Identity Theft Investigation Guide
Freezing your credit and filing a report stops the bleeding, but it does not answer the question every victim eventually asks: who did this, and how? Investigating identity theft is a separate job from preventing it. It means reconstructing how your information was taken, tracing the fraudulent accounts, addresses, and phone numbers the thief opened in your name back toward a real person or ring, and assembling a clean evidence file that police, the FTC, and creditors can actually act on. This guide walks through that investigation, lawfully, from the first suspicious alert to a documented case — starting with the federal right almost no guide mentions, which puts the thief’s own application in your hands within 30 days, free, and lets you have it sent straight to a detective you name.
The Short Version
If this happened to you in the last few days, the order is this:
- Contain it. Freeze your credit files, then file an FTC Identity Theft Report and a police report. Those two documents are not paperwork for its own sake — they are inputs the statutes below name.
- Catalog it. Pull your full credit reports and list every account, charge, address, phone number, and email that is not yours.
- Demand the records. Send each business a written §1681g(e) request, with your identification and the report or affidavit, for the application behind every fraudulent account — 30 days, free.
- Then work what comes back. The addresses, numbers, and emails on those applications are the leads; resolving them is the investigation, and it is set out step by step further down this page.
An identity-theft investigation has two halves: documenting how your identity was used, and tracing that use back toward whoever did it. Start by pulling everything the thief left behind — fraudulent account numbers, the addresses and phone numbers they listed, and whatever application detail a creditor is willing to release. Federal law does more than let you ask: on a written request, backed by proof of who you are and proof of the claim, 15 U.S.C. §1681g(e) requires the business that extended credit to whoever misused your identity to provide a copy of the application and business transaction records evidencing that transaction within 30 days and without charge, and to provide the same records to a law-enforcement agency or officer you name in the request. Be realistic about one category: the same statute lets a business decline a victim’s request for Internet navigational data where, in the exercise of good faith, it determines that this is what is being sought, so IP and device logs are generally something police reach with a subpoena or warrant rather than something you can demand. Those breadcrumbs are leads. Many of them resolve, through lawful public-records and skip-tracing work, to a real name, an address history, and the people connected to it. Be clear about the division of labour as well: identifying and charging a thief is law enforcement’s job, and no private firm can open a bank’s internal fraud file, obtain a merchant’s CCTV, or compel a carrier. A victim’s real leverage is statutory — the §1681g(e) records demand, the FTC Identity Theft Report, the police report, and the §1681c-2 block — and this page is about using it. The goal is not vigilante justice; it is a documented, dated evidence file that gives a detective something to work with, the FTC a complete affidavit, and creditors and a civil attorney the facts they need. We build that file; you keep control of how it is used.
Watch: Investigating Identity Theft
How a stolen identity is traced back toward a person, lawfully.
Watch Overview
Prevention Is Over. Now You Investigate.
The work that begins after the credit freeze.
Most identity-theft advice stops at the wall: freeze your credit, change your passwords, set fraud alerts. That is essential, and you should do all of it. But it is defense, not investigation. It seals the doors the thief used; it does not tell you who walked through them or how. Once the immediate damage is contained, a very different question opens up, and it is the reason this page exists: can the fraud be traced back toward a real person? Surprisingly often, yes.
The reason is simple. To use your identity, a thief had to do things — open an account, ship a card somewhere, list a phone number, give a delivery address, sometimes show up at a counter. Each of those acts leaves a record, and many of those records are disclosable to you as the victim. An identity-theft investigation is the disciplined work of collecting those records, turning the fragments into leads, and following the leads through lawful research until they resolve to a person, an address, and a connection you can hand to law enforcement. This is post-incident investigation and evidence-building, not pre-transaction verification of someone you are about to deal with — a different page for a different moment.
What the Thief Left Behind
Every fraudulent act creates a record you can request.
Fraudulent Accounts
Cards, loans, or utilities opened in your name carry an application address, contact phone, and email the thief controlled.
Shipping Addresses
Goods or replacement cards had to be sent somewhere a person could collect them. That drop address is a lead.
Phone Numbers
The number on a fraudulent application or used to bypass verification often ties to a real subscriber or pattern.
Emails & Logins
The email used to register an account, and the username patterns around it, frequently reappear elsewhere online.
