In this lesson
- Opening
- 1. First Move — Pull Your Report Free, and Sort Error From Fraud
- 2. Two Problems, Two Toolkits — the Error/Fraud Fork
- 3. Your Legal Right to Dispute — the FCRA §611 Reinvestigation
- 4. Who You Dispute With — the Bureau AND the Furnisher
- 5. How to Dispute — In Writing, With Proof, and the Method of Verification
- 6. The 30-Day Clock, and Your Rights on the Result
- 7. Document Walkthrough — Priya's §611 Dispute Letter, Field by Field
- 8. What Comes Off, and What Doesn't — the 7-Year Rule and the Honest Line
- 9. Goodwill Deletion, and Why "Pay for Delete" Backfires
- 10. Predator Watch — the Credit-Repair Scam and the Free-DIY Truth (CROA)
- 11. The CPN Trap and the "Magic 609 Letter" Myth
- 12. Immigrant-Targeted "Fix Your Credit" Scams — Fatima's Near-Miss
- 13. Document Walkthrough — the Credit-Repair Contract (specimen)
- 14. The Scam Contract, Field by Field — Every CROA Violation
- 15. Identity Theft — What It Is, and How Maya Found It
- 16. New-Account Fraud vs. Account Takeover
- 17. Synthetic Identity Theft — the Frankenstein File
- 18. Child Identity Theft and the Authorized-User Trap — Priya
- 19. SSN and ITIN Misuse, and Tax Identity Theft — Fatima, and the IRS IP PIN
- 20. The Recovery Plan — IdentityTheft.gov in Three Moves
- 21. Document Walkthrough — Maya's FTC Identity Theft Report (specimen)
- 22. The Identity Theft Report, Field by Field
- 23. Step 2 — Place a Fraud Alert or a Freeze
- 24. Document Walkthrough — the FCRA §605B Block Letter, Field by Field
- 25. Your §609(e) Records, §615(g) Shield, and the Police Report
- 26. Freeze vs. Fraud Alert vs. Credit Lock — Which Wall, When
- 27. Document Walkthrough — the Credit-Freeze Confirmation, Field by Field
- 28. When It Starts With a Breach — Maya's Data-Breach Response
- 29. The Repeatable Routine — Check → Freeze → Dispute
- 30. If This Already Happened to You
- 31. Where to Turn — the Recourse Stack, and Your Right to Sue
- 32. Most Common Questions
- 33. Check Yourself — the Identity-Theft & Dispute Action Planner
- Glossary — Every Term This Lesson Taught
Credit Repair & Identity Theft
The fix for a wrong or fraudulent credit report is free, learnable, and legally yours — how to dispute an error under the FCRA, tell a real repair from the scam that charges you for it, and work the identity-theft recovery plan step by step, from a card you never opened to a misused Social Security number.
What you'll learn
- Sort the two problems a report can have — an error (a wrong balance, someone else's account, an item that should have aged off) versus fraud (accounts you never opened) — and know that each has its own free, legal fix, so "my report is wrong and only paid repair can fix it" becomes "here is the letter I send, for nothing."
- Exercise your FCRA §611 right to dispute: file with the credit bureau AND the furnisher, in writing with proof, demand the method of verification, and hold them to the 30-day reinvestigation clock (45 if you add documents) — following Priya as she deletes a late payment that was never hers.
- Know exactly what comes off a report and what doesn't — the seven-year rule (ten for a Chapter 7 bankruptcy), why paying a debt never restarts the clock and re-aging is illegal, and the honest line no one can cross: accurate, timely negatives stay, which is the truth every "we'll delete anything" pitch denies.
- Read the credit-repair industry on sight through the Credit Repair Organizations Act — no fee before the work is done, a written contract, a three-day cancel, and no promise to remove accurate information or to sell you a "new credit identity" — and internalize the one rule that ends the whole pitch: everything they charge for, you can do free.
- Recognize identity theft in its real forms — new-account fraud versus account takeover, synthetic identities built on a child's or a stranger's Social Security number, and the ITIN-to-SSN misuse that targets immigrants — following Maya, whose data breach became a card she never opened, and Fatima, whose new SSN was turned against her.
- Work the identity-theft recovery plan in order: report to the FTC at IdentityTheft.gov to get your Identity Theft Report, place a fraud alert or a credit freeze, and block the fraudulent accounts with an FCRA §605B letter — reading the affidavit, the block request, and a freeze confirmation field by field, and knowing a freeze is free, a fraud alert lasts a year (seven for victims), and a paid "credit lock" is neither of those things.
- Build the repeatable habit that keeps all of it small — check your free weekly reports, keep your credit frozen between applications, and dispute or report the moment something is wrong — and know exactly where to turn, from the bureaus to the FTC to the SSA and the IRS, when a fix won't come on its own.
Opening
A lesson-header card for Lesson 36, Credit Repair & Identity Theft, in Level 300. It shows the lesson title and a one-sentence overview: fixing a wrong or fraudulent credit report is free, learnable, and legally yours — dispute an error under the FCRA, refuse the repair-scam, and work the identity-theft recovery plan step by step. It lists the five things you can do by the end: dispute an error yourself for free under the FCRA, contacting both the bureau and the furnisher, using the 30-day clock and the method of verification; know what comes off a report and what does not, the seven-year rule and the honest line no scam can cross; spot a credit-repair scam on sight through the CROA, and know a CPN is a federal crime, not a fresh start; work the identity-theft recovery plan through IdentityTheft.gov, a fraud alert or freeze, and the section 605B block that clears fraud in four business days; and choose the right wall — freeze versus fraud alert versus paid lock — and keep it up with a check, freeze, dispute routine. It introduces the three people you will follow: Fatima Osman, an immigrant with a new SSN who is targeted by a “credit fixer,” then suffers SSN misuse that reaches her taxes; Maya Okafor, a data-breach victim with a card she never opened, blocked off her report in four business days; and Priya Nair, thin-file, who disputes her first reported error and faces the synthetic-fraud risk a young SSN runs.
Almost everyone who opens this lesson is carrying one of three specific fears, and it is worth saying all three out loud at the start, because the whole lesson is built to take them apart. The first is the one that arrives like a cold shock: "There are accounts on my report I never opened — someone is using my name, and I don't know how far it's gone." The second is quieter and more grinding: "My report has errors on it, the negative marks are dragging down everything I try to do, and the only people who say they can fix it want a monthly fee." And the third is the one that freezes people in place before they even start: "Even if I wanted to fix this myself, I wouldn't know where to begin — who do I call, what do I send, and does any of it actually work?" If you have felt any of these, it is not because you are careless or naive. It is because no one has ever shown you that the machinery for fixing a credit report and recovering from fraud is a defined, legal process with your name on it — free, ordered, and enforceable. That is exactly what this lesson hands you.
Here are the honest answers, stated now and earned across the lesson, so the reassurance sits at the front and not just the end. To the first fear: if someone opened accounts in your name, federal law gives you a specific recovery plan — report the theft to the FTC and get an Identity Theft Report, wall off your credit with a freeze or a fraud alert, and force the fraudulent accounts to be blocked and deleted — and none of it costs a dollar. To the second: the errors dragging down your report can be disputed by you, directly, under the Fair Credit Reporting Act, and the bureau has a legal deadline to investigate; the companies charging a monthly fee to do this are selling you something the law already gives you for free, and the honest ones cannot do a single thing you cannot do yourself. To the third: "where do I begin" has a real answer — you pull your report, you sort error from fraud, and you follow the exact ordered steps this lesson walks, the same ones the government's own recovery site walks. The fear that this is too complex to face alone is the fear the scam industry feeds on. We are going to starve it.
We follow three people, because trouble on a credit report wears more than one face. Fatima Osman, a 33-year-old certified nursing assistant in Minneapolis, came to the United States as a refugee and spent six careful years building a thin, clean file; she recently moved from an ITIN to a real Social Security number — and that new number became a target, first for an "immigrant credit fixer" who wanted her documents, then for the fraud that followed. Maya Okafor, a 24-year-old dental hygienist in Columbus whose credit we have watched climb since Lesson 1, does everything right and still gets hit: her data is spilled in a corporate breach she had nothing to do with, and a card she never applied for shows up on her report, maxed out and already late. And Priya Nair, a 19-year-old community-college student in California with a young, thin file, carries the everyday version of all of this — a single reported late payment that was never hers, and the quieter risks a thin file runs of being borrowed against, built on, or stolen outright. Their three stories are the three doors into this lesson: an immigrant targeted through a stolen SSN, a careful person caught by someone else's breach, and a beginner learning to dispute her first error.
A boundary, so you know what this lesson is and isn't. It is about fixing what is wrong on your credit report — genuine errors — and recovering when the wrong is fraud, plus seeing the "credit repair" industry that sells you back your own free rights for exactly what it is. It is not the lesson on how the score itself is built: that machine — the factors, the models, the point movements — was Lesson 25, and here we care about correcting the data underneath a score, not re-deriving the score. It is not the lesson on documents and records: keeping your proof, the seven-year reporting clock versus the state statute of limitations, and the "zombie debt" that revives were Lesson 28, and we will use that groundwork, not repeat it. And it is emphatically not the lesson on a debt you actually owe: disputing a collector, demanding validation, and your rights under the Fair Debt Collection Practices Act are Lesson 38, and being sued over a debt is Lesson 35. This lesson lives in one specific place — the report has something on it that is either wrong or fraudulent, and you are going to fix it, for free, yourself. We start where every fix starts: getting the report in front of you and telling the two problems apart. That's §1.
1. First Move — Pull Your Report Free, and Sort Error From Fraud
Before you can fix anything on a credit report, you have to see it — and seeing it is free, which is the first fact the "repair" industry would rather you not know. Your credit report is the file the three nationwide bureaus keep on you: your accounts, their balances and limits, your payment history month by month, your collections and public records, the inquiries when someone pulled your file, and your personal identifiers (name, addresses, Social Security number). It is not your score. The score is a number a separate company (FICO or VantageScore) computes from that file — that machine was all of Lesson 25. Here we care about the file underneath, because a score only reflects the data, and if the data is wrong or fraudulent, the fix is to correct the data, not to argue with the number.
You get the report itself from one place: AnnualCreditReport.com, the only website Congress authorized for free reports (you can also call 1-877-322-8228 or mail a request). Since October 2023 the free reports are permanent and weekly — you can pull all three bureaus every week at no cost, a right that used to be once a year. Watch the word "free" on any other site: many are subscription funnels that ask for a card and enroll you in paid "monitoring." AnnualCreditReport.com never charges. And know what it gives you — the report (the file), not the score; scores you get free from your card issuer or the free tools covered in Lesson 25. Beyond the weekly reports, federal law entitles you to additional free copies in specific situations: within 60 days after any adverse action (a denial or worse terms based on your report), if you are unemployed and plan to look for work within 60 days, if you are on public assistance, or if you are a victim of fraud or identity theft.
Pull all three bureaus, not one, because they do not hold identical files — a furnisher may report to only one or two, and a fraudulent account or an error can appear on one report and be invisible on another. Then read each report for two different kinds of trouble, because they have two different fixes. The first is an error: something on the report is inaccurate but not criminal — a balance that is wrong, a payment marked late that you made on time, an account that is actually your ex-spouse's, an item that should have aged off years ago, or a "mixed file" where someone with a similar name or a transposed SSN has been folded into your report. The second is fraud: an account, an inquiry, or a collection that exists because someone used your identity — a card you never applied for, a loan you never signed, a name and address you do not recognize. That distinction is the whole map of this lesson.
Our three people each arrive at this first step from a different direction. Priya pulls her report because her VantageScore dropped and she wants to know why, and finds a 30-day-late mark on her credit-builder loan for a month she knows she paid on time — an error. Maya pulls hers because a company that held her data emailed to say it was breached, and finds a credit card she never opened, already maxed out and reported late — fraud. Fatima pulls hers because an "immigrant credit fixer" asked for copies of her documents and her brand-new Social Security card, and something felt wrong — and she is right to look, because SSN misuse is exactly what that pitch sets up. Same first move for all three: get the report, in front of you, for free. What they do next depends on which kind of trouble they found, and that fork is §2.
2. Two Problems, Two Toolkits — the Error/Fraud Fork
It is worth slowing down on the fork itself, because choosing the wrong toolkit wastes weeks. An error and fraud can look identical on the page — both show up as a negative mark you do not recognize — but they route to different processes with different laws, different letters, and very different speeds. Send a fraud problem down the ordinary error path and you will wait 30 days for a reinvestigation when a four-business-day block was available; treat an ordinary error as identity theft and you will file affidavits you did not need. So before you write a single letter, you decide: is this thing wrong, or is this thing not mine?
A decision diagram called the error slash fraud fork. At the top, one framing box: first pull your report for free at AnnualCreditReport.com, then ask a single question — is the item WRONG, or is it NOT MINE? The answer forks into two side-by-side panels. The left panel, tinted green and tagged “it is mine,” is headed ERROR — a wrong detail on a real account. Its examples are: a wrong balance; a payment marked late that you paid on time; an ex-spouse's account; an item past its 7-year window; and a mixed file. Its tool badge points to an FCRA section 611 dispute, resolved in about 30 days. The right panel, tinted amber and tagged “it is not mine,” is headed FRAUD — an account, inquiry, or address that is not yours. Its examples are: a card you never opened; a loan you never signed; and an unfamiliar address or inquiry. Its tool badge points to a recovery plan built from IdentityTheft.gov plus an FCRA section 605B block, completed in 4 business days. A muted note at the bottom advises: when you can't tell which side an item belongs to, treat it as fraud — that path is stronger, faster, and free.
The test is simple. If the account is genuinely yours but a detail is wrong — the balance, a payment status, the dates, the account's ownership after a divorce, or an item that has outlived the seven-year reporting limit — that is an error, and the tool is the FCRA dispute: your right to make the bureau reinvestigate and delete anything it cannot verify (§3 through §7). If the account is not yours at all because someone opened it or took it over in your name, that is identity theft, and the tool is the recovery plan: report it to the FTC to get an Identity Theft Report, freeze or flag your credit, and block the fraudulent items in four business days (§15 through §25). The dispute path fixes what is wrong; the recovery path removes what is not yours and walls off the rest.
Two honest complications, so the fork is not too clean. First, some cases are both — a mixed file can be an innocent data mix-up (an error) or the fingerprint of synthetic identity fraud (someone building a fake identity on your SSN); when in doubt, treat a "not mine" account as fraud, because that path is stronger and faster and costs you nothing to over-protect. Second, a fraudulent account often leaves an ordinary-looking error behind it — a hard inquiry you did not authorize, an address you never lived at — and those get cleaned up as part of the recovery, not with a separate stamp-collection of disputes. Keep the fork in mind as a first sort, not a rigid wall: wrong detail on a real account goes left to the dispute; not-mine goes right to the recovery plan. We take the left branch first, because it is the one everyone eventually uses, and it is the branch the whole "credit repair" scam is built to overcharge you for.
3. Your Legal Right to Dispute — the FCRA §611 Reinvestigation
Here is the single most valuable sentence in this lesson: the Fair Credit Reporting Act gives you the right to dispute anything on your credit report, for free, and forces the bureau to investigate it on a deadline. This is not a favor, a loophole, or a service you buy — it is §611 of the FCRA (15 U.S.C. §1681i), and it is the exact power that "credit repair" companies charge $99 a month to exercise on your behalf. When you tell a bureau that an item is inaccurate or incomplete, the bureau must, free of charge, conduct a "reasonable reinvestigation" and either verify the item, correct it, or delete it — and it must finish, in the usual case, within 30 days of receiving your dispute.
