Skip to content

Fraud Alert

A fraud alert is a statement placed in your credit file that tells any lender pulling it to verify who is applying before opening credit in your name. Unlike most identity-theft remedies it is available before anything has happened to you, and what it obliges a lender to do depends on which of the three alerts you placed.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • An initial alert requires only a good-faith suspicion that you have been or are about to become a victim, so it is available after a breach notice rather than only after a loss.
  • The duty an alert imposes is two-tier. An initial or active duty alert requires the lender to form a reasonable belief it knows who is applying; an extended alert requires the lender to contact you.
  • It does cover a new credit card. The statute's "other than under an open-end credit plan" language reaches draws on a plan you already have, not the opening of a new one.
  • Every alert can be cancelled early on request, because each duration runs only until you ask for the alert to be removed.
  • Placing an alert entitles you to a free file disclosure, and the bureau has three business days to deliver it once you ask.

Definition

A fraud alert is a statement included in a consumer's file at a nationwide credit bureau which, under 15 USC 1681a(q)(2), notifies every prospective user of a report on that consumer that the consumer may be a victim of fraud, including identity theft, and which must be presented so that any person requesting the report gets "a clear and conspicuous view" of it. Three exist: an initial fraud alert, an extended fraud alert, and an active duty alert for a deployed service member. Their triggers and durations differ, and the published material on identity theft sets all three out.

The feature that distinguishes an alert from every other tool in this area is who may use it. Under 1681c-1(a)(1) an initial alert requires nothing but a consumer who "asserts in good faith a suspicion that the consumer has been or is about to become a victim of fraud or related crime, including identity theft". The statute reaches forward. A data-breach notice, a lost wallet or a phishing message you clicked is enough, and no loss, no police report and no proof of anything are required.

Advanced Explanation

What the alert actually obliges a lender to do, and the fact that it is two different duties. For an initial or active duty alert, 15 USC 1681c-1(h)(1)(B)(i) provides that no prospective user of the report may establish a new credit plan or extension of credit, issue an additional card on an existing account at the consumer's request, or grant a requested credit limit increase, "unless the user utilizes reasonable policies and procedures to form a reasonable belief that the user knows the identity of the person making the request". That is a standard about the lender's process. If you specified a telephone number for identity verification when you placed the alert, (h)(1)(B)(ii) sharpens it: the user must contact you on that number or take reasonable steps to verify your identity and confirm the application is not the result of identity theft.

An extended alert is stronger, and the difference is the point of paying the price of admission for one. Under (h)(2)(A)(ii) the alert itself must carry "a telephone number or other reasonable contact method designated by the consumer", and (h)(2)(B) then bars a prospective user from opening the account unless "the user contacts the consumer in person or using the contact method described in subparagraph (A)(ii)". No process standard, no reasonable belief. Contact, or no account.

The carve-out does not exclude new credit cards, though the operative text looks as though it might. Both (h)(1) and (h)(2) qualify the notification and the duty with the words "other than under an open-end credit plan". Read alone that seems to exempt exactly the product identity thieves most often open. It does not, and the definitions section settles it: 15 USC 1681a(q)(5) provides that "new credit plan" means "a new account under an open end credit plan ... or a new credit transaction not under an open end credit plan". A new card account is therefore squarely inside the term the duty attaches to. The cross-reference inside that definition still reads "section 1602(i)"; the notes to the United States Code record that the open-end credit plan definition was redesignated 15 USC 1602(j) in 2010. What the carve-out reaches is an extension of credit under a plan that is already open, which is consistent with the way the same sentences separately name adding a card to an existing account and raising an existing limit as things the alert does cover.

Every duration is a maximum you can shorten. The one-year, seven-year and twelve-month periods in subsections (a), (b) and (c) each run "unless the consumer or such representative requests that such fraud alert be removed before the end of such period, and the agency has received appropriate proof of the identity of the requester". The prescreen exclusions attached to the extended and active duty alerts are separately rescindable on request. So an alert placed after a breach that turns out to be harmless is not something you are stuck with, and a seven-year alert is not a seven-year commitment.

The alert travels with the score, and it travels through resellers. Each of (a)(1)(A), (b)(1)(A) and (c)(1) requires the bureau to include the alert in the file "and also provide that alert along with any credit score generated in using that file", so a lender that buys only a score still sees it. Subsection (f) then requires a reseller to include in its report any alert another agency placed, which matters because a mortgage lender typically buys a merged reseller report rather than three separate files. Under subsection (e), a bureau that receives a referred alert from another bureau must follow the same procedures "as though the agency received the request from the consumer directly", so a referred alert is not a weaker copy of the original.

Two smaller provisions close predictable gaps. Subsection (g) requires any consumer reporting agency that is not one of the nationwide bureaus, and that a consumer contacts about suspected fraud, to tell that consumer how to reach the Bureau and the nationwide agencies in order to request an alert. Subsection (d) requires each nationwide bureau to maintain procedures that let consumers request any of the three alerts "in a simple and easy manner, including by telephone", so a website cannot be the only route.