IP & Device Data (Limited)
Many lenders do log the IP and device that submitted a fraudulent application, but federal law lets a business decline a victim’s request for Internet navigational data where, in the exercise of good faith, it determines that this is what is being sought. Treat this as a lead police may reach with a subpoena or warrant, not a record you can demand.
Known-Person Patterns
In many cases the thief is not a stranger — a relative, ex, or roommate who had access. The records often point inward.
None of these fragments is proof on its own. Each is a thread. The investigation is the work of pulling each thread, under the Fair Credit Reporting Act provisions that let a victim request the records of accounts opened in their name, and seeing which ones lead somewhere real. The provision that does the work is 15 U.S.C. §1681g(e), added to the Fair Credit Reporting Act by the FACT Act of 2003. Under §1681g(e)(1), a business entity that extended credit to, provided products, goods, or services to, accepted payment from, or otherwise entered into a commercial transaction with a person who allegedly made unauthorized use of your means of identification “shall provide a copy of application and business transaction records … evidencing any transaction alleged to be a result of identity theft” — to you, or to any federal, state, or local government law enforcement agency or officer you specify in the request — “not later than 30 days after the date of receipt of a request.” Under §1681g(e)(4), that information “shall be so provided without charge.” The conditions attached to that right, and the grounds on which a business may lawfully refuse, are what the next section sets out clause by clause.
Federal Law Already Put the Thief’s Application in Your Hands
What §609(e) requires, what it costs, and exactly where it stops.
Nearly every guide to identity theft tells a victim to report the fraud. Very few tell them that a separate provision of federal law entitles them to the paperwork behind it — the application the thief filled in, in the thief’s own words, with whatever contact details the thief chose to give. Getting hold of that paperwork is the first move, and it is a written request rather than an investigative technique. The FTC puts it plainly in its consumer alert of 13 April 2022: “The law gives you that right — in fact, it’s Section 609(e) of the Fair Credit Reporting Act (FCRA) … To get information related to your identity theft, send your request in writing to the company where the fraud took place. They have 30 days to give you those records, free of charge.”
Section 609(e) is codified at 15 U.S.C. §1681g(e). It is short, and every clause in it matters to how you write the letter. Below is what each one does.
Who owes you the records
The duty reaches any business entity that dealt commercially with the person who misused your identity — not only banks, but a phone carrier, a retailer, a utility, an online marketplace. It covers records “in the control of the business entity, whether maintained by the business entity or by another person on behalf of the business entity,” so a servicer or vendor holding the file is no answer. And the duty runs to the transaction records too, not just the application: the FTC has told businesses that this includes the documents tied to the unauthorised charges, such as copies of billing statements.
It can go straight to a named officer
The recipient list is disjunctive: the victim, or “any Federal, State, or local government law enforcement agency or officer specified by the victim in such a request,” or any agency investigating the theft that you authorise to receive them. The FTC’s own business guidance spells out the consequence for the business: “the law enforcement officials who ask for these records in writing may get them from your business without a subpoena, as long as they have the victim’s authorization.”
The request has a required form
It must “be in writing” and “be mailed to an address specified by the business entity, if any” — so if the business specifies one, use it: the thirty days runs from receipt of a request made “in accordance with paragraph (3),” and a request that does not comply may not start the clock. Where no address is specified, that half of the paragraph has nothing to bite on. If the business asks, include the date of the application or transaction and any account or transaction number, in each case “if known by the victim (or if readily obtainable by the victim).”
What they may demand back
Before releasing anything the business may require proof of identity, at its election: a government-issued identification card, the same categories of personal information the thief gave it, or whatever it normally asks of new applicants. It may also require proof of the claim — “a copy of a police report evidencing the claim of the victim of identity theft” and a properly completed standardised identity-theft affidavit. This is why the police report is not optional housekeeping; it is an input the statute names.
One way to decline, one defence in court
A business “may decline to provide information … if, in the exercise of good faith, the business entity determines that” the subsection does not require disclosure, that it lacks a high degree of confidence in who is asking, that the request rests on a misrepresentation of fact, or that what is sought “is Internet navigational data or similar information about a person’s visit to a website or online service.” Separately, §1681g(e)(10) gives a business an affirmative defence in a civil enforcement action — which it must establish by a preponderance of the evidence — if it files an affidavit or answer stating that it made “a reasonably diligent search of its available business records” and the records “do not exist or are not reasonably available.”
