A fraud alert is a flag a consumer can place on their own bureau file, typically after suspecting or confirming identity theft, that signals to anyone pulling the file that extra identity verification should occur before new credit is extended in that consumer's name. It does not prevent credit from being issued outright, and it does not itself change the consumer's score or remove any trade lines — it is a caution flag layered on top of the existing file.
Equifax and TransUnion each describe offering versions of this protection, sometimes distinguishing between an identity alert and a fraud alert with slightly different triggering conditions, but functioning on the same basic principle: flag the file so anyone checking it slows down and verifies who they are actually dealing with.
Because Equifax and TransUnion operate as separate companies with separate databases, a fraud alert placed with one bureau has no effect on the other. A consumer who has reason to believe their identity has been compromised needs to contact each bureau independently to have the alert placed on both files — a step that is easy to miss if a client assumes, reasonably but incorrectly, that flagging one bureau covers them everywhere.
This is worth raising proactively with any client who mentions being a victim of identity theft, a data breach affecting them, or a lost wallet with identification — better to have them contact both bureaus early than to discover mid-application that only one file was ever protected.
A fraud alert remains on file for six years from the date it was placed, on both Equifax and TransUnion, unless the consumer requests it be removed sooner in writing. This is a meaningfully long default period, and a client who placed an alert years ago after a since-resolved incident may not realize it is still active and still affecting how their file is treated at the point of a new mortgage application.
If a client's file shows a fraud alert that they believe is no longer necessary, they have the option to request its removal directly with the bureau rather than simply waiting out the six years, which is worth mentioning if the alert appears to be creating friction in a live file.
A file carrying an active fraud alert generally prompts a lender to take additional steps to confirm the applicant's identity before proceeding — this can mean additional documentation, a direct phone verification, or other identity-confirmation steps beyond what a standard file would require. This is a reasonable and expected response, not a sign that the lender suspects the current applicant of wrongdoing; it simply means the file itself is flagged as one where identity has been a concern in the past.
Brokers should set this expectation with the client in advance rather than let an unexpected identity-verification request feel alarming partway through the process. Explaining that the alert they placed for their own protection is now doing exactly what it was designed to do tends to land much better than an unexplained extra document request.
A client placed a fraud alert with Equifax two years ago after a data breach. A lender pulls their TransUnion file for a new mortgage application. What should the broker expect?
Equifax and TransUnion are separate organizations with separate files, so a fraud alert placed with one has no bearing on the other — the client would need to have contacted TransUnion directly for their file to carry the same protection. Assuming the alert transfers automatically is exactly the mistake this module flags. Fraud alerts last six years, not one, so an alert from two years ago on the bureau it was actually placed with would still be active. And fraud alerts apply to any new credit application, including mortgages, not only credit cards.
The intro and first module are free to read. Add your name and email once and the rest of this course opens — along with every other course on the site. No card, no trial.
Already unlocked on another device?