The first hour
Work from a device you trust. Change the password on your email account first, because it controls the reset of everything else, then sign out of all active sessions. Move on to your password manager, banking, and any account that shares the compromised password.
Call your bank using the number printed on your card, not one supplied in a message. Freeze cards showing unfamiliar activity and ask what recall options exist for recent transfers, which shrink rapidly after the first day.
- Email password and sessions first
- Password manager and banking next
- Bank called on a number you already trust
- Screenshots and timestamps saved as evidence
The first day
Report the theft to the police or national fraud reporting service in your country and keep the reference number, because banks, insurers and credit bureaus will ask for it. Notify the credit reference agencies that operate where you live and ask about a fraud alert or credit freeze, which prevents new accounts being opened in your name.
Check the recovery settings on every important account: forwarding rules, recovery phone numbers, backup email addresses and connected applications are the usual places an attacker leaves a way back in.
The following weeks
Review bank and card statements line by line for small test charges, which often precede larger ones. Watch for post that stops arriving, since redirected mail is a common tactic, and for unexpected letters about accounts you did not open.
Replace any identity document that was stolen, and keep a written log of every call, reference number and response. Disputes are won with records.
- Line-by-line statement checks for small test charges
- Watch for missing post or unexpected account letters
- Replace stolen identity documents
- Keep a dated log of every contact
What dark-web monitoring really does
Monitoring services scan breach dumps, criminal marketplaces and forums for your email addresses, card numbers and identity details, then alert you when something appears. That is genuinely useful as an early warning, and services such as Norton, Bitdefender, Aura and NordProtect package it with recovery assistance and, in some markets, insurance.
Be clear about the limits. Nothing can remove your data once it is circulating, alerts often arrive after the data has already been traded, and coverage of closed or private channels is partial. You are buying notice and help, not prevention.
Is it worth paying for?
The free foundation matters more than any subscription: unique passwords in a manager, strong second factors, a credit freeze where available and a habit of reading statements. Those cost nothing and prevent more harm than monitoring detects.
A paid service is worth it when it includes restoration assistance, because the exhausting part of identity theft is the paperwork, or when you have already been a victim once and want faster warning next time.
