Identity theft remediation

Someone Opened an Account With Your Phone Number. Here Is What You Can Actually Do.

You did not authorize it and you want a name. The blunt truth is that a private citizen rarely gets one directly. What federal law does give you is faster and more useful than a name: the power to stop the account cold, wipe it off your file, and compel the business that opened it to hand over the paperwork behind it. This page walks that ladder in the order the statutes let you climb it.

Every deadline read at the statute We never name a suspect Records routed to police, not rumor
4Business days for a bureau to block theft entries
30Days for a business to produce the fraud records
7 yrsLength of an extended fraud alert
1Business day to place a freeze by phone or online

The short version

You probably will not learn the person’s name yourself, and any site promising otherwise is selling you something. What you can do, in this order, is: place a fraud alert so a lender has to verify identity before opening anything else in your name; freeze your credit and separately freeze the telecom file that carries phone accounts; file the report at identitytheft.gov and, if you can, a police report, because those two documents unlock everything below; demand a block of the fraudulent entries; and then send a written records request to the business itself, which has thirty days to give you the application it accepted. That last step is the closest thing to an answer, and almost nobody knows it exists.

Watch: the remedy ladder, in the right order

Sixty-seven seconds on why the sequence matters. Filing the reports before you demand records is what makes the demand enforceable.

Victim briefing

One sentence, two completely different emergencies

Before you do anything else, work out which of these happened to you. The remedies barely overlap, and doing the wrong one first wastes the hours that matter most.

The phrase “someone opened an account with my phone number” gets used for two events that have almost nothing in common. The first is impersonation: a stranger walked into a store or filled in a web form as you, and put your mobile number on the application as the contact detail, because a working number makes an application look real and because it is where the one-time codes will land. The account is new, it is in your name, and your own phone still works normally. The second is takeover: your existing number itself was moved, either onto a SIM card the thief controls or across to a different carrier entirely. Here the tell is the opposite – your handset drops to no service, sometimes in the middle of an ordinary afternoon, and the codes start landing on someone else’s device.

If your phone still has signal and the problem is a bill, a welcome letter, or a collection call for a service you never bought, you are in the first case and the rest of this page is written for you. If your phone has gone dead and you cannot get a signal back, stop reading and call your carrier from another line right now, because every minute the number is in someone else’s hands is a minute they can reset a password on an account you own. The people who chase the perpetrator side of that scenario are handled on our page about tracing a SIM swap after the number has already moved; we will not duplicate it here.

The takeover case has federal rules written for it that are worth knowing even if it is not what happened to you, because they describe what a carrier’s port-out process is meant to look like. Under the FCC’s number portability rules for wireless providers, a carrier is to use secure methods to authenticate a customer that are reasonably designed to confirm the customer’s identity before effectuating a port-out request, to review and update those methods at least annually, and to train its staff specifically on fraudulent port-out attempts and on recognizing when a caller is a victim rather than a customer. One qualification matters, and it is the reason we phrase that as a standard rather than a live obligation: as that section currently reads, compliance is not required until its final paragraph is removed or given a compliance date. It is still the benchmark the FCC has set, and a port that happened without those safeguards is a fact worth putting in writing to the carrier.

Impersonation is the far more common of the two and the more frustrating, because nothing dramatic happens. There is no dead handset, no alarm. There is a letter, or a text, or a call from a collections desk, and it arrives weeks or months after the account was opened. By then the trail has cooled and the thief has usually moved on. What follows is how to make the cold trail work anyway. If you want the wider survey of what an exposed number enables in the first place, we keep that on a separate page about the ways a phone number gets used against its owner.

Read the notice you already got – it is more informative than it looks

Most victims are holding a text or an email that told them almost nothing. There is a reason it was written that way, and knowing the reason tells you what to ask for.

Three messages typically arrive, and each one means something different. A verification code you did not request means somebody had your number in a form and hit submit; it does not mean they got in, and if you did nothing with the code they probably did not. A “welcome to your new account” message means an account was actually created, which is far worse, and the timestamp on that message is the single most valuable piece of evidence you own. A collections call for a service you never bought means the account was created some time ago, ran up a balance, went unpaid, and has now been sold or referred; ask the caller in writing for the original creditor’s name and the account number, because you will need both.

There is a fourth message that confuses everyone: a bare notice from your own carrier that something on your account changed, with no detail about what. That vagueness is required. Under the FCC’s safeguards on customer proprietary network information, a carrier must notify you immediately whenever a password, the answer to a back-up authentication question, an online account, or the address of record is created or changed – and the rule expressly says the notification must not reveal the changed information and must not be sent to the new account information. In other words, the notice was deliberately uninformative and was deliberately sent to your old contact details, so that a thief who had already changed them would not receive it and you would. It is a tripwire, not a report. Treat it as confirmation that something moved, and call the carrier to find out what.

