Reviews
Reporting and recovery: review checklist and 2027 updates
Reporting and recovery in the order that limits the loss: the calls with hours on them, the evidence to keep, where to report, and the second scam.
Being scammed is disorienting, and the disorientation is part of how it works. The hours right after you realize what happened are the ones where your actions matter most, and they are also the hours when you are least able to think in order. This page is the order, so you do not have to invent one.
Read the first section now and the rest later. Nothing here requires you to talk to the person who scammed you, and nothing here costs money.
What to take away
- Do these in this sequence, and stop reading between steps only when a step is done.
- The instinct to delete everything is strong and it works against you.
- Different payment rails have genuinely different reversibility.
- Work outward from whatever the scam actually touched.
The first hour: stop the loss
Do these in this sequence, and stop reading between steps only when a step is done.
- Break contact, but do not delete anything. Stop replying. Do not tell them you know. Do not threaten them or demand your money back: it gives them a reason to move funds and to burn the accounts you would otherwise be reporting. Leave the messages, emails, and profile where they are.
- Cut the money route before you do anything else. If a payment is in flight, or a card or account is exposed, call the bank or payment provider now. That call comes before screenshots, before reporting, before telling family. See the payment table below for who to call and what to ask for.
- Get remote access off your device. If you were talked into installing a "support", "security", or "screen sharing" app, disconnect the device from the internet, then remove the app. Assume anything you typed while it was running was seen.
- Take back the accounts you still control. Change the password on your primary email first, it is the key to everything else, then on the accounts you reused that password on. Sign out all other sessions. Check for a forwarding rule, a new recovery address or phone number, or a new app password you did not create.
- Write down the timeline while it is fresh. Dates, amounts, names used, phone numbers, handles, and what you were told. You will be asked for this several times by several organizations, and your memory of it degrades quickly.
Preserve the evidence before you clean up
The instinct to delete everything is strong and it works against you. Every organization you are about to contact will ask for some of this.
- Screenshots that include the full sender address or handle and the full link, not just the visible text. Widen the window or expand the header so the real address is captured.
- The transaction records: reference numbers, the amount, the exact date and time, the receiving name, account, wallet address, or phone number.
- The original messages, kept in place. Forwarded copies lose headers; exported chats keep more than screenshots do.
- Any files or apps you were sent or asked to install, and the page you were sent to.
- Your own timeline note from step 5, which is the thing that ties the rest together.
Keep a copy somewhere that is not on the device you think was compromised.
Money: who to call, and what to ask for
Different payment rails have genuinely different reversibility. This is the single biggest factor in what happens next, and it is worth knowing which one you used before you make the call.
| How you paid | Call | Ask for |
|---|---|---|
| Credit card | The card issuer's fraud line | A dispute or chargeback, and a new card number |
| Debit card | Your bank's fraud line, immediately | A dispute, and the card blocked; debit protections are governed by different rules than credit and several are time-limited |
| Bank transfer or wire | Your bank, then the receiving bank if your bank will contact it | A recall or fraud freeze on the receiving account |
| Instant bank-to-bank payment app | Your bank and the app provider | A fraud claim; say clearly that you were deceived into sending it |
| Gift card codes | The card's issuer or the retailer that sold it | A freeze on the remaining balance: sometimes it is unspent |
| Cryptocurrency | The exchange you sent from, if any | The receiving address flagged; transfers themselves cannot be reversed |
| Money transfer service | The service's fraud line | A hold on the transfer if it has not been collected |
Two things to say on the call, in plain words: "I was defrauded" and "this payment was not authorized by me in the way you would normally understand it." The distinction between a payment you never made and a payment you were tricked into making matters to how the claim is handled, and it is better that you name it than that it surfaces later.
Do not let embarrassment shrink the story. Fraud teams hear this every day, and a partial account produces a partial investigation.
Accounts, devices, and the things behind them
Work outward from whatever the scam actually touched.
- Email first. New password, sign out everywhere, check forwarding rules, filters that auto-delete or auto-archive, connected apps, and the recovery phone and address. A rule that quietly deletes the bank's emails is a common way for the loss to keep running after you think it stopped.
- Phone number. If your number could have been ported away, or texts stopped arriving, call your mobile carrier and ask for a port-out or transfer PIN on the account. A hijacked number defeats text-based codes on everything else.
- Move off text-based codes where the account offers something stronger, such as an authenticator app, a passkey, or a hardware security key.
- The rest. Financial accounts, the app stores, the cloud account behind your photos and backups, and anything sharing the old password. There is a fuller sweep in account security.
- Devices. If remote access software was installed, or you ran a file they sent, treat the device as untrusted until it has been checked or reset. Change passwords from a different device, not from the one in question.
If your identity data was exposed
Card numbers are replaceable. A national ID number, a date of birth, and a scan of your passport or driving license are not: they support new accounts opened in your name months later.
- Place a security freeze with each of the nationwide credit bureaus. In the US that is Equifax, Experian, and TransUnion, and each has to be done separately. A freeze blocks most new credit checks in your name; you lift it temporarily when you actually need credit. Check the current terms and process on each bureau's own site.
- A fraud alert is the lighter option: it does not block anything, it flags to lenders that they should verify identity. A freeze is stronger.
- Get your credit reports and read them for accounts you did not open. Do this again after a few months, because damage often appears late.
