Situation

A lender mails a welcome letter for a personal loan you never requested, and a hard inquiry appears on one of your credit reports.

Confirm the lender and account without activating anything

Start by treating a lender account opened in your name without your application as a specific response problem rather than as proof that every part of your identity has been taken over. A confirmed lender account means stolen identity data moved beyond exposure into a new-credit application, so the response should be faster and more formal than routine monitoring. Independently verify the lender’s contact information and confirm the application date, product type, balance, mailing address, and whether funds were disbursed.

Hang onto the physical or digital notice, log the date, and confirm which account or data type it points to before taking further action. Do not activate a card, sign loan documents, or use an account simply to access details; tell the lender it is unauthorized and ask for the fraud process.

Reach the lender's fraud department through a number or website you independently verify. Ask for the account opening date, product type, application channel, mailing address, and any non-sensitive details it can share while the fraud review begins. Do not rely on the phone number in an unexpected text claiming to be the lender's security team.

Tell the fraud department you did not make the application

Prioritize the action that shuts down the most urgent path to misuse. Ask the lender to freeze or close the fraudulent account and prevent additional disbursement or account use while it investigates.

Do not try to solve every possible consequence at once. Place freezes with all three nationwide credit bureaus to make additional new-credit applications harder while the incident is active.

State clearly that you did not apply for or authorize the account. Ask the lender to stop further use, flag the application as disputed, and tell you what documents are required. Obtain a case number and request written confirmation when the investigation closes; that result can be important if the account also appears on a credit report or reaches collections.

Freeze new-credit access while the application is investigated

Here, the lender controls the application and account records, while each credit bureau controls the inquiry or tradeline in its own file.

A document request is not automatically legitimate — verify it before uploading anything sensitive. Send identity-theft documentation through the lender’s verified fraud channel and retain a copy of every submission and case number.

Pull all three credit reports and look for the account, a related hard inquiry, or other products opened near the same date. An identity thief may submit multiple applications in a short window. Freeze your reports if new-credit fraud is a realistic risk so the investigation does not run in parallel with additional applications.

Match the account to inquiries and bureau records

Credit freezes solve a specific problem — new-account fraud — so they only apply when that risk is present. CFPB explains that identity-theft information can be blocked from a consumer report when the required identity theft report, proof of identity, and identifying letter are provided.

If credit monitoring fits this situation, anchor it with a dated report from annualcreditreport.com first. Check all three reports for related inquiries, addresses, accounts, or variations of the same creditor name.

Ask for records that can document how the account was opened

The paper trail being built here directly supports resolving the situation, not just logging it. IdentityTheft.gov notes a right to request documents related to identity theft; those application records can help clarify the address, contact information, or channel used by the thief.

Once misuse actually happens, the process pivots to identity-theft recovery rather than continued monitoring for risk. Create an FTC Identity Theft Report and add the fraudulent lender account to the recovery plan so the lender and bureaus receive consistent documentation.

Create an FTC Identity Theft Report once the fraudulent application is confirmed or you have concrete misuse to report. Keep it with the lender's application records, correspondence, and bureau disputes. Consistent dates and identifiers make it easier to show that several report items came from the same unauthorized application.

Closing the account does not automatically clean the credit file

One control rarely fixes everything here. A lender can close its account while a hard inquiry, collection record, or sold debt remains elsewhere, so each downstream record requires confirmation.

Also separate exposure from confirmed misuse. A preapproval or marketing offer is not the same as an opened account, so confirm the account status before initiating a full fraud dispute.

Avoid fake “loan cancellation” messages

Expect follow-up scams that use this same pretext. Impostors may contact you after a lender notice and offer to “cancel” the loan if you send a fee or move funds through another account.

A legitimate recovery process should be verifiable through an established channel. Call the lender through its published customer or fraud number and ignore any demand to pay to prove that you are the victim.

Verify the account, inquiry, and balance all reach zero

Memory fades faster than these timelines require, so put follow-up dates on a calendar instead. Obtain written closure, then recheck credit reports and any lender portal for zero balance, no active account, and corrected inquiry or tradeline status.

The lender incident is closed when the account cannot be used, no balance is attributed to you, and the consumer reports reflect the identity-theft correction.

After the lender says the account is closed, verify the downstream effects. Check that the balance is not being billed, the account is not still reporting as yours, and a collection agency has not received it. A fraud determination is the beginning of cleanup, not the final proof that every reporting system has been corrected.

Primary sources used

Check the official source before you submit sensitive information.