What this page does not do is help you work out which apps and services your number is registered to across the internet, which is a different question with a different method. That belongs to our guide on auditing the online accounts attached to a phone number, and it is genuinely worth running afterwards – not because it identifies the thief, but because it shows you which of your own logins still use the compromised number for recovery.

Why your credit report came back clean

A great many victims pull all three credit reports, find nothing, and conclude they imagined it. The account is usually real. It is filed somewhere else.

A mobile, cable, or utility account is not a credit account in the sense the three big bureaus were built for. It generally does not appear on your Equifax, Experian, or TransUnion file at all unless and until it goes bad and gets charged off or handed to a collection agency. Up to that point the account can be live, accruing charges in your name, and completely invisible on the report everyone tells you to check first. That is the single most common reason a victim of phone-account fraud believes nothing happened.

The file that does carry it is the National Consumer Telecom & Utilities Exchange. The CFPB’s entry for NCTUE describes it as a consortium of member companies that collects and shares information on new telecom and utility connect requests, along with paid-as-agreed and past-due account and payment histories, across telecommunications, pay TV, and utility service; Equifax Information Services is the contracted servicer that manages the database on the members’ behalf and is not itself a member. Two details on that page matter enormously to you: the company will provide one free report every twelve months on request, and it will freeze your consumer report if you ask. A connect request is exactly the event you are trying to find.

Here is the part almost no consumer article mentions. The free annual file everyone knows about comes from a specific corner of the statute, and telecom is not in it. Section 1681j of the Fair Credit Reporting Act guarantees a free annual disclosure from the nationwide credit bureaus and from “nationwide specialty” agencies, and that specialty category is confined by definition to medical records or payments, residential or tenant history, check writing history, employment history, and insurance claims. A telecom exchange is none of those. But the same section carries a much broader key at subsection (c)(3): any consumer reporting agency must give you a free file disclosure once in any twelve-month period if you certify in writing that you have reason to believe your file with them contains inaccurate information due to fraud. That sentence reaches specialty databases the annual-report route never touches, and a one-paragraph written certification is all it takes to use it.

So the honest search order is: all three credit files, then the telecom and utility exchange, then any specialty database plausibly connected to the kind of account you are chasing – a check-writing or deposit-account database such as ChexSystems if a bank account is involved, for instance – each of them approached under subsection (c)(3) with your written fraud certification attached. If you are trying to work out how your number got into circulation in the first place, that provenance question is covered separately in our guide to checking whether a phone number has been exposed.

Five remedies, and what each one really buys you

They are not alternatives. They stack, and the order matters, because two of them require documents that only the others produce.

RemedyWhat it actually doesWhat it does not do
Written records request to the businessForces the company that opened the account to send you, or a law enforcement agency you name, the application and transaction records it holds, free, within thirty days of receiving a compliant request Closest to an answerDoes not identify anyone for you. The business may decline in good faith on limited grounds, or answer that a diligent search found no such records
Initial fraud alertSits on your credit file for at least a year and obliges a prospective lender to form a reasonable belief it knows who is applying; if you gave a phone number for verification, it must call you on it before opening new creditDoes not stop anything by itself. It is a duty on the lender, not a lock, and it does not reach telecom or utility applications
Extended fraud alertRuns seven years instead of one, and additionally keeps you off prescreened credit and insurance offer lists for fiveCannot be placed on a suspicion alone. It requires an identity theft report, which means you have to file with the FTC or the police first
Security freezeBars the bureau from releasing your report at all. Free, placed within one business day when you request it by phone or secure electronic means, and lifted within one hour the same wayDoes not apply to existing creditors reviewing your accounts, to collection agencies working an existing debt, or to court and government requests
FTC report and police reportTogether they are the identity theft report that the block and the records request are built on, and the police report is the route by which anyone becomes authorized to investigate the person behind the accountFiling does not open an investigation. Most reports are recorded rather than worked, and no agency will report back to you on a suspect
Block of the fraudulent entriesOnce a bureau has your identity proof, a copy of your identity theft report, your identification of the specific entries, and your statement that they do not relate to any transaction of yours, it must block the reporting of those entries within four business days and notify whoever furnished them. It is the fastest hard stop on this list – and it can be rescinded if the bureau later concludes the block was requested on a material misrepresentation, so keep your statement precise and true.

