Active Incident? 24/7 Response →
SleuthX

For Individuals & Families

Identity Theft Investigation

Just had identity theft? We investigate how exposure happened, find ongoing access, and document evidence for police, banks, and counsel. Same-week response.

What this service does

Identity theft moves fast, so we respond the same week. The first days decide how much evidence survives and how much money can still be clawed back. Here is what to do in the first 48 hours — and where we come in.

  1. Freeze your credit at all three bureaus — Equifax, Experian, and TransUnion — and add a fraud alert. It is free, it stops new accounts from being opened in your name, and our credit-freeze and carrier port-out-PIN guide walks through it step by step.
  2. Lock down email and banking first. Change those passwords and turn on app-based two-factor — your email is the master key to everything else.
  3. Report it on the record. File the FTC affidavit at IdentityTheft.gov and a local police report; you will need both to dispute fraudulent accounts.
  4. Preserve the evidence. Do not delete the fraudulent emails, texts, or statements — screenshot everything with dates before it disappears.
  5. Bring in forensics. We trace how your information was exposed, find any ongoing access, and turn the trail into a documented case banks, regulators, and counsel cannot wave away.

For many routine cases those free steps — a credit freeze and the recovery plan at IdentityTheft.gov — resolve the problem on their own, and they cost nothing.

A forensic investigation earns its keep when there is stolen money to trace, complex multi-account or synthetic-identity fraud to untangle, or a perpetrator to identify.

If your case is not there yet, we will tell you that on the first call rather than sell you an engagement you do not need.

Engagements are confidential and structured to begin within 48 hours of the consultation.

Some service tracks are offered at a fixed fee; complex investigations are billed hourlywith a clear scope, milestone updates, and a cap agreed up front.

Quinn (Founder and CEO) sets the methodology every engagement runs under and reviews case findings before they leave the practice; the practitioner team executes the technical work under her methodology.

What this means for you

How an engagement begins

  1. Confidential consultation. NDA-protected. 30-60 minutes. Direct conversation, no sales process.
  2. Scoped engagement. Written proposal with defined deliverables and pricing — fixed fee where it applies, hourly with milestone caps for open-ended investigations.
  3. Investigation and findings. Documented methodology and chain of custody so findings can withstand courtroom scrutiny. Written report you can act on.

Why this work matters

Quinn sets the methodology behind every identity theft recovery engagement and holds 9 active certifications across GIAC — a methodology informed by her own work as a contractor inside Fortune 50 enterprise environments and built to hold up under litigation scrutiny.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

How We Work

A confidential, structured engagement.

01

Confidential Consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process.

02

Scoped Engagement

A clear written proposal with defined deliverables, timeline, and pricing. No hidden costs.

03

Investigation and Findings

Forensic work conducted to court-admissible standards, with regular communication and a written summary you can act on.

Certified Expertise

GIAC

Frequently asked about identity theft investigation

How is forensic identity-theft investigation different from credit monitoring?
Credit monitoring tells you when something has already happened. Forensic investigation works the other direction: trace how your information was obtained, identify which accounts and devices were compromised in the chain, document the attacker's footprint with evidentiary artifacts, and produce a report law enforcement, regulators, and civil counsel can act on. Credit monitoring is a useful safety net but doesn't help you understand or prove what happened.
What can you actually find in an identity-theft investigation?
Source of compromise (data breach exposure, account takeover, physical mail theft, insider, malware, phishing), timeline of unauthorized activity, accounts opened or accessed under your identity, devices and IP addresses associated with attacker activity, dark-web exposure of your credentials and identity documents, and where applicable, attribution clues (geographic patterns, infrastructure links, naming reuse). What's findable depends on the case; we tell you the realistic discovery scope on the first call.
How much does an identity-theft investigation cost?
You have two ways to work with us. Run the investigation yourself in the SleuthX tool for $995 once — lifetime access, with usage metered from a prepaid balance you top up anytime. Or have our team do it for you in a done-for-you device package: $3,000 for one device, $7,000 for three, $12,000 for five, each including the $995 lifetime license. Multi-account or business identity theft beyond a package (synthetic identity, EIN takeover, tax identity theft, complex multi-institution fraud) is scoped per case at a flat $400/hour, with no multipliers. Sliding-scale pricing is available for elder-fraud and financial-loss survivors — that conversation happens on the first call.
How long does an investigation take?
Focused single-vector cases: 2-3 weeks from intake to written report. Complex multi-account or longstanding cases (synthetic identity built over years, business identity theft with regulatory exposure): 4-8 weeks. Where there are statute-of-limitations or insurance-claim deadlines, the timeline is structured around those.
Will the investigation help me recover money I lost?
The investigation produces a documented evidentiary record that supports recovery claims — bank fraud disputes, FTC identity theft affidavits, IRS Identity Theft Victim Assistance, civil litigation against responsible parties, and insurance claims. Recovery itself is handled by your bank, attorney, or insurance carrier; we don't directly recover funds, but we provide the documentation that makes recovery claims much harder for institutions to dismiss.
Can I file police reports, IC3, or FTC reports based on your findings?
Yes — and the report is structured to support those filings. Findings are presented in a way that maps to FTC IdentityTheft.gov affidavits, FBI IC3 complaint structures, and local-police identity-theft report templates. Where federal jurisdiction applies (interstate wire, federal-tax-related fraud), we can also produce a referral package suitable for FBI Cyber Division or USPIS depending on the vector.
Quinnlan Varcoe, Founder & CEO
Quinnlan Varcoe
GIAC-certified · Founder & CEO

Schedule Your Session

Schedule a confidential consultation

A direct conversation with Quinn, the founder and CEO who oversees every engagement. NDA-protected. No sales process. Most engagements begin within 48 hours.

Free, confidential · NDA-protected · no obligation.

  1. 1. Book a 15-minute call — we scope your situation, no charge.
  2. 2. You get a written scope — deliverables, timeline, and price — before any work begins.
  3. 3. Approve it and we start; most engagements begin within 48 hours.

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management