You already found identity-theft activity and want a longer fraud alert than the standard one-year alert.
Use an extended alert only after identity theft is documented
An extended fraud alert is different from the one-year alert available when you merely suspect fraud. FTC guidance says the extended version is for people who have experienced identity theft and completed an FTC Identity Theft Report at IdentityTheft.gov or filed a police report. That documentation matters because the alert is tied to an established theft event, not just a general concern after hearing about a breach.
If a company only told you that your information was exposed and you have not found misuse, a credit freeze or one-year fraud alert may fit the situation better. Once you find an account, charge, inquiry, or other activity that was actually created with your identity, document it and use the recovery tools meant for identity-theft victims.
Know what the seven-year alert changes
A fraud alert does not block access to your credit report. Instead, it tells businesses reviewing your file that they should take steps to verify that the person asking for new credit is really you. The extended alert lasts seven years, which makes it useful when a thief has already shown that they can use your identity to apply for accounts.
That difference is important when comparing it with a freeze. A freeze limits access to the report until you lift or remove it, while an extended alert leaves the report available but adds a verification signal. Some people use both because they solve different problems: the freeze restricts new-credit access, while the alert adds an identity-verification instruction when access is permitted.
Create the FTC Identity Theft Report first
Go to IdentityTheft.gov and describe the misuse you actually discovered. The site can generate an FTC Identity Theft Report and a recovery plan. Keep the report as a PDF or printed copy because it can support several later steps, including blocking fraudulent credit information and requesting an extended fraud alert.
Be specific about the problem you are reporting. If the thief opened a card, made a loan inquiry, or used another account, include the facts you can verify rather than guessing about every possible consequence of the breach. A clean incident record is easier to reuse when a bureau, creditor, or collector asks for supporting documentation.
Contact a nationwide credit bureau through its official channel
FTC consumer guidance says you can contact one of the three nationwide credit bureaus—Equifax, Experian, or TransUnion—to place the extended alert. Use the bureau contact information linked from FTC or IdentityTheft.gov rather than a search ad, sponsored result, or link inside an unexpected email. You will need to verify your identity and provide the theft documentation the bureau requests.
Keep a screenshot, confirmation number, letter, or email showing when you submitted the request. Identity-theft recovery often requires repeated follow-up weeks or months later, and a dated confirmation can save time if a lender or bureau later says the alert is not showing the way you expected.
Give creditors a reliable way to reach you
IdentityTheft.gov explains that an extended fraud alert means potential creditors must contact you before issuing new credit in your name. That makes the contact information attached to the alert operationally important. Use a phone number or other contact method you control and can monitor reliably, especially if the identity theft involved your mobile account or primary email.
If the phone number itself has been compromised through a SIM swap or account takeover, restore that account before depending on it for verification. The point of the alert is to create a useful checkpoint. A contact method that a thief can intercept weakens the protection you are trying to add.
Do not treat the alert as a replacement for a freeze
The alert does not stop a lender from seeing your credit file. If your goal is to make new-account fraud harder while you are not applying for credit, a freeze is the stronger access control. FTC guidance says a freeze is free, lasts until you lift or remove it, and is available to anyone for any reason.
For a person already dealing with confirmed identity theft, the practical approach can be layered: keep freezes on the three bureau files, lift a freeze only when a legitimate lender needs access, and retain the extended alert as an additional instruction to verify your identity. The right combination depends on how often you need new credit and how much friction you can tolerate.
Expect separate confirmations and check your reports
After the request is processed, keep any confirmation each bureau sends. IdentityTheft.gov says credit bureaus send confirmation when an extended alert is placed. Review your credit reports afterward so you can see whether new suspicious activity appears even with the alert in place.
An alert is preventive, not a cleanup tool for fraud that already exists. If a fraudulent account or inquiry is already on a report, dispute or block that information using the identity-theft procedures that apply. Do not wait for the alert to somehow remove existing entries; it is designed to affect how future new-credit applications are handled.
Understand the prescreened-offer effect
FTC guidance says an extended fraud alert also causes the credit bureaus to remove you from marketing lists for unsolicited credit and insurance offers for five years unless you ask otherwise. That is separate from the seven-year duration of the alert itself.
Treat this as a side effect of the recovery tool, not as the main reason to use it. The core purpose is the verification signal on your credit file. If unwanted prescreened offers are your only concern and you have not experienced identity theft, use the normal opt-out tools rather than creating an identity-theft record that does not match your situation.
Update the recovery file when your contact details change
Seven years is a long time. You may change phone numbers, move, refinance a mortgage, or switch email providers while the alert is still active. Keep the alert confirmations with a simple recovery log that notes the date placed, the contact information you used, and later changes that might affect verification.
If you learn that a bureau has outdated information, use the bureau’s official support channel to correct the problem. Avoid sending identity documents to an address or upload page that you reached from an unsolicited message. The same theft that justified the alert can make you a more attractive target for follow-up phishing.
Example: combining an extended alert with a freeze
Suppose a thief opened a store card after your SSN was exposed. You report the theft at IdentityTheft.gov, save the FTC report, dispute or block the fraudulent account, and place freezes with all three bureaus. You then request an extended fraud alert so that if you later lift a freeze for a legitimate application, the lender still sees an instruction to verify you before issuing credit.
Six months later you apply for an auto loan. You ask the lender which bureau it will check, lift that freeze for the necessary window, watch for the lender’s verification contact, and then restore the freeze. This workflow uses each tool for the job it actually does instead of assuming one control solves every form of identity misuse.