“It’s confidential” is not an answer
The standard brush-off is that financial-privacy law forbids the disclosure. Congress addressed that directly: “No provision of subtitle A of title V of Public Law 106–102 [15 U.S.C. 6801 et seq.], prohibiting the disclosure of financial information by a business entity to third parties shall be used to deny disclosure of information to the victim under this subsection.” That public law is the Gramm-Leach-Bliley Act. The limit is in (e)(9)(B): outside that carve-out, the subsection does not licence a business to disclose what other federal or state law forbids it to disclose.
Two more clauses shape how you use the right in practice. Under §1681g(e)(4) the records are free: “Information required to be provided under paragraph (1) shall be so provided without charge.” And under §1681g(e)(6), “[e]xcept as provided in section 1681s of this title, sections 1681n and 1681o of this title do not apply to any violation of this subsection” — those two sections are the FCRA’s private damages remedies for wilful and negligent noncompliance, and §1681s is administrative enforcement. So a business that ignores your §609(e) request is not something you can sue over for FCRA damages. The escalation is regulatory, and the FTC names it in the same 2022 alert: “If you have problems getting the records from banks and lenders, let the Consumer Financial Protection Bureau (CFPB) know.”
One refusal you should not accept is the one the FTC has already told businesses is wrong. Writing for compliance officers on 18 December 2017, FTC staff attorney Amanda Koulousias addressed businesses that decline because the victim once received the paperwork themselves: “Denying the victim’s request because the victim previously had access to the records does not comply with Section 609(e).” Send the request anyway, keep the mailing receipt, and diary the thirtieth day.
Four Jobs People Confuse
Investigating theft is not preventing it, not verifying someone, and not policing.
| Task | When It Happens | The Question It Answers | The Output |
|---|---|---|---|
| Identity Verification | Before a transaction | Is this person who they claim to be? | A go/no-go on dealing with someone now. |
| Prevention & Cleanup | Right after discovery | How do I stop the damage and fix my credit? | Freezes, disputes, restored accounts. |
| Records Investigation This Page | After the damage is contained | What do the thief’s own records show, and where do they lead? | A documented evidence file for police, the FTC, and creditors. |
| Criminal Investigation | Once a case is opened | Who is charged, and on what evidence? | An arrest, a charging decision, a prosecution. |
All four matter, and they are sequential. You verify before you transact, you contain damage the moment you discover fraud, you work the records once the fires are out, and the last job belongs to somebody else. This page is squarely about the third. If you are still at the “stop the bleeding” stage, do that first; the trail will keep.
The fourth row is the one most pages leave off, so it is worth being exact about the line it draws. A records-research firm cannot open a bank’s internal fraud file, cannot obtain a merchant’s CCTV, cannot compel a phone carrier to identify a subscriber it will not identify voluntarily, cannot serve a subpoena, and cannot arrest anyone. Every one of those requires legal process or a badge. What a victim actually has is leverage of a different kind, and it is statutory rather than investigative: the §1681g(e) records demand, the FTC Identity Theft Report, the police report, and the §1681c-2 block. Those instruments produce documents. Resolving what the documents contain — addresses to occupants and history, numbers to subscribers, emails to connected accounts — is ordinary public-records work, and it is the part we do. Naming and charging a person is the fourth job, and it is not ours.
That is a narrower offer than the one usually made on this subject, and it is the one that survives contact with reality. A packet a detective can act on is worth more than a promise nobody outside law enforcement is in a position to keep.
How a Lead Becomes a Name
Turning a drop address or burner number into a real person.
The single most useful artifact in most identity-theft cases is an address the thief actually used — the place a fraudulent card was mailed, the delivery address on a stolen-card order, or the address listed on a credit application that is not yours. People are remarkably tied to addresses. A residence resolves, through public records, to current and former occupants, the people associated with them, and an address history that can be walked forward and backward in time. A drop that looks anonymous often turns out to belong to, or sit beside, someone with a real connection to the fraud.
Phone numbers behave the same way. A number used on a fraudulent application or to defeat a one-time passcode can be run through a lawful reverse phone lookup to identify a subscriber, carrier, and line type, and a suspected burner can be approached with the techniques in our guide on identifying a scammer by phone number. Emails and usernames are threads too — a registration email frequently reappears across other accounts, and the pattern around a handle can be followed using the same methods we describe for tracing the person who scammed you. Layer the address result over the phone result over the email result, and a single name often sits where all three overlap.