- If a tax or benefits number was exposed, the relevant revenue or benefits agency has its own identity-theft process. Use it: the credit bureaus do not cover that.
- Watch for mail you did not expect: a card you did not apply for, a bill from a service you never used, a letter about an account in your name. That is often the first visible sign.
Where to report, and why each one is worth doing
None of these will call you back with your money. They are still worth the time, because they are what shuts down the account or number that will otherwise be used on the next person, and because some of them produce a document you will need.
- The platform. Report the profile, listing, message, or ad through the platform's own reporting tool, not by messaging support through a link someone sent you. This is the report most likely to have a fast, concrete effect, and where the account doing the damage is a copy of yours rather than your own, the route is in impersonation scams.
- Your bank or payment provider, as above. Their fraud claim is the one attached to your money.
- In the US, the Federal Trade Commission. The FTC takes consumer fraud reports and runs a separate identity-theft service that produces a personal recovery plan and an identity theft report: the document some creditors ask for before they will remove fraudulent accounts. Reach it by searching for the FTC's own site directly rather than through a link in any message.
- In the US, the FBI's Internet Crime Complaint Center (IC3). This is the route for internet-enabled crime, and the one worth using for larger losses and for wire and cryptocurrency transfers.
- Local police, particularly where identity documents were taken, where you were threatened, or where a creditor asks for a police report number.
- The sector regulator, where one exists for what was involved: a financial conduct authority, a telecoms regulator, a state attorney general. Outside the US, look for the national consumer protection body and the national cybercrime reporting service.
Keep every reference number in the same note as your timeline. The routing question, meaning which body handles which kind of loss, is answered plainly at USAGov's page on where to report a scam, and the identity side has its own guided process at IdentityTheft.gov.
The follow-up nobody tells you about
The first hour is loud and the next month is quiet, which is when things get missed.
- Check whether the bank's fraud claim actually opened, and what its reference is. Ask what happens next and when you should chase it.
- Re-read your credit report on a schedule rather than once, and check what is visible about you while you are at it, which is the work in privacy settings.
- Watch the email account for password reset messages you did not request, that means someone still has your address on a list and is trying.
- Expect more approaches, on other channels, most of them arriving as messages rather than as people, which is the ground covered in phishing scams. Being scammed once makes you a target for the next round, and not because of anything you did wrong.
The second scam: "recovery services"
This is the part most people are not warned about, so treat it as the main warning on this page.
After a loss, you will often be contacted by someone offering to get the money back. They may claim to be an investigator, a lawyer, a blockchain-tracing firm, a regulator, or the platform's fraud department. They may already know your name, the amount, and the details of what happened, because victim details get resold, and because you may have posted about it.
The tells are consistent:
- They contacted you, not the other way round.
- They ask for a fee, a deposit, or a tax before anything is recovered.
- They want remote access to your device, your banking login, or a "verification" payment to prove the account is yours.
- They promise an outcome: a percentage back, a timeframe, a guarantee. Nobody honest can promise that.
- They press for speed and secrecy, often saying the window is closing.
Agencies that take fraud reports do not charge you to take them, and they do not cold-call demanding payment to release your funds. If someone claims to be from a bank or an agency, hang up and call the number on your card or on the agency's own site. Real professional help exists (a lawyer you found and hired, your own bank's fraud team), but you find them; they do not find you.
Helping someone else who has been scammed
If the person in front of you is a relative or a friend, the fastest route to the first hour above is not an explanation of what they did wrong.
- Lead with "we can still do things right now", not with how it happened.
- Take the practical steps for them if they will let you: the bank call, the screenshots, the password changes.
- Do not repeat the amount back to them or ask how they fell for it. Shame is the single biggest reason losses are reported late or never.
- Expect the possibility that they are not yet convinced it was a scam. In that case, the useful move is a verification they can do themselves, calling the real organization on a number they look up, rather than an argument.
What recovery honestly looks like
Some losses come back in full. Card disputes work more often than wires do. Some losses do not come back at all, and no amount of correct procedure changes that. Anyone who tells you otherwise before looking at the payment rail and the timing is guessing or selling.
What is genuinely in your control is the size of the loss from this point forward: the accounts you secure, the identity data you freeze, the reports that get filed, and the second approach you recognize and refuse. That is the work, and it is worth doing even on a day when it feels pointless.
Common questions
Should I confront the scammer or try to get my money back directly?
No. It rarely works, and it tells them to move the funds and abandon the accounts you have just reported. It can also escalate into threats. Let the bank and the platform act on the accounts while they are still live.
Is it too late if this happened weeks ago?
It is worth doing anyway. Some claims are time-sensitive and some are not, and the account-security, credit-freeze, and reporting steps have no expiry at all. Start with the payment provider and ask directly what the position is.
Do I have to report it if I only lost a small amount, or nothing?
You do not have to. It is still useful. Reports of attempts and near misses are how patterns get spotted, and the profile or number you report is often the one about to be used on someone with more to lose.
Someone says they can trace my cryptocurrency. Is that real?
Tracing as a discipline is real; the person who cold-messaged you offering it is not. Any legitimate engagement starts with you approaching a firm you found and verified, and no honest one asks for an upfront payment to release funds that are supposedly already located.
What if the scam started on a platform I want to keep using?
Report it and stay if you want to. Then tighten who can find and contact you there: the discovery and message settings in a social media privacy audit are what determine whether the next approach reaches you at all.