Anyone who has ever had a credit card opened in their name by a stranger knows the damage can take months to untangle. Federal law now gives every consumer a free tool to stop that from happening: a security freeze placed at Equifax, Experian, and TransUnion. The three nationwide credit bureaus must place, lift, or remove these freezes at no cost, and when a freeze is active, creditors cannot pull a report, which means they typically deny the fraudulent application outright.
How federal law made free freezes mandatory at all three bureaus
The legal foundation sits in Section 1681c-1 of the Fair Credit Reporting Act, which establishes consumers’ rights to place, temporarily lift, and remove security freezes. The statute requires nationwide consumer reporting agencies to perform these actions free of charge. Before this provision took full effect in September 2018, many states allowed bureaus to charge fees ranging from a few dollars to more than ten dollars per freeze, per bureau. That cost barrier discouraged millions of people from using the protection at all.
The Federal Trade Commission highlighted the shift in a September 2018 release explaining that the new federal law also extended fraud alerts from 90 days to a full year. A fraud alert tells lenders to take extra steps to verify identity before opening new credit, but it expires automatically after that one-year period unless renewed. A freeze, by contrast, remains in place indefinitely until the consumer decides to lift or remove it, which gives it a structural advantage over alerts that expire on a set schedule.
Under the law, consumers can initiate a freeze or lift one temporarily by phone, mail, or secure online portal. The nationwide bureaus must provide simple procedures and clear disclosures so that people understand the difference between a permanent removal and a short-term thaw designed to allow a specific credit application to go through. The same federal framework applies across all states, replacing the earlier patchwork of state-level fee rules and timelines.
Why creditors cannot bypass a frozen file
The mechanism is straightforward. A credit freeze restricts access to a consumer’s credit file. Because creditors generally will not extend new credit if they cannot review a report, an identity thief who applies for a loan or card using stolen personal information hits a dead end. The FTC’s own consumer guidance describes a freeze as the strongest protection against someone opening new accounts in another person’s name.
The statute also sets strict timing requirements. When a consumer requests removal of a freeze by phone or through a secure electronic method, the bureau must act within one hour, according to the text of the law and regulatory summaries from the Consumer Financial Protection Bureau. For requests sent by mail, the deadline is three business days after receipt. These tight timelines are designed to ensure that people can still apply for legitimate credit-such as a mortgage or auto loan-without weeks of delay.
Consumers must contact each bureau separately to activate or lift the protection, because lenders may check any of the three when evaluating an application. Federal agencies such as USAGov direct people to use each company’s online portal or phone line to manage their freezes. Once in place, a freeze does not affect existing accounts, credit scores, or the ability to request a free annual credit report. It simply blocks most new inquiries from lenders who have no current relationship with the consumer.
That distinction matters because it means there is little downside to keeping a freeze active during periods when no new credit is needed. Routine use of existing credit cards, on-time payments, and account management all continue as normal. Existing creditors and certain other authorized parties, such as debt collectors or government agencies with appropriate authority, may still access a frozen file, but strangers trying to open fresh accounts cannot.
Gaps in public data on freeze effectiveness
No publicly available FTC or CFPB dataset currently measures how many consumers maintain active freezes at all three bureaus simultaneously. That gap makes it difficult to quantify the real-world reduction in new-account fraud directly tied to freezes rather than to fraud alerts or credit monitoring services. Researchers and policymakers can estimate overall identity theft trends from complaint data and enforcement actions, but they lack a clean way to separate out the specific impact of widespread freeze adoption.
The hypothesis that households with simultaneous freezes at all three bureaus experience far fewer successful new-account fraud incidents is intuitively appealing. A thief who cannot get a lender to access a file is unlikely to see an application approved. Yet without bureau-level reporting on freeze uptake and duration, analysts cannot easily test how strongly freezes correlate with lower fraud losses, or whether certain demographic groups are more likely to use the tool.
This absence of granular data has policy consequences. If freezes are dramatically more effective than subscription monitoring services, regulators and consumer advocates might want to push harder for public education campaigns that emphasize freezes as a default choice after any data breach. Conversely, if many people struggle with the logistics of lifting and replacing freezes when they legitimately need credit, that could argue for further refinements in how the law is implemented.
For now, what is clear from the legal framework and federal guidance is that a no-cost freeze at each major bureau gives consumers a powerful, permanent lever to block most new-account identity theft. Until better statistics emerge, the decision to use one rests less on quantified risk reduction and more on a straightforward trade-off: a few minutes spent setting and occasionally lifting a freeze, in exchange for making it significantly harder for a stranger to open credit in your name.