Follow Priya. Her VantageScore slipped and she pulled her report to find out why: her Golden State Credit Union credit-builder loan — the $1,000 loan at 12% she opened in Lesson 4 to build history — shows a 30-day late payment for January. She knows this is wrong, because that loan is on autopay from her checking account and the January payment cleared on time; she has the bank statement showing it. This is the textbook error case: a real account of hers, a payment status that is simply false. Under §611 she does not need a lawyer, a fee, or a "repair" company. She needs a letter, her proof, and the deadline the law puts on the other side. The word the statute uses is reinvestigation, and the standard is that it be reasonable — which, as we will see, is exactly where the fights happen and exactly where knowing your rights pays off.
The reason this right exists is that you are not the one who put the data there. A furnisher — the bank, lender, or collector that reports to the bureaus — sent the information, and both the furnisher and the bureau have legal duties to keep it accurate. When you dispute, you are triggering those duties: the bureau must look again, and it must lean on the furnisher to justify the item or give it up. The three things to understand before you write are who you send the dispute to (§4), how you write it so it actually works (§5), and what the 30-day clock does and what you are owed at the end of it (§6). Get those three right and you can delete a genuine error from your own report — the entire "service" the scam industry sells — at the cost of a stamp.
4. Who You Dispute With — the Bureau AND the Furnisher
The first mistake people make is disputing with only one party. There are two you can dispute with, and the smart move uses both — but in a specific order, for a specific legal reason. The two parties are the credit bureau (Equifax, Experian, or TransUnion — whichever one shows the error) and the furnisher (the company that reported it — for Priya, her credit union's loan servicer). The FCRA gives you a right to dispute directly with each. But they are not interchangeable, and how you route the dispute quietly decides what you can do later if they get it wrong.
A two-track diagram for disputing a credit-report error, drawn as two stacked panels under the header “Dispute both — but file through the bureau.” Panel 1, the primary track, is labeled 1 · THE BUREAU and names the three nationwide bureaus: Equifax, Experian, and TransUnion. Filing here means the bureau must run a reasonable reinvestigation, generally within 30 days; must notify the furnisher and forward your information within 5 business days; and this route preserves your right to sue the furnisher later under FCRA section 623(b) and section 1681s-2(b). Its tag reads: PRIMARY — always start here. Panel 2, the secondary track, is labeled 2 · THE FURNISHER, meaning the bank, lender, or collector that reported it. You also have a direct-dispute right under section 623(a)(8); you should send your proof here too so it does not depend on the bureau's e-OSCAR forwarding; but direct-only disputes are enforced by regulators, not by you in court. Its tag reads: BELT-AND-SUSPENDERS. A closing rule box states: always file through the bureau; dispute with the furnisher too. It is what keeps your power to enforce the outcome.
Start with the bureau, and here is why the order matters. When you dispute with the bureau, it must notify the furnisher and forward the relevant information you provided within 5 business days, and the furnisher must then investigate and report back. That bureau-forwarded dispute is the one that unlocks your strongest right: if the furnisher later keeps reporting the error, your ability to sue it in court runs through §623(b) of the FCRA (15 U.S.C. §1681s-2(b)), and that section is triggered only when the furnisher receives the dispute from a bureau. If you dispute only directly with the furnisher and skip the bureau, you have a right to that direct investigation under §623(a)(8) — but the direct-dispute duties are enforced by regulators and states, not by you in a private lawsuit. So the rule of thumb: always file through the bureau, because that is what preserves your own power to enforce the outcome. Disputing with the furnisher too, in parallel, is belt-and-suspenders — useful, especially to send the furnisher your proof directly, but not a substitute for the bureau route.
One quiet piece of plumbing worth seeing, because it explains why disputes sometimes come back with a rubber-stamp "verified." When a bureau forwards your dispute, it usually does not mail your documents to a human at the bank. It sends an electronic form through a system called e-OSCAR: a one-page "ACDV" with a three-digit code describing your dispute, and the furnisher answers with a two-digit code. If the furnisher's automated system simply matches its own records and returns "verified," and the bureau accepts that, your carefully written letter and your bank statement can vanish into a code. This is not a reason to give up — it is a reason to be precise, to keep proof, and to know your escalation rights. In 2025 the CFPB sued one of the major bureaus, alleging exactly this kind of superficial reinvestigation — failing to forward consumers' documents and uncritically accepting furnisher responses — and that case is in active litigation in 2026. The system's weakness is real; your leverage against it is the method-of-verification demand and the "unverifiable must be deleted" rule, which are §5 and §6.
5. How to Dispute — In Writing, With Proof, and the Method of Verification
You can dispute online, by phone, or by mail, and all three legally trigger the same 30-day duty. But the method you choose changes your evidence and, some argue, your rights. Consumer attorneys generally recommend disputing in writing by mail, sent certified with a return receipt, for two reasons: you get dated proof that you disputed and when the clock started, and you avoid the online portals' terms of use, which in some cases have been read to steer disputes into the bureau's own app and away from the paper trail you would want in a lawsuit. Online is faster and fine for a simple, well-documented error; certified mail is the disciplined choice when the item is serious or you expect a fight. Either way, the content is what matters.
A dispute letter that works is short and specific. It identifies you (name, current address, and enough to match your file — never a full SSN on the letter itself beyond what the bureau requires); it names the exact item in dispute (the creditor, the account number as shown, and the specific field that is wrong); it states plainly what is wrong and what the correct information is; and it attaches copies — never originals — of the proof. For Priya, that is one clean paragraph: "The Golden State Credit Union installment loan, account ending 4021, reports a 30-day late payment for January 2026. This is inaccurate. The payment was made on time by automatic transfer; the enclosed bank statement shows it posted on January 3, 2026. Please investigate and delete the late-payment notation." She encloses the bank statement, keeps the original, and mails it certified. That is the entire "service."
If the bureau comes back saying the item was "verified" and you believe it did not truly investigate, you have a specific statutory right most people never use: §611(a)(7) lets you request a description of the procedure the bureau used to determine the accuracy of the item, including the business name, address, and — if reasonably available — the telephone number of the furnisher it contacted, and the bureau must provide it within 15 days. This is the "method of verification" (MOV) request. It forces the bureau to show its work: who did it actually ask, and how? A "verified" that turns out to be an automated code-match with no real review is the vulnerable point, because §611(a)(5) says that anything the bureau cannot verify must be deleted — not merely inaccurate items, but unverifiable ones too. The MOV demand is how you turn a rubber-stamp back into a real question.
Two habits make the difference between a dispute that sticks and one that evaporates. Keep a copy of everything — the letter, the enclosures, the certified-mail receipt, and every response — in one folder per problem, exactly the recordkeeping discipline from Lesson 28; your paper trail is your evidence if this ever escalates. And send your documents to the furnisher too, directly, so your proof does not depend on the bureau forwarding it through the e-OSCAR code. You are not being paranoid; you are making it hard for a "verified" to be anything other than true. Now the clock, and what you are owed when it runs out.
6. The 30-Day Clock, and Your Rights on the Result
The deadline is the teeth of the whole right. Once the bureau receives your dispute, it generally must complete its reinvestigation within 30 days — the clock runs from receipt, not from when you mailed it, which is one more reason to send it certified and know the delivery date. There are two ways the window can stretch to 45 days, and it is worth keeping them straight because people blur them. First, if you send the bureau additional relevant information during the 30 days, it may take up to 15 more days to consider it (30 + 15 = 45) — but that extension does not apply once the item has already been found inaccurate or unverifiable. Second, and separately, if you filed the dispute after pulling your free annual report, a different provision (§612 / §1681j) gives the bureau a flat 45 days. Both roads can reach 45; they are different roads.
A horizontal timeline of Priya's Section 611 dispute clock, showing four milestones in order along a green line. The first node, Day 0 on Thursday February 26, 2026, is when Priya mails her dispute by certified mail; mailing does not start the clock. The second node, labeled Clock starts, on Monday March 2, 2026, is when the bureau actually receives the dispute — the clock runs from receipt, not from mailing, so this is Day 1. The third node, the 30-day deadline, on Wednesday April 1, 2026, is the ordinary reinvestigation deadline: the bureau must finish within 30 days of receiving it. The fourth node, marked with an amber dashed marker, is the 45-day cap on Thursday April 16, 2026: if Priya sends extra documents during the first 30 days, the bureau gets 15 more days, capped at a maximum of 45. Below the line are two notes. First, a separate 45-day rule under FCRA Section 612 (Section 1681j) applies if you disputed after pulling your free annual report. Second, within 5 business days of finishing, the bureau must send written results plus a free revised report, and anything it cannot verify must be deleted, under Section 611(a)(5).
Trace Priya's clock on real dates. She mails her certified dispute on Thursday, February 26, 2026; it is delivered and the bureau receives it on Monday, March 2, 2026 — that Monday is day zero, when the clock starts. The bureau's ordinary 30-day deadline is Wednesday, April 1, 2026. If, on day ten, she mails the bureau a second document (say, the credit union's own letter admitting the reporting error), the bureau can take up to 15 additional days, pushing the deadline to Thursday, April 16, 2026 — but no further, and if it confirms the error before then, it must act promptly rather than run out the clock. Concrete dates matter here because the deadline is enforceable: a bureau that blows it, or that "verifies" without a reasonable investigation, has failed a legal duty, and that failure is what a complaint or a lawsuit is built on.
When the reinvestigation is done, you are owed a specific package, not just a yes or no. Within 5 business days of finishing, the bureau must send you written results, and with them: a statement that the reinvestigation is complete, a free copy of your revised report, notice of your right to the method-of-verification description, notice that you can add your own statement of dispute to the file, and notice that you can ask the bureau to send the correction to anyone who pulled the report recently. Three of those rights are worth naming out loud. If the item stays and you disagree, you can attach a brief statement of dispute — often capped at about 100 words — that then travels with your file into future reports. If a deleted item ever reappears, the bureau cannot simply reinsert it: the furnisher must certify it is complete and accurate, and the bureau must notify you in writing within 5 business days of any reinsertion. And you can ask the bureau to notify prior users of the correction — anyone who pulled the report in the last 6 months, or 2 years for employment purposes. For Priya, the result is the good one: the credit union cannot verify a late payment that never happened, the bureau deletes it, her revised report arrives, and her score recovers over the next cycle — the entire outcome a "repair" company would have billed her monthly to pursue.
7. Document Walkthrough — Priya's §611 Dispute Letter, Field by Field
This is the document the whole "credit repair" industry is built on — a one-page dispute letter that costs you a stamp. Here is the letter Priya actually mails. Take it in as a whole first: it is short, plain, and unemotional, because a dispute is not a plea, it is a demand that a legal duty be performed. Notice the shape — the date and the bureau's dispute address at the top, a clear identification of Priya so the bureau can match her file, a single italicized "Re:" line naming the exact item, one tight paragraph of what is wrong and what is true, an explicit request to investigate and delete, and a list of what she enclosed. Every part is doing a job; we will read each one.
A sample credit-report dispute letter written by Priya Nair to a credit bureau's dispute department, dated February 26, 2026. The letter is laid out in reading order. A recipient block addresses the credit bureau's dispute department at an illustrative P.O. Box 000000, Allen, Texas 75013. A sender block identifies Priya Nair at 000 College Ave, Apartment 4, in a California city, with a redacted date of birth, the last four digits of her Social Security number, 6088, and a report confirmation number, 3829-4471-2205. The highlighted section this lesson reads is the reference line and the body. The reference line states this is a dispute of an inaccurate late-payment on a Golden State Credit Union installment loan, account ending 4021. The body explains that the account reports a 30-day late payment for January 2026, that this is inaccurate because the payment was made on time by automatic transfer and posted on January 3, 2026, and it asks the bureau to investigate and delete the late-payment notation if it cannot be verified. An enclosures line lists a bank statement showing the on-time payment and a copy of the report page with the disputed line circled. The letter is signed Priya Nair. Sample for learning — not an actual dispute letter or bureau address.
The date and the delivery method (top). Date — "February 26, 2026." What it is: the day Priya signs and mails the letter. What it does for her: paired with the certified-mail receipt, it fixes when the dispute was sent, and the return receipt will fix when the bureau received it — the moment the 30-day clock starts. Why it matters: the entire enforceability of the deadline depends on a provable receipt date, so the humble date line and the green-and-white certified slip are not bureaucratic decoration; they are the evidence that the clock is running.
The recipient — the bureau's dispute department. Addressed to the credit bureau's dispute address (each bureau publishes one), not to a general customer-service address and not to the credit union. What it does for her: it routes the dispute to the party with the §611 reinvestigation duty, and — critically — it is the bureau route that later preserves her right to sue the furnisher under §623(b) if the error is not fixed (§4). Why it matters: sending only to the credit union would give up that leverage; the bureau is the door that opens all the others.
Who Priya is — the identifying block. Her full name, current mailing address, date of birth, and only the last four digits of her Social Security number, plus the report confirmation number from the copy she pulled. What it does for her: it gives the bureau exactly enough to find her file and no more — she does not write her full SSN or send original documents. Why it matters: a dispute the bureau cannot match to a file can be brushed off as unverifiable-of-the-consumer, and over-sharing (a full SSN on a loose letter) is a needless exposure; the identifying block threads that needle.
The item in dispute — the "Re:" line and the body. "Re: Dispute of inaccurate late-payment — Golden State Credit Union, account ending 4021." The body then says, in one paragraph: this account reports a 30-day late payment for January 2026; the information is inaccurate; the payment was made on time by automatic transfer and posted on January 3, 2026; please investigate and delete the late-payment notation. What it is: a precise identification of the creditor, the account, and the single field that is wrong, followed by the correct fact. What it does for her: it makes the dispute impossible to misread — one item, one error, one correction — which is what forces a real answer rather than a generic "we reviewed your account." Why it matters: vague, kitchen-sink disputes ("everything on my report is wrong") are the ones bureaus are allowed to treat as frivolous; a specific, documented dispute is the one they must reinvestigate.
The request and the enclosures. The letter explicitly asks the bureau to investigate and to delete the notation if it cannot be verified, and lists what is attached: a copy of the bank statement showing the January 3 payment, and a copy of the report page with the disputed line circled. What it does for her: it hands the bureau the proof and states the remedy she wants, so a completed-but-uncorrected result has no excuse. Why it matters: §611(a)(5) says an item that cannot be verified must be deleted — so by supplying the proof that the "late" payment was on time, Priya makes verification impossible for the furnisher to fake, and deletion the only lawful outcome. She keeps every original, mails copies, and files her certified receipt. That is the entire craft of "credit repair," done for the price of postage. And it teaches the one thing the scam depends on you not knowing: this is easy, it is free, and it is yours.
8. What Comes Off, and What Doesn't — the 7-Year Rule and the Honest Line
Now the hard, honest boundary — the one that separates real credit repair from the lie. A dispute deletes information that is inaccurate, incomplete, or unverifiable. It does not delete information that is accurate and still within its reporting window, no matter how much you wish it gone, and no company on earth can make it. This is the line every "we'll remove anything, guaranteed" pitch crosses, and understanding exactly where it sits is what lets you spot the scam and also know your real options. Most negative information is not permanent — it ages off on a clock — so the honest question is never "can I erase this accurate late payment?" but "when does it fall off on its own, and is there anything genuinely wrong I can dispute in the meantime?"
