If you just received a loan preapproval or “your application is under review” message for a loan you never started, treat it as a potential identity theft warning. Quick, calm steps can stop new accounts from being opened in your name and help you find out whether it’s aggressive marketing, a misdirected notification, or attempted fraud.
First, Determine What Type of Message You Received
Not all unexpected loan messages mean fraud. Some are broad marketing, while others indicate someone tried to use your identity. Your first task is to classify the message without clicking any links.
- Generic preapproval marketing: “You’re preapproved for up to $X” with no specific application ID. These offers are often based on “soft inquiries” or marketing lists and may be sent by lenders or finance marketplaces. They should not ask you to reply with sensitive information.
- Application-related notice: “Thanks for your application,” “We’re processing your loan,” or “We need more information to verify your identity,” often with a reference or application number. This can signal that someone used your information.
- Phishing or smishing attempt: Messages pressuring you to click a link, provide a code, or share your SSN, bank login, or driver’s license to “claim” or “prevent cancellation.” These are high-risk and should be ignored and reported.
Do not click links or call numbers in the message. If you recognize the lender name, independently find their official website or phone number to verify whether a real application exists under your name.
Immediate Steps to Protect Your Identity
If there’s any chance your information was used, lock down your credit identity before investigating further.
- Place a free fraud alert with one credit bureau. Contact Equifax, Experian, or TransUnion and add a 1-year initial fraud alert. The bureau you contact must notify the others. A fraud alert tells lenders to verify your identity before approving credit.
- Consider a credit freeze at all three bureaus. A freeze is stronger than a fraud alert. It blocks new creditors from accessing your credit report, preventing most new accounts from being opened without your explicit unfreeze. It’s free and reversible online.
- Secure your email and mobile accounts. Change passwords for your primary email and your mobile carrier account (and enable two-factor authentication). Attackers who control your inbox or phone number can intercept verification codes and open accounts.
- Review recent credit inquiries. Once your reports are accessible to you, look for unfamiliar inquiries or accounts. Hard inquiries from lenders you don’t recognize can indicate attempted applications.
Verify the Message with the Alleged Lender
When you contact the lender, do it safely.
- Use official channels: Type the lender’s URL directly into your browser or use a trusted phone number from their website. Do not use numbers or links from the suspicious message.
- Ask for verification: Provide only your basic details as needed to look up an application (never full SSN over email or text). Request the application date, the address and email used, and the funding status.
- If the application is fake: Ask the lender to cancel it, flag it as identity theft, and provide you with written confirmation. Request that they suppress the inquiry if possible and report the incident to the credit bureaus as fraud-related.
- If it’s just marketing: Ask to be removed from their marketing lists and confirm no application exists under your identity.
Document Everything
Good records help you dispute charges, reverse inquiries, and build a paper trail if you need to file an identity theft report.
- Save screenshots of the original message (with timestamps).
- Record dates, times, contact names, and case numbers from calls and chats with lenders and credit bureaus.
- Keep copies of dispute letters, email confirmations, and postal receipts.
Dispute Unauthorized Inquiries and Accounts
Unauthorized inquiries and accounts can hurt your credit and signal broader misuse of your personal information.
- Dispute directly with the lender: Ask for removal or reclassification of fraudulent hard inquiries and closure of any unauthorized account. Provide your documentation.
- Dispute with the credit bureaus: File disputes with Equifax, Experian, and TransUnion to remove fraudulent inquiries and accounts. Attach your evidence and any identity theft report number.
- Use an identity theft report if needed: If accounts were opened, file an identity theft report with the FTC (IdentityTheft.gov) to get a recovery plan and a report you can use with creditors. Consider a police report if requested by a creditor.
Understand Why This Happens: Data Exposure and Targeting
Unexpected loan messages often trace back to two realities: widespread data sharing and credential compromise.
- Marketing lists and pre-screening: Credit bureaus and data brokers compile consumer data for prescreened offers. These are legal under certain regulations and can result in “preapproved” mail or texts, even if you never applied.
- Data broker exposure: People-search sites and data brokers publish names, addresses, ages, phone numbers, and sometimes partial SSN patterns. This exposure makes targeted fraud easier and increases spam and phishing.
- Breached logins and identity data: Compromised email or phone accounts can be used to initiate loan applications and intercept verification codes. Past data breaches can expose personal identifiers used in credit applications.
