Situation

You discover a loan you did not open and need documentation for the lender and credit bureaus.

Know what the FTC report is for

IdentityTheft.gov is the federal government’s one-stop resource for identity-theft victims. The site asks what happened and uses the answers to create a personal recovery plan. It can also generate an FTC Identity Theft Report that supports later recovery steps.

The FTC does not individually adjudicate every consumer dispute. The value of the process is the formal report, tailored plan, forms, and record of what you reported.

Gather facts before opening the form

Have the names of affected companies, account identifiers you can safely reference, dates you noticed the problem, amounts or transactions involved, and any case numbers. You do not need to solve every detail before reporting, but a clean timeline makes the report more useful.

Keep sensitive documents nearby rather than copying everything into an unsecured note.

Describe the misuse, not just the breach

If you received a breach notice but have not seen misuse, the immediate response may be freezes, monitoring, and account security. If someone opened a loan, used a card, filed a tax return, or created another account in your name, describe that actual event in the identity-theft report.

Specific misuse lets the recovery plan point you toward the institutions and letters that matter.

Save the report and track each recovery step

Download or print the FTC Identity Theft Report and store it securely. If you create an account on IdentityTheft.gov, the service can help track progress and pre-fill forms and letters.

Use your own incident log alongside the federal plan so you can record phone calls, mailing dates, upload confirmations, and responses from companies.

Use the report where the process calls for it

Credit bureaus and creditors may request an identity-theft report as part of blocking or fraud-resolution procedures. The CFPB specifically describes using an identity theft report, proof of identity, and a letter identifying fraudulent items when asking a credit reporting company to block identity-theft information.

Do not send your full report to unrelated companies simply because it exists. Provide it where a verified recovery process requires it.

Use precise categories and dates in the report

Describe the account or transaction that was actually fraudulent, not only the company where your information was breached. Include the date you discovered the misuse, the institution involved, and the type of identity information used when known. If there are multiple fraudulent accounts, list them separately so the recovery plan can address each one.

If an amount is disputed, use the amount shown in the current statement or credit report and note that it may change. Avoid guessing at losses you have not verified.

Create an account only if you want the tracking features

IdentityTheft.gov can provide the federal recovery flow and offers account-based features that help track steps and pre-fill forms. Read the site’s privacy information before deciding how much information to provide and whether to create an account. Store the login with the same care you use for other identity-related accounts.

Whether you create an account or not, save the FTC Identity Theft Report and any letters you generate. Those files can be needed long after the browser session ends.

Update your own incident log when institutions respond

The federal recovery plan organizes recommended actions, but your personal log should capture what actually happened: who received a dispute, when a bureau confirmed a block, when a creditor closed an account, and what follow-up date was promised. This prevents unresolved tasks from disappearing among completed ones.

If a new fraudulent account appears later, add it to the incident record and update the recovery process rather than assuming the original FTC report permanently covers every future event without additional documentation.

What to prepare before opening IdentityTheft.gov

Make a short list of each fraudulent event: the company, account or transaction type, date discovered, amount if known, and the case number from the institution. Keep statements and credit reports nearby so you can describe the activity accurately. If the theft involved several systems—such as a loan, a credit card, and tax fraud—separate those events rather than collapsing everything into one vague statement.

Use a device and network you trust, type IdentityTheft.gov directly, and follow the questions about what happened. Read the privacy information before deciding how much optional information to provide or whether to create an account. When the process generates an FTC Identity Theft Report and recovery plan, download or print them immediately and store them in your incident folder.

Then convert the plan into a task list. Mark which creditor needs a fraud packet, which bureau needs a block request, whether a police report is required by any recipient, and which accounts must be secured. Add dates and confirmation numbers as each step is completed. The FTC report is most useful when it becomes the organizing document for real follow-up rather than a file that sits unopened after submission.

  • Use verified amounts and dates where possible.
  • Save the FTC report immediately.
  • Keep each fraudulent account as a separate recovery task.
  • Record mailing or upload confirmations.
  • Update the incident log when new misuse appears.

Keep the report usable

Store the FTC Identity Theft Report somewhere you can retrieve it without exposing it to shared household folders, work drives, or public cloud links. When a creditor or bureau asks for a copy, verify the destination first and send only through the process that institution documents. If your situation changes, keep the original report and add new records rather than overwriting the first version. A clean chronology is valuable because identity-theft recovery often involves several organizations working on different timelines.

Primary sources used

Check the official source before you submit sensitive information.