The durations and deadlines above come from the fraud alert and national security freeze provisions of the Fair Credit Reporting Act, which set the one-year initial alert, the seven-year extended alert with its five-year prescreen exclusion, and the freeze timings and exceptions. Where a case needs more than form-filling – working out which corporate entity actually holds the records and where a written demand has to be posted to be effective – that is the kind of public-records legwork we do, and it is described honestly further down this page.

The records request most victims never hear about

It is the only provision on this page that points at the fraud itself rather than at your file. Used properly, it puts the thief’s own application in your hands.

Buried in section 1681g of the Fair Credit Reporting Act, at subsection (e), is a right that belongs to victims rather than to consumers generally. For the purpose of documenting fraudulent transactions resulting from identity theft, a business entity that provided credit, goods, services, or accepted payment from a person who allegedly made unauthorized use of your means of identification must provide a copy of the application and business transaction records evidencing that transaction. It is free. The deadline is not later than thirty days after the entity receives a compliant request. And the records can go to you, or to a federal, state, or local law enforcement agency you specify in the request, or to an agency already investigating that you authorize to receive them.

The procedural conditions are strict and they are where most requests die. The request has to be in writing and mailed to an address the business specifies, if it has specified one. You have to prove who you are – a government-issued identification card, or personally identifying information of the same type the impostor supplied, or the sort of information the business normally asks new applicants for. You also have to prove the claim: a copy of a police report evidencing your claim, and a properly completed identity theft affidavit, either the standardized one the Bureau makes available or another affidavit of fact the business will accept. If the business asks, include the date of the application or transaction and any account or transaction number, to the extent you know them or can readily get them. That is why the FTC report and the police report come first in the ladder; without them this request has no legs.

Two provisions in the same subsection are worth knowing because businesses sometimes get them wrong. First, financial-privacy law is not a defense: the statute states plainly that the Gramm-Leach-Bliley provisions prohibiting a business from disclosing financial information to third parties may not be used to deny disclosure to the victim under this subsection. If a company tells you it cannot send the file because of financial privacy rules, that is the specific argument Congress foreclosed. Second, the entity may decline in good faith on a short list of grounds – that the subsection does not require the disclosure, that after reviewing your proof it lacks a high degree of confidence in your identity, that the request rests on a misrepresentation of fact, or that what you asked for is internet navigational data about someone’s visit to a website. Nothing else is on that list.

Set your expectations at the right level. The subsection creates no new obligation to keep records the business would not otherwise have kept, and it gives the business an affirmative defense if it made a reasonably diligent search and the records simply do not exist or are not reasonably available. Retail and prepaid channels are especially thin. What you get when it works is the application as submitted, the transaction records, and whatever the company captured at the point of sale – the paperwork, not a name and address you can act on. The right way to use it is to name a law enforcement agency as a recipient in the request itself, so the material lands with people who can lawfully do something with it, at the same time it lands with you.

Once you have your identity theft report, the block is the fastest thing you can do to your file: section 1681c-2 gives a bureau four business days from receiving the four required items to block the reporting of the entries you identify, and requires it to tell the furnisher that a block has been requested and when it takes effect. The report itself is generated at the Federal Trade Commission’s identity theft reporting site, which also produces the affidavit you will attach to the records request. Do that first, then everything else has something to stand on. If your interest runs past remediation and into attribution – how a paper trail becomes a person, and when it realistically can – that is the subject of a separate guide on identifying the person behind an identity theft, and this page deliberately stops short of it.

Six situations this page is written for

The right first move is different in each of them. Find yours before you start dialing.

Codes keep arriving for a bank you do not use

Someone is putting your number into applications. Nothing has been opened yet that you know of. Place the alert and the freeze now, while it is still cheap, and keep every timestamp.

A collections agency wants payment for a phone plan

The account is old and has already charged off. Demand written validation from the collector, get the original creditor’s name, and aim the records request at that creditor rather than the agency.

Your credit reports are spotless and you feel foolish

You are almost certainly not imagining it. Telecom and utility accounts sit in a different exchange until they default. Pull that file before you conclude nothing happened.

The carrier says it needs a subpoena

For most of what you want, that is wrong, and the written victim records request is the instrument that says so. Send it to the address the company specifies, with your affidavit and police report attached.

Your lawyer needs the file to sue or to defend you

Where a fraudulent account has already produced a judgment or a collection suit, the application records are evidence. The request can be built and posted while the litigation runs.