A two-column ledger card titled “What comes off — and what stays,” sorting credit-report items into those you can remove and those that stay until they age off. The left column, on a green tint and headed “Comes off — you can remove,” lists five items, each marked with a small green check: first, genuine errors, such as a wrong balance, wrong status, or an account that isn't yours; second, incomplete or unverifiable items the furnisher can't confirm; third, mixed-file entries, where someone else's data has been folded into your file; fourth, anything past its 7-year reporting window, or 10 years for a Chapter 7 bankruptcy; and fifth, identity-theft items, which are blocked under section 605B, not merely disputed. The right column, on an amber tint and headed “Stays until it ages off,” lists three items, each marked with a small cross: accurate late payments still within their on-time clock; legitimate charge-offs and collections you actually owe; and a bankruptcy that is still within its reporting window. Below both columns, an amber note box states the honest line: no one can legally remove accurate, timely negatives — the truth every “delete anything, guaranteed” pitch denies. A smaller muted line adds that medical-debt reporting rules are in flux in 2026, which is covered in Lesson 39.
The clock is the seven-year rule, in §605 of the FCRA (15 U.S.C. §1681c). Most adverse items — late payments, charge-offs, collections, and accounts closed for cause — report for about seven years. A Chapter 7 bankruptcy is the notable exception at ten years; a completed Chapter 13 is generally removed by the bureaus at seven. And the clock is anchored to a specific, fixed date: the date of first delinquency, or DOFD — the month you first fell behind on the original account and never caught back up. The seven-year window actually runs to about seven years plus 180 days from that date, because the statute measures from roughly 180 days after that first missed payment. This is the same date-of-first-delinquency you met in Lesson 28, and the same rule with teeth: the DOFD is fixed to the original delinquency and cannot be moved forward.
A timeline of the Fair Credit Reporting Act seven-year clock, which is anchored to a single fixed date. A vertical rail runs top to bottom with three markers. First, at the top, the anchor: the DOFD, or Date of First Delinquency — the first missed payment you never caught up on. This is the fixed starting point; nothing moves it. Second, about seven years and 180 days after that anchor, most negative items fall off your reports on their own: late payments, charge-offs, and collections. Third, at ten years — shown in amber — a Chapter 7 bankruptcy finally falls off. A red warning box underneath explains that paying, settling, or selling the debt does not move this clock, and that reporting a fresher date to restart it — called re-aging — is illegal under FCRA section 623(a)(5). A separate muted note clarifies that a different clock, the state statute of limitations to be sued, can restart if you pay — that is a different clock, covered in Lessons 35 and 38.
That fixed clock is why the most common "repair" promise is a lie. Paying a collection does not remove it and does not reset its clock; settling it does not; selling it to a new collector does not — the DOFD stays pinned to the original delinquency, and a furnisher that reports a fresher date to restart the seven years is committing the illegal practice called re-aging (the FCRA's furnisher rules, §1681s-2(a)(5), require reporting the true date the delinquency began). So when a company promises to "delete" an accurate, in-window collection, one of three things is true: they are going to file a bogus dispute in your name that will bounce back, they are going to do nothing and bill you monthly, or they are going to commit fraud on your behalf. There is a real and dangerous twist to keep straight, though: while paying never changes the credit-reporting clock, in some states making a payment or even acknowledging an old debt can restart the entirely separate statute-of-limitations clock that governs whether you can be sued for it — a different clock, a different lesson (35 and 38), and a reason never to "pay to make it look better" without understanding both clocks.
So here is the clean two-column truth. What legitimately comes off: genuine errors (wrong balance, wrong status, not-your-account), incomplete or unverifiable items, mixed-file entries, anything past its seven- or ten-year window, and — the strongest removal of all — accounts that exist because of identity theft, which get blocked, not just disputed (§20 through §25). What does not come off before its time: accurate, on-clock negatives — real late payments, legitimate charge-offs and collections you actually owe, and bankruptcies within their window. One area is genuinely in motion and belongs to another lesson: medical-debt reporting. The bureaus voluntarily stopped reporting paid medical collections and small medical balances, and the federal rules around medical debt have been changing and contested through 2025 and 2026 — that whole moving story is Lesson 39, and you should treat any 2026 claim about medical debt as something to verify, not assume. For everything else, the map is stable: dispute what is wrong, block what is fraud, and wait out what is accurate — while knowing there is one softer, non-legal lever for the borderline case, which is §9.
9. Goodwill Deletion, and Why "Pay for Delete" Backfires
Between "I can dispute this because it is wrong" and "this is accurate, so it stays" lives a narrow, non-legal gray zone worth naming honestly, because it is real but oversold. The first tool in it is the goodwill deletion. If a negative mark is genuinely accurate — say, one 30-day late on an account you have otherwise paid perfectly for years — you can write the creditor a goodwill letter: not a dispute, not a claim that anything is wrong, but a courtesy request that they remove the mark as a gesture, given your good history and whatever real circumstance caused the slip. It is crucial to understand what this is and is not. It is a request for mercy, not the exercise of a right; the creditor is under no obligation to agree, and a bureau cannot be made to delete an accurate item this way. It works sometimes — most often for an isolated late on an otherwise strong, active account with a lender you have a relationship with — and it costs nothing to ask politely. But it is a favor, and treating it as a guaranteed fix is exactly the overpromise that separates it from a dispute.
The second tool in the gray zone is "pay for delete," and it deserves a warning label. The idea is to offer a collector payment in exchange for deleting the collection from your report. In practice it is discouraged and unreliable for several reasons. Deleting accurate information conflicts with the accuracy duties the FCRA places on furnishers and with the bureaus' own furnishing agreements, so many collectors will not do it and the ones that promise often do not follow through. Paying can also, as we just saw, restart the state statute-of-limitations clock and expose you to a lawsuit on a debt that was about to become unsuable. And if you are dealing with a debt you actually owe and a collector, you have a different and stronger toolkit — debt validation and your rights under the Fair Debt Collection Practices Act — which is the whole of Lesson 38. If you do settle a debt and the collector agrees to delete, get the deletion promise in writing before you pay a cent, and keep it — but go in expecting the payment to help your conscience and your risk of suit far more than your credit report.
Hold the distinction, because the scam industry blurs it on purpose. A goodwill letter is you, for free, politely asking a creditor to show mercy on an accurate mark it is allowed to keep. A dispute is you, for free, forcing a bureau to remove a mark that is wrong. Neither of those is a service worth a monthly fee, and neither promises what it cannot deliver. The credit-repair pitch takes these modest, honest, free tools, wraps them in a guarantee they were never capable of, adds a few things that are outright crimes, and sells the bundle to the people least able to afford it. So we turn to that industry directly — what it legally cannot do, the specific cons to recognize, and the one rule that ends every pitch. That's §10.
10. Predator Watch — the Credit-Repair Scam and the Free-DIY Truth (CROA)
Everything you have learned so far — the free dispute, the 30-day clock, the honest line about what comes off — is exactly the knowledge a whole industry is betting you do not have. The "credit repair" business sells, for a monthly fee, the free rights this lesson just handed you, wrapped in guarantees the law says are impossible and, at the worst end, crimes that can put you in prison. Congress saw this coming and passed a law aimed squarely at it: the Credit Repair Organizations Act, or CROA (15 U.S.C. §§1679 and following). CROA does not ban credit-repair companies; it fences them in with rules so strict that an honest one has almost nothing left to sell you, and a dishonest one breaks the law the moment it takes your money. Here are the pitches to recognize on sight, and the single rule that unmasks all of them.
A Predator Watch warning card about the credit-repair scam and identity-theft cons, naming five schemes that target people repairing credit and explaining how to report them. The first is pay-upfront “credit repair” and “plus 100 points guaranteed”: a company charging an enrollment fee or monthly fee to “fix” your credit — the tell being that charging before the work is done is illegal under the Credit Repair Organizations Act's advance-fee ban, that no one can guarantee a point number or remove accurate information, and that anything they can do, you can do free. The second is “we'll delete everything, even accurate items”: a promise to remove real late payments, collections, or a bankruptcy — the tell being that no one can legally remove accurate, timely information and that “dispute everything” is a frivolous tactic that can backfire on you. The third is “buy a CPN or a new credit identity”: a nine-digit number sold as an SSN substitute for a “fresh start” — the tell being that a CPN is a fabricated or stolen Social Security number, often a child's, and using one on a credit application is a federal crime under 42 U.S.C. section 408 and 18 U.S.C. section 1014. The fourth is “the magic 609 letter”: a template sold as a secret loophole that forces deletion — the tell being that section 609 is only your right to a copy of your file, not a deletion power, and the real, free tool is the ordinary section 611 dispute. The fifth is immigrant-targeted “fix your credit and status” fixers: an in-language fixer who wants your documents and SSN card and links credit to immigration status — the tell being that credit repair cannot touch immigration status, that you should never hand over your SSN card or originals, and that the free FCRA rights protect everyone regardless of status. It closes with a blame-free how-to-report block: where to report, the FTC at reportfraud.ftc.gov which enforces the CROA, your state attorney general, and the CFPB at consumerfinance.gov slash complaint, whose enforcement was cut or contested through 2025 to 2026 so use it alongside the others; what to have ready, the company's name, site, and phone, what you were promised and paid, texts, emails, and contracts, and if a CPN was involved, stop using it now; and why reporting matters, because your report feeds the cases that shut these operations down, since CPN sellers traffic in stolen identities, often children's.
Start with what CROA forbids, because each prohibition maps to a scam. It bans charging any fee before the promised service is fully performed (§1679b(b)) — so a company that takes an "enrollment fee" today or bills you monthly in advance is already breaking the law. It bans false or misleading statements about what they can do to your credit (§1679b(a)), which makes every "+100 points guaranteed" and "we remove all negatives, even accurate ones" pitch illegal on its face, because no one can promise a point total and no one can lawfully remove accurate, timely information. It bans advising you to make untrue statements to a creditor or bureau, and it bans helping you create a "new credit identity" (§1679b(a)(2)) — the hook that makes CPN and file-segregation schemes flatly illegal. And it requires, before you sign anything, a separate written disclosure titled "Consumer Credit File Rights Under State and Federal Law" that says in plain terms you can dispute for free yourself and that accurate negative information cannot be removed — the very sentence the salesperson is talking over.
CROA also arms you. A legitimate contract must be in writing and spell out the total cost, the exact services, any guarantee, and a completion date (§1679d), and it must give you a three-business-day right to cancel for any reason (§1679e), with a cancellation form in duplicate. You cannot sign those rights away — any waiver is void (§1679f). If a company violates CROA you can sue for your actual losses or the amount you paid, whichever is greater, plus punitive damages and attorney's fees (§1679g), and you have five years to do it (§1679i). Real nonprofit credit counselors and your own creditors are exempt from CROA because they are not selling "repair" — which is a tell in itself: legitimate help comes from a 501(c)(3) nonprofit counselor or from you, not from a for-profit "repair" shop. The FTC and CFPB enforce CROA, and the enforcement record is blunt: in 2024 the FTC permanently banned the operators of a sprawling credit-repair pyramid (Financial Education Services) that charged roughly a $99 sign-up plus about $89 a month for false "permanently remove" promises; in 2025 it moved against another operation (Growth Cave) that took some $50 million, settling in early 2026; and in 2022 it shut down a "repair" operation that filed fake identity-theft reports to strip accurate items — a crime we will name in §11.
The one rule that ends every pitch: no one can legally remove accurate, timely information from your credit report, and everything a credit-repair company can lawfully do — dispute genuine errors, ask for goodwill, wait out the clock — you can do yourself for free. So there are only three kinds of "credit repair" company: the ones that charge you for the free disputes you just learned to file, the ones that do nothing and bill you monthly, and the ones that commit crimes on your behalf. None of the three is worth a dollar, and the third can cost you your freedom. If you have already paid one, that is not a verdict on you — these operations are engineered by professionals to sound reasonable to stressed people — and there is a clean way out, which is §30.
Being pitched or charged by one of these is not your fault, and reporting is fast, free, and it stacks up into the cases that shut them down. Where to report: the FTC at ReportFraud.ftc.gov (the agency that enforces CROA) and your state attorney general's consumer-protection office; you can also file with the CFPB at consumerfinance.gov/complaint, with the honest caveat that its enforcement capacity has been cut and contested through 2025–26, so use it alongside the others, not alone. What to have ready: the company's name, website, and phone; what you were promised and what you paid; and every text, email, contract, and receipt. If you paid, dispute the charge with your bank or card issuer — charging before performing violates CROA — and know you can sue under §1679g for what you paid plus fees. If a CPN or a "new credit identity" was involved, stop using it immediately and consider talking to a free legal-aid or consumer attorney (§11). And if you were targeted through an in-language "immigrant credit fixer," the same free rights protect you regardless of immigration status — report it so the next family in your community is warned (§12).
11. The CPN Trap and the "Magic 609 Letter" Myth
Two specific cons deserve their own section because they are the most dangerous and the most viral — one can make you a criminal, and the other just wastes your money while pretending to be a secret. The first is the CPN. Sold as a "credit privacy number" or "credit profile number," it is pitched as a nine-digit substitute for your Social Security number that lets you "start fresh" with a clean file. It is fraud, without exception. Those nine-digit numbers are either fabricated or, far more often, real Social Security numbers stolen from other people — disproportionately children, the incarcerated, and the recently deceased, because their numbers are unmonitored. When you put any number other than your own SSN on a credit application, you are committing a federal crime: Social Security number misuse (42 U.S.C. §408), false statements on a credit application (18 U.S.C. §1014), and identity fraud (18 U.S.C. §1028). A CPN is not a privacy tool and not a legal loophole; it is the front end of stealing someone's identity, and the person whose identity you are handed may be a seven-year-old.
The scam is professionally packaged to look like the opposite of a crime. Sellers call it a "legal" number for privacy, sometimes claim it is an "alternative to an SSN" for people who use an ITIN, and pair it with "file segregation" advice — build a whole new, clean file under the new number. Every piece of that is illegal under CROA's ban on creating a new credit identity and under the federal fraud statutes above. The tells are consistent: any offer of a nine-digit number to use in place of your SSN, any "fresh start" that involves a number that is not your own, any instruction to stop using your real SSN on applications. The only lawful identity you have for credit is your own SSN (or, for those who have one, an ITIN used for its actual tax purpose). A patient, honest rebuild under your real number works — it is slower than a lie, and it is the only path that does not risk prison.
The second con is quieter but everywhere on social media: the "magic 609 letter." Influencers and template-sellers claim that §609 of the FCRA contains a secret technicality — that if you send a specially worded "609 dispute letter" demanding "proof" or the "original signed contract," the bureau is forced to delete anything it cannot produce, including accurate negatives. This is false. Section 609 is simply your right to obtain a copy of the information in your own file — a disclosure right, not a deletion power. There is no magic wording, no loophole sentence, no template that forces deletion of accurate items; the actual dispute mechanism is the ordinary §611 reinvestigation you already know, and it deletes items because they are inaccurate or unverifiable, not because of a clever demand. People pay real money for "609 letter" packages that are just the free dispute dressed up as a secret. Worse, some "repair" scripts cross into crime by telling you to file a false identity-theft report to strip accurate items — the FTC shut down exactly that operation in 2022, and filing a false report is itself a federal crime. The honest tools are the ones in this lesson; there is no cheat code, and anyone selling one is selling you either nothing or a felony.
