You review your credit report after a breach and find a lender inquiry from a date when you did not apply for anything.
First determine whether the inquiry is hard or soft
CFPB guidance divides credit inquiries into hard and soft inquiries. Hard inquiries commonly occur when a lender checks your report after you apply for credit, such as a credit card, auto loan, mortgage, refinance, or credit-limit request. Soft inquiries include things like your own report checks, some existing-account reviews, and prescreening. Soft inquiries do not affect your credit scores and are visible differently from hard inquiries.
That distinction changes the urgency. An unfamiliar soft inquiry may have a routine explanation, while a hard inquiry from a lender can signal that someone submitted a credit application using your information. Read the inquiry section carefully and write down the company name, date, and bureau before taking action.
Check your own recent applications before calling it fraud
A lender name on a credit report may not match the brand you remember. Retail cards can be issued by banks with different names, and a loan shopping process can involve companies you do not immediately recognize. Look at your calendar, email receipts, preapproval activity, apartment or utility applications, and any recent financing requests before concluding that the inquiry is unauthorized.
If the date lines up with something you did, contact the business using a verified number and ask what application produced the inquiry. If the date does not line up with any activity you recognize, move quickly to the identity-theft workflow instead of waiting for an account to appear.
Capture the inquiry exactly as it appears
Save the credit report page or PDF showing the inquiry. Record the bureau, company name, inquiry date, and any contact information printed with the entry. Do not rely on a screenshot that cuts off the date or the report source. A complete record helps you compare all three reports and explain the problem to the lender or bureau.
If you later discover a fraudulent account tied to the inquiry, the timeline becomes useful evidence: the inquiry may show when the application was attempted, while the new account may show when credit was actually opened. Keeping those facts separate avoids confusing the application event with the resulting account.
Contact the company through a verified channel
Use the company’s official website, a phone number from your credit report, or another trusted source to ask why it accessed your report. Do not call a number from a text message that suddenly arrives after you start investigating. Explain that you found an inquiry you do not recognize and ask whether an application exists in your name.
If the company confirms an application you did not submit, ask its fraud department what documentation it needs and request a reference number. Avoid volunteering unnecessary sensitive information before you have verified that you are speaking with the real company.
Report confirmed misuse at IdentityTheft.gov
CFPB directs identity-theft victims to IdentityTheft.gov, where the FTC provides an Identity Theft Report and recovery plan. Include the unauthorized application or inquiry you confirmed. The report can support later requests to correct credit information and can help create a consistent record across multiple companies.
If you only have an unexplained inquiry and the company has not yet confirmed what happened, you can still start documenting the issue. The important part is not to invent facts. Update your recovery file when you learn whether an account was opened, denied, abandoned, or still pending.
Dispute inaccurate information with the bureau
CFPB says consumers have the right to dispute errors on credit reports and generally should contact both the credit reporting company and the company that supplied the information. Explain what is wrong, why you believe it is wrong, and include copies of supporting records rather than sending original identity documents.
For identity theft, use the theft-specific instructions where available because they may differ from a routine factual dispute. Keep the dispute confirmation, upload receipt, or certified-mail record so you can show when the bureau received your request.
Freeze credit if new-account fraud is a realistic risk
A mysterious hard inquiry after a breach means someone may be testing whether they can obtain credit in your name. If you are not actively applying for new credit, place freezes with Equifax, Experian, and TransUnion while you investigate. A freeze helps prevent new creditors from accessing your reports, which makes new-account fraud harder.
The freeze does not remove the inquiry or close an account that is already open. Continue the lender and bureau cleanup even after the freezes are in place. Think of the freeze as a containment step while the dispute process handles existing damage.
Compare all three reports for the same application trail
One lender may pull only one bureau, while another application may produce activity at more than one. Review each nationwide credit report for additional inquiries, new accounts, unfamiliar addresses, and name variations. A single suspicious inquiry can be the first visible piece of a larger identity-theft pattern.
Do not assume the absence of an inquiry on one bureau proves nothing happened. Different lenders use different reporting companies. Build a short table of what appears on each report so you can tell which organizations need to be contacted.
Watch for a new account even after the inquiry is disputed
An inquiry can appear before the resulting account is reported. Continue checking your reports and lender correspondence for several weeks after you discover the problem. If a new account appears, contact the creditor’s fraud department and update your FTC recovery report with the account details.
Also monitor the primary email, phone number, and postal address tied to your financial identity. Fraudsters may intercept verification messages or change contact information while applying. Securing those channels can prevent the inquiry from turning into a successful account takeover or new-credit approval.
Example: an auto-lender inquiry you never authorized
Imagine your report shows a hard inquiry from an auto-finance company dated three days after a breach notice. You did not shop for a vehicle. You save the report, find the lender’s official fraud number, and learn that an online application was submitted using your name and SSN. The lender marks the application as fraudulent and gives you a case number.
You then report the identity theft at IdentityTheft.gov, freeze all three credit files, dispute the unauthorized inquiry with the affected bureau, and review the other reports for related activity. A week later, no new loan appears, but you keep monitoring because the attempted application shows that the exposed data was actually being used.



