PanicStation.org
uk Death, bereavement & serious family crises

What to do if…
you receive alerts that accounts are being accessed after a death and you suspect identity misuse

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Treat this as possible active account takeover. Secure the email account and mobile number used for password resets, then tell the affected providers and reduce the risk of new credit being opened in the deceased person’s name.

Do not do these things

  • Do not click links in security-alert emails or texts; use the provider’s official app or type the website address yourself.
  • Do not keep trying repeated logins if you think someone else is active in the account; it can trigger lockouts and create confusion.
  • Do not share extra personal details about the death, date of birth, address history, account names, or documents in public posts or messages.
  • Do not assume an alert is harmless if it names a real service, real device, password reset, one-time code, or transaction you did not expect.
  • Do not send death certificates, probate papers, or ID documents through a link sent in an unexpected message.

What to do now

  1. Capture the alert without using its links.
    Take screenshots of the alert, the sender, the date and time, the service named, and any device, location, one-time code, or password-reset wording. Start a simple note of who you contact, when, and any reference numbers.

  2. Secure the email account that controls resets.
    Sign in through the email provider’s official app or typed website address. Change the password if you are authorised and able to do so, turn on two-step verification where possible, check for unknown forwarding rules or recovery details, and sign out unknown devices or sessions.

  3. Protect the mobile number used for one-time codes.
    If there are unexpected one-time codes, SIM-change messages, porting messages, or missing texts and calls, contact the mobile network through its official route. Say the account-holder has died and you are worried the number is being used for account recovery; ask what they can do to lock the account, block a SIM change, or add stronger account security.

  4. Contact the provider named in the alert.
    Use the provider’s official fraud, security, or bereavement route. Say the account-holder has died and you have received signs of possible unauthorised access. Ask them to freeze risky activity, stop online changes until reviewed, preserve access logs, and tell you what documents they need from the person handling the estate.

  5. Prioritise money, credit, and reset accounts.
    Deal first with banks, cards, payment apps, investment platforms, email accounts, mobile accounts, and any service that can create debt or reset other accounts. If money has moved, ask the provider how to report an unauthorised transaction and what evidence they need.

  6. Use death-notification routes to reduce gaps.
    If the death was registered in England, Scotland, or Wales and you have a Tell Us Once reference that is still usable, use it to tell government organisations. For banks and building societies, consider the Death Notification Service, which can notify participating firms, though each firm may still ask for its own checks.

  7. Check for new credit or debt in the deceased person’s name.
    Contact Experian, Equifax, and TransUnion and ask how to mark the person as deceased, dispute suspicious searches or accounts, and request a credit report if you are authorised to do so. They may ask for a death certificate and proof that you are allowed to deal with the estate, such as probate or letters of administration if available.

  8. Report suspected fraud through the correct police route.
    If you are reporting from England, Wales or Northern Ireland, use Report Fraud. If you are in Scotland, or the incident needs reporting to Police Scotland, use Police Scotland’s non-emergency reporting route or call 101. If there is an immediate risk to someone’s safety, call 999.

  9. Reduce post and document risks.
    Keep incoming post secure, redirect mail if you are authorised and it is appropriate, and avoid leaving documents with the deceased person’s name, address, date of birth, account details, or National Insurance number where others can see them.

  10. Keep proof together.
    Put the death certificate copies, your authority to act if you have it, alert screenshots, provider messages, police or Report Fraud references, and credit-reference correspondence in one folder.

What can wait

  • You do not need to work out who did it today.
  • You do not need to close every account today; start with the accounts named in alerts and any account that controls money, credit, email, or phone recovery.
  • You do not need to decide about legal action now.
  • You do not need to settle the estate before taking urgent steps to stop further misuse.

Important reassurance

This can happen after a death and it is very upsetting, especially when alerts arrive unexpectedly. You are not overreacting by slowing down, using official routes, preserving evidence, and asking providers to lock down access.

Scope note

These are first steps only to stabilise the situation and reduce further misuse. Later decisions about estate administration, credit-file corrections, disputed transactions, complaints, or legal action may need specialist help.

Important note

This guide is general information for urgent first steps. It is not legal, financial, law-enforcement, cyber-security, bereavement, or professional advice; providers and official bodies may ask for different documents or use different processes.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us