12. Immigrant-Targeted "Fix Your Credit" Scams — Fatima's Near-Miss
Some of these scams are aimed with precision at immigrant communities, and Fatima's story shows why and how — not because anyone in those communities is naive, but because the scam is engineered to exploit specific, understandable circumstances. Fatima spent six years in the United States building a thin, careful file, first on an ITIN and recently on a new Social Security number. A man who advertised in Somali on a community WhatsApp group and at events near her mosque offered to "fix your credit and help with your status" for a few hundred dollars up front — he just needed copies of her documents and her new Social Security card to "get started." Several things about that pitch are engineered to work on someone in exactly her position: it is delivered in her language through a trusted community channel, it bundles credit with immigration "status" (which credit cannot touch), it targets a new SSN attached to a thin file that is easy to build fraud on, and it counts on unfamiliarity with the free rights this lesson teaches and on a reluctance to involve official agencies.
Name the tells plainly, because they are specific. No one can "fix your credit and your status" together — credit repair has nothing to do with immigration status, and anyone linking the two is lying to build trust and fear at once. No legitimate helper needs your original documents or your physical Social Security card; a "fixer" who photographs your SSN card has just collected exactly what is needed to open accounts in your name. Upfront cash for credit repair is illegal under CROA regardless of who is asking or in what language. And a pitch that offers a CPN or a "new number" as an "ITIN alternative" is offering you the federal crime from §11. Fatima's instinct was right — she declined to hand over her documents — but the near-miss was real: the fixer had already photographed her Social Security card during the meeting, and, as we will see, a card she never opened surfaces on her report weeks later. The scam did not need her cooperation; it needed one photo.
The protection is the same for everyone, and that is the point worth ending on without an ounce of stigma. The Fair Credit Reporting Act's free rights — pull your report, dispute errors, freeze your credit, block fraud — apply to every person regardless of immigration status; you do not need to be a citizen, and you do not need anyone's paid help to use them. An ITIN holder or a new SSN holder disputes and freezes for free, exactly like anyone else. Real help, when you want a human, comes from a nonprofit HUD-approved or NFCC counselor who never charges upfront and never promises to touch your immigration status — not from a "fixer" in a group chat. And because a misused SSN can do damage beyond the credit report — into your taxes and your Social Security earnings record — Fatima's case needs the tax-and-SSA defenses that are §19. First, though, let us read the artifact at the center of the credit-repair scam: the contract itself, and every place it breaks the law. That's §13.
13. Document Walkthrough — the Credit-Repair Contract (specimen)
The most useful way to learn CROA is to watch it broken. Here is a specimen credit-repair contract — the kind Fatima's "fixer" or a slick online outfit would put in front of you — and almost every line of it is illegal. Take it in as a whole first. It looks professional: a company name, a services list, a price, a guarantee, a signature line. That polish is the point; the illegality is not hidden in fine print, it is the business model. Notice the shape — the enrollment fee due today, the monthly charge, the sweeping "we remove everything" promise, the point guarantee, the "fresh start" add-on, and what is conspicuously missing: the disclosure of your rights and the three-day cancellation notice the law requires. We will read it line by line and mark each violation.
A sample credit-repair services agreement from a fictional company, Apex Credit Solutions LLC, shown as a specimen of an illegal contract with every red flag annotated. A danger-colored accent bar and a “SAMPLE — FOR LEARNING” pill mark it as a teaching document. It is presented as document field rows; each row shows a contract term on the left and a small danger tag on the right naming the violation. Row one: an enrollment fee of $199 due today plus an $89 monthly service fee — illegal under the advance-fee ban of the Credit Repair Organizations Act, section 1679b subsection b. Row two: a promise to remove all negative items — late payments, collections, charge-offs, and bankruptcies — guaranteed, which is illegal because accurate information can't be removed, section 1679b subsection a. Row three: a guaranteed one-hundred-point score increase within ninety days — an illegal false guarantee, section 1679b subsection a. Row four: an offer of a CPN, or Credit Profile Number, program for a fresh start — a federal crime because it is a new identity, section 1679b subsection a paragraph 2 and title 42 United States Code section 408. Row five: a non-refundable, no-cancellation-after-signing clause, which is void because the three-day right to cancel is non-waivable, sections 1679e and 1679f. Row six: the client authorizes Apex to act as attorney-in-fact and sign on the client's behalf — the dangerous mechanism by which false disputes get filed in your name. A closing “Missing, and that's the tell” box notes there is no Consumer Credit File Rights Under State and Federal Law disclosure, section 1679c, and no bold three-day cancellation notice, section 1679d — both of which would tell you the truth this contract hides. Sample for learning — a fictional specimen of an unlawful contract, not a real company or agreement.
Read it as a checklist of everything CROA forbids, and you will never mistake one of these for a real service again. The next section walks each field and names the specific statute it breaks — because the goal is not just to feel that this is wrong, but to know exactly why, well enough to say so to a bank, a state attorney general, or a family member about to sign one.
14. The Scam Contract, Field by Field — Every CROA Violation
The company and the framing (top). "Apex Credit Solutions LLC — Credit Repair Services Agreement." What it is: a for-profit credit-repair organization, which means CROA applies to it in full (unlike an exempt 501(c)(3) nonprofit counselor or your own creditor). What it does here: nothing yet, but the label matters — the moment a for-profit company offers to improve your credit for a fee, every rule in §10 attaches. Why it matters: a real nonprofit counselor does not use a contract like this because it is not selling "repair"; the product category itself is the first flag.
The fees — "Enrollment fee: $199, due today. Monthly service fee: $89, billed on the 1st." What it is: money charged before any service is performed. Why it is illegal: CROA's advance-fee ban (§1679b(b)) forbids charging any fee before the promised service is fully performed — so both the $199 due today and the first $89 billed in advance are violations on day one, before a single dispute is filed. What it means for you: the $199 is not a deposit toward a service; it is the evidence that this company is breaking the law, and it is money you can demand back and report. Any "credit repair" that wants a dollar up front has already disqualified itself.
The services promise — "We will remove ALL negative items — late payments, collections, charge-offs, and bankruptcies — from your report, guaranteed. Our specialists dispute every item until it is deleted." What it is: a promise to remove accurate, in-window negatives, plus a "dispute everything" tactic. Why it is illegal: promising to remove accurate information is a prohibited misrepresentation under §1679b(a), because no one — including you — has the right to have accurate, timely information removed; and "dispute every item" is the frivolous mass-dispute approach that bureaus are entitled to reject and that can backfire on you. What it means for you: this single sentence is the lie at the center of the industry — the thing §8 taught you is impossible, sold as a guarantee.
The guarantee — "We guarantee a minimum 100-point score increase within 90 days or your money back." What it is: a specific numeric outcome guarantee. Why it is illegal: no one can control or promise a score result — the score is computed by FICO and VantageScore from bureau data the company does not control — so this is a false and misleading representation of what the service can do (§1679b(a)). The "money back" clause does not cure it; the promise itself is the violation. What it means for you: a guaranteed point number is mathematically undeliverable and legally prohibited, which makes it one of the fastest tells there is.
The add-on — "Ask about our Credit Profile Number (CPN) program for clients who want a fresh start." What it is: an offer to set you up with a new nine-digit identity. Why it is illegal: CROA bars advising you to create a new credit identity (§1679b(a)(2)), and using a CPN in place of your SSN is federal fraud (42 U.S.C. §408; 18 U.S.C. §1014; §1028), as §11 laid out. What it means for you: this line moves the contract from "civil violation" to "federal crime," and the number they hand you is very likely stolen from a real person. Walk out; do not "ask about" it.
The cancellation and authorization terms — "Non-refundable. No cancellation after signing," and "Client authorizes Apex to act as attorney-in-fact and to sign documents on the client's behalf." What it is: a denial of your cancellation right and a broad grant of authority. Why it is illegal or dangerous: CROA gives you a non-waivable three-business-day right to cancel (§1679e, §1679f), so "no cancellation" is void; and a clause letting the company sign documents "on your behalf" is how false disputes and false identity-theft reports get filed in your name — the crime from §11. What it means for you: never grant a credit-repair company power to act as your agent, and know that "non-refundable" is unenforceable against your three-day right.
And the tell in what is missing. A lawful credit-repair contract must be accompanied by a separate written disclosure titled "Consumer Credit File Rights Under State and Federal Law" (§1679c) and must include a bold-face three-day cancellation notice next to your signature (§1679d, §1679e). This contract has neither — because both documents would tell you, in the company's own required words, that you can dispute for free yourself and that accurate information cannot be removed, which is the truth the entire agreement is designed to hide. The absence of your rights disclosure is not sloppiness; it is the strategy. You have now read the scam end to end. We turn to the other half of the lesson — when the trouble on your report is not an error you dispute but a theft you recover from. That's §15.
15. Identity Theft — What It Is, and How Maya Found It
Identity theft is simply this: someone uses your personal information — your name, Social Security number, birth date, account numbers — without your permission, usually to get money or credit in your name. It is not rare and it is not a personal failing. In its 2024 data, the FTC logged 6.5 million fraud reports, with identity theft the second-largest category at 18 percent, more than 1.1 million of them filed through the government's own recovery site, and total reported fraud losses topping $12.5 billion, up a quarter in a single year. The people it happens to did nothing wrong; their data was spilled, guessed, phished, or — as in Fatima's case — photographed. What separates people who recover quickly from people who spiral is not whether they were careful enough to avoid it. It is whether they know the ordered, free plan for afterward. This half of the lesson is that plan, and it starts by naming the different shapes the theft takes, because — like error versus fraud — different shapes route to different first moves.
Maya's is the most common shape. A company that held her personal data — the kind of data broker or service that quietly stores millions of people's records — was breached, one of the enormous 2024-era breaches in which billions of records including names, addresses, and Social Security numbers were exposed at once. Maya did nothing but exist in a database. Weeks later, pulling her free report, she finds a credit card she never applied for: opened in her name at an address she does not recognize, run up near its limit, and already reported 30 days late. This is new-account fraud, and it is exactly why she was breach-exposed but not doomed — because the tools to shut it down and strip it off her report are the ones we are about to walk. Her data being out there is a risk, not a sentence; the card on her report is the harm, and the harm is reversible.
Before the recovery plan, it helps to see the family of identity thefts side by side, because "someone stole my identity" covers several different crimes with different fingerprints and different defenses. Some show up as new accounts on your credit report; some hide inside accounts you already have; some build a whole fake person on your real Social Security number; some target children and go undetected for a decade; and some never touch your credit report at all — they attack your taxes or your Social Security earnings instead, which is why a credit freeze alone cannot cover you. We will take them one at a time, then assemble the single recovery plan that answers all of them.
16. New-Account Fraud vs. Account Takeover
The first and most important split is between fraud that opens something new and fraud that hijacks something you already have, because the single most powerful protection in this lesson — the credit freeze — stops one of them cold and does nothing against the other. Getting this distinction right is what tells you whether a freeze solves your problem or whether you also have to go account by account.
A taxonomy grid titled “The shapes of identity theft — and what stops each,” with a stat line noting that in the FTC's 2024 data, identity theft was 18% of 6.5 million fraud reports, and new credit-card accounts were about 44% of ID-theft reports. Five cards each name a type, describe its fingerprint (how it shows up), and give a green defense line for what stops it. Card one, New-account fraud: the fingerprint is accounts and hard inquiries you never opened, on your credit report; the defense is that a credit freeze stops it, because a lender can't pull a frozen file. Card two, Account takeover: the fingerprint is a changed address or email and unfamiliar charges on an account you already have; the defense is that a freeze does not stop it — passwords plus two-factor authentication do. Card three, Synthetic identity: the fingerprint is a fabricated person built on a real, unmonitored SSN, often a child's; the defense is to freeze every household file, including kids under 16. Card four, Child identity theft: the fingerprint is a minor's SSN used for years, unseen — collection calls or IRS notices for a child; the defense is a free protected-consumer freeze for children under 16. Card five, SSN, tax and employment misuse: the fingerprint is wages or a tax return filed under your number, which never touches your credit report; the defense is that a freeze can't cover it — the IRS with an IP PIN and the SSA do.
New-account fraud is Maya's case: the thief uses your identity to open a brand-new account — a credit card, a loan, a phone contract, a utility. Its fingerprint is on your credit report as accounts and hard inquiries you do not recognize, because opening new credit requires pulling your file. This is the most common form by far; in the 2024 breakdown, new credit-card accounts alone were about 44 percent of identity-theft reports, with new-account loan and bank fraud close behind. And this is precisely the fraud a credit freeze prevents: with your file frozen, a lender cannot pull it, so the fraudulent application dies at the door. Account takeover, by contrast, is when the thief gets into an account you already own — your bank login, an existing card, an email that controls your other accounts. Its fingerprint is not new tradelines but changes and charges: a switched address or email, a new payee, transactions you did not make, a card "replacement" you did not request. A freeze does nothing here, because no new credit is being pulled; the defenses are different — strong, unique passwords, two-factor authentication, and watching your existing statements.
Keep the two responses distinct, because mixing them wastes effort. If you find a new account you did not open, the recovery plan in §20 — report, alert or freeze, block — is built for it, and the freeze is your wall against more. If someone has taken over an existing account, freezing your credit will not touch it; instead you contact that account's fraud department directly, lock or close it, reset the password, and turn on two-factor authentication, ideally with an authenticator app or a security key rather than text messages, which can themselves be hijacked. Many real cases are both at once — a thief who takes over your email can then open new accounts using the password resets your email controls — which is exactly why the recovery plan starts with securing your logins and then walls off new credit. Two more shapes to see before we assemble that plan, and the next one is the one lenders fear most because it is the hardest to catch: the synthetic identity.
17. Synthetic Identity Theft — the Frankenstein File
Synthetic identity theft is the strange, fast-growing cousin of ordinary identity theft, and it is worth understanding even though it often victimizes a lender as much as a person, because the person whose Social Security number sits at its center is frequently a child — and could be yours, or you. Where classic identity theft impersonates a real, whole person, synthetic identity fraud fabricates a new one: a criminal takes a real, valid Social Security number — ideally one with no credit history and no one watching it, which is why children's and sometimes newly issued numbers are prized — and attaches a made-up name, birth date, and address to build a "person" who does not exist. The Federal Reserve calls it the fastest-growing financial crime in the country, and lender losses to it reached a record of roughly $3.3 billion by the end of 2024.
The mechanics matter because they connect to things you already know. The fabricated identity is nurtured like a real thin file: the criminal often adds the synthetic "person" as an authorized user on established tradelines (the piggybacking from §18, weaponized), applies for small credit and gets declined, and each application and add slowly builds a real-looking file at the bureaus. After months or years of patient building, the synthetic identity gets approved for real credit, maxes everything out in a coordinated "bust-out," and vanishes — leaving lenders holding the loss and, sometimes, a real child's Social Security number now tangled in fraud. This is the darkest use of the CPN and file-segregation schemes from §11: a "credit privacy number" sold as a fresh start is often exactly the raw material of a synthetic identity, and the number handed to the buyer may be a seven-year-old's.
For you, the defensive lesson is concrete even though the crime is exotic. Because synthetic fraud feeds on unmonitored Social Security numbers, the two habits that starve it are the ones this lesson keeps returning to: freeze the credit files of everyone in your household, including your children (a free protected-consumer freeze, §18), so a fabricated identity cannot be built on their numbers; and check your own report for the tells of a hijacked SSN — accounts, inquiries, addresses, or even other names associated with your file that are not yours. A mixed file with a stranger's name on it is sometimes an innocent data error and sometimes the visible edge of synthetic fraud on your number; when you cannot tell, you treat it as fraud and use the stronger recovery path. The through-line from §11 holds: the same stolen numbers that credit-repair "fresh start" scams traffic in are the fuel for this, which is one more reason the CPN pitch is not a victimless shortcut.
