Skip to main content

The Money Overview

A fraud alert placed with one credit bureau automatically covers all three

Placing a fraud alert with any one of the three national credit bureaus sets off a legal notification requirement that automatically covers the other two, so a single phone call or online request to Equifax, Experian, or TransUnion protects a credit file everywhere a lender might check it. That single-contact design is what separates a fraud alert from a credit freeze, which has to be requested at each bureau separately. The tradeoff for that convenience is that an alert does not block a new account from opening the way a freeze does — it only forces a lender to verify identity first.

One Contact Triggers a Legal Notification Requirement

The relay mechanic is spelled out directly by the FTC: to place an initial fraud alert, a consumer should contact one of the three national credit bureaus, which is required to notify the other two so the alert appears on all three files. There is no need to separately contact each bureau, fill out three forms, or track three confirmations — the single request is the entire process, and the alert is active everywhere within the timeframe the contacted bureau processes it.

What the alert actually does once it is in place is narrower than a freeze. A fraud alert tells a business pulling the credit file to check with the consumer before opening a new account in their name, typically by calling the phone number on file to confirm the person applying is really who they claim to be. Unlike a freeze, a fraud alert does not stop a lender from viewing the credit report at all — it adds a verification step to the process rather than removing access outright, which is why a determined lender can still approve credit quickly once identity is confirmed.

That single point of failure also cuts the other way: because one bureau’s alert governs what happens at all three, a consumer only has to remember which bureau they originally contacted if they ever need to renew, cancel, or upgrade the alert later, rather than tracking three separate accounts and three separate expiration dates.

None of the three bureaus is permitted to charge for placing, renewing, or removing any version of the alert, which matters because third-party identity-theft protection services routinely sell monitoring subscriptions marketed as a substitute for exactly this step. A consumer who is already paying monthly for a commercial monitoring product has not replaced the fraud alert with it — the alert is a separate, no-cost legal mechanism that works whether or not a paid service is also in place.


Free retirement updates: Miss an enrollment or claim deadline and it may be gone. Our free Retirement Shield newsletter keeps readers ahead of the ones that matter. Get the free newsletter.

The Alert Now Lasts a Full Year, Not 90 Days

The one-year duration is more recent than many consumers realize. Before a 2018 federal law took effect, a standard fraud alert lasted just 90 days before it had to be renewed. Starting September 21, 2018, the CFPB confirmed that a fraud alert placed with any of the three bureaus lasts a full year instead of 90 days, and remains free to place or renew. That change alone roughly quadrupled how long a single alert protects a file before a consumer has to think about it again.

Renewal itself follows the same single-contact rule as the original request — there is no requirement to renew at all three bureaus separately, since the same relay obligation that placed the alert everywhere the first time applies again at renewal. A consumer who simply keeps a recurring reminder to renew once a year, at whichever bureau they used originally, keeps continuous coverage across all three files indefinitely at no cost.

The one-bureau relay is often the fastest response available to an older adult who has just learned a Social Security number or Medicare card was exposed in a data breach or a phone scam, since that population is the one identity thieves and scam callers target most deliberately. The CFPB frames the alert as the accessible first step precisely because a consumer who thinks they may have been the victim of identity theft can file a fraud alert that lasts up to one year unless they choose to remove it sooner. Placing it costs nothing and takes effect everywhere at once, which spares someone already dealing with a compromised account from also having to manage three separate bureau requests in the same afternoon.

Three Versions Exist, and the Strongest Requires a Police or FTC Report

The one-year initial alert is the version available to anyone, for any reason, with no proof required. A stronger version, the extended fraud alert, lasts seven years instead of one but is only available to someone who has actually experienced identity theft and can back that up with either an FTC identity theft report filed at IdentityTheft.gov or an official police report. In exchange for that documentation requirement, an extended alert also forces credit bureaus to remove the consumer from prescreened credit and insurance offer mailing lists for five years unless the consumer asks to stay on them.

A third version, the active duty alert, exists specifically for military servicemembers being deployed. It lasts one year and is renewable for the length of the deployment, and like the extended alert it also triggers removal from prescreened marketing lists, though only for two years rather than five. All three versions share the same underlying design that makes the fraud alert useful in the first place: one phone call or one online form reaches every bureau a lender is likely to check, which is precisely the tradeoff for accepting a verification step instead of an outright block on new credit.

This article was researched and drafted with the assistance of artificial intelligence.

More Financial Reading


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.