A credit freeze after an SSN breach is the job when a password change is not enough. Freeze at Equifax, Experian, and TransUnion using official bureau pages. Start recovery at IdentityTheft.gov if you see fraud. This is not legal advice. Last updated: September 2026.
A credit freeze after an SSN breach is what you do when the leak is identity data, not just a login. A new password stops credential stuffing. It does not expire a Social Security number, a date of birth, or a government ID. Those fields stay useful for new-account and tax fraud for years.
This page is US-focused, educational, and not legal, tax, or personalized financial advice. We are not lawyers. Official steps live on the FTC’s credit freeze article, USA.gov’s freeze page, and IdentityTheft.gov. If those pages disagree with anything here, they win.
The hour-by-hour login work is still in what to do after a data breach. Do that too. This page is the identity half.
When is a password change not enough after a data breach?
A password change is the right first move when the result listed a password, a hash, or credentials. It is the wrong only move when the result listed identity fields.
Treat a password change as not enough when the named incident included any of:
- Social Security number or other national ID
- Driver’s license or government-issued ID
- Date of birth plus a full name and address
- Tax or background-check files
- Bank account numbers used to open credit, not just a reusable website password
People-search and background-check dumps are the usual case. National Public Data is the 2024 example on this site: names, emails, phones, addresses, dates of birth, and government-issued IDs. No passwords. Changing Gmail does not close that door.
An email-only scrape is different. Phishing risk, not new-credit risk. Use the quieter playbook on the after-breach page. If you are also retiring junk inboxes, use email aliases after a data breach.
As of 2026, public catalogs still describe on the order of a thousand named incidents and more than 12 billion compromised records. Identity rows do not age out the way a password does. The Verizon 2024 Data Breach Investigations Report is about stolen logins. This page is about the other file.
- Password leak → unique passwords and a second factor.
- SSN / ID leak → freeze, then official recovery if you see fraud.
- A checker match is a to-do list. It is not a diagnosis that fraud already happened.
- You cannot un-leak a Social Security number. You can make new credit harder to open.
What is a credit freeze and what does it not do?
The FTC’s name for this is a credit freeze (also called a security freeze). While it is on, nobody can open a new credit account in your name — including you — until you lift it.
What it does, per the FTC:
- Makes it harder for someone else to open new credit in your name
- Costs nothing to place or lift (federal rule since 21 September 2018)
- Does not change your credit score
- Lasts until you lift it
- Is available to anyone, for any reason — you do not have to wait for a breach
What it does not do:
- It does not lock existing cards, loans, or bank logins
- It does not stop someone who already has a card number from charging that card
- It does not remove you from a breach file
- It does not replace a unique email password
- It does not automatically notify the other two bureaus — you must freeze each one
The CFPB notes that paid credit locks are no more effective than a free security freeze. If a dashboard tries to sell a lock as stronger than a freeze, leave.
A freeze is also not a card freeze at your bank. If a payment card may have leaked, contain that card with the issuer. The generic walkthrough is how to close a bank or card account.
How do you place a credit freeze at the major bureaus?
Use official pages. Do not call a number from a text that says your credit is “already frozen.”
The FTC says you must contact all three nationwide bureaus:
- Equifax — equifax.com credit freeze
- Experian — experian.com freeze center
- TransUnion — transunion.com/credit-freeze
Start from the FTC article or USA.gov if a bureau URL has moved. Phone numbers and form URLs change. We will not treat a blog phone list as the last word.
USA.gov states the statutory timing, as of its November 2025 update:
- Freeze online or by phone: the bureau must place it within one business day
- Freeze by mail: within three business days
- Lift online or by phone: within one hour
- Lift by mail: within three business days
When you later need a mortgage, a card, or a job check, the FTC says you can lift only the bureau that lender will use, then freeze it again. Ask the lender which bureau they pull.
You will create a login at each bureau. Use a unique password and a second factor. Save those logins in a password manager. Losing the freeze PIN or account is a miserable recovery.
If a child is under 16, the FTC has a separate minor-freeze path. Follow the bureau instructions linked from the FTC article. Do not improvise.
See which named incidents include this inbox. Check if your email was exposed → — free, no signup. A match that lists government ID is the freeze playbook. A password-only match is not.