This is the same disciplined records method behind any serious financial-crime workup; if you want the broader framework, see our overview of how to investigate fraud. Applied to identity theft, it simply starts from the artifacts the thief left in your name rather than from a business deal gone wrong.
Cleaning Your Credit File Does Not Erase the Trail
The block, the alerts, and the deadlines that run alongside your investigation.
A reasonable fear stops some victims from cleaning up their file while they are still trying to work out what happened: if the fraudulent accounts are wiped from the credit report, does the evidence go with them? The statute answers that directly, and the answer is no.
The instrument is 15 U.S.C. §1681c-2, the FCRA provision usually called by its original section number, 605B. A consumer reporting agency “shall block the reporting of any information in the file of a consumer that the consumer identifies as information that resulted from an alleged identity theft, not later than 4 business days after the date of receipt” of four things: proof of the consumer’s identity, a copy of an identity theft report, the consumer’s identification of the information, and a statement that the information does not relate to any transaction by the consumer. Four inputs, four business days.
Two consequences of that provision belong on an investigation page rather than a cleanup checklist. First, blocking is not a quiet administrative act. Under §1681c-2(b) the agency “shall promptly notify the furnisher” that the information may be a result of identity theft, that an identity theft report has been filed, that a block has been requested, and of the effective dates. So the furnisher is told, by the agency and promptly, that an identity theft report has been filed and a block requested. Second, §1681c-2(f) preserves the evidence: “No provision of this section shall be construed as requiring a consumer reporting agency to prevent a Federal, State, or local law enforcement agency from accessing blocked information in a consumer file to which the agency could otherwise obtain access under this subchapter.” The record is hidden from creditors, not from police.
The block also has teeth pointing the other way, which is why we say plainly that this is a route only a genuine victim can use. Under §1681c-2(c)(1) an agency may decline or rescind a block if it reasonably determines that the information was blocked in error, that the block was requested “on the basis of a material misrepresentation of fact by the consumer,” or that “the consumer obtained possession of goods, services, or money as a result of the blocked transaction or transactions.”
| Instrument | How long it lasts | What it also gets you | Authority |
|---|---|---|---|
| Initial fraud alert | “a period of not less than 1 year” | One free copy of your file, and all §1681g disclosures within 3 business days of the request | §1681c-1(a)(1)(A), (a)(2) |
| Extended fraud alert | “the 7-year period beginning on the date of such request” — requires an identity theft report | Two free copies of your file in the 12 months after the alert is added; plus a separate 5-year exclusion from prescreened credit and insurance lists | §1681c-1(b)(1)(A)–(B), (b)(2) |
| Block of fraudulent information | Effective within 4 business days of a complete request | Formal notice to the furnisher; blocked data still reachable by law enforcement | §1681c-2(a), (b), (f) |
One of those figures is worth checking against whatever else you are reading. A great deal of identity-theft advice still describes the initial fraud alert as lasting 90 days, including pages published by large, well-resourced brands. That was the law until 2018. The Editorial Notes to §1681c-1 record the change in terms: “2018—Subsec. (a)(1)(A). Pub. L. 115–174, §301(a)(1), substituted ‘1 year’ for ’90 days’.” The amendment took effect 120 days after 24 May 2018, which is nearly eight years ago. A source still printing ninety days is printing pre-2018 law. It does not follow that the source is old — a page can be maintained carefully and still carry a figure nobody went back to check — so treat it as a reason to verify that source’s other numbers against the statute rather than as evidence of when it was last revised.
The Investigation, Step by Step
From scattered alerts to a file someone can act on.
Catalog the Fraud
List every account, charge, address, phone, and email that is not yours. Pull your full credit reports, then send each creditor a written §1681g(e) request, with your identification and a police report or identity-theft affidavit, for the application and business transaction records behind every fraudulent account — 30 days, without charge.
Extract the Leads
From those records, isolate the usable artifacts — drop addresses, contact numbers, registration emails, and any IP or device data a creditor chooses to release, which the FCRA lets it withhold on a good-faith determination.
Trace Each Thread
Resolve addresses to occupants and history, numbers to subscribers, and emails to connected accounts through lawful public records and licensed databases.