Reduce Your Exposure Going Forward
Lowering your data footprint reduces the chance your identity can be misused.
- Opt out of prescreened credit offers: Visit the official opt-out service (OptOutPrescreen.com or by mail) to reduce unsolicited credit offers based on soft pulls.
- Remove yourself from data broker sites: Search for your name on major people-search sites and submit removal requests. Repeat periodically; re-listing is common.
- Harden your accounts: Use a password manager, create unique passwords, and enable two-factor authentication using an authenticator app rather than SMS where possible.
- Set carrier protections: Add a port-out/PIN lock to your mobile account to reduce SIM-swap risk that could compromise verification codes.
- Minimize public info: Limit what you share on social media (dates of birth, addresses, schools, pet names) that can be used to answer security questions.
How to Handle Similar Messages in the Future
When another unexpected loan or credit message arrives, follow a consistent routine to separate noise from danger.
- Don’t click, don’t reply. Treat any link or “verify now” prompt as suspicious until proven otherwise.
- Inspect the sender details. Check the domain, short codes, and email headers if you know how. Misspellings, off-brand domains, or free webmail senders are red flags.
- Verify on your own. Use the lender’s official site or app to check for an application. If nothing is on file, it’s likely marketing or phishing.
- Report and block. Report phishing texts to 7726 (SPAM) and phishing emails to your provider. Block the sender after you’ve captured evidence.
- Monitor your credit and identity. Look for new inquiries, accounts, or changes in your personal data that don’t match your activity.
What If You Already Clicked a Link or Gave Info?
If you interacted with a suspicious message, act immediately to limit damage.
- If you entered credentials: Change the password for that account and any other accounts using the same password. Enable two-factor authentication.
- If you provided SSN or ID images: Place a credit freeze at all three bureaus and consider an extended fraud alert (7 years) if you have an identity theft report.
- If you shared bank or card details: Contact your bank to lock or replace cards, monitor transactions, and enable alerts for new payees or transfers.
- If you installed an app or profile: Remove it, run a reputable security scan on your device, and update your operating system.
Signals That It’s More Than Marketing
Escalate your response if you notice any of the following:
- Hard inquiries from lenders you don’t recognize.
- New accounts, collection notices, or mailed loan documents you did not request.
- Account verification codes (email or SMS) for services you didn’t try to access.
- Address change, SIM-swap, or email-forwarding alerts.
- Unfamiliar deposits or withdrawals tied to loan disbursements.
When to Seek Additional Help
If the issue escalates or you’re unsure about next steps, get assistance.
- Identity theft recovery resources: Use IdentityTheft.gov to create a recovery plan and get template letters.
- Your state attorney general or consumer protection agency: They may offer guidance or accept complaints against persistent bad actors.
- Financial institutions’ fraud departments: Many lenders have dedicated teams that can fast-track closures and remove fraudulent data.
Practical Checklist
- Classify the message: marketing, application notice, or phishing.
- Do not click links; verify via official websites or phone numbers.
- Place a fraud alert; consider a full credit freeze at all three bureaus.
- Secure email and mobile accounts; enable two-factor authentication.
- Check credit reports for unfamiliar inquiries or accounts.
- Contact the lender to cancel any fraudulent application and get written confirmation.
- Dispute unauthorized inquiries/accounts with creditors and credit bureaus.
- File an identity theft report if needed.
- Reduce exposure: opt out of prescreened offers; remove data-broker listings.
- Monitor credit and financial activity for ongoing misuse.
Optional Next Step: Evaluate Ongoing Monitoring
Once you’ve contained the immediate risk, ongoing monitoring can help you catch new issues early. If you want a single dashboard to track credit changes and identity-related activity, consider evaluating a tool that monitors credit reports and alerts you to key changes. You can explore an option here: SmartCredit for privacy, credit monitoring, and identity protection.
Conclusion
An unexpected loan preapproval or application message is a signal to pause and verify. Many messages are just broad marketing, but some point to attempted or successful identity misuse. By avoiding links, freezing your credit, confirming details directly with the lender, and disputing any fraudulent activity, you can stop further damage. Reducing your digital footprint and setting up ongoing monitoring will help you stay ahead of new attempts and keep your identity more secure over the long term.
Good to Know
Legitimate lenders can send broad “preapproved” marketing based on soft credit pulls, but they never need your full SSN or a code over text to “claim” an offer. Any urgent request for sensitive data is a red flag for fraud.