18. Child Identity Theft and the Authorized-User Trap — Priya
Children are the perfect victims of identity theft, and that sentence should land with some weight. A child has a Social Security number, no credit history, and no one checking a credit report — so a number stolen at age six can be used for a decade before anyone notices, usually when the young person applies for their first card or student loan and discovers a file full of debt, evictions, or collections they could not possibly have incurred. The warning signs a parent or guardian can catch early are specific: collection calls or pre-approved credit offers in a child's name, an IRS notice saying a child's Social Security number was used on a tax return, or a benefits application denied because the number is "already in use." Foster youth are especially exposed, because their information passes through many hands. The defense is proactive and free: you can create and then freeze a credit file for a child under 16 as a "protected consumer," which means no one can open credit against that number until the child grows up and thaws it themselves. Freezing a child's credit is one of the highest-value, lowest-effort protections a family can put in place.
This is also where an honest word about authorized users belongs, because it is a legitimate tool with a fraudulent twin, and Priya sits right on the line. Being added as an authorized user on someone else's card — the card reports to your file and its history helps build yours — is exactly how a huge share of people, including Priya in Lesson 4, first built credit; her authorized-user spot on a family member's twelve-year-old First Tech Federal Credit Union Visa is real, legal, and good for her thin file. That is not the trap. The trap is the commercial version: paying a stranger, or a "tradeline rental" company, to be added as an authorized user on an unrelated person's old, high-limit account purely to inflate a score. That is deceptive, it is a CROA violation for the company arranging it, and when it is used to qualify for a mortgage it becomes bank fraud that people have been indicted for. The clean rule: a real relationship (a parent, a spouse, a family member who actually knows you are on their account) is fine; paying a stranger to rent their history is not, and it is often entangled with the synthetic-fraud machinery from §17.
Priya's exposure is the ordinary young-adult version, and worth making explicit because it is so common. Her file is thin and her Social Security number is relatively fresh and clean — which is attractive to synthetic fraud — so her defensive moves are the same ones this lesson gives everyone: check her free reports (a thin file is faster to scan, and a single fraudulent account stands out against it starkly), keep her real authorized-user and credit-builder accounts, and freeze her credit when she is not actively applying for anything. She should also understand the flip side of being an authorized user: if the primary account holder's card is compromised, it can affect her file, so she watches the accounts she is attached to as well as her own. A thin file is not only a limitation to build past, as Lesson 4 framed it; it is also a surface to protect, because it moves more, up and down, than a thick one — which we will make concrete when we look at how a single fraudulent account hits a thin score versus a thick one.
19. SSN and ITIN Misuse, and Tax Identity Theft — Fatima, and the IRS IP PIN
Fatima's case forces the lesson past the credit report, because a misused Social Security number can do harm in places a credit freeze cannot reach — and this is the single most important thing for anyone whose SSN has been exposed to understand. A credit freeze stops someone from opening new credit in your name. It does nothing to stop someone from using your Social Security number to get a job, or to file a tax return and steal your refund, because those systems are not the credit bureaus. For Fatima, whose SSN was photographed by a "fixer," the exposure runs on two tracks at once: the credit track (fraudulent accounts, handled by the recovery plan in §20) and the tax-and-employment track, which needs the IRS and the Social Security Administration.
A two-track card titled “A freeze doesn't cover this — a misused SSN needs two defenses.” An amber header note warns that a credit freeze stops only NEW CREDIT and does nothing to stop tax-refund fraud or someone working under your number, because those run on different systems. Below, two side-by-side tracks. The left track, labeled CREDIT track, lists two defenses: first, freeze your credit at all three bureaus; second, block fraudulent accounts under section 605B, which takes four business days. The right track, labeled TAX and EMPLOYMENT track, lists four defenses: first, get an IRS Identity Protection PIN, or IP PIN — a six-digit number available to any SSN or ITIN holder, renewed yearly, which blocks a return filed under your number; second, file IRS Form 14039 if a fraudulent return was already filed; third, check your Social Security earnings record through your my Social Security account and lock your SSN with E-Verify Self Lock; fourth, report to SSA-OIG for program fraud, the IRS for tax matters, and the FTC for general identity theft. A muted bottom note explains that an ITIN does not authorize work, which is why SSN misuse for employment is a distinct harm the credit bureaus can't fix, and advises that for Fatima you should run both tracks.
Start with why immigrants moving from an ITIN to an SSN are specifically exposed. An ITIN — an Individual Taxpayer Identification Number — exists for one purpose: to let someone without work authorization file and pay taxes. The IRS is explicit that an ITIN does not authorize work and cannot be used on an employment form. So when someone misuses a real SSN to get a job — a common form of identity theft aimed at, and sometimes committed against, immigrant workers — the fraud shows up not as a new credit card but as wages reported to the IRS and the SSA under your number that you never earned. The IRS flagged more than 818,000 such employment-identity cases in a single recent year. You might learn of it from an IRS notice — a CP01E, telling you someone may have used your SSN for employment — or from a mismatch when you file. The damage is distinct from credit fraud: the IRS may come after you for tax on wages you never received, and your Social Security earnings record can be distorted, affecting future benefits.
The defenses on this track are their own toolkit, and Fatima should run all of them. For tax identity theft — where a thief files a return with your SSN to grab a refund — you file IRS Form 14039, the Identity Theft Affidavit (unless the IRS has already sent you an identity-verification letter such as a 5071C, in which case you verify through the tool it names instead). The strongest ongoing protection is the IRS Identity Protection PIN, or IP PIN: a six-digit number, now available to any taxpayer with an SSN or an ITIN, that you opt into and that changes every year — with it, no return can be filed under your number without the current PIN, which shuts tax-refund fraud down cold. You enroll fastest through an IRS online account, or by Form 15227 if your income is under the threshold (about $84,000 for an individual, $168,000 for a married couple, indexed each year). On the Social Security side, you check your earnings record through your "my Social Security" account to catch wages that are not yours, you can lock your SSN against employment misuse through E-Verify's Self Lock, and you report Social Security program fraud to the SSA's Office of the Inspector General. The rule to carry out of this section: for a misused SSN, freeze your credit and defend your taxes and Social Security — both, because neither one covers the other. With the shapes of theft and their separate tracks in view, we can finally assemble the ordered recovery plan. That's §20.
20. The Recovery Plan — IdentityTheft.gov in Three Moves
Here is the plan that dissolves the first fear this lesson opened with — "someone is using my name and I don't know how far it's gone." It is ordered, it is free, and the government built a website to walk you through it: IdentityTheft.gov, the FTC's recovery site, which takes your report of what happened and gives you back a personalized recovery plan, pre-filled dispute and notification letters, and — the keystone document — your FTC Identity Theft Report. Everything else in the recovery hangs off that report. The plan comes down to three moves, plus one urgent thing to do the moment you discover the theft.
The identity-theft recovery plan, drawn as numbered step panels with the heading three moves, all free. It opens with an urgent amber pre-step: first, if an account was taken over, call its fraud department, close or lock it, change the password, and turn on two-factor authentication, especially on the email that controls your resets. Then move 1, labeled REPORT: report at IdentityTheft.gov to get your FTC Identity Theft Report plus a personalized recovery plan, the document that unlocks every strong right that follows. Move 2, labeled WALL OFF: place a fraud alert, where one free call notifies all three bureaus, or, stronger, a freeze at all three, and pull your free reports to see the full extent. Move 3, labeled CLEAN: send each bureau a section 605B block for the fraudulent items, which are blocked within 4 business days, and contact the fraud department of each company where an account was opened to close it. It closes with a green tagline: report, wall off, block, in that order, none of it costing a dollar.
The urgent thing first: if a specific account has been compromised or taken over, secure it right now — call that company's fraud department, close or freeze the account, and change the password and turn on two-factor authentication, especially on the email that controls your password resets. Then the three moves. Move one: report the theft at IdentityTheft.gov to generate your FTC Identity Theft Report and your recovery plan — this is the document that unlocks every strong right that follows, so it comes first. Move two: wall off your credit — place a fraud alert (one free call to any one bureau, which notifies the other two) or, stronger, a freeze at all three, and pull your free reports to see the full extent. Move three: clean the report — send each bureau an FCRA §605B block request for the fraudulent items, and contact the fraud department of each company where an account was opened to close it and stop the billing. Report, wall off, block: three moves, in that order, none of them costing a dollar.
It helps to see what the fraud did to Maya's file and what the block undoes, because it makes the stakes and the recovery concrete. Before the fraud, Maya's revolving utilization — the balances-to-limits ratio that Lesson 25 showed is one of the biggest score levers — sat at a healthy 22 percent: about $990 owed against $4,500 in limits across her real cards. The fraudulent card added roughly $4,800 of balance on a $5,000 limit, 96 percent used on that account alone, dragging her overall utilization to about 61 percent — $5,790 against $9,500 — and it arrived already reported late, a fresh derogatory on a file that had none. The exact point cost is not something anyone can quote precisely, and this lesson will not pretend otherwise (that honesty was Lesson 25's whole discipline), but a jump from 22 to 61 percent plus a new delinquency can pull a near-prime score down substantially, into a range that changes the price of everything she borrows.
A before-and-after data visualization of what identity-theft fraud did to Maya's credit file and what the §605B block undoes, shown as three horizontal utilization bars on a shared axis from 0% to 100% with an amber dashed guide-line at the commonly cited 30% mark. The first bar, “Before the fraud,” sits at 22% in green — $990 owed against $4,500 in limits on her real cards. The second bar, “With the fraud card,” jumps to 61% and is filled red for danger — $5,790 owed against $9,500 in limits, because a fraud card ran up $4,800 on a $5,000 limit, or 96% used, plus it added a new delinquency. The third bar, “After the §605B block,” returns to 22% in green — the fraud card is blocked and deleted, utilization returns to baseline, and the derogatory is gone. An amber score note gives an honest range rather than a fake point number: a jump from 22% to 61% plus a fresh delinquency can pull a near-prime score down substantially, with the exact points depending on the model, and once the block strips the account the score recovers over a cycle or two. A muted note adds that Fatima's thin file moves more in both directions: a single fraudulent account hits harder, and the block clears it cleaner.
Now the recovery, which is the reassuring half. Because this is fraud and not an error, Maya does not have to argue the balance down or wait out a clock — she blocks the account under §605B, and once it is blocked and deleted, it comes off her file entirely: the $4,800 vanishes from her utilization, which drops back to 22 percent, and the derogatory disappears with it. Her score recovers as the corrected file re-reports, typically over a cycle or two. Fatima's thin file behaves the same way but more sharply in both directions: because a thin file has few accounts to average against, a single fraudulent account moves it more than it would move a thick one — down hard when the fraud lands, and back up cleanly once the block strips it out. The lesson of the illustration is the lesson of the whole recovery: fraud is reversible, the reversal is a defined legal process, and the process is free. Let us read the document at the center of it. That's §21.
21. Document Walkthrough — Maya's FTC Identity Theft Report (specimen)
This is the keystone. When Maya reports her stolen-identity credit card at IdentityTheft.gov and completes the affidavit, the site generates her FTC Identity Theft Report — the single document that turns "someone opened a card in my name" into a set of enforceable rights. It replaced the old paper FTC affidavit in 2016, and it is what a bureau, a creditor, and a collector must accept as proof that the fraud is real. Take it in as a whole first. Notice the shape: the FTC masthead and a unique report number at the top, Maya's identifying information, a plain-language account of what happened, an itemized list of the fraudulent accounts, and — the part that gives it teeth — a statement she signs under penalty of perjury that the accounts are not hers.
A sample FTC Identity Theft Report — the sworn affidavit at the center of this lesson — prepared for Maya Okafor. The masthead reads “FTC Identity Theft Report” above a small “Federal Trade Commission” line, with a “Sample — for learning” badge. A mono sub-line reads Report number IDT-2026-0004182, prepared for Maya Okafor, dated today. The report is organized in reading order. A “Victim Information” section lists Maya Okafor of Columbus, Ohio, date of birth redacted, contact on file. A “What Happened” section explains her personal data was exposed in a company data breach, a credit card was subsequently opened in her name without her knowledge or authorization at an address she does not recognize, and she discovered it on pulling her free credit report. The highlighted section this lesson reads is “Fraudulent Accounts,” marked “the items to block,” listing the card issuer Retail Bank, account ending 7731, balance about 4,800 dollars, opened in the breach month, at an unfamiliar address. A “Sworn Statement,” also highlighted, declares under penalty of perjury that the listed accounts are not hers and were not authorized, signed by Maya Okafor with a signature line and date. A closing note explains that because it is filed with a federal agency under penalty of perjury, this is an identity theft report under FCRA section 603(q) — the document that unlocks the section 605B block, the seven-year extended fraud alert, and your victim records. Sample for learning — not an actual FTC Identity Theft Report.
Read it knowing what it is legally, because that is what makes it powerful. Under the FCRA (§603(q), 15 U.S.C. §1681a(q)), an "identity theft report" is a report that (a) alleges identity theft with as much detail as reasonably possible and (b) is submitted to a federal, state, or local agency — and is subject to criminal penalties for false statements. The completed IdentityTheft.gov affidavit meets that definition on its own, which is why it, and not a paid service, is what unlocks the four-business-day block, the extended seven-year fraud alert, the right to the thief's transaction records, and the right to stop collection of the fraud debt. The next section walks each field and shows exactly what job it does in Maya's recovery.
22. The Identity Theft Report, Field by Field
The masthead and report number (top). The Federal Trade Commission seal, the title "FTC Identity Theft Report," and a unique report number and date. What it is: proof that this is an official report filed with a federal agency, not a self-written note. What it does for Maya: the report number is what she quotes to every bureau and creditor, and it is what lets them confirm the report is genuine. Why it matters: the entire legal weight of the document — its status as an "identity theft report" under §603(q) — comes from its being an official agency filing, and the number and seal are that status made visible.
The victim's identifying information. Maya's full name, current address, date of birth, and contact details, plus confirmation that she is the person filing. What it is: the identity the report is protecting. What it does for Maya: it ties the report to her file at the bureaus so the block and alerts attach to the right person, and it is the information a creditor matches against the fraudulent application to confirm the mismatch. Why it matters: the recovery only works if the report and Maya's credit file are provably the same person — this block is where that link is made.
The narrative — what happened. A plain-language account: that Maya's personal data was exposed in a data breach, that a credit card was subsequently opened in her name without her knowledge or authorization at an address she does not recognize, and when she discovered it. What it is: the "as much detail as reasonably possible" the statute asks for. What it does for Maya: it gives the bureaus and the card issuer the story they need to distinguish fraud from a forgotten account, and it documents the timeline. Why it matters: a vague report is easy to question; a specific narrative — breach, unauthorized account, unfamiliar address, date discovered — is what makes the fraud claim credible and hard to bounce.
The itemized fraudulent accounts. A list naming each fraudulent item: the card issuer, the account number as it appears, the approximate balance and open date, and the address the thief used. For Maya, that is the one card — issuer, account ending in its last digits, roughly $4,800 balance, opened the month of the breach, at the unfamiliar address. What it is: the precise identification of exactly what should be blocked. What it does for Maya: §605B requires her to identify the specific items to be blocked, and this list is that identification — it is what she copies into her block letter. Why it matters: the block only removes what is named; a complete, exact list is the difference between clearing the fraud and leaving a piece of it behind.