Build the Evidence File
Assemble a dated, sourced report tying the leads together — ready for a police report, the FTC affidavit, creditor disputes, or a civil claim. Total your own losses across every account and across a rolling twelve months rather than reporting each card on its own; as the next section explains, the statute measures the offender’s whole take rather than yours, and your dated total is the part of it you are able to supply.
Why a Detective Cares About Your Arithmetic
The federal offences behind identity theft, and the number that moves the ceiling.
Victims are often told to report each fraudulent account separately, to the creditor that opened it. That is right for the disputes and wrong for the case. The higher federal band turns on an aggregate rather than on any single account, and the statute measures that aggregate on the offender’s side — everything they obtained, across every victim, inside a rolling year. Nobody outside law enforcement can see the whole of that. What you can supply is your share of it, as one dated total rather than four complaints that each look too small to matter.
The core offence is 18 U.S.C. §1028(a)(7). The Department of Justice describes it as prohibiting “knowingly transfer[ring] or us[ing], without lawful authority, a means of identification of another person with the intent to commit, or to aid or abet, any unlawful activity that constitutes a violation of Federal law, or that constitutes a felony under any applicable State or local law,” and says the offence “in most circumstances, carries a maximum term of 15 years’ imprisonment, a fine, and criminal forfeiture of any personal property used or intended to be used to commit the offense.”
What decides whether that 15-year ceiling is available is a dollar figure. Under §1028(b)(1)(D) the fifteen-year band applies to an offence under paragraph (7) involving one or more means of identification “if, as a result of the offense, any individual committing the offense obtains anything of value aggregating $1,000 or more during any 1-year period.” Absent that aggregate, §1028(b)(2) puts the same conduct in a five-year band. Forfeiture runs alongside either: for any offence under subsection (a), §1028(b)(5) provides for “forfeiture to the United States of any personal property used or intended to be used to commit the offense.”
So a stack of four cards at $400 each is $1,600, which is above the statutory figure — but only once somebody has added it up. Reported one at a time, each card reads as a small annoyance and nobody is left holding the total. That is not a legal argument you have to make; it is arithmetic somebody has to have done. It is also the reason the evidence file is dated and sourced rather than narrated.
One further provision belongs in the picture, briefly. Under 18 U.S.C. §1028A, an enumerated predicate felony carries an extra “term of imprisonment of 2 years” that is imposed “in addition to the punishment provided for such felony,” and §1028A(b) forbids running that term concurrently with the sentence for the felony it attaches to. Nobody reading this page charges it, chooses the predicate, or argues it in court. It is here for one reason only: it is a further reason a detective who can see one complete pattern behaves differently from one holding four separate complaints.
Where Your Evidence File Goes
A good investigation is only useful if someone can act on it.
The point of the investigation is not the thrill of the chase; it is producing something the right parties can use. Start with the FTC’s IdentityTheft.gov, where you file an Identity Theft Report — a complete, fact-rich affidavit is far stronger than a vague one, and the leads you developed go straight into it. That FTC report, paired with a police report, is also the document creditors and the credit bureaus must honor when you dispute fraudulent accounts and demand the underlying records.
Why an Identity Theft Report carries weight
It is fair to ask why a form a victim fills in themselves should move a bank at all. The answer is in the FCRA’s own definition. Under 15 U.S.C. §1681a(q)(4), an “identity theft report” means, at a minimum, a report “(A) that alleges an identity theft; (B) that is a copy of an official, valid report filed by a consumer with an appropriate Federal, State, or local law enforcement agency, including the United States Postal Inspection Service, or such other government agency deemed appropriate by the Bureau; and (C) the filing of which subjects the person filing the report to criminal penalties relating to the filing of false information if, in fact, the information in the report is false.” FTC staff put the same point to businesses in operational terms: “An FTC Identity Theft Report subjects the person filing the report to criminal penalties if the information is false, and businesses can treat it as they would a police report.”
That is what an affidavit is: an assertion with consequences attached. It is also why the FTC’s guidance to victims tells them to send both documents rather than one. Alongside the written records request, the FTC’s records alert of 13 April 2022, linked above, says to send “Proof of your identity, like a copy of your driver’s license or other valid form of identification. A completed FTC Identity Theft Report from IdentityTheft.gov. A police report about the identity theft from your local police department.” The FTC report does not replace the police report; each does something the other does not.
