If you already acted
You acted. Now reduce the harm.
Scammers are persuasive by design. Set blame aside and move quickly. Choose what happened below for practical first steps.
Choose what happened
Go straight to the right response.
More than one may apply. Start with money or active device access, then work through every relevant section.
Clicked or opened something
Check what happened after the click.
If you only opened a link, but entered nothing, downloaded nothing and installed nothing, the UK NCSC says further action is unlikely to be needed. Stay alert for unusual account activity.
- Close the page and stop interacting.
Do not return through the same link, approve a prompt or call a number shown there.
- Check for a download or installation.
If a file opened, software was installed or the device behaves strangely, run a full scan with its updated security software and let it remove what it finds.
- Tell your workplace if it was a work device.
Contact the IT or security team promptly. Early reporting helps them protect you and other people.
Password or security code shared
Secure the real account from a trusted device.
- Open the real service yourself.
Use its official app, a saved bookmark or an address you already know. Change the exposed password immediately.
- Replace every reused password.
Start with email, banking and social accounts. Give each account a different strong password.
- Remove access the scammer may have kept.
Sign out unfamiliar sessions, check recovery email and phone details, remove unknown forwarding rules, and turn on strong multi-factor authentication.
- Contact official support if you are locked out.
If you shared a one-time code or approved a login, tell the provider that the account may have been taken over.
Money sent
Contact the payment provider immediately.
Recovery is not guaranteed, but speed can affect whether a provider can stop or reverse a transaction.
- Use a number or app you know is official.
Tell the bank, card issuer, payment app, wire service, gift-card company or crypto platform that the payment was connected to a scam.
- Ask what can be stopped.
Ask whether the transaction can be cancelled, reversed or refunded, and whether cards, accounts or transfers should be frozen.
- Keep the payment records.
Save receipts, transaction IDs, account or wallet addresses, dates and the original contact. Keep the physical gift card and receipt if one was used.
Remote access allowed
End access, then protect accounts elsewhere.
- Disconnect the affected device from the internet.
End the remote session if you can do so safely. Do not follow uninstall or cleanup instructions from the caller.
- Use a separate trusted device.
Contact your bank and secure your email, financial and other important accounts. Review recent activity and active sessions.
- Clean the affected device before sensitive use.
Remove the remote-access tool, update security software and run a full scan. If you are unsure what changed, use a trusted technical professional before banking on it again.
Identity details shared
Protect the records that could be misused.
- List exactly what was exposed.
Note whether it included an identity document, banking details, address, tax or national identifier, phone number or account login.
- Contact the organisations behind those records.
Ask the document issuer, bank, phone carrier or account provider what replacement, monitoring or account-protection steps are available.
- Use the identity-protection process where you live.
Credit alerts or freezes are available in some countries. Local consumer-protection, cybercrime or identity-theft authorities can explain the correct route.
- Watch for follow-on attempts.
Check statements, login alerts, new accounts and unexpected loss of phone service. A sudden SIM failure can be a sign to contact your carrier.
Preserve and report
Save evidence without re-engaging.
Keep screenshots or exports when safe, usernames, email and phone details, transaction records, dates and a short timeline. Do not return to a dangerous page simply to create evidence.
Contact local police or your national fraud or cybercrime service for significant loss, threats or identity misuse. Report the account or message to the platform it used, and contact the real organisation if it was impersonated.
U.S. readers can use ReportFraud.ftc.gov and IdentityTheft.gov. UK readers can follow the reporting route linked by the NCSC.
One more warning
Recovery scams target people twice.
Someone may claim they can recover your money, trace cryptocurrency or move you to the front of a refund list—for an upfront fee or more personal information. Do not pay. Verify any offer through the organisation’s independently found official channel.
Helping someone else?
Calm helps people act.
Avoid blame. Sit with them, call the official provider together and write down the next three actions. Shame delays reporting; practical support makes recovery easier.
Research basis
Official guidance behind this page.
Reviewed 26 July 2026. Stop & Verify summarises these sources for general education; legal rights and reporting routes vary.