identity

10 Warning Signs of Identity Theft (and What to Do in the First 48 Hours)

The fraud you notice last

Most scams announce themselves the moment they succeed: the parcel never comes, the transfer vanishes, the investment app stops paying out. Identity theft is the opposite. It is at its quietest precisely when it is doing the most damage — while a stranger, holding enough of your personal details to pass for you, opens accounts, borrows money and runs up bills in your name somewhere you cannot see. By the time it becomes loud, in the form of a debt letter or a refused mortgage, the harm has been accumulating for weeks.

That gap between the crime and your awareness of it is the whole problem, and closing it is the whole defence. The good news is that identity theft leaves a trail of small, early signals long before it turns into a crisis — odd post, a stray text, a number on a statement that should not be there. This article lists ten of those signals, then sets out a calm plan for the first 48 hours after you spot one, because in the early stages the difference between an inconvenience and a nightmare is mostly how fast you move.

What identity thieves are actually doing with your details

Identity theft is not one act but a supply chain. First a criminal gathers the raw material — your name, date of birth, address, and ideally a document number or a login — harvested from a data breach, a phishing page, a stolen wallet, or a rummaged-through bin. Then they put it to work: applying for credit cards, loans, phone contracts or benefits in your name, taking over an account you already hold, or redirecting your post so the evidence never reaches you. The person whose details are used is often the last to find out, because none of the paperwork is coming to them.

Understanding that shape tells you where to watch. The early signs cluster around two things a thief cannot fully control: the paper trail that a new account generates, and the small verification messages that leak out when someone tries to use your identity. Learn to notice those and you close the gap between their action and your knowledge.

The ten warning signs

Any one of these can have an innocent explanation. Two or three together, or even one that you genuinely cannot account for, is a reason to start the containment steps below rather than wait and hope.

| # | Warning sign | Why it matters | | --- | --- | --- | | 1 | Transactions on your statement you did not make | The most direct sign your card or account is being used | | 2 | Bills, receipts or invoices for things you never bought | A new account has been opened and is already active | | 3 | A "welcome" letter or email for an account you never opened | Credit or a contract taken out in your name | | 4 | A card, cheque book or PIN you did not request arrives | Someone applied as you and had it sent to your address | | 5 | Post you expect suddenly stops coming | A possible mail redirection put on to hide the trail | | 6 | Being refused credit, or a sharp unexplained score drop | Applications and debts you cannot see are dragging it down | | 7 | Debt collectors chasing money that is not yours | Borrowing in your name has already gone unpaid | | 8 | Wages, a pension or benefits that stop arriving | Bank details on file may have been quietly changed | | 9 | HMRC or the DWP contacts you about a job or claim you do not recognise | Your details are being used for tax or benefit fraud | | 10 | Two-step codes or "was this you?" alerts you did not trigger | Someone is actively trying to get into one of your accounts |

The last one deserves particular attention because it is the earliest of all. A verification code landing on your phone when you were not logging in anywhere is not spam — it is the sound of someone standing at one of your doors with most of a key. Treat it as a live attempt, not a nuisance.

The first 48 hours: contain, then investigate

If a sign checks out, resist the urge to spend the evening working out exactly how it happened. The forensics can wait; the containment cannot. Work in this order.

The first hour — close what is bleeding now

Start with anything that moves money or grants access today. Ring the bank or card provider behind any unfamiliar transaction and have the card stopped and reissued. If you can still get into an affected online account, change its password immediately — to something you have never used elsewhere — and switch on two-step verification if it is not already on. If you have been locked out of an email or phone account, prioritise that above almost everything else, because whoever controls your email can reset the passwords to everything attached to it. This is the account-takeover heart of a lot of identity theft, and email is usually the master key.

The first day — shut the doors and start the record

Once the immediate leak is stopped, widen out. Change the password on any other account that shared the compromised one, since reused passwords are how one breach becomes ten. List every place your exposed details could open a door — banking, email, shopping accounts, anything holding a saved card — and secure each. And from the very first call, keep a written record: who you spoke to, when, and any reference number they gave you. That log is not bureaucracy; it is the evidence every later step, from a bank dispute to a police report, will lean on.