The sworn statement and signature. A declaration that the listed accounts and information are not Maya's and were not authorized by her, signed under penalty of perjury. What it is: the oath that converts a complaint into a legal instrument. What it does for Maya: it is what makes the report acceptable to bureaus and creditors as proof — and it is why filing a false identity-theft report is itself a crime, the line the §11 scammers cross. Why it matters: the penalty-of-perjury signature is the source of the report's authority; it is the reason a bureau must act on it, and the reason you must only ever file a true one. With this document in hand, Maya's rights switch on — starting with the wall she puts up while she cleans the file. That's §23.
23. Step 2 — Place a Fraud Alert or a Freeze
With the report in hand, Maya walls off her credit before she does anything else, because while she spends the next days blocking the fraudulent card, she does not want the thief opening a second and a third. She has two tools, and as an active victim she uses both. The lighter, faster one is the fraud alert: a single free call (or online request) to any one of the three bureaus, which is required to notify the other two, placing a flag that tells any lender pulling her file to take extra steps to verify her identity before granting credit. An initial fraud alert lasts one year. But Maya qualifies for the stronger version: because she has an Identity Theft Report, she can place an extended fraud alert that lasts seven years, comes with two free credit reports in the first year, and removes her from prescreened-offer lists for five years. The fraud alert does not stop her from using her own credit; it just makes a lender verify that the applicant is really her.
The stronger tool is the credit freeze, and Maya places one at all three bureaus. Where a fraud alert asks lenders to verify, a freeze simply locks the door: with her file frozen, a lender cannot pull it at all, so a new fraudulent application cannot even be evaluated. A freeze is free, it does not affect her score, and she controls it with a PIN or login — thawing it temporarily when she herself wants to apply for something and refreezing after. The two tools are complementary, not either-or: the extended fraud alert flags her file for seven years and secures the prescreen opt-out and free reports, while the freeze is the actual wall against new-account fraud in the meantime. The full comparison of freeze versus fraud alert versus the paid "credit lock," and exactly which to keep in place long-term, is §26; for the recovery, the move is simply do both now. With the wall up, she cleans the file — which means the block letter. That's §24.
24. Document Walkthrough — the FCRA §605B Block Letter, Field by Field
This is the letter that does the actual removal, and it is stronger and faster than the ordinary dispute from §5, because it invokes a different, tougher part of the law: FCRA §605B (15 U.S.C. §1681c-2), the identity-theft block. Where a §611 dispute triggers a 30-day reinvestigation, a §605B block forces the bureau to block fraudulent information within four business days of receiving four things: proof of your identity, your identity theft report, identification of the specific items, and your statement that the information does not belong to you. Here is Maya's block letter — she sends one to each bureau. Take it in as a whole, then we will read every field and see the four-day clock it starts.
A sample FCRA section 605B identity-theft block-request letter written by Maya Okafor to a credit bureau and sent by certified mail. The masthead reads “section 605B identity-theft block request” with a sample-for-learning pill, and a sub-line saying it is from Maya Okafor, to the credit bureau, sent certified. The letter is laid out as reading-order rows: a date of April 3, 2026, noted as sent certified; a recipient line addressing the credit bureau's identity theft block-request unit at a post office box; and a sender identity line giving Maya's name, address, date of birth, and the last four of her Social Security number, all shown as blanks in this sample. The highlighted section this lesson reads is the invocation: Maya states she is a victim of identity theft and, under FCRA section 605B, which is 15 U.S.C. section 1681c-2, asks the bureau to block the listed information within four business days of receiving the request and to notify the furnisher. She then encloses the four required elements: one, proof of identity — a copy of her driver's license plus a utility bill; two, her FTC Identity Theft Report, number IDT-2026-0004182; three, the items to block, listed below; and four, her statement that this information does not result from any transaction she made or authorized. An items-to-block row names a Retail Bank credit card account ending 7731, one unauthorized hard inquiry dated the breach month, and an unfamiliar address she never used. The letter is signed Maya Okafor. A closing note explains that the bureau must block within four business days — faster than a 30-day dispute — and may decline or rescind only in narrow cases, such as a material misstatement or if she actually received goods on the account. Sample for learning — not an actual legal letter.
The date and certified mailing. Dated and sent certified, exactly like the dispute in §7 and for the same reason: the four-business-day block clock runs from the bureau's receipt, so Maya needs provable delivery. For a concrete timeline: if the bureau receives her complete package on Monday, April 6, 2026, the four-business-day deadline to block falls on Friday, April 10, 2026 — Tuesday, Wednesday, Thursday, Friday. What it does for Maya: it pins the fastest deadline in this entire lesson. Why it matters: four business days versus thirty is the whole reason to use §605B rather than a §611 dispute when the item is fraud.
The invocation and the four required elements. The letter states plainly that Maya is a victim of identity theft and requests a block of the identified information under FCRA §605B, and it supplies the four things the statute requires: (1) proof of identity — a copy of her driver's license and a utility bill; (2) a copy of her FTC Identity Theft Report; (3) the identification of the items to block — the fraudulent card, account ending in its digits, and the unauthorized hard inquiry and address that came with it, copied from the report's itemized list; and (4) her statement that this information does not result from any transaction she made or authorized. What it is: the exact statutory checklist. What it does for Maya: supplying all four is what obligates the bureau to block within four business days — miss one and the bureau can hold the request. Why it matters: §605B is a machine with four required inputs; the letter's job is to deliver all four, cleanly, so the machine has to run.
What the block does, and its limits. The letter asks the bureau to block the items and to notify the furnisher — because once a furnisher is told the information stems from identity theft, §623(a)(6) bars it from continuing to report that information. What it does for Maya: the fraudulent card disappears from her file within days, and the card issuer is put on notice to stop furnishing it. The honest limit, which the letter does not pretend around: a bureau may decline or later rescind a block in narrow cases — if the block was based on a material misstatement, or if it turns out Maya actually received goods or services on the account — which is simply the system's guard against false reports, the same penalty-of-perjury seriousness from §22. For a genuine victim with a complete package, the block is fast and near-automatic. Blocking the account is most of the job; the last piece is using the rest of a victim's rights — the records, the shield against collection, and the police report — which is §25.
25. Your §609(e) Records, §615(g) Shield, and the Police Report
An Identity Theft Report does more than power the block; it switches on several other victim rights worth knowing, because they close the loops the block alone leaves open. The first is the right to the thief's paper trail. Under FCRA §609(e) (15 U.S.C. §1681g(e)), a business where the thief opened an account or made a transaction must give you — free, within 30 days of your written request — the records of that fraudulent application and transactions: the application the thief filled out, the account statements, the transaction records. You can also authorize law enforcement to receive them directly. The business can ask you to prove your identity and to attach a police report or your FTC affidavit, and it can decline in narrow good-faith cases. Why this matters: those records show where the thief operated and what identifying information they had, which helps you find every account and helps any investigation — and it is a right, not a favor you beg for.
The second is a shield against being chased for the fraud debt. Under FCRA §615(g) (15 U.S.C. §1681m(g)), once you give a debt collector the information identifying the debt as the product of identity theft — your Identity Theft Report and a statement that it is fraud — the collector may not sell, transfer, or place that debt for collection. This is the answer to the fear that a fraud debt will follow you: it is not yours, you do not pay it, and the law bars the collector from passing it down the chain to hound you. Combined with the §605B block that removes it from your report and the §623(a)(6) duty that stops the furnisher from re-reporting it, this means a genuine fraud debt can be walled off from your report, your payments, and the collection machine — all through free rights you now know by section number.
That leaves the police report, and the honest rule about when you still need one. Your FTC Identity Theft Report is, by itself, enough for most bureaus and companies. But a police report is still worth filing, and sometimes required, in specific situations: when you know or can identify the thief (a relative, an ex, the "fixer" who photographed Fatima's card), when a particular creditor or bureau insists on a police report in addition to the FTC report, or when your state's law requires one. Filing it is straightforward — bring your government ID, your FTC Identity Theft Report, proof of your address, and any evidence of the theft to your local police. Together, the FTC report plus a police report make the strongest possible "identity theft report," the version that leaves no creditor room to stall. For Maya, the FTC report alone clears her card; for Fatima, who can point to the specific "fixer" who took her SSN card, a police report adds a named suspect and an official record that strengthens both her credit recovery and the SSA and IRS tracks from §19. With the fraud blocked and the loops closed, the lesson turns to keeping the wall up for the long run — which starts with choosing the right wall. That's §26.
26. Freeze vs. Fraud Alert vs. Credit Lock — Which Wall, When
Three products claim to protect your credit file, they are constantly confused, and only one of them is both free and strongest. Getting them straight is what lets you build a wall that actually holds without paying for one that does not. The three are the security freeze, the fraud alert, and the "credit lock," and they differ on exactly the axes that matter: what they stop, how long they last, what they cost, and what legal force stands behind them.
A comparison card titled “Freeze vs. fraud alert vs. lock,” laid out as a three-column table that compares a credit freeze, a fraud alert, and a credit lock across seven rows. The credit-freeze column is visually favored with a green-tinted header. Row one, what it does: a freeze locks your file so no new lender can pull it; an alert flags your file so lenders must verify it's really you; a lock toggles your file on and off via the bureau's app. Row two, does it stop new-account fraud: freeze, yes and strongest; alert, helps but relies on lenders verifying; lock, yes while locked. Row three, cost: freeze is free at all three bureaus; alert is free; a lock is sometimes free but often paid, around $24.99 a month at one bureau. Row four, how long: a freeze lasts until you lift it; an alert lasts one year initially, seven years for victims, one year for active-duty; a lock lasts while subscribed. Row five, legal backing: the freeze and alert are backed by federal law — the freeze free since 2018, the alert under FCRA section 605A — while a lock is only a contract with its own terms, including arbitration and limited liability. Row six, speed: a freeze is placed within one business day and lifted within one hour online; one call places an alert at all three bureaus; a lock is instant in the app. Row seven, does it affect your score: no for all three. A green note below states the FTC's own guidance that a paid lock is no more effective than the free freeze, and advises using the freeze and adding an extended fraud alert if you're a victim. A closing caveat warns that product names, prices, and one bureau's standalone lock shift year to year, so verify current details before relying on them.
The security freeze is the strongest and, since a 2018 federal law (the Economic Growth, Regulatory Relief, and Consumer Protection Act), completely free at all three bureaus. A freeze locks your credit file so no new lender can pull it — which means no one, including you, can open new credit against it until you thaw it. That is the point: if your file cannot be pulled, a thief's application cannot be approved. It does not affect your credit score, it stays in place until you lift it, and you control it with a PIN or online login. The law even puts clocks on the bureau: it must place a freeze within one business day of an online or phone request and lift it within one hour of an online or phone thaw, so temporarily opening your file to apply for something is quick. The one piece of friction is that you must place it separately at each of the three bureaus — a freeze at one does not propagate — and you thaw the relevant one when you apply. For most people not actively shopping for credit, a freeze on all three is the correct default.
The fraud alert is lighter and free, and it works differently: instead of locking the door, it posts a notice on your file telling any lender who pulls it to take reasonable steps to verify that the applicant is really you. You place it with one call or online request to any one bureau, which must notify the other two — simpler than the three-bureau freeze. An initial alert lasts one year; a victim with an Identity Theft Report can place an extended alert lasting seven years (with two free reports and a five-year prescreen opt-out); active-duty servicemembers have their own one-year alert. The trade-off versus a freeze: an alert does not stop you from opening your own credit and relies on lenders actually verifying, so it is more convenient but less absolute. A freeze is the wall; an alert is the "check ID" sign.
The "credit lock" is the one to see clearly, because it is where money changes hands for something the law already gives you free. A lock is not a statutory freeze — it is a product the bureau sells under its own terms of service, usually as an app that toggles your file on and off. Some are free (one bureau offers a free lock-and-alert app), but others are paid: one bureau's lock is bundled into a premium subscription running about $24.99 a month, roughly $300 a year, for locking a file you can freeze for nothing. And because a lock is a contract rather than a statutory right, its protections can be weaker — the terms may include mandatory arbitration and limited liability, where a freeze carries the FCRA's statutory damages if a bureau mishandles it. The FTC's own guidance is blunt: locks are no more effective than the free security freeze. So the honest recommendation: use the free freeze as your wall, add an extended fraud alert if you are a victim, and do not pay a monthly fee for a "lock" that does less than the freeze you can place for free. (Product names, prices, and one bureau's on-again-off-again standalone lock shift year to year — verify the current offering before you rely on it, but the principle holds: never pay for what the freeze does free.) To make the freeze concrete, read its confirmation. That's §27.
27. Document Walkthrough — the Credit-Freeze Confirmation, Field by Field
When Maya places her freeze, each bureau sends back a confirmation, and it is worth reading because it quietly proves every claim §26 just made — that the freeze is free, that it is bureau-by-bureau, that it does not touch her score, and that she stays in control. Here is the confirmation from one bureau. Take it in as a whole, then we will read each line and see the right it documents. It is a short, plain notice; the reassurance is in the details.
A sample security-freeze confirmation notice from a credit bureau, prepared for Maya Okafor as of today. It confirms, in reading order: a “Status” section stating that a security freeze has been placed on her credit file, effective immediately today. The highlighted section this lesson reads is “Cost,” showing a large $0.00 in green with the pointer “free, bureau-by-bureau, no score impact” and the note that there is no charge to place, lift, or remove the freeze. A “Your access / how to lift” section explains she can use her PIN or online login to lift the freeze temporarily or permanently, online or by phone, and that an electronic thaw takes effect within one hour. A highlighted “Scope” section explains the freeze applies only to her file at this bureau, so she must place a freeze separately at the other two bureaus for full protection. A “Your score” section states that placing a security freeze does not affect her credit score. A “Duration” section states the freeze is in effect until she removes it. Sample for learning — not an actual bureau freeze confirmation.
The header and status. The bureau's name, "Security Freeze Confirmation," the date, and the line that a security freeze has been placed on Maya's credit file, effective immediately. What it is: proof the freeze is active. What it does for Maya: it is her record that the door is locked as of a specific date — useful if a lender later claims it pulled her file anyway. Why it matters: the effective date is the moment her file stops being available to new lenders, the start of the protection.
The cost line. "Cost: $0.00." What it is: the price of the freeze, which is nothing. What it does for Maya: it documents that she paid nothing and that no subscription was created. Why it matters: this single zero is the whole argument against the paid "lock" — the confirmation itself certifies that the strongest protection is free, so any monthly charge to "lock" the same file is paying for what this line proves you already have.
The control and thaw instructions. A PIN or online login, and instructions to lift the freeze — temporarily or permanently — online or by phone, with the promise that an electronic thaw takes effect within one hour. What it is: Maya's key to her own file. What it does for her: when she wants to apply for credit, she thaws the relevant bureau for a set window and refreezes after, in minutes. Why it matters: a freeze is not a trap — she is never locked out of her own credit; she holds the key, and the one-hour thaw is what makes keeping a freeze up between applications practical rather than painful.
The scope and the score note. A statement that this freeze applies only to Maya's file at this one bureau — she must place it separately at the other two — and that placing a freeze does not affect her credit score. What it is: the boundary and the reassurance. What it does for Maya: it reminds her the wall is only as complete as the three separate freezes, and it lays to rest the common fear that freezing "hurts your credit." Why it matters: the two most common freeze mistakes are freezing only one bureau (leaving two doors open) and not freezing at all for fear of a score hit — this line corrects both. With the wall understood and confirmed, we look at the event that most often sends people to build it: a data breach. That's §28.
