Identity Theft After a Scam
If you shared ID or personal data, act to prevent and limit identity theft.
Last reviewed: 1 August 2026
First 10 minutes
- List what personal data or documents you shared
- Secure your email and key accounts first
First 24 hours
- Contact credit reference agencies about a fraud alert or freeze
- Tell your bank and relevant providers your data may be compromised
- Report identity theft to the appropriate national service
- Replace compromised documents (ID, cards) through official channels
Contact your bank or payment provider
- Ask your bank to add extra verification and monitoring
- Watch for new accounts or credit opened in your name
Evidence to preserve
- Record what was shared, with whom, and when
- Keep copies of any fraudulent activity you spot
Secure your accounts and devices
- Reset passwords and enable 2FA everywhere
- Check for unfamiliar logins, devices, and forwarding rules in email
Report it
- Report to your national identity-theft / fraud service
- Notify credit reference agencies
- Report to providers of any misused accounts
If a scam involved sharing identity documents or personal details — a photo of your passport or driving licence, your date of birth and address, bank details, or a 'verification selfie' — treat that data as compromised from this moment on. That doesn't mean disaster is certain; much stolen data is never used. But identity theft has a long fuse: criminals sell data on, and misuse can surface months or even years after the original scam, when your guard is down. The goal now is to make your identity hard to use, and to create a record that protects you if someone tries.
Start with an inventory. Write down exactly what the scammer got: which documents, which numbers, which accounts, and when. This list drives everything else — and it's what banks, credit agencies, and police will ask for. Be honest with yourself about the worst case; it's better to over-protect than to discover later that the 'harmless' detail you left off was your date of birth.
Secure your accounts next, starting with email, because a compromised inbox lets a thief intercept the very alerts and reset messages you're about to rely on. Strong unique password, app-based two-factor authentication, then check forwarding rules, recovery contacts, and signed-in devices for anything you didn't add. Repeat for banking and any account that shares a password with a compromised one. While you're there, review the security questions on important accounts — if the scammer learned your mother's maiden name, first school, or pet's name, change the answers (they don't have to be true, only memorable to you).
Then put obstacles between the thief and new credit. Contact the credit reference agencies operating in your country and ask about fraud alerts and credit freezes. An alert tells lenders to take extra care verifying identity before approving applications in your name; a freeze goes further and blocks most new credit checks entirely until you lift it. A freeze is the stronger protection and usually costs nothing — the trade-off is a small delay when you genuinely apply for credit yourself. Where more than one agency operates, contact each one; they hold separate files.
Replace what was compromised. If card numbers were shared, your bank should reissue cards. If identity documents were photographed or sent, ask the issuing authority about replacement — in some cases the document number changes, which limits the stolen copy's usefulness — and report the document as compromised so it's flagged if presented. If your national identity or tax number was exposed, check whether your country's tax or benefits agency offers extra verification measures for fraud victims; several do, and enrolling early prevents the nastiest surprises, like a fraudulent tax refund claimed in your name.
Report the identity theft to the appropriate national service, even before any misuse appears. A report with a date on it is powerful: if fraudulent accounts surface later, you can show the compromise was reported at the time, which makes disputing them far easier. Keep the reference number with your inventory.
Then settle into monitoring, because vigilance is what catches the long fuse. Check bank and card statements regularly for transactions you don't recognise, however small. Review your credit report from each agency — look for accounts you didn't open, applications you didn't make, and addresses you've never lived at. Watch your post: both unexpected mail (statements for unknown accounts, debt letters, welcome packs) and the sudden absence of expected mail, which can indicate a fraudulent redirection. Treat calls or messages about 'your application' or 'your missed payment' for things you know nothing about as signals worth checking directly with the named organisation — via its official number, never the contact details in the message.
If you do find misuse — an account opened, a loan taken, a purchase made in your name — don't panic, and don't pay anything to make it go away. Contact the provider's fraud team, state that the account or transaction is fraudulent and that your identity was stolen, supply your report reference, and ask for it to be investigated and removed from your record. Put disputes in writing where you can, keep copies, and dispute any related marks with the credit agencies. It can take persistence, but the general principle in most places is that victims should not carry debts criminals ran up in their name — and the paper trail you started on day one is what makes your case. Expect targeted phishing too — criminals who hold your details can write convincing messages — and be rightly suspicious of anyone who contacts you offering to 'fix' your identity theft for a fee.
Frequently asked questions
I shared a photo of my ID — what should I do?
Assume it may be misused. Set up fraud alerts or freezes with credit agencies, monitor for accounts opened in your name, ask the issuing authority about replacing the document, and report to your national identity-theft service so there's a dated record of the compromise.
What's the difference between a fraud alert and a credit freeze?
A fraud alert asks lenders to verify identity more carefully before approving credit in your name; a freeze blocks most new credit checks entirely until you lift it. The freeze is stronger protection, usually free, and the only real cost is a small delay when you apply for credit yourself. Where several credit agencies operate in your country, set it up with each.
How long do I need to keep monitoring?
Longer than feels natural — stolen data is resold and misuse can appear months or years later. Make statement checks routine, review your credit reports periodically, and treat unexpected letters, missing post, or calls about unknown applications as prompts to investigate through official channels. A freeze left in place makes the long tail much safer.