What is IdentityTheft.gov and when should you use it?
IdentityTheft.gov is the US Federal Trade Commission’s official site to report identity theft and get a recovery plan. It can produce an FTC Identity Theft Report and a step list. If you create an account there, the FTC says it can walk you through steps and pre-fill some letters.
Use it when:
- You see accounts, tax filings, or credit applications you did not open
- A lender, IRS notice, or collection letter points at fraud in your name
- You want an official report so you can ask for an extended fraud alert (seven years), which the FTC ties to an IdentityTheft.gov report or a police report
You do not have to wait for IdentityTheft.gov to freeze your credit. Anyone can freeze for any reason. Freeze first if the leak listed an SSN or government ID. Then decide whether you have actual fraud to report.
The FTC warns that it is illegal to knowingly file a false identity theft report. A checker match, by itself, is not proof someone opened credit in your name. Do not invent a victim report because a headline scared you.
IdentityTheft.gov also offers a data breach path if you were notified and are not sure you are a victim yet. Use that path for the official checklist. This blog post is not a substitute.
What is the difference between a credit freeze and a fraud alert?
Both are free. They are not the same lock.
| Tool | What it does | How you place it | How long |
|---|---|---|---|
| Credit freeze | Blocks new credit until you lift it | Each bureau, separately | Until you lift it |
| Initial fraud alert | Lenders should verify it is you | One bureau; it tells the other two | One year, renewable |
| Extended fraud alert | Same idea, after proven identity theft | One bureau + FTC or police report | Seven years |
The FTC says you can use a freeze and a fraud alert together. A fraud alert does not block access to the report. A freeze does.
An initial alert also entitles you to a free credit report from each bureau, per the FTC. Pull reports from AnnualCreditReport.com — the official site — and look for accounts you do not recognize.
Active-duty servicemembers have a separate alert type on the same FTC page. Follow that page, not a third-party “military freeze” ad.
What should you do after a National Public Data or similar identity leak?
Start with what the row actually says.
The National Public Data explainer is a 2024 people-search / background-check exposure. Sellers claimed about 2.9 billion rows. This catalog lists about 134 million unique emails. The row is unverified. Passwords were not included. The first SSN-heavy file associated with that story did not include emails.
So:
- Check the address. A match means that email appeared in the later corpus we can search.
- Do not read the match as proof your SSN was on the same line.
- If the incident class is identity data — this row, or a notice that named SSN or license — freeze at all three bureaus anyway. The FTC says you do not have to wait.
- Skip the “reset National Public Data password” instinct. Most people never had a login there.
- Watch for new-account and tax fraud, not stuffing of a password that was never in the file.
Browse the breach catalog when you want the story of a named incident. Other identity-class rows get the same freeze-first order. Password-class rows get the password playbook.
What official steps come after you place the freeze?
Finish the identity list. Then return to ordinary account hygiene.
- Pull your free reports at AnnualCreditReport.com. Dispute errors through the bureau that shows them.
- If you see fraud, report it at IdentityTheft.gov and follow that plan. Consider a police report if the FTC plan says to.
- If a card or bank login was also in a different incident, contain the card with the issuer. Use official numbers on the physical card or a statement you already have.
- Tax: if an SSN may be exposed, the IRS explains Identity Protection PINs at irs.gov. Use that page. We will not walk a tax filing for you.
- Email and leftover logins: unique password via the password reuse checklist, 2FA, then the account security checklist. Close unused sites from the delete-account hub.
Do not pay for “dark web removal” of an SSN. Copies do not get recalled. A freeze and official recovery steps are the work.
This is general consumer information for a US reader. It is not a lawyer, a credit counselor, or your state attorney general. If you are already in a dispute, use the letters IdentityTheft.gov prepares and the bureau’s own process.
- Password changes do not expire an SSN or government ID.
- Freeze at Equifax, Experian, and TransUnion from official pages.
- IdentityTheft.gov is the official recovery start when you see fraud.
- A National Public Data email match is not proof of SSN exposure.
- We are not lawyers. FTC, USA.gov, and IdentityTheft.gov win if they differ.
Want to know which named incidents include your address? Check if your email was exposed →