You are here: I think my identity was stolenThe FTC Identity Theft Report: What It Is and How to Use It
I think my identity was stolen

The FTC Identity Theft Report: What It Is and How to Use It

The FTC Identity Theft Report is a formal record created through IdentityTheft.gov that can support specific recovery rights and requests.

The FTC Identity Theft Report: What It Is and How to Use It — editorial illustration
By Simone Baptiste · Consumer Identity & Security Writer · Published 2026-09-03 · Updated 2026-09-07
This guide summarizes official consumer and security sources. It is not individualized legal advice, and state-specific breach, court, medical, or regulatory duties can require professional review.

The FTC Identity Theft Report is created when you report identity theft through IdentityTheft.gov. It is more than a generic complaint receipt: in the right context it can help support a request to block identity-theft information from a consumer report and a request for transaction or application records connected to fraud. Its value depends on accuracy. State only what you know, save the report number and a copy, and make later letters consistent with the facts you originally reported. The report is a foundation for recovery paperwork; it does not automatically close accounts, erase credit entries, or replace every police or agency report.

What the report actually proves

The report records your statement that identity theft occurred and the details you provided to the FTC. It does not independently prove that every disputed transaction was fraudulent, and it does not tell a bank exactly how to resolve its own investigation. Think of it as a standardized identity-theft record that other processes can rely on. When you send it to a bureau or creditor, pair it with a clear request: identify the item you want blocked, the records you want produced, or the account you say was opened without your authorization. A report without a specific requested action often creates another round of correspondence.

IdentityTheft.gov also provides a recovery plan. Use that plan as a task list, but preserve your own chronology as well. A plan can tell you what category of action comes next; your log should show the account number fragment, date, representative, reference number, deadline, and outcome. Those are the details that become important when several organizations are handling the same incident on different clocks.

For example, suppose one unfamiliar card appears on two credit reports and a lender confirms an application was submitted in your name. The FTC report should describe that account and the facts you can support, while the bureau packet should identify the exact tradeline to block. The lender request is different again: it can ask for the application or transaction records associated with the fraudulent account. Using the same factual core in three narrowly worded requests is stronger than sending one large narrative to every organization and expecting each recipient to decide what you want it to do.

Avoid believing that an FTC report is a finding by the government that every listed event definitely happened as described. The report records your identity-theft statement and supports specific recovery processes; it does not replace the creditor’s records or the bureau’s review of the item you identify. That is why unsupported theories about where the thief obtained your data do not help. The useful part is the stable set of facts: the account, date, notice, transaction, or report entry that you can point to. Keep those facts consistent even when your understanding of the incident grows later.

Build the report from evidence, not from assumptions

Before submitting, gather the fraudulent statement, credit-report entry, breach notice, collection letter, rejected tax return, or account-opening email that triggered the report. Write down dates exactly as they appear. If you do not know how a thief obtained your SSN, say that you do not know rather than inventing a breach source. If you know an account is unfamiliar but cannot yet see the application, describe it that way. Precision is more useful than certainty you cannot support.

After filing, save the generated report in a durable location. Give the file a date and incident name instead of leaving it in a downloads folder. Keep a second copy of important supporting records. If you later discover a second fraudulent account, add that new evidence to your recovery file and follow the current IdentityTheft.gov instructions for updating or creating the documentation needed for that issue. Avoid rewriting old facts in a way that makes later packets contradict each other.

The workflow changes when the first report is accurate but incomplete because a second account appears later. Do not rewrite the chronology as though you knew about both on day one. Preserve the original report and add a dated note showing when the second account was discovered, then follow the current IdentityTheft.gov process for the additional issue. That approach makes later packets easier to audit. A bureau, creditor, police department, or regulator can see what was known at each stage rather than trying to reconcile two documents that appear to contradict each other only because the newer facts were backdated into the older story.

Where the report can change the credit-report process

A normal accuracy dispute and an identity-theft block are not identical. CFPB guidance explains that a consumer reporting company must block qualifying identity-theft information within four business days after it receives the required package, which includes proof of identity, an identity-theft report, identification of the fraudulent information, and a statement that the information is not related to a transaction by the consumer. That is a specific remedy with specific prerequisites. If you are only disputing a billing error or stale balance, the ordinary dispute process may be the correct tool instead.

For a block request, make the packet easy to audit. Highlight the tradeline or inquiry, state that it resulted from identity theft, include the FTC report, and retain proof of delivery or portal submission. If the bureau asks for missing information, respond to the missing item rather than resending a pile of unrelated documents. The goal is to make the relationship between the report and the item unmistakable.

UseWhat to attach or preserveWhat not to assume
Credit-report identity-theft blockFTC Identity Theft Report, proof of identity, marked report item, written requestThat a normal accuracy dispute automatically invokes the identity-theft block rule
Fraudulent account recordsReport plus the creditor’s required identity documents and a precise description of the application or transactionThat the FTC itself will retrieve the creditor’s records for you
Police report supportFTC report, identification, statements, screenshots, mail or account evidenceThat every police department uses the same intake process
Recovery chronologyA stable copy of the report and dated notes for later discoveriesThat the first report must predict facts you had not yet learned

Record requests can reveal how the fraud happened

Federal law gives identity-theft victims a route to request certain business records relating to transactions or accounts resulting from identity theft. The FTC report can be part of that request. Ask for the actual application, signature records, addresses, phone numbers, device or order information that the company is permitted to provide under the process. Those records can help identify where an account was opened, whether an old address was used, and which other organizations may need notice. Do not expect a creditor’s fraud department to volunteer the records automatically; a recovery decision and a records request are different tasks.

When a police report still matters

Some creditors, motor-vehicle agencies, courts, employers, or state programs may ask for a police report. Physical document theft, mail theft, criminal impersonation, and local records are also situations where law enforcement may have a distinct role. The FTC report does not make that local process unnecessary. Instead, it gives you a concise factual starting point. Bring a copy and supporting documents, ask for the local case number, and keep the officer or agency name if one is provided.

Treat the FTC report as a reusable evidence anchor

Track outgoing packets the same way you would track any multi-recipient dispute: a short log with the date sent, the recipient, the specific ask, and the method of delivery. Note whether a submission was online, mailed, or handed to an officer in person, since that affects what proof of delivery you can later produce. When a recipient responds, file that response next to the log entry instead of in a separate folder by date received. A reviewer who picks up the file later should be able to see which request produced which outcome without re-reading every attachment.

Questions specific to The FTC Identity Theft Report: What It Is and How to Use It

Can I get an FTC Identity Theft Report without creating an account?

IdentityTheft.gov provides the reporting and recovery workflow. Account features can help you save and return to a plan, but follow the site’s current prompts because the exact workflow can change. Always save the report or confirmation you receive.

Does the FTC Identity Theft Report automatically remove fraudulent credit items?

No. It can support an identity-theft block request, but you still have to identify the fraudulent information and provide the bureau with the required package. The report is evidence for the request, not an automatic deletion command.

Should I change details in the report if I learn something later?

Preserve the original facts and document later discoveries with dates. If IdentityTheft.gov provides a way to update the matter, follow that workflow, but avoid making old and new documents conflict without an explanation.

Why would a creditor need the FTC report if it already closed the account?

Closing the account stops further use, while later tasks may involve correcting consumer reports or obtaining application and transaction records. The same incident can therefore require different documents at different stages.

References used for this guide