Account safety · International; IdentityTheft.gov and credit-freeze references are US-specific

Identity theft after a scam: respond to the information you exposed

A password, passport copy and bank account number create different risks. Build a focused response rather than changing everything blindly.

By Stonebridge Resolution · Published 4 October 2026 · Updated 4 October 2026

An abstract identity card protected by overlapping translucent panels

AI-generated illustration; not a depiction of a real case.

The short answer

List what was exposed and secure the relevant accounts through official channels. In the US, IdentityTheft.gov can help create a recovery plan; credit protections and document-replacement processes differ by country.

Make an exposure inventory

Separate login credentials, card details, bank information, identity documents, national identifiers and wallet secrets. Record where they were sent and whether the scammer had remote access.

You do not need to copy the sensitive values into a new spreadsheet. A list of information types is enough to plan the response. Avoid creating another document that contains every credential an attacker would need.

Secure accounts that control other accounts

Start with email and any compromised password manager, then financial accounts. Use a clean device, change exposed or reused passwords and review recovery methods, forwarding rules and active sessions.

Enable available multifactor authentication and replace exposed backup codes through the provider's official process. If your phone number or mobile account may be compromised, contact the carrier through a trusted route as well.

Ask providers about financial safeguards

Contact card issuers and banks to report the exposure and ask whether replacement cards, account restrictions or other measures are appropriate. Review recent activity and report transactions you do not recognise.

In the US, a credit freeze can help restrict new-credit access, but it does not stop every form of identity misuse or fraudulent activity on existing accounts. Follow IdentityTheft.gov and official credit-bureau guidance rather than a paid monitoring advertisement.

Handle identity documents through the issuing authority

If a passport, licence or national identifier was shared, ask the issuing authority what reporting or replacement process applies. Requirements vary; automatic replacement is not always the right or available step.

Keep a record of the disclosure and any subsequent misuse. A document being exposed and a new fraudulent account being opened are related but distinct events, so report both accurately if they occur.

Maintain a recovery record without oversharing

Store complaint references, provider responses and disputed-account records securely. If an unfamiliar debt or account appears, use the relevant official dispute procedure and retain proof of your response.

Be cautious of unsolicited identity-restoration offers. A genuine recovery plan does not require you to email a complete set of identity documents, bank logins and wallet words to someone who found you after the scam.

Checklist

  • List exposed information types, not secret values.
  • Secure email and account recovery settings.
  • Notify banks, card issuers and document authorities.
  • Use official identity-theft and credit-protection guidance.

Common questions

Does a credit freeze protect my existing bank account?

Not by itself. It primarily concerns access to credit reports for new credit in the US; existing-account security requires separate action.

Should I send Stonebridge my passport to assess the risk?

No. Do not submit identity-document copies, passwords or wallet secrets through a general enquiry form.

Sources

Related guides

Find private, tailored next steps