28. When It Starts With a Breach — Maya's Data-Breach Response
Maya's whole ordeal began with an email she did not ask for: a company that held her data announcing it had been breached. This is the most common on-ramp to identity theft now, and it deserves its own calm playbook, because the first thing to get right is the distinction between exposure and theft. A breach means your data is out there and your risk is elevated; it does not mean your identity has been stolen. The scale is genuinely staggering — recent breaches have exposed billions of records at once, including names, addresses, and Social Security numbers pulled from data brokers most people never knowingly dealt with — but the right posture after a breach is prevention and monitoring, not panic. You did nothing wrong, and there is a concrete list of moves that turns exposure back into safety.
A checklist card titled “After a breach: match the move to the data,” opening with an amber note that a breach means your data is exposed, not that your identity is stolen, so the posture is prevention and monitoring, not panic. Each row maps a type of leaked data to the moves it calls for. Row one, marked most serious, SSN exposed: freeze all three bureaus, pull free reports, get an IRS IP PIN, check your SSA earnings, and use E-Verify Self Lock. Row two, password or login leaked: change it everywhere you reused it and turn on two-factor authentication, where an authenticator app or security key beats text codes. Row three, card number leaked: watch the statement and let the issuer replace the card. Row four, bank account leaked: call the bank. Row five, always: expect phishing that uses the real leaked details, so reach companies by numbers you already have, opt out of prescreened offers at OptOutPrescreen.com for five years, and pull free weekly reports at AnnualCreditReport.com. A closing muted note explains that free credit monitoring after a breach is worth accepting but reactive — it alerts you after the fact and does not prevent new-account fraud the way a freeze does, so you generally don't need to pay for it.
Match your response to the kind of data that leaked, because different data calls for different walls. If your Social Security number was exposed — the most serious case — freeze your credit at all three bureaus, pull your free reports to check for anything you did not open, and, because a freeze does not cover taxes, get an IRS Identity Protection PIN and check your Social Security earnings record (the two-track defense from §19). If a password or login leaked, change it everywhere you reused it — reused passwords are how one breach becomes ten account takeovers — and turn on two-factor authentication, ideally an authenticator app or a security key rather than text-message codes, which can be intercepted. If a card number leaked, watch the statement and let the issuer replace the card; if a bank account leaked, call the bank. And in every case, expect phishing: criminals use the real details from a breach to send convincing "your account has a problem" messages, so treat unexpected contact as suspect and reach companies through numbers you already have, not links you were sent.
Two more moves close the gaps a breach leaves. Opt out of prescreened credit offers at OptOutPrescreen.com (or 1-888-567-8688), which removes you from the preapproved-offer lists for five years (permanently if you mail the form) across all the major bureaus including Innovis — those mailed "you're preapproved" offers are a raw material for new-account fraud, and turning them off shrinks the attack surface. And know the limits of the "free credit monitoring" a breached company usually offers: it is worth accepting, but it is reactive — it alerts you after something happens; it does not prevent new-account fraud the way a freeze does, and "dark-web monitoring" cannot pull your leaked data back. The CFPB's guidance is that you generally do not need to pay for monitoring, because the strongest protection — the freeze — is already free. One coverage note for the thorough: beyond the big three bureaus there are specialty reporting agencies for bank accounts, checks, utilities, and insurance (ChexSystems, NCTUE, LexisNexis, Early Warning, Innovis), and you can request reports and freezes from them too if your exposure warrants it. Maya accepts the free monitoring, freezes all three bureaus, opts out of prescreen, and adds an IP PIN — turning a breach that could have owned her into a Tuesday's worth of free steps.
29. The Repeatable Routine — Check → Freeze → Dispute
Everything in this lesson collapses into one small, repeatable habit that keeps the whole subject from ever becoming a crisis again. It is three verbs — check, freeze, dispute — and the reason it works is timing: a problem caught in its first week is a four-business-day block or a one-page dispute, while the same problem caught in its second year is a file full of collections, a denied loan, and months of cleanup. The routine is the difference between the two, and it costs nothing but a little attention.
The repeatable credit-safety routine drawn as a three-step loop you run on a schedule: check, then freeze, then dispute or report, and repeat. Step 1, check: pull your free weekly credit reports, rotating one bureau a month or pulling all three a few times a year and after any data breach; read each report for errors and for fraud, and check your children's files too. Step 2, freeze: keep your credit frozen between applications, thawing only the bureau you need and then refreezing; opt out of prescreened offers; and if your Social Security number is exposed, add an IRS Identity Protection PIN. Step 3, dispute or report, the moment something is wrong: an error goes to the Section 611 dispute, filed with both the bureau and the furnisher on a 30-day clock; fraud goes to the recovery plan, meaning IdentityTheft.gov, a fraud alert or a freeze, and a Section 605B block. A small loop indicator shows the routine repeats. It closes with the tagline: caught early, a fraud is a four-business-day block, not a year of collections.
Check: pull your free reports on a rhythm you will actually keep. Because AnnualCreditReport.com now gives you all three bureaus free every week, a simple system is to rotate — one bureau's report each month, so you touch all three each quarter — or to pull all three together a few times a year, and always after any breach notice or before a big application. Read each one for the two things from §2: errors (wrong details on real accounts) and fraud (accounts, inquiries, or addresses that are not yours). If you have children, check and freeze their files too. Reading a report takes ten minutes once you know what you are looking at, and it is the single act that catches everything early.
Freeze, and dispute. Freeze is the standing posture: keep your credit frozen at all three bureaus whenever you are not actively applying for something, thaw the relevant bureau for the days you need it, and refreeze after — plus a prescreen opt-out and, if your SSN is exposed, an IRS IP PIN. A freeze in place turns most new-account fraud from a problem into a non-event, because the fraudulent application never gets pulled. Dispute (or report) is the reflex for the moment you find something: an error goes to the §611 dispute — bureau and furnisher, in writing, with proof, on the 30-day clock; fraud goes to the recovery plan — IdentityTheft.gov, alert or freeze, §605B block. That is the entire discipline. Check so you see it early, freeze so most of it never happens, and dispute or report the instant something slips through. Run that loop and you never again have to wonder whether you are protected or where to begin — the two fears this lesson opened with — because the answer is a habit you already keep. When the loop is not enough and a fix will not come, you escalate, and the ladder for that is §31, right after a word for anyone this has already happened to.
30. If This Already Happened to You
Some people reading this did not recognize a warning about the future — they recognized something that already happened. Maybe you are in the middle of it right now: accounts you never opened, a report you are afraid to look at, a sense that it is spiraling. Maybe you paid a "credit repair" company for months and got nothing. Maybe, at a low and pressured moment, you bought or used a CPN because someone made it sound like a legal fresh start. Maybe a "fixer" in your community took your documents and your trust. This section is for you, and the first thing to say is the gentlest: none of that makes you foolish. Data breaches are not your fault, the scams are engineered by professionals to sound reasonable, and being targeted — especially when you are new to this country, new to credit, or just stretched thin — is not a verdict on your judgment. Set the self-blame down. It is aimed at the wrong person, and it only keeps you from the steps, which are real and start today.
A reassurance card for someone who has already been hurt around credit repair and identity theft. It says that whatever happened — you're mid-spiral in a fraud, you paid a “credit repair” company that delivered nothing, you bought or used a CPN at a low moment, or a “fixer” took your trust — it doesn't make you foolish, because breaches aren't your fault and the scams are professional, so you can set the self-blame down. It then walks through four situations with what you can still do in each. If you are a fraud victim mid-spiral: there is an ordered plan you know — report at IdentityTheft.gov, freeze, and block under section 605B, where fraud is off in four business days — so do the first move today. If you paid a repair company: dispute the charge with your bank because charging before performing violates CROA, report them to the FTC and your state attorney general, and you can sue for what you paid plus fees under section 1679g, then do the real disputes yourself, free. If you bought or used a CPN: stop using it now before another application becomes another count, talk to a free legal-aid or consumer attorney about anything already filed, and use your own SSN and a patient rebuild, the only safe path, which does work. If a fixer took your info: report them, run the SSN defenses — freeze, IP PIN, and check your SSA earnings — and warn your community, because the next family deserves the warning you didn't get. It closes by saying the exit is the free, ordered, legitimate version of what the scam counterfeited — real disputes, a real freeze, a real recovery plan, real time — and that you are now equipped to do all of it.
Now the steps, matched to what happened. If you are a fraud victim and it feels out of control: it is not, because there is an ordered plan and you now know it — report at IdentityTheft.gov to get your Identity Theft Report, freeze your credit, and block the fraudulent items under §605B, which forces them off in four business days (§20 through §25). Do the first move today; the rest follows. If you paid a credit-repair company that delivered nothing: you may be able to dispute the charges with your bank (charging before performing violates CROA), you can report them to the FTC and your state attorney general, you can sue for what you paid plus fees under §1679g — and then do the real disputes yourself, free, because they were always yours to do. If you bought or used a CPN: stop using it now, before another application becomes another count, and talk to a free legal-aid or consumer attorney about anything already filed; going forward, your own Social Security number and a patient rebuild are the only safe path, and they work. And if a "fixer" took your information: report them, run the SSN-misuse defenses from §19 — freeze, IP PIN, check your Social Security earnings — and warn your community, because the next family deserves the warning you did not get.
The through-line, whatever your situation: the exit is the free, ordered, legitimate version of what the scam counterfeited — real disputes, a real freeze, a real recovery plan, real time — and you are now equipped to do every step of it. What the "repair" company sold you a broken imitation of, you can do yourself, correctly, for nothing. When a step will not move — a bureau that will not fix a clear error, a company that ignores you — you do not just keep pushing at the same door. You climb the ladder. That's §31.
31. Where to Turn — the Recourse Stack, and Your Right to Sue
When something is wrong with your report or someone has stolen your identity, there is a ladder of places to turn, and the skill is matching the problem to the right rung, because they do different jobs and most problems are solved on the bottom two. Aiming at the wrong rung — sending an identity-theft case to a scam-reporting portal, or expecting a federal agency to fix a data error the bureau and furnisher control — is the most common way people waste weeks.
A recourse stack for a credit-report error or identity theft, drawn as a numbered ladder you climb from the bottom rung, where most problems live, up to the top. Rung 1 at the bottom: dispute with the bureau — Equifax, Experian, or TransUnion — and the furnisher for errors, and use IdentityTheft.gov plus a Section 605B block for fraud; errors get reinvestigated in about 30 days, fraud gets blocked in 4 business days, and a security freeze walls off the rest. Rung 2: a police report, worth filing when you know the thief, a creditor demands one, or your state requires it, because it strengthens the FTC report. Rung 3: the FTC at ReportFraud.ftc.gov, for credit-repair and CPN scams, because the FTC enforces the Credit Repair Organizations Act and builds cases. Rung 4: the SSA Office of Inspector General at oig.ssa.gov slash report plus the IRS with Form 14039 and an IP PIN, for a misused Social Security number that reached your Social Security earnings or your taxes, where a credit agency cannot substitute. Rung 5: the CFPB at consumerfinance.gov slash complaint, to escalate a stuck error, with the honest caveat that its enforcement has been cut and contested through 2025 to 2026, so treat it as one channel and never the only one. Rung 6: your State Attorney General, for scams and unfair practices in your state, often more responsive to an individual. Rung 7 at the top: NFCC nonprofit counseling at nfcc.org or 1-800-388-2227, real and free help that is never a paid repair promise, and your right to sue under the Fair Credit Reporting Act Sections 616 and 617 — for willful violations you can recover actual damages or statutory damages of 100 to 1,000 dollars per violation, plus attorney's fees. It closes with a match-the-door guide: errors go to the bureau and furnisher; fraud goes to IdentityTheft.gov and a block; SSN or tax problems go to the SSA and IRS; scams go to the FTC and the state Attorney General; a stuck dispute goes to the CFPB; real help comes from a nonprofit counselor; and a willful violation can become a lawsuit.
Start at the bottom, where most problems live. A wrong item goes to the bureau and the furnisher as a §611 dispute; a fraudulent item goes to IdentityTheft.gov for your FTC Identity Theft Report and then to the bureaus as a §605B block — and a freeze walls off the rest. That is rung one and two, and the great majority of everything in this lesson is resolved there, for free, on the timelines you now know. Above that sit the escalations, each for a specific kind of trouble. A police report is the next rung when you know the thief, when a creditor demands one, or when your state requires it. The FTC's scam-reporting portal (ReportFraud.ftc.gov) is where credit-repair and CPN operations go, because the FTC enforces CROA and builds cases from your report. And for a misused Social Security number that reached your taxes or wages, the SSA's Office of the Inspector General and the IRS (Form 14039 and an IP PIN) are the rungs a credit agency cannot substitute for.
Higher still are the agencies you escalate to when a fix will not come, and here the honest caveat this course repeats matters most. The CFPB (consumerfinance.gov/complaint) takes complaints about credit reporting and can pressure a bureau that will not fix a documented error — but its enforcement capacity has been cut hard and remains contested through 2025 and 2026: a 2025 law slashed its funding cap, its staffing has been driven down sharply and is in active litigation, and it has abandoned nearly two dozen enforcement actions. File there to build a record, but never treat it as your guaranteed backstop. Your state attorney general's consumer-protection office is often more responsive to an individual and is filling part of the gap. For real, free help with your credit and debt — never a paid "repair" promise — a nonprofit HUD-approved or NFCC counselor (nfcc.org, 1-800-388-2227) is the legitimate door. Match the door to the problem: data errors to the bureau and furnisher; fraud to IdentityTheft.gov and the block; SSN and tax misuse to the SSA and IRS; scams to the FTC and your state AG; a stuck dispute to the CFPB; real help to a nonprofit counselor.
And at the top of the ladder is the one most people never realize they have: the right to sue. The FCRA is not just a set of duties; it is enforceable by you in court. If a bureau or furnisher violates it willfully — including reckless disregard for accuracy, not just deliberate malice — you can recover your actual damages or statutory damages of $100 to $1,000 per violation without even proving a dollar of loss, plus possible punitive damages and your attorney's fees (§616, 15 U.S.C. §1681n). If the violation is merely negligent, you can recover your actual damages plus fees (§617, §1681o). You generally have two years from when you discover the violation, and no more than five years from when it occurred, to file (§618). This is why the disciplined paper trail from §5 matters: the certified receipts, the "verified" responses to a documented dispute, the missed deadlines are the evidence a consumer attorney — often working on contingency because the FCRA pays fees — uses to make a bureau take you seriously. You do not have to accept an unfixed error as the final word. The law gives you a courtroom, and knowing that changes how the lower rungs answer you. A few questions people always ask, then a self-check. That's §32.
32. Most Common Questions
These are the questions people actually ask about fixing a report and recovering from identity theft, in plain words, answered with what this lesson built.
A frequently-asked-questions card answering the eleven questions people ask most about credit repair and identity theft. Question one: is “credit repair” ever legitimate? Answer: only disputing genuine errors — which you can do free; no one can remove accurate information. Question two: how long does a negative mark stay, and does paying remove it? Answer: about seven years from the date of first delinquency, or ten for a Chapter 7 bankruptcy; paying doesn't remove it or reset the clock. Question three: will disputing hurt my score? Answer: no — a dispute is free and doesn't lower your score, and fixing a wrong negative can help. Question four: should I dispute online or by certified mail? Answer: both work; certified mail gives dated proof and a cleaner trail for anything serious. Question five: what is the difference between a freeze and a credit lock? Answer: a freeze is free, statutory, and strongest, while a lock is a bureau product, often paid, and no stronger. Question six: someone opened an account in my name — what is the fastest fix? Answer: file an IdentityTheft.gov report, then request a section 605B block; the bureau must block it in four business days. Question seven: is a CPN a legal fresh start? Answer: no — it is a fabricated or stolen Social Security number, and using one is a federal crime. Question eight: do I need a police report? Answer: the FTC report is usually enough; add a police report if you know the thief, a company demands one, or your state requires it. Question nine: my Social Security number was in a breach — what do I do? Answer: freeze all three bureaus, pull your free reports, get an IRS Identity Protection PIN, and watch for phishing; monitoring is only reactive. Question ten: does a freeze stop tax-refund or employment fraud? Answer: no — that needs an IRS Identity Protection PIN and the Social Security Administration; a freeze only stops new credit. Question eleven: can I stop a collector chasing a fraud debt? Answer: yes — under section 615(g), once you give them your Identity Theft Report, they can't sell or keep collecting it. Full answers are in section 32.
"Is 'credit repair' ever legitimate?" Only in the narrow sense of disputing genuine errors — which you can do yourself for free. No one, no matter what they charge, can legally remove accurate, timely information from your report, so any company promising to do that is selling you a scam, a crime, or the free disputes you already know how to file (§8, §10).
"How long does a negative mark stay, and does paying remove it?" Most accurate negatives report for about seven years from the date of first delinquency; a Chapter 7 bankruptcy stays ten. Paying, settling, or selling the debt does not remove it or reset that clock — and in some states paying can restart the separate clock for being sued, so know both clocks before you pay (§8).
"Will disputing an item hurt my credit score?" No. Filing a dispute is free and does not lower your score; if anything, correcting or deleting a wrong negative item can help it. An item under dispute may be flagged as such while it is investigated, but the dispute itself is not a negative (§3–§6).
"Should I dispute online or by certified mail?" Both legally trigger the same 30-day duty. Online is fine and fast for a simple, well-documented error; certified mail with a return receipt is the disciplined choice for anything serious, because it gives you dated proof the clock started and a cleaner paper trail if you ever need to escalate or sue (§5).
"What is the difference between a credit freeze and a credit lock?" A freeze is free at all three bureaus, backed by federal law, does not affect your score, and is the strongest wall against new-account fraud. A lock is a bureau's own product, sometimes free but often a paid monthly subscription, governed by its terms rather than the statute — and the FTC says it is no more effective than the free freeze. Use the freeze (§26).
"Someone opened an account in my name — what is the fastest way to get it off?" Report the theft at IdentityTheft.gov to get your Identity Theft Report, then send the bureaus an FCRA §605B block request with that report, proof of identity, and the list of fraudulent items. The bureau must block them within four business days — faster and stronger than an ordinary 30-day dispute (§20–§24).
"Is a CPN a legal way to start over?" No. A CPN is a fabricated or stolen Social Security number — often a child's — and using any number but your own SSN on a credit application is a federal crime. There is no legal "new credit identity"; the only lawful path is your real number and a patient rebuild (§11).
"Do I need a police report, or is the FTC report enough?" For most bureaus and companies, your FTC Identity Theft Report is enough on its own. File a police report too when you know who the thief is, when a specific creditor or bureau insists on one, or when your state requires it — together they make the strongest possible identity theft report (§25).
"My Social Security number was in a data breach — what should I actually do?" Freeze your credit at all three bureaus, pull your free reports to check for anything you did not open, and because a freeze does not cover taxes, get an IRS Identity Protection PIN and check your Social Security earnings record. Expect phishing that uses the leaked details. Accept free monitoring if offered, but know it is reactive — the freeze is the real protection (§19, §28).
"Does a credit freeze stop someone from stealing my tax refund or working under my number?" No — those systems are not the credit bureaus. A freeze stops new credit; tax-refund fraud is stopped by an IRS IP PIN and Form 14039, and employment misuse is addressed through the SSA (checking your earnings record) and E-Verify's Self Lock. A misused SSN needs both defenses (§19).
"A collector is chasing me for a debt that is not mine because of fraud — can I make them stop?" Yes. Once you give the collector your Identity Theft Report and notice that the debt is the product of identity theft, FCRA §615(g) bars them from selling, transferring, or continuing to collect it. Combined with the §605B block, a genuine fraud debt can be walled off entirely (§25).
33. Check Yourself — the Identity-Theft & Dispute Action Planner
One interactive to turn the whole lesson into a plan you can act on. You pick the situation you are actually in — a wrong item on a real account (an error), an account you never opened (new-account fraud), a takeover of an account you already have, or a misused Social Security number reaching your taxes — and it lays out the exact ordered steps for that case, marks which are free (all of them), and shows the deadline each one runs on. It is pre-filled with two of the cases from this lesson so it reproduces them: Maya's breach-driven new-account fraud, which routes to the report-alert-block plan, and Fatima's SSN misuse, which adds the tax-and-Social-Security track a freeze cannot cover. Clear it and run your own situation.
An interactive identity-theft and dispute action planner. You pick one of four situations — an error on a real account, new-account fraud, account takeover, or Social Security number and tax misuse — and the planner shows an ordered, numbered list of the exact steps for that case. Every step is marked free, and steps with legal deadlines carry a deadline tag: a bureau dispute starts a 30-day clock, a demand for the method of verification runs 15 days, and a section 605B block request is honored within 4 business days. Two example buttons pre-fill real cases — Maya's breach selects new-account fraud, and Fatima's SSN case selects SSN and tax misuse — and a Clear button empties the selection. For each situation a line explains what a credit freeze does and does not cover; for example, a freeze does not stop an account takeover but it does block new-account fraud. It defaults to Maya's new-account-fraud plan. Nothing you pick is saved.
Sit with what it shows. The four situations route to different first moves — an error to the §611 dispute, new-account fraud to IdentityTheft.gov and the §605B block, an account takeover to the account's own fraud department plus a freeze against more, and SSN misuse to both the credit freeze and the IRS-and-SSA defenses — and every path is free, which is the quiet rebuttal to the entire "credit repair" industry. Notice that the freeze appears in three of the four plans but never as the whole answer: it is the wall against new credit, not a fix for an existing takeover and not a shield for your taxes. And notice the deadlines the planner surfaces — the 30-day dispute, the four-business-day block — because they are the reason speed matters: the sooner you act, the smaller and faster every fix is. Change the inputs and the shape holds: sort the problem, take the ordered free steps, and know exactly where each one goes. That is the whole lesson, made into a routine you can run whenever you need it.
Glossary — Every Term This Lesson Taught
- Credit report vs. credit score — the report is the file the bureaus keep (accounts, balances, payment history, inquiries, personal info); the score is a number a separate company (FICO, VantageScore) computes from that file. This lesson fixes the file; the score follows.
- AnnualCreditReport.com — the only federally authorized site for free credit reports; since October 2023 you can pull all three bureaus free every week. It gives the report, not the score.
- Fair Credit Reporting Act (FCRA) — the federal law (15 U.S.C. §1681 and following) that gives you free reports, the right to dispute errors, the right to block identity-theft items, fraud alerts, and a free security freeze, and lets you sue for violations.
- FCRA §611 dispute (reinvestigation) — your free right to make a credit bureau reinvestigate an item you say is inaccurate or incomplete and delete or correct it, generally within 30 days of receiving your dispute.
- Reasonable reinvestigation — the standard a bureau must meet on a dispute; more than mechanically relaying the item to the furnisher and accepting a one-word "verified."
- Furnisher — the bank, lender, or collector that reports information about you to the bureaus; you can dispute with it too, and disputing through the bureau preserves your right to sue it under §623(b).
- Method of verification (MOV) — your §611(a)(7) right to make the bureau describe how it verified a disputed item, including the furnisher's name, address, and phone, within 15 days.
- Unverifiable-must-be-deleted — the rule (§611(a)(5)) that a bureau must delete any disputed item it cannot verify, not only items proven inaccurate.
- Statement of dispute — a brief statement (often up to about 100 words) you can add to your file if a disputed item stays; it travels into future reports.
- Reinsertion notice — the rule that a deleted item cannot simply reappear unless the furnisher certifies it is accurate, and the bureau must notify you within 5 business days if it is reinserted.
- Date of first delinquency (DOFD) — the fixed date you first fell behind on the original account and never caught up; it anchors the 7-year reporting clock and cannot legally be moved forward.
- Seven-year rule (FCRA §605) — most accurate negative items report for about seven years (plus ~180 days) from the DOFD; a Chapter 7 bankruptcy reports for ten years.
- Re-aging — illegally reporting a fresher delinquency date to restart the seven-year clock; paying, settling, or selling a debt never resets that clock.
- Goodwill deletion — a courtesy request asking a creditor to remove an accurate negative mark as a favor; it is not a right, the creditor need not agree, and it works best for an isolated late on an otherwise clean account.
- Pay for delete — offering payment to a collector in exchange for deleting a collection; discouraged and unreliable, it conflicts with accuracy duties, is often not honored, and paying can restart the state clock to be sued.
- Credit Repair Organizations Act (CROA) — the federal law (15 U.S.C. §1679) that bars credit-repair firms from charging before the work is done, from misrepresenting what they can do, and from selling a "new credit identity," and requires a written contract, a rights disclosure, and a 3-business-day cancel right.
- CPN (credit privacy number) — a nine-digit number sold as a Social Security-number substitute; it is fabricated or stolen (often a child's SSN), and using one on a credit application is a federal crime.
- "Magic 609 letter" myth — the false claim that a specially worded letter under FCRA §609 forces deletion of accurate items; §609 is only your right to a copy of your file, not a deletion loophole.
- Identity theft — someone using your personal information without permission to obtain money, credit, employment, or benefits in your name.
- New-account fraud — identity theft that opens a brand-new account in your name; it shows on your report as unfamiliar accounts and hard inquiries, and a credit freeze prevents it.
- Account takeover — identity theft that hijacks an account you already have; it shows as changed contact info and unfamiliar charges, and a freeze does not stop it — strong passwords and two-factor authentication do.
- Synthetic identity theft — fabricating a new "person" by attaching a real, unmonitored Social Security number (often a child's) to a made-up name and birth date; the fastest-growing financial fraud, often built via rented tradelines and CPNs.
- Child identity theft — misuse of a minor's Social Security number, undetected for years because no one checks a child's report; countered by a free protected-consumer freeze for children under 16.
- Authorized user vs. tradeline renting — being added to a real family member's account to build history is legitimate; paying a stranger or a company to rent their account to inflate a score is deceptive, a CROA violation, and can be fraud.
- IdentityTheft.gov / FTC Identity Theft Report — the FTC's recovery site, which takes your report and generates a personalized recovery plan and your FTC Identity Theft Report — the sworn affidavit (an "identity theft report" under FCRA §603(q)) that unlocks the block, the extended alert, and victim records.
- FCRA §605B block — the identity-theft block; on receiving your proof of identity, Identity Theft Report, list of items, and statement that they are not yours, the bureau must block the fraudulent information within 4 business days — faster than a §611 dispute.
- Fraud alert — a free flag telling lenders to verify your identity before granting credit: an initial alert lasts 1 year, an extended alert (for victims with an Identity Theft Report) lasts 7 years, and an active-duty alert lasts 1 year.
- Credit freeze (security freeze) — a free lock on your credit file at each bureau so no new lender can pull it; it does not affect your score, lasts until you thaw it, and is the strongest protection against new-account fraud (free at all three bureaus since 2018).
- Credit lock — a bureau's own product that toggles your file on and off, governed by its terms rather than the statute; sometimes free but often a paid subscription, and no more effective than the free freeze.
- FCRA §609(e) records — a victim's right to obtain, free within 30 days, the thief's application and transaction records from a business where the fraud occurred.
- FCRA §615(g) shield — once you give a collector your Identity Theft Report and notice that a debt is from identity theft, the collector may not sell, transfer, or continue to collect it.
- IRS Identity Protection PIN (IP PIN) — a six-digit number, available to any taxpayer with an SSN or ITIN and renewed yearly, that blocks anyone from filing a tax return under your number without it — the defense a credit freeze cannot provide.
- IRS Form 14039 (Identity Theft Affidavit) — the form you file to report tax-related identity theft, unless the IRS has already sent you an identity-verification letter to use instead.
- ITIN (Individual Taxpayer Identification Number) — a tax-filing number for people without work authorization; it does not authorize work, which is why SSN misuse for employment is a distinct harm needing the IRS and SSA, not the credit bureaus.
- Data breach — an exposure of your personal data held by a company; it raises your risk but is not itself identity theft, and the response is prevention (freeze, IP PIN, passwords) and monitoring.
- Prescreen opt-out (OptOutPrescreen.com) — removing yourself from preapproved-credit-offer lists (5 years online, permanent by mail) to shrink a new-account-fraud vector.
- Specialty consumer reporting agencies — bureaus beyond the big three that report on bank accounts, checks, utilities, and insurance (e.g., ChexSystems, NCTUE, LexisNexis, Early Warning, Innovis); you can request reports and freezes from them too.
- Right to sue (FCRA §616/§617) — you can sue for willful violations (actual or $100–$1,000 statutory damages per violation, plus punitive damages and attorney's fees) or negligent ones (actual damages plus fees), generally within 2 years of discovery.
Key takeaways
- A wrong or fraudulent credit report has a free, legal fix with your name on it: under the Fair Credit Reporting Act you dispute directly, the bureau must reinvestigate within 30 days (45 if you add documents), and anything it cannot verify must be deleted. The companies charging a monthly fee to do this are selling you back a right the law already gave you.
- Dispute with the bureau AND the furnisher, in writing, with copies of your proof — and file through the bureau, because that is what preserves your right to sue the furnisher later. If an item comes back "verified" with no real investigation, ask for the method of verification: the bureau must describe how it checked, including the furnisher's name and contact, within 15 days.
- There is an honest line no one can cross: accurate, on-time-clock negative information stays until it ages off — about 7 years from the date of first delinquency for most items, 10 for a Chapter 7 bankruptcy — and paying, settling, or selling a debt never restarts that credit-reporting clock. Any pitch to "delete anything, guaranteed" is selling a scam or a crime.
- Everything a "credit repair" company can legally do, you can do yourself for free. The Credit Repair Organizations Act bars charging before the work is done, requires a written contract and a 3-day cancel, and forbids promising to remove accurate information or selling a "new credit identity." A CPN — a nine-digit SSN substitute — is a fabricated or stolen Social Security number, and using one is a federal crime, not a fresh start.
- Identity theft wears several faces — a new account opened in your name, a takeover of an account you already have, a synthetic identity built on a stolen SSN (often a child's), and the SSN or ITIN misuse that targets immigrants. A credit freeze stops new-account fraud cold, but it does not stop tax or employment identity theft — for that you need the IRS (Form 14039, an IP PIN) and the SSA.
- If it is fraud, work the plan in order: report to the FTC at IdentityTheft.gov to get your Identity Theft Report, place a fraud alert or a freeze, and block the fraudulent accounts with an FCRA §605B letter — which forces deletion within 4 business days, faster than an ordinary dispute. Your Identity Theft Report also unlocks free business records of the fraud (§609(e)) and stops a collector from selling or collecting the fraud debt (§615(g)).
- Build the wall and keep it up: a credit freeze is free at all three bureaus and does not touch your score, a fraud alert lasts a year (seven for victims with an Identity Theft Report), and a paid "credit lock" is no stronger than the free freeze. Check your free weekly reports, keep your credit frozen between applications, and dispute or report the moment something is wrong — and when a fix won't come, climb the ladder from the bureaus to the FTC, the SSA and IRS, your state attorney general, and, if it is willful, a lawsuit.
Knowledge check
6 questions
Priya finds a late payment on her credit report that she knows she paid on time. A company advertises that it will remove it for $99 a month. What is the accurate picture?