The first 48 hours — set the alarms and check the record

Now move from stopping today's damage to catching tomorrow's. Two steps matter most here. First, consider a CIFAS Protective Registration: for a small fee, this flags your name in the national fraud-prevention database so that lenders carry out extra identity checks before granting credit in your name — deliberate friction that frustrates a thief trying to borrow as you. Second, check your credit report. In the UK your file is held by three credit reference agencies — Experian, Equifax and TransUnion — and you are entitled to see it; read it for accounts, searches or addresses you do not recognise, as those are the fingerprints of borrowing taken out behind your back. Checking your own report does not harm your score, so look at more than one agency if you can, because not every lender reports to all three.

Who to tell, and where

Reporting is not just a formality; it creates the official record that unlocks refunds, corrects your credit file and lets investigators connect the dots. Where you go depends on what was hit.

  • Your bank or card provider — always first, for anything involving your money or a card. Say plainly that you are a victim of fraud.
  • Action Fraud — the national fraud reporting service covering England, Wales and Northern Ireland, reachable online or by phone; in Scotland it is Police Scotland on 101 that takes the report instead. Keep the reference number they issue.
  • The credit reference agencies — ask about a notice of correction or a fraud marker on entries that are not yours, and dispute the fraudulent accounts.
  • HMRC or the DWP — directly, if the misuse touches tax, a National Insurance number, or benefits, since those bodies handle their own fraud.
  • The ICO — the Information Commissioner's Office, if your details were exposed through an organisation mishandling your data, which is a separate matter from the fraud itself.

If your bank details were exposed and money has already gone, the quickest ways to try to recover it are the ones our getting your money back guide runs through — and be ready for a follow-up call that claims to come from your bank's fraud department, a common sequel leaning on the very details just stolen, exactly as a bank impersonation scam does.

Before you go

Here is the reframe worth carrying away, because it will save you a lot of wasted worry. You cannot make yourself un-leakable. Your details already sit in dozens of databases you will never audit, and every breach that hits a shop, an insurer or an app you once used spills a little more of them into circulation, entirely beyond your reach. Chasing the impossible goal of never being exposed only leads to helplessness.

So change the goal. Stop trying to be un-leakable and aim instead to be un-surprisable. A house fire is not prevented by hoping no spark ever lands; it is survived by smoke alarms that go off in minutes rather than hours. Wire your financial life the same way — transaction alerts on your accounts, an eye on your credit report, a fraud marker if you have been hit once — so that the moment someone uses your name, you hear about it while the damage is still small. The victory condition was never "my data never leaked". It is "a stranger used my identity and I knew before they got anywhere". That is a fight you can actually win, and the first 48 hours are where you win it. The checker being put together at CheckAScam is really just one more alarm you can wire in, and an honest one about its limits: it cannot see the details already circulating about you, nor read your credit file, and it only speaks up about a website before you feed it fresh ones. Guarding that front door is a different job from catching what has already slipped out the back, and while the tool is still unfinished, the front door is the part it is being built for.

Frequently Asked Questions

What is the very first thing to do if I think my identity has been stolen?

Deal with whatever is losing money or access right now, before anything else. That usually means phoning the bank or card provider behind any transaction you do not recognise and having the card frozen, then changing the password on any account you fear has been reached — starting with your email, because control of your email lets a thief reset almost everything else. Only once the immediate bleeding is stopped should you move on to reporting the crime, alerting the credit agencies and working out how it happened. Speed in that first hour does more to limit the damage than a perfect understanding of the breach ever will, so act first and investigate afterwards.

How do I check whether accounts have been opened in my name?

Look at your credit report, which is the ledger where borrowing in your name shows up. In the UK three agencies hold your file — Experian, Equifax and TransUnion — and you can see what each holds; read through it for accounts, credit searches or linked addresses you do not recognise, since those are the signs a criminal has borrowed as you. Because not every lender reports to all three agencies, it is worth checking more than one. Reviewing your own report has no effect on your score, so you can do it as often as you like, and spotting a fraudulent account early is what lets you dispute it before the debt grows.

Is a data breach the same thing as identity theft?

No, though one often leads to the other. A data breach is the moment an organisation loses control of your details — a leak of names, dates of birth, passwords or card numbers from a company's systems. Identity theft is what a criminal then does with that raw material: opening accounts, borrowing money or impersonating you. Being caught in a breach does not guarantee you will be defrauded, but it does raise the odds, so treat any breach notification as a prompt to change the exposed password, watch the affected accounts closely, and stay alert for the warning signs above rather than assuming nothing will come of it.

More From CheckAScam

Want more ways to stay safe?

Browse our full library of plain-English guides — how to spot fake shops, safe ways to pay, and how to get your money back if something goes wrong.

Browse the Guides