Identity theft: recovery steps and honest advice on monitoring

    Identity theft usually begins with data you never chose to expose: a breached retailer, a leaked credential set, a stolen document. What decides how bad it becomes is how quickly you act once the first sign appears. This guide sets out the order of operations and explains what monitoring services can and cannot do.

    By Rui Matos · Cybersecurity Editor · Updated 18 September 2026

    The first hour

    Work from a device you trust. Change the password on your email account first, because it controls the reset of everything else, then sign out of all active sessions. Move on to your password manager, banking, and any account that shares the compromised password.

    Call your bank using the number printed on your card, not one supplied in a message. Freeze cards showing unfamiliar activity and ask what recall options exist for recent transfers, which shrink rapidly after the first day.

    • Email password and sessions first
    • Password manager and banking next
    • Bank called on a number you already trust
    • Screenshots and timestamps saved as evidence

    The first day

    Report the theft to the police or national fraud reporting service in your country and keep the reference number, because banks, insurers and credit bureaus will ask for it. Notify the credit reference agencies that operate where you live and ask about a fraud alert or credit freeze, which prevents new accounts being opened in your name.

    Check the recovery settings on every important account: forwarding rules, recovery phone numbers, backup email addresses and connected applications are the usual places an attacker leaves a way back in.

    The following weeks

    Review bank and card statements line by line for small test charges, which often precede larger ones. Watch for post that stops arriving, since redirected mail is a common tactic, and for unexpected letters about accounts you did not open.

    Replace any identity document that was stolen, and keep a written log of every call, reference number and response. Disputes are won with records.

    • Line-by-line statement checks for small test charges
    • Watch for missing post or unexpected account letters
    • Replace stolen identity documents
    • Keep a dated log of every contact

    What dark-web monitoring really does

    Monitoring services scan breach dumps, criminal marketplaces and forums for your email addresses, card numbers and identity details, then alert you when something appears. That is genuinely useful as an early warning, and services such as Norton, Bitdefender, Aura and NordProtect package it with recovery assistance and, in some markets, insurance.

    Be clear about the limits. Nothing can remove your data once it is circulating, alerts often arrive after the data has already been traded, and coverage of closed or private channels is partial. You are buying notice and help, not prevention.

    Is it worth paying for?

    The free foundation matters more than any subscription: unique passwords in a manager, strong second factors, a credit freeze where available and a habit of reading statements. Those cost nothing and prevent more harm than monitoring detects.

    A paid service is worth it when it includes restoration assistance, because the exhausting part of identity theft is the paperwork, or when you have already been a victim once and want faster warning next time.

    Frequently asked questions

    Can stolen data be removed from the dark web?

    No. Once circulating, it cannot be recalled. The realistic response is to invalidate what you can, such as passwords and cards, and monitor for misuse of what you cannot.

    Is a credit freeze better than monitoring?

    For preventing new fraudulent accounts, usually yes, and it is free or low cost where offered. Monitoring tells you after something happens; a freeze stops a common form of it.

    How long does recovery take?

    Simple card fraud can be resolved in days. Full identity theft involving loans or documents often takes months, which is why keeping a written log matters.

    Does identity theft insurance pay back stolen money?

    Usually it covers costs of restoration such as fees and lost wages rather than the stolen funds themselves, which are normally a matter for your bank. Read the policy limits closely.

    What is the single most effective free step?

    Unique passwords stored in a manager, with strong two-factor authentication on email. Credential reuse is behind the majority of account takeovers.