First, stop the interaction
- Do not send more money, codes, documents, or explanations.
- Do not use contact details, links, or remote-support tools supplied by the suspected scammer.
- If a call is ongoing, end it. Contact the real organization through its official website, statement, card, or app.
- If someone is physically threatened or in immediate danger, contact local emergency services.
If money or payment details are at risk
- Credit or debit card: call the issuer using the number on the card or official site, report the fraudulent charge or exposed card, and ask about replacement and dispute steps.
- Bank transfer or account: contact the bank's fraud department immediately and ask whether the transfer can be recalled or the account protected.
- Payment app: report the transaction inside the official app and contact the linked bank or card issuer as appropriate.
- Gift card: contact the issuing company, keep the card and receipt, and report the card number and transaction without sharing it publicly.
- Wire transfer: contact the wire company and the sending financial institution immediately to request a reversal or fraud hold.
- Cryptocurrency: contact the exchange or platform through its official channel, report the destination address and transaction, and expect that completed transfers may be difficult or impossible to reverse.
Move quickly, but do not let urgency send you back to the scammer. Use a separate official channel for every contact.
If an account or password may be compromised
- From a device you trust, change the password on the affected account.
- If that password was reused, change it on every other account where it appears, beginning with email, banking, cloud storage, and mobile service.
- Sign out other sessions where the service allows it.
- Enable multifactor authentication, preferably with an authenticator app or security key where available.
- Check recovery email, phone, forwarding rules, connected apps, and recent login activity for changes you did not make.
- Contact the provider through its official account-recovery process if you are locked out.
If identity information was exposed
- Make a precise list of what was shared, such as a government identifier, driver's license, passport, bank information, date of birth, or address.
- In the United States, use IdentityTheft.gov to create a recovery plan and report identity theft.
- Consider a credit freeze with each nationwide credit bureau if the exposed information could be used to open accounts.
- Review bank, card, credit, benefits, tax, health, and mobile accounts that could be affected.
- Replace compromised identity documents through the issuing authority when advised.
If a device was accessed
- Disconnect the device from the network if a stranger still has remote access or malicious activity is continuing.
- From another trusted device, secure email, financial, and cloud accounts first.
- Remove remote-access software you were instructed to install and run updates and a reputable security scan.
- Contact the device maker, operating-system provider, employer support team, or a qualified security professional through an independently found channel if you are unsure the device is safe.
- Restore or reset only after preserving information needed for reporting and confirming that important files are safely backed up.
Preserve evidence
- Save messages, email headers, usernames, phone numbers, websites, advertisements, payment receipts, transaction IDs, wallet addresses, and shipping details.
- Write a short timeline while events are fresh, including what the person claimed and what information or access was provided.
- Keep original files where possible. Screenshots are useful, but they may omit headers or metadata.
- Do not keep interacting merely to collect more evidence.
Report through the right channels
- Report the payment or account incident to the financial provider first.
- In the United States, report fraud to ReportFraud.ftc.gov and identity theft to IdentityTheft.gov.
- Report impersonated businesses, government agencies, marketplaces, social platforms, and communication accounts through their official abuse channels.
- Contact local law enforcement where required for a financial institution, insurer, identity document, or immediate local investigation.
- If the incident involves another country, use that country's national fraud and cybercrime reporting services.
Watch for the second scam
Details of victims can circulate. Someone may claim to be an investigator, lawyer, government agent, hacker, or recovery company and say that lost money has been found. Treat any demand for an upfront fee, tax, deposit, secrecy, or unusual payment as a fresh warning sign.
- Do not pay to release recovered money.
- Verify every organization through a phone number or website you find independently.
- Tell a trusted person what happened so that a second request is easier to pause and check.
Scope and limits
The useful next step depends on what was sent, which accounts or devices were exposed, and the country involved. Payment reversal and recovery are not guaranteed. Use official contact details you find independently, and use local emergency services if there is an immediate threat to safety.
Sources and further help

Explore the book
Everyday Scam Defense Systems by Mara Ellison is published by Alderwake Press in the Practical Systems line.
About the bookRelated Alderwake resources
Practical notesCommon Scam Warning Signs and the Pause-Before-You-Act System
A behavioral interruption system for urgency, secrecy, impersonation, unusual payment, unexpected account claims, and pressure to bypass normal channels.
How to Build a First Emergency Fund When Money Is Tight
A staged way to create a first buffer, protect a small reserve, and build longer-term resilience when there is little room in the budget.