The tax track runs separately, and one of its forms is an evidence source
If a return was filed in your name, that fraud does not travel with the credit-file paperwork; the IRS handles it on its own track, and one instrument on that track belongs in your leads section rather than your reporting section. The IRS guide for individuals, last reviewed 4 June 2026, says: “To get a copy of a fraudulent return, send us Form 4506-F, Identity Theft Victim’s Request for Copy of Fraudulent Tax Return.” That is the tax-side analogue of a §609(e) demand — a route to the actual document the thief submitted. The same guide repeatedly directs victims to “[c]heck if you should file Form 14039, Identity Theft Affidavit.”
Where the misuse shows up as benefits or employment income rather than a return — the IRS instructs, on a Form 1099 from an unknown employer, “Don’t put the income on your return or amend a return you’ve already filed. Contact the Social Security Administration” — that is the agency to approach, and it is worth understanding first what someone can actually do with a Social Security number. We route you there on the IRS’s instruction; we state no SSA procedure or deadline of our own.
From there, the same file does double duty. A local detective can do little with “someone stole my identity,” but a packet that names a likely address, a subscriber behind a number, and a documented connection gives an investigator a place to start and a charge to consider. And if the loss is large enough to justify civil action, your attorney can use the evidence to support claims and, where appropriate, to locate and pursue the responsible party. One disciplined investigation; several places it pays off. We hand you the file and the documentation behind it; the decision of where to take it stays yours.
The Second Call Is Often the Second Thief
A firm that sells investigative help owes you this warning before it sells you anything.
People searching for someone to help them find who stole their identity are a defined and purchasable population, and the people who buy those lists know exactly what they are buying. The FTC published the current warning on 3 August 2026: “Refund and recovery scammers buy lists of people who’ve already been scammed, hoping they can be scammed again. The scammers contact you, saying they’ll help get your money back or recover the prize or merchandise you never got. To sound trustworthy, they might say they’re with a government agency (even the FTC), a consumer advocacy group, or a law firm — but it’s all a lie. They’ll then tell you to pay a ‘retainer fee,’ ‘processing fee,’ or ‘administrative charge,’ or share your financial information so they can (supposedly) deposit the refund.”
The consequence, in the FTC’s words: “if you pay, they’ll steal your money…and if you share your information, they might steal your identity.” The rule it gives is short enough to keep: “Never pay up front for a refund…or for help getting one. Neither government agencies nor legitimate organizations will ever ask for money or financial info in exchange for help getting a refund.”
The FBI’s Internet Crime Complaint Center publishes the matching warning about impersonation of itself, under the heading “Scammers are Impersonating the IC3”: “The IC3 does not work with any non-law enforcement entity, such as law firms or crypto services, to recuperate lost funds or investigate cases. The IC3 will never directly contact you for information or money.” If someone tells you they are working with a federal agency to get your money back, that sentence is the test.
Applied to us, the same warning is a set of facts you can check. We do not contact identity-theft victims out of the blue — every file here begins with the client’s own approach. We are a records-research firm, not a fund-recovery service, and we do not offer to get money back; what we produce is a sourced, dated report. And we are not affiliated with the FTC, the FBI, the IC3, or any law-enforcement agency, and never represent ourselves as calling on their behalf. Anyone who phones you claiming otherwise is describing a business that does not exist. The cryptocurrency version of that pattern — the one the IC3 warning above names when it lists “crypto services” — is the subject of our guide to tracing crypto recovery scammers.
Who This Helps
Victims and the professionals who support them.
Theft Victims
Answers beyond the credit freeze
Attorneys
Evidence for civil recovery
Fraud Units
Leads packaged for review
Creditors & Bureaus
Documented fraud disputes
Family Cases
When the thief is known
Small Businesses
Business-identity fraud traced
Whatever your role, the obstacle is the same: a stack of fraudulent activity with no name attached. We work the artifacts the thief left in your name, resolve them through lawful records, and deliver a sourced, dated report. We are a skip-tracing and public-records research firm operating under the FCRA, GLBA, and DPPA, not licensed private investigators, and we never use deception or pretexting to obtain information. For a legitimate victim with a real case, a first round of leads typically comes back within 24 hours. One boundary belongs alongside those: we are not a consumer reporting agency, and the sourced report we produce is not a consumer report, so it cannot be used to screen anyone for a job, a tenancy, credit, or insurance. We also decline any file where an identity-theft frame is cover for reaching a person who left because of domestic violence, stalking, or harassment, and a request touching those facts gets more scrutiny at intake, not less. We also do not build a dossier or a compiled profile on a private individual on request: the work is bounded by the artifacts a documented identity-theft case actually produces, and naming or charging anyone remains law enforcement’s decision.