An alert is not a freeze and does not try to be. An alert leaves your file in circulation and regulates what a lender must do with it; a freeze withholds the file. The published material on credit freezes sets out that machinery, including its ten statutory exceptions, and the two can be used together.

How to Remember

A freeze hides the file. An alert leaves it visible and puts an obligation on whoever reads it. Which obligation depends on the alert: the ordinary one asks a lender to be satisfied it knows you, and the extended one requires it to reach you.

Used in a Sentence

“The breach notice named her Social Security number, so Rosa placed a fraud alert with one bureau the same afternoon and listed the mobile number she wanted lenders to call.”

How It Works

You contact one nationwide bureau, assert your suspicion and prove who you are. The bureau adds the alert, refers it to the other two, and tells you that you may request a free copy of your file. Any lender that pulls the file, or a score generated from it, sees the alert and takes on the verification duty that the alert type carries. When you no longer want it, you ask for it to be removed.

A hypothetical example of why the alert type matters. Dmitri receives a breach notice and places an initial alert, giving his mobile number for verification. Two weeks later a thief applies for a store card in his name. The store's lender may not open the account unless it uses reasonable policies and procedures to form a reasonable belief that it knows who is applying, and because Dmitri supplied a number, it must call that number or take reasonable steps to verify his identity and confirm the application is not identity theft.

Now suppose the theft succeeds elsewhere and Dmitri obtains an identity theft report, which lets him convert to an extended alert. The next lender's obligation changes in kind. Under (h)(2)(B) it may not open the account unless it contacts him in person or by the contact method printed in the alert. A reasonable internal process is no longer enough.

One deadline to hold the bureau to. Placing either alert entitles Dmitri to a free file disclosure under 15 USC 1681j(d), and once he asks for it, the bureau must provide the disclosures "not later than 3 business days" after the request ((a)(2)(B) for an initial alert, (b)(2)(B) for an extended one). If he asks on a Monday, they are due by that Thursday.

Pros and Cons

Pros

  • It is available before you are a victim, on a good-faith suspicion alone, which no other remedy in this part of the statute is.
  • It is free, and one request to any nationwide bureau is referred to the other two.
  • It imposes an affirmative duty on the lender rather than merely informing it, and an extended alert requires actual contact with you.
  • It reaches a new credit card, notwithstanding the open-end language in the operative text.
  • It follows the file into a score and into a reseller's merged report, so it survives the way lenders actually buy data.
  • It can be removed at any time on request, so placing one costs you nothing you cannot undo.

Cons

  • It leaves your file available. A lender willing to satisfy the verification standard can still open an account, which is why it is the weaker of the two free tools.
  • On an initial or active duty alert the obligation is a process standard, so compliance is judged by the lender's procedures rather than by the outcome.
  • The strong version, the extended alert, is conditioned on obtaining an identity theft report, which means involving law enforcement.
  • It does nothing about fraud on accounts you already hold, and nothing about tax, medical or benefit identity theft.
  • The carve-out does apply to extensions of credit under a plan already open, so an alert is not protection against misuse of an existing line.
  • Its usefulness depends on lenders honoring it, and you have no way to see whether a given lender did.

People Also Asked

Answers to the most frequently asked questions.

Does a fraud alert stop someone opening a credit card in my name?
It does not stop it outright, but it does cover it. The duty in 15 USC 1681c-1(h) is qualified by the words "other than under an open-end credit plan", which reads as though new cards were excluded. 15 USC 1681a(q)(5) resolves it: "new credit plan" means a new account under an open-end credit plan or a new credit transaction not under one, so a new card is inside the duty. The carve-out reaches extensions of credit under a plan you already have.
What is the difference between an initial and an extended fraud alert?
The trigger and the duty. An initial alert needs only a good-faith suspicion, and it requires a prospective lender to use reasonable policies and procedures to form a reasonable belief that it knows who is applying. An extended alert requires you to submit an identity theft report, and in return 15 USC 1681c-1(h)(2)(B) bars a lender from opening the account unless it contacts you in person or by the contact method you designated. It also runs far longer.
Can I cancel a fraud alert before it expires?
Yes. Each of the three durations in 15 USC 1681c-1 runs unless the consumer requests that the alert be removed earlier, with appropriate proof of identity, and the prescreened-offer exclusions attached to the extended and active duty alerts are separately rescindable the same way. Nothing locks you in for the full period.
Do I get a free credit report for placing a fraud alert?
Yes, through 15 USC 1681j(d). When a bureau places an initial alert it must tell you that you may request a free copy of your file, and when it places an extended alert it must tell you that you may request two free copies during the following 12 months. In either case, once you ask, the bureau must provide the disclosures no later than three business days later.
Do I have to place a fraud alert at all three bureaus?
No, and this is the practical difference from a freeze. Each of 15 USC 1681c-1(a)(1)(B), (b)(1)(C) and (c)(3) requires the bureau you contacted to refer the alert to the other nationwide bureaus, and subsection (e) requires each recipient to treat the referral as though you had asked it directly. A freeze, by contrast, has to be placed at each bureau separately.

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor