Credit Freeze After an SSN Breach — EmailLeaked
Guides

Credit Freeze After an SSN Breach

Credit freeze after an SSN breach: when a password change is not enough, how freezes work, and IdentityTheft.gov as the official start. Check your email.

On this page

A credit freeze after an SSN breach is the job when a password change is not enough. Freeze at Equifax, Experian, and TransUnion using official bureau pages. Start recovery at IdentityTheft.gov if you see fraud. This is not legal advice. Last updated: September 2026.

A credit freeze after an SSN breach is what you do when the leak is identity data, not just a login. A new password stops credential stuffing. It does not expire a Social Security number, a date of birth, or a government ID. Those fields stay useful for new-account and tax fraud for years.

This page is US-focused, educational, and not legal, tax, or personalized financial advice. We are not lawyers. Official steps live on the FTC’s credit freeze article, USA.gov’s freeze page, and IdentityTheft.gov. If those pages disagree with anything here, they win.

The hour-by-hour login work is still in what to do after a data breach. Do that too. This page is the identity half.

When is a password change not enough after a data breach?

A password change is the right first move when the result listed a password, a hash, or credentials. It is the wrong only move when the result listed identity fields.

Treat a password change as not enough when the named incident included any of:

  • Social Security number or other national ID
  • Driver’s license or government-issued ID
  • Date of birth plus a full name and address
  • Tax or background-check files
  • Bank account numbers used to open credit, not just a reusable website password

People-search and background-check dumps are the usual case. National Public Data is the 2024 example on this site: names, emails, phones, addresses, dates of birth, and government-issued IDs. No passwords. Changing Gmail does not close that door.

An email-only scrape is different. Phishing risk, not new-credit risk. Use the quieter playbook on the after-breach page. If you are also retiring junk inboxes, use email aliases after a data breach.

As of 2026, public catalogs still describe on the order of a thousand named incidents and more than 12 billion compromised records. Identity rows do not age out the way a password does. The Verizon 2024 Data Breach Investigations Report is about stolen logins. This page is about the other file.

  • Password leak → unique passwords and a second factor.
  • SSN / ID leak → freeze, then official recovery if you see fraud.
  • A checker match is a to-do list. It is not a diagnosis that fraud already happened.
  • You cannot un-leak a Social Security number. You can make new credit harder to open.

What is a credit freeze and what does it not do?

The FTC’s name for this is a credit freeze (also called a security freeze). While it is on, nobody can open a new credit account in your name — including you — until you lift it.

What it does, per the FTC:

  • Makes it harder for someone else to open new credit in your name
  • Costs nothing to place or lift (federal rule since 21 September 2018)
  • Does not change your credit score
  • Lasts until you lift it
  • Is available to anyone, for any reason — you do not have to wait for a breach

What it does not do:

  • It does not lock existing cards, loans, or bank logins
  • It does not stop someone who already has a card number from charging that card
  • It does not remove you from a breach file
  • It does not replace a unique email password
  • It does not automatically notify the other two bureaus — you must freeze each one

The CFPB notes that paid credit locks are no more effective than a free security freeze. If a dashboard tries to sell a lock as stronger than a freeze, leave.

A freeze is also not a card freeze at your bank. If a payment card may have leaked, contain that card with the issuer. The generic walkthrough is how to close a bank or card account.

How do you place a credit freeze at the major bureaus?

Use official pages. Do not call a number from a text that says your credit is “already frozen.”

The FTC says you must contact all three nationwide bureaus:

Start from the FTC article or USA.gov if a bureau URL has moved. Phone numbers and form URLs change. We will not treat a blog phone list as the last word.

USA.gov states the statutory timing, as of its November 2025 update:

  • Freeze online or by phone: the bureau must place it within one business day
  • Freeze by mail: within three business days
  • Lift online or by phone: within one hour
  • Lift by mail: within three business days

When you later need a mortgage, a card, or a job check, the FTC says you can lift only the bureau that lender will use, then freeze it again. Ask the lender which bureau they pull.

You will create a login at each bureau. Use a unique password and a second factor. Save those logins in a password manager. Losing the freeze PIN or account is a miserable recovery.

If a child is under 16, the FTC has a separate minor-freeze path. Follow the bureau instructions linked from the FTC article. Do not improvise.

See which named incidents include this inbox. Check if your email was exposed → — free, no signup. A match that lists government ID is the freeze playbook. A password-only match is not.

What is IdentityTheft.gov and when should you use it?

IdentityTheft.gov is the US Federal Trade Commission’s official site to report identity theft and get a recovery plan. It can produce an FTC Identity Theft Report and a step list. If you create an account there, the FTC says it can walk you through steps and pre-fill some letters.

Use it when:

  • You see accounts, tax filings, or credit applications you did not open
  • A lender, IRS notice, or collection letter points at fraud in your name
  • You want an official report so you can ask for an extended fraud alert (seven years), which the FTC ties to an IdentityTheft.gov report or a police report

You do not have to wait for IdentityTheft.gov to freeze your credit. Anyone can freeze for any reason. Freeze first if the leak listed an SSN or government ID. Then decide whether you have actual fraud to report.

The FTC warns that it is illegal to knowingly file a false identity theft report. A checker match, by itself, is not proof someone opened credit in your name. Do not invent a victim report because a headline scared you.

IdentityTheft.gov also offers a data breach path if you were notified and are not sure you are a victim yet. Use that path for the official checklist. This blog post is not a substitute.

What is the difference between a credit freeze and a fraud alert?

Both are free. They are not the same lock.

ToolWhat it doesHow you place itHow long
Credit freezeBlocks new credit until you lift itEach bureau, separatelyUntil you lift it
Initial fraud alertLenders should verify it is youOne bureau; it tells the other twoOne year, renewable
Extended fraud alertSame idea, after proven identity theftOne bureau + FTC or police reportSeven years

The FTC says you can use a freeze and a fraud alert together. A fraud alert does not block access to the report. A freeze does.

An initial alert also entitles you to a free credit report from each bureau, per the FTC. Pull reports from AnnualCreditReport.com — the official site — and look for accounts you do not recognize.

Active-duty servicemembers have a separate alert type on the same FTC page. Follow that page, not a third-party “military freeze” ad.

What should you do after a National Public Data or similar identity leak?

Start with what the row actually says.

The National Public Data explainer is a 2024 people-search / background-check exposure. Sellers claimed about 2.9 billion rows. This catalog lists about 134 million unique emails. The row is unverified. Passwords were not included. The first SSN-heavy file associated with that story did not include emails.

So:

  1. Check the address. A match means that email appeared in the later corpus we can search.
  2. Do not read the match as proof your SSN was on the same line.
  3. If the incident class is identity data — this row, or a notice that named SSN or license — freeze at all three bureaus anyway. The FTC says you do not have to wait.
  4. Skip the “reset National Public Data password” instinct. Most people never had a login there.
  5. Watch for new-account and tax fraud, not stuffing of a password that was never in the file.

Browse the breach catalog when you want the story of a named incident. Other identity-class rows get the same freeze-first order. Password-class rows get the password playbook.

What official steps come after you place the freeze?

Finish the identity list. Then return to ordinary account hygiene.

  • Pull your free reports at AnnualCreditReport.com. Dispute errors through the bureau that shows them.
  • If you see fraud, report it at IdentityTheft.gov and follow that plan. Consider a police report if the FTC plan says to.
  • If a card or bank login was also in a different incident, contain the card with the issuer. Use official numbers on the physical card or a statement you already have.
  • Tax: if an SSN may be exposed, the IRS explains Identity Protection PINs at irs.gov. Use that page. We will not walk a tax filing for you.
  • Email and leftover logins: unique password via the password reuse checklist, 2FA, then the account security checklist. Close unused sites from the delete-account hub.

Do not pay for “dark web removal” of an SSN. Copies do not get recalled. A freeze and official recovery steps are the work.

This is general consumer information for a US reader. It is not a lawyer, a credit counselor, or your state attorney general. If you are already in a dispute, use the letters IdentityTheft.gov prepares and the bureau’s own process.

  • Password changes do not expire an SSN or government ID.
  • Freeze at Equifax, Experian, and TransUnion from official pages.
  • IdentityTheft.gov is the official recovery start when you see fraud.
  • A National Public Data email match is not proof of SSN exposure.
  • We are not lawyers. FTC, USA.gov, and IdentityTheft.gov win if they differ.

Want to know which named incidents include your address? Check if your email was exposed →

Frequently asked questions

Is a password change enough if my Social Security number may have leaked?
No. A password change stops stuffing on logins. A Social Security number, date of birth, or government ID does not expire when you change Gmail. The US work is a credit freeze at each nationwide bureau and, if you see fraud, a report at IdentityTheft.gov. This is general information, not legal advice.
Does a credit freeze hurt my credit score?
The FTC says placing or lifting a credit freeze is free and does not affect your credit score. Existing cards and loans keep working. You cannot open new credit in your name while the freeze is on — including you — until you lift it at the bureau a lender will use.
Do I freeze at one bureau or all three?
A freeze must be placed at each nationwide bureau separately: Equifax, Experian, and TransUnion. One bureau will not tell the other two. A fraud alert is the tool you can place at one bureau and have it copied to the others. Start from the FTC credit-freeze page so you use each bureau’s current freeze form.
Should I use IdentityTheft.gov if I only got a breach notice?
Use IdentityTheft.gov when you see signs of identity theft or you want an official recovery plan. The site also has a data-breach path. A notice or a checker match is not the same as confirmed fraud. Do not file a false report. If you are not sure, read the FTC freeze article first and freeze anyway — anyone can freeze for any reason.
Does a National Public Data match mean my SSN was stolen?
No. That 2024 people-search row is unverified. Later files list about 134 million unique emails plus names, phones, addresses, dates of birth, and government-issued IDs. Passwords were not included. An email match means your address appeared in that later corpus. It is not proof your Social Security number was on the same row.
What is the difference between a credit freeze and paid credit monitoring?
A freeze blocks new creditors from opening accounts in your name until you lift it. Monitoring tells you after something already appeared. The CFPB notes that paid “credit locks” are no more effective than a free security freeze. Company-offered monitoring after a breach is optional. It is not a substitute for the freeze.
I do not live in the United States. Does this page apply?
The freeze steps and IdentityTheft.gov are United States tools. Other countries use different credit files and police or consumer agencies. This page does not map those systems. If your email appeared in a named incident, still change reused passwords and use the after-breach playbook. Do not treat US bureau links as global law.

Founder and editor of EmailLeaked. A software and web developer, he built the site's breach checker and its no-storage privacy model, and writes its plain-English guides for people who need a straight answer about a leak — not a data dump. LinkedIn

Our editorial standards →
Breach response

Use the after-breach checklist

Prioritize password changes, 2FA, login history review, fraud monitoring, and phishing defense.

Open the hub

Get monthly breach alerts — free

One email per month. Biggest breaches, what was exposed, what to do. No spam.

No spam · Unsubscribe anytime · Your email is never shared

Find out where you stand.

Check which breaches include your email — free, instant, never stored.

Check my email — free
No signup · Under 2 seconds · Never stored