Our Commitment
We trace the fraud committed in your name back toward a real person, lawfully, and hand you a documented evidence file your detective, the FTC, and your creditors can actually use. Public-records research for identity-theft victims since 2004 — no pretexting, no guesswork.
Frequently Asked Questions
Can identity theft actually be traced to a person?
Often the trail leads toward one, which is not the same as naming them. To misuse your identity the thief had to open accounts, ship items, and list contact details, all of which leave records. Drop addresses, application phone numbers, and registration emails frequently resolve, through lawful research, to a real name or a small set of connected people. What no private firm can do is open a bank’s internal fraud file, obtain a merchant’s CCTV, or compel a phone carrier; each of those takes legal process. We hand you those documented leads; identifying and charging anyone is law enforcement’s job, not ours.
How is this different from identity verification?
Verification happens before a transaction and asks whether someone is who they claim to be. An identity-theft investigation happens after the fraud and asks who committed it and how. This page is about the post-incident investigation and the evidence file, not pre-transaction verification.
What information should I gather first?
Pull your full credit reports and list every account, charge, address, phone number, and email that is not yours. As a victim you can request the underlying application records for fraudulent accounts, which is where the most useful leads usually live. Federal law backs that request: on a written request, with proof of identity and a police report or identity-theft affidavit, 15 U.S.C. section 1681g(e) requires the business to provide the application and business transaction records within 30 days and without charge, and to send them to a law-enforcement agency or officer you name — the FTC’s guidance to businesses is that an officer asking in writing with your authorization does not need a subpoena. Mail the request to the address the business specifies. The business can decline in good faith on limited grounds, including where what is sought is Internet navigational data, or answer on affidavit that a reasonably diligent search found no such records.
What can a drop address or phone number reveal?
An address used by the thief resolves to current and former occupants, associated people, and an address history. A phone number can be traced to a subscriber, carrier, and line type. Layered together, these leads often converge on a single name.
Do you ever find the thief is someone I know?
It is common. A meaningful share of identity theft is committed by a relative, ex-partner, or someone with household access. The records frequently point inward, which is exactly why a careful, documented investigation matters before any accusation. One limit goes with that, because this is the frame most often misused: we decline any file where an identity-theft frame is cover for reaching a person who left because of domestic violence, stalking, or harassment, and we do not build a dossier or a compiled profile on a private individual on request.
What do I do with the evidence file?
File an Identity Theft Report at the FTC’s IdentityTheft.gov and a police report. That report carries weight for a specific reason: under 15 U.S.C. section 1681a(q)(4), filing it subjects the person filing to criminal penalties if the information in it is false. With it in hand you can ask a credit bureau to block the fraudulent information, which section 1681c-2 requires within 4 business days of a complete request and which obliges the bureau to notify the furnisher. Blocking does not bury the evidence — section 1681c-2(f) preserves law-enforcement access to blocked information. The same documented leads strengthen creditor and bureau disputes, give a detective a place to start, and support a civil claim if the loss justifies one.
Is this legal, and do you use pretexting?
Yes, it is legal, and no, we never pretext. We are a skip-tracing and public-records firm working under the FCRA, GLBA, and DPPA. We use lawful records and licensed databases only, never deception, and never claim to be licensed private investigators.
How fast can you develop leads, and what do you need?
For a legitimate victim with a documented case, a first round of leads typically comes back within 24 hours. Send the fraudulent addresses, phone numbers, account details, and emails you have catalogued, and we build from there. One thing to know before anyone else calls you: we never contact identity-theft victims out of the blue, we are not a fund-recovery service and do not offer to get money back, and we are not affiliated with the FTC, the FBI, or any law-enforcement agency. The FTC’s standing warning is that neither government agencies nor legitimate organizations will ever ask for money or financial information in exchange for help getting a refund.
Want to Know Where the Trail Leads?
We trace the fraud in your name back toward a real person and hand you a documented evidence file for police, the FTC, and your creditors — typically a first round of leads within 24 hours. Contact us to get started.
Start Your Request →