A free fraud alert on your credit file tells lenders to double-check that it’s really you.

Businessman hand holding credit card to online shopping from home with laptop payment ecommerce internet banking man enters the card details on the website

A fraud alert is one of the simplest and least disruptive tools a person has for guarding a credit file, and like a credit freeze it costs nothing. An alert places a flag on the file that tells any lender pulling it to take extra steps to verify the applicant’s identity before opening a new account. Unlike a freeze, it does not lock the file down; credit keeps flowing, just with a verification check built in. For older adults who worry about identity theft but are reluctant to freeze their credit outright, it is a low-friction middle ground.

How a fraud alert works

The mechanism is a notice attached to a credit report. When a lender processes an application and sees the alert, it is expected to contact the consumer or otherwise confirm the applicant’s identity before extending credit. That extra verification is what trips up a criminal using stolen personal details, because the impostor usually cannot answer a callback to the real person’s phone number or satisfy the identity check. The alert does not block the application outright the way a freeze does; it inserts a speed bump rather than a wall, relying on the lender to slow down and look closer.

Like a freeze, a fraud alert targets new-account fraud rather than the misuse of accounts that already exist, so it works best alongside a regular review of statements. Placing one is quick: the bureau contacted verifies the requester’s identity using basic details it already holds, then flags the file and passes the alert to the other two. No fee changes hands at any point in the legitimate process, and a real bureau never sets up an alert through an unsolicited call demanding payment or account logins — a request like that is the scam the alert is meant to guard against.

A convenient feature sets the fraud alert apart from a freeze in effort. According to the Federal Trade Commission’s guidance on credit freezes and fraud alerts, a consumer only has to contact one of the three nationwide credit bureaus to place an alert, and that bureau is required to notify the other two. A single request therefore covers all three files, where a freeze must be set at each bureau individually. That one-call convenience is a large part of why fraud alerts appeal to people who find the three-bureau freeze process daunting.


Free for readers: Scam calls targeting retirees change every week. The free Retirement Shield newsletter flags the ones going around and the one tell that stops each. Sign up free.

Three kinds of alerts

The alerts come in three forms, each matched to a different situation. An initial fraud alert is available to anyone who suspects or simply worries about identity theft, and it lasts one year before it must be renewed. An extended fraud alert lasts seven years but is reserved for confirmed identity-theft victims. An active-duty alert protects servicemembers deployed away from home, lasting one year and reducing the prescreened credit offers that can be intercepted and turned into fraudulent accounts. All three cost nothing to place.

That active-duty version carries a useful side effect: for the year it is active, the servicemember’s name is removed from the prescreened-offer lists that generate unsolicited credit and insurance mailings, cutting off a channel identity thieves sometimes exploit. Across all three versions, the common thread is that an alert has to be maintained — renewed after a year, upgraded to the seven-year version once a theft is documented, or eventually converted to a full freeze — rather than set once and forgotten. A note on the calendar to renew is usually all it takes to keep the protection from lapsing at the moment it is needed most.

The extended, seven-year alert carries a paperwork requirement the others do not: the consumer must first file an official identity-theft report. That report is generated through the Federal Trade Commission’s IdentityTheft.gov, the government’s official reporting and recovery site, which produces the documentation the bureaus require and lays out the rest of a recovery plan. Anyone who has actually been victimized should pursue the extended alert rather than settling for the one-year version, since the longer protection matches how long stolen data can stay in circulation.

Fraud alert versus credit freeze

The two tools solve overlapping problems with different trade-offs. A credit freeze is the stronger of the two: it blocks new-account access entirely until the file is thawed, which suits someone not actively seeking credit and willing to unlock the file when needed. A fraud alert is lighter: credit still flows, so there is nothing to thaw before applying for a loan, but the protection depends on lenders actually honoring the verification step rather than a hard block. Nothing prevents using both at once, and layering an alert on top of a freeze is a reasonable way to add an early warning.

The renewal difference matters in daily practice. An initial fraud alert quietly expires after one year, so a person relying on it has to remember to renew, whereas a freeze stays put until it is deliberately lifted. For someone who wants durable protection without recurring upkeep, a freeze is the more reliable backbone, with a fraud alert layered on as a flag. For someone who applies for credit often and finds repeated thawing a nuisance, the alert alone may be the more comfortable fit.

When a fraud alert is the right call

A fraud alert fits several common situations for older adults. It makes sense right after a data-breach notice arrives, when the risk of misuse jumps but nothing has happened yet. It suits someone who applies for credit frequently enough that the repeated thawing of a freeze would be a real inconvenience. And it is the immediate first move for anyone who spots an unfamiliar account or credit inquiry and wants a fast, no-cost safeguard while sorting out whether genuine fraud has occurred.

Because placing one takes a single phone call or online request and costs nothing, the most common mistake people make with a fraud alert is not using it at all. Setting a reminder to renew the one-year initial alert, or upgrading to the seven-year extended version after filing an identity-theft report, keeps the protection from lapsing unnoticed. For a tool that asks so little and guards against the costliest form of identity crime, letting it sit unused is the only genuinely wrong choice.


Free for readers: One number can cost or save hundreds a month in retirement. The free Retirement Shield newsletter surfaces the ones worth knowing. Sign up free.

This article was researched and drafted with AI assistance and reviewed against the linked primary sources.

Social Security and Medicare change every year, and nobody sends you a memo. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.