questions about what type of information was misused.
  2. Work through the category-specific questions — for example, a misused Social Security number, a new account opened in the consumer's name, or a fraudulent tax return.
  3. Review the recovery plan the site generates, which lists the organizations to notify and the order in which notifications usually happen.
  4. Download or print the FTC Identity Theft Report and store a copy in a secure file.
  5. Return to the account and update the report if additional fraudulent activity surfaces later.

Completing the FTC report does not require a police report, although some creditors and insurers ask for one separately and a police report is a recognized supporting document. Filing with the FTC does not replace notifying law enforcement, the credit reporting agencies, or individual creditors.

What happens after a report is filed

An FTC Identity Theft Report functions the way an affidavit functions: it documents the claim that specific activity was not authorized. Credit reporting agencies and businesses that receive it can compare it against their own records. Disputes filed with a credit reporting agency under the FCRA generally must be investigated within 30 days, and that period can extend to 45 days if the consumer provides additional information during the initial 30-day window.

One distinction is worth stating plainly: not every disputed item is removed. Most negative information, including late payments, stays on a credit report for 7 years; a Chapter 7 bankruptcy stays for 10 years and a Chapter 13 bankruptcy stays for 7 years. Fraudulent accounts are handled differently from accurate-but-unfavorable accounts, and section 605B blocking is the provision that addresses information resulting from identity theft.

Fraud alerts, freezes, and how they relate to the report

Fraud alerts and security freezes are separate tools from the FTC report, and both are governed by the FCRA. An extended fraud alert lasts 7 years and is tied to having an identity theft report on file, as described by the FTC. The table below summarizes what each protection does and how long it lasts.

ProtectionDurationWhat it does
Initial fraud alert1 yearAsks businesses to take reasonable steps to verify identity before extending credit.
Extended fraud alert7 yearsAvailable to consumers who have an identity theft report on file.
Security freezeUntil removed by the consumerRestricts access to a credit file; under federal law it is free to place, temporarily lift, or remove.

A freeze is placed separately with each of the three nationwide credit reporting agencies — Equifax, Experian, and TransUnion — and a lock is a commercial product offered by a credit reporting agency that operates similarly to a freeze. More detail on those mechanics is in the pages on security freezes and credit locks.

Reporting to the IRS and other organizations

Tax-related identity theft runs on a separate track. When a Social Security number is misused on a tax return, the filing made with the Internal Revenue Service using Form 14039 is distinct from the FTC report. Other organizations that commonly receive notification include banks and card issuers for the specific accounts involved, state attorneys general, and the postal inspection service when mail was diverted. If your identity is stolen, you can report it at IdentityTheft.gov and to the IRS using Form 14039.

How identity theft interacts with credit scores

Most credit scores, including FICO and VantageScore, use a range of 300 to 850, and they are calculated from the contents of credit reports rather than from any filing made with the FTC. FICO's published factor weights are payment history at 35%, amounts owed at 30%, length of credit history at 15%, new credit at 10%, and credit mix at 10%. VantageScore uses its own factor weighting and does not publish fixed percentages.

Because fraudulent accounts are reported into credit files as if they belonged to the consumer, they can be counted in the same factors as legitimate accounts. An unpaid fraudulent balance can appear within amounts owed, and inquiries from applications the consumer never submitted can appear within new credit. Hard inquiries typically remain on a credit report for 2 years. That is why the record created at IdentityTheft.gov and the dispute process that follows are connected: the report establishes that the activity was fraudulent, while a change to the credit file changes what the scoring factors are reading. Background on those factors is in the guides on how credit scores are calculated, credit utilization, and payment history.

Documentation that supports a report over time

Identity theft cases often unfold over months, and records assembled early tend to answer later questions. Documentation that is commonly retained includes:

Ongoing review of credit files also plays a role after an initial report, since new accounts can surface well after the first filing. The pages on credit monitoring, credit reports, and the identity theft hub explain how files are tracked and how dispute records are organized. Complaints about how a credit reporting agency handled a dispute can also be submitted to the Consumer Financial Protection Bureau, which was created by the Dodd-Frank Act in 2010 and began operating in 2011.

This page is for education only and is not financial advice.

Compare three-bureau credit scores and reports from a single place. Educational links, disclosed below.

Three Bureau Credit Scores and Reports

CreditMonitored.com may earn a commission from partner links at no additional cost to you.

Frequently asked questions

How do you report identity theft to the FTC?

Identity theft is reported through IdentityTheft.gov, the FTC's dedicated reporting site, where an online report is completed and an FTC Identity Theft Report and recovery plan are generated from the information provided. The FTC's main site also maintains an identity theft information page describing the process.

Is an FTC Identity Theft Report the same as a police report?

No. The FTC report is a record created with a federal agency, while a police report is filed with local law enforcement. Some creditors and insurers ask for a police report as supporting documentation, so the two records can serve different purposes in the same case.

Does filing at IdentityTheft.gov remove fraudulent accounts from a credit report?

The filing itself does not change a credit file. It creates documentation that supports the processes that can change a file: disputes with the credit reporting agencies, which generally must be investigated within 30 days, and identity theft report blocking under FCRA section 605B.

What is the difference between an initial fraud alert and an extended fraud alert?

An initial fraud alert lasts 1 year and asks businesses to take reasonable steps to verify identity before extending credit. An extended fraud alert lasts 7 years and is tied to having an identity theft report on file.

Can identity theft be reported somewhere other than the FTC?

Yes. Tax-related identity theft is reported to the Internal Revenue Service using Form 14039, and notifications commonly go to creditors, the credit reporting agencies, and law enforcement. Each organization maintains its own records and does not automatically share a filing made with another.

Related guides

Related terms

Sources