Situation

You have spoken with a bank, a lender, a credit bureau, and the FTC, but the case numbers and promised follow-up dates are scattered across texts and notes.

Build one timeline before the case branches into ten companies

Start by treating the records you keep during identity-theft recovery as a specific response problem rather than as proof that every part of your identity has been taken over. Identity-theft recovery often fails administratively when the victim cannot reconstruct who was contacted, what was sent, or what a company promised. Start with original evidence such as the breach notice, fraudulent bill, credit report, lender letter, or bank statement and keep those separate from your own summaries.

Before contacting anyone about them, save the notice, note when you received it, and write down the exact data element or account it says was involved. The goal is not to store every email forever; it is to preserve documents that show the event, your response, and the organization’s resolution.

Build one incident timeline before the paperwork spreads across email, portals, and phone notes. For each event, record the date, organization, problem, action taken, case number, and promised next step. A chronological log makes it easier to see which correction is overdue and prevents the same explanation from being reconstructed differently for every company.

Separate source documents from your own incident notes

Prioritize the action that closes the fastest route to misuse first. Create a simple timeline with date, organization, department, channel, case number, action requested, and next expected event.

Do not try to solve every possible consequence at once. Capture an account or report before it changes, especially when an online portal may remove old alerts or a company may reverse a transaction later.

Keep source documents, not just summaries. Save the breach notice, credit-report pages, bank statements, bills, collection letters, security alerts, and written investigation results that relate to the identity theft. When a portal only shows information temporarily, download a PDF or take a screenshot that includes the date and enough context to identify the account.

Track every organization, case number, and promised date

Each company should have its own small subfolder or label so a bureau dispute is not mixed with a bank transaction case or FTC recovery plan.

When an organization asks for identity documents during recovery, verify the destination before uploading anything. When you submit documents, save the upload receipt, certified-mail tracking, portal confirmation, or other proof showing when the organization received them.

Separate sensitive originals from the working file you use for calls. A masked account number or last four digits are usually enough in ordinary notes. Store full SSNs, passport scans, licenses, tax forms, or medical records only where they are actually required, and avoid repeatedly attaching the same identity document to unverified email threads.

Save report versions before disputes change them

A credit-report review is warranted here only if the leaked information could support a new-credit application. Save baseline and post-dispute credit reports with dates so you can show whether a fraudulent account, inquiry, or address was removed and whether it later returned.

Where credit monitoring is warranted, don't skip the baseline — a dated report from annualcreditreport.com comes first. Use reminders based on the company’s stated response period instead of repeatedly checking every account with no schedule.

Keep delivery proof for letters and uploaded documents

What gets written down now is part of solving the problem, not paperwork saved for a rainy day. CFPB and IdentityTheft.gov materials repeatedly emphasize keeping copies and notes of communications, which helps if the same debt or account resurfaces.

The response changes shape entirely once misuse is confirmed — from watching for risk to recovering from it. Keep the FTC Identity Theft Report and recovery plan with the incident file, but do not distribute it to every organization unless that organization’s process calls for it.

Track outbound submissions. Note what you sent, to whom, through which official channel, and when. Keep certified-mail receipts or portal confirmations where relevant. If a bureau, lender, collector, or agency later says it did not receive a document, proof of delivery can be as important as the document itself.

Avoid creating a new security problem with the recovery file

One control rarely fixes everything here. An incident file is sensitive because it can contain identifiers, balances, addresses, and fraud details, so storage security matters as much as completeness.

Also separate exposure from confirmed misuse. Screenshots without dates, account numbers, or context can be hard to interpret months later, so add a short label explaining what each image proves.

Record outcomes, not just outgoing requests

Expect follow-up scams that reference this kind of paperwork. Fake “recovery specialists” may ask you to upload the entire file to a new portal or send originals by email.

A legitimate recovery process should be verifiable through an established channel. Share only the subset of documents required by a verified organization and keep originals under your control.

Archive the file after the urgent work is over

The initial response wraps up with scheduled reminders, not an intention to keep track mentally. After each resolution, add the written closure, zero-balance letter, corrected report, or final bank notice and mark the issue closed on the timeline.

You can archive the active file when every open issue has a final status and future monitoring dates are on a calendar rather than hidden in correspondence.

Do not throw the file away immediately after the first correction. Durable identifiers can be misused again, and a previously corrected debt or account can resurface. Retain the records long enough to cover promised correction cycles and future follow-up, then dispose of unnecessary sensitive copies securely rather than leaving them in ordinary trash or abandoned cloud folders.

Use a status field for every open task: reported, documents sent, under investigation, corrected, or needs follow-up. Add the promised response date beside each item. This turns the recovery file into a working dashboard rather than an archive you only open after something goes wrong. When an organization closes a case, save the written outcome before marking it complete. If the correction affects a credit report, bank balance, carrier account, tax record, or medical file, verify the underlying record itself after the stated processing period; a closure email is useful evidence, but the corrected system is the result you actually need.

Primary sources used

Check the official source before you submit sensitive information.