The boilerplate advice I keep reading at the end of every article about the Equifax hack is… Everybody freeze their credit! That certainly is an option, but perhaps it might be overkill to expect 150 million people to do that? The credit reporting agencies seem to make it an painful experience on purpose, charging you $10 a pop x 3 bureaus for freezing/thawing. Some good news: Equifax just announced a new free instant lock/unlock feature, which probably wouldn’t have happened if it wasn’t for this breach.
For a more practical perspective, I recommend bookmarking the post Identity Theft, Credit Reports, and You by Patrick McKenzie. He has real-world experience in helping others deal with the credit bureaus and navigating the Fair Credit Reporting Act (FCRA). My notes:
- You don’t need to do anything just because your data was leaked or might have been leaked and nothing has actually happened.
- Don’t pay money for credit monitoring.
- If you find unauthorized charges on an credit card you opened yourself, just call your bank or card issuer. This shouldn’t be a big headache.
- If you find an account NOT opened by yourself, either due to fraud or some sort of clerical error, then read the entire post for detailed instructions. You need to create a paper trail because this could easily turn into a big headache.
A lot of nuance is covered and sample text is helpfully included, such as:
On August 5th, 20XX I accessed my credit report from Experian, numbered 1234567. It shows an account with your institution in my name, with account number XXX123. I am unaware of the full account number. I have no knowledge of this account. I did not open it or authorize anyone to open it.
Please correct this tradeline and confirm this to me in writing within the timeframe specified by law. If you cannot correct this tradeline, provide me with your written justification for why your investigation concluded that this tradeline was accurate.
Here are some important things to note if you have to deal directly with a financial institution regarding an unauthorized account:
- Do not call. Communicate only via written letters sent by postal mail to their official address. Create a paper trail. Keep a scan/copy of everything.
- Never pay debt which isn’t yours, even if you are being harassed.
- Never speak to debt collectors on the phone, either. Just ask for their address and hang up so you can communicate in writing. You are not breaking any laws if you hang up on them.
- You can do this. In his experience, most issues were resolved after 2-3 letters send via certified mail/return receipt.