You suspect somebody close to you did it

Read the boundaries section below before you act on that. This is the situation where a wrong move causes the most damage, and it is the one we handle most carefully.

The order to do it in, and why the order is not arbitrary

Each step produces the document the next step requires. Skip one and the later demands arrive without their legs.

1

Alert, then freeze, in that order

The alert takes one call and propagates to the other bureaus for you. The freeze is stronger but has to be placed at each bureau separately, and separately again at the telecom exchange, which the credit freeze does not reach.

2

File the FTC report and get the affidavit

This is the document that converts a complaint into an identity theft report. It is what upgrades you to the seven-year alert, and it is half of what the block and the records request need.

3

File with police and keep the report number

Expect it to be recorded rather than investigated. File anyway. It is the other half of the proof, and it is the only path by which anyone gains lawful authority to look at the person behind the account.

4

Block the entries, then post the records request

Block first, because it runs on a four-business-day clock and cleans your file while everything else is slow. Then send the written request to the business, naming the police agency as a recipient alongside yourself.

What we will do on a case like this, and what we refuse

The limits below are not decoration. On this topic in particular, the wrong kind of help causes more harm than no help at all.

Our part is narrow and practical. We help a victim assemble the packet: identifying which corporate entity actually holds the records behind a fraudulent account when the brand on the bill is not the legal entity, finding the address that entity has specified for victim record requests, locating the correct registered agent or corporate service address when it has not specified one, tracking which bureaus and exchanges hold a file on you, and keeping a dated log of what was sent where and what came back. A surprising number of requests fail purely because they were posted to a retail store or a general customer-service address. That is public-records research, it is what we are good at, and it does not involve identifying anybody.

We will not tell you who did this, and we will not help you work it out. No matching an application address to a household, no resolving an email or a second number to a person, no checking who had access. That is a deliberate refusal rather than a limit of skill. The predictable outcome of that kind of research in the hands of a frightened victim is a confrontation with the wrong person, and there is no undoing a false accusation. The records go to the police agency you name in your request, and the police decide what they mean.

We are a skip-tracing and public-records research firm, and we never present ourselves as any. Surveillance, interviewing a suspect, and the rest of the licensed-investigator toolkit are outside what we do and outside what this page recommends. Every engagement starts with a lawful purpose stated and recorded before any research begins; if the stated purpose does not survive a plain reading, the file does not open.

We do not pretext, at all. Nobody here rings a carrier claiming to be you, or claiming to be anyone else, to talk an agent into releasing account details. That impersonation is how the account got opened in the first place, and answering it with more impersonation would be both unlawful and grotesque. In the same vein, we do not obtain account balances, statements, transaction contents, call detail records, message contents, or device location. Those are not public records, they are not ours to have, and a firm that offers them is describing an offense rather than a service.

People Locator Skip Tracing is not a consumer reporting agency, and nothing we produce is a consumer report under the Fair Credit Reporting Act. Our work may not be used, in whole or in part, as a factor in deciding a person’s eligibility for credit or insurance, for employment, for housing or tenancy, for a government license or benefit, or for any other purpose the Act covers. Where a decision of that kind is on the table, the law wants a licensed consumer reporting agency and the notice, accuracy, and dispute rights that come with one – and it is worth saying that in your own case those rights run in your favor, which is exactly why the block and the disclosure provisions above exist.

If the person who used your details lives in your home, used to, or shares a child with you, stop and get advice before you file anything. An identity theft complaint that names a household member reaches that person, and in a relationship where there is already violence or control, the paperwork itself becomes the trigger. Speak to a domestic violence advocate or a victim-witness coordinator first and let them time the filings around your safety. And we decline the mirror image of that request outright: we will not accept an identity theft matter that is in substance an attempt to locate someone who left an abusive home, however the file is dressed up, and no amount of documentation changes that answer.

Everything on this page is general information about federal law as written, not legal advice about your circumstances, and no reading of it creates a lawyer-client or any other professional relationship. Deadlines, forms, and agency practice change; your own state may give you rights beyond the federal floor described here. If money has already been lost or a lawsuit has already been filed, talk to a consumer-protection attorney, and take this page with you.

Who brings us a case like this

Different starting points, the same statutory ladder, and the same refusal to name anybody.

Victims mid-remediation

Stuck on which entity to write to

Consumer attorneys

Building the record for a claim

Families helping a parent

Filing on behalf of an older relative

Small businesses

Trade lines opened on an owner’s identity

Victim advocates

Sequencing filings around a safety plan

Estate and guardianship

Accounts opened against a protected person

In every one of those, the deliverable is the same: a correctly addressed set of statutory requests, a dated log of what went out and what came back, and a file that a police agency or an attorney can pick up and use. Not a suspect.

We would rather tell you the request is a dead end

If the records you want were never kept, or the entity has a good-faith basis to refuse, we will say so before you pay for the work rather than after. A victim who has already lost money should not lose more of it buying an answer that does not exist. When we can help, you get the packet and the log; when we cannot, you get the reason, in writing, at no charge.

People Locator Skip Tracing Investigation Team — a public-records research practice that has been working victim files since 2004. Researched against the statutory text and current federal regulations, reviewed 2026. General information about federal law, not legal advice.

Questions victims ask us in the first week

Can you just tell me who opened the account?

No, and neither can any other private firm, whatever it advertises. A business is not permitted to hand a private party the identity of another customer, and the records provision that does exist gives you the application and the transaction documents rather than a verified name and address you can act on. What we can do is make sure the request goes to the right legal entity at the right address with the right proofs attached, and that a police agency is named as a recipient so that somebody with actual authority sees the same file you do.

What is the single most useful thing I can do in the next hour?

Place a fraud alert. It takes one call or one web form, it costs nothing, it lasts at least a year, and the agency you contact is required to pass it to the other nationwide bureaus for you, so one call covers all three. It obliges a prospective lender to form a reasonable belief that it knows who is applying, and if you supply a telephone number for verification, the lender has to contact you on that number before opening new credit in your name. Then set aside a longer block of time for the freeze and the reports.

Why is my credit report completely clean?

Because a phone, cable, or utility account normally is not reported to the three big bureaus at all until it defaults and gets charged off or sold to a collector. Until that happens it can be perfectly real and perfectly invisible there. The file that records new telecom and utility connect requests is the National Consumer Telecom and Utilities Exchange, serviced by Equifax on behalf of its member companies; the CFPB’s entry for it confirms one free report every twelve months on request and a freeze on request. Pull that before you decide nothing happened.

What exactly arrives when a records request works?

The application as it was submitted and the business transaction records evidencing the transaction, in whatever form the company holds them. In practice that can be an online application form with the details the impostor typed, an in-store agreement, a copy of whatever identification was presented, delivery or activation records, and account statements. It varies enormously by channel: a postpaid contract opened at a dealership usually generates far more paper than a prepaid activation. The statute creates no obligation to have kept records the business would not ordinarily keep.

Can the company simply refuse to send it?

Only on a short list of grounds, exercised in good faith: that the provision does not require the disclosure, that after reviewing your proofs it does not have a high degree of confidence in your identity, that your request rests on a misrepresentation of fact, or that what you asked for is internet navigational data about a person’s visits to a website. It also has an affirmative defense if it made a reasonably diligent search and the records do not exist or are not reasonably available. What it cannot do is cite financial-privacy law, because the statute expressly bars using the Gramm-Leach-Bliley disclosure prohibitions to deny a victim these records.

Does a credit freeze stop somebody opening another phone line?

Not reliably. The federal freeze right attaches to the nationwide credit reporting agencies, and a carrier that screens an applicant through a telecom exchange rather than a credit bureau will not be stopped by it. That is why the freeze at the telecom and utility exchange is a separate step rather than an optional extra. Also be aware that a credit freeze does not apply to your existing creditors reviewing your accounts, to a collection agency working a debt you already owe, or to court and government requests.

I think a family member did it. What should I do?

Get advice before you file, not after. An identity theft complaint that identifies a household member will reach that person, and if there is any history of violence or coercion in the relationship, the filing itself can put you at risk. Speak to a domestic violence advocate or a victim-witness coordinator and let them help you time it. Please do not try to confirm your suspicion yourself, and do not ask us to: we decline that work, because the cost of being wrong falls entirely on somebody who did nothing, and it is not recoverable.

How quickly can you turn a case around?

Identifying the correct legal entity behind a brand, locating its specified address for victim record requests, and assembling the packet usually takes a few business days once you have your identity theft report in hand. After that the clocks are statutory and out of everybody’s control: four business days for a bureau to act on a block once it has all four required items, and thirty days from receipt for the business to produce the records. We will give you a realistic date range before you commit, and tell you plainly if we think the request is likely to come back empty.

You do not have to work out who holds the file

Send us what you have – the message, the letter, the collector’s name – and we will identify the entity that has to answer, find where the request has to be posted, and hand you a packet you can sign and mail. If you would rather ask a question first, put it to a researcher and you will get a straight answer within 24 hours about whether the work is worth doing at all.

Get the records packet built