After a scam,
what next?

What we think you could consider … if you’re the victim of a scam or fraud.

NOTE: This is a general informational guide written to help you think through possible next steps after a scam or fraud. In no way is it to be considered professional advice. Please consider your own circumstances or seek independent support where needed.

Realising you’ve just fallen for a scam or fraud can bring a mix of emotions.

It’s completely normal to feel overwhelmed, upset, embarrassed, or confused.

But try, where possible, to set those emotions aside so you can focus on what matters most: you, your money, and your personal information.

We’ve pulled together practical steps which victims of scams often find helpful. It’s longer than the usual short series of bullet points, simply because it reflects what we believe is genuinely important.

Of course, none of this guarantees you’ll recover your losses. Recovery can be tough or, in some cases, impossible and that’s a difficult truth for many victims.

RESPONSE

response.png

Part 1 is all about stopping what you were doing when the scam happened. It’s about regaining control and doing so quickly. It’s about securing your current data and money, and cutting off the scammer, no matter who they appear to be.

Others can and likely will try to help (banks, law enforcement, etc.), but acting quickly yourself can make a real difference in limiting further harm. Too often, scammers rely on continued engagement to extend access and escalate financial loss.

The situation can feel urgent but acting calmly and quickly can put you back in control.

Depending on your circumstances, consider the following:

If you’re on a call, exchanging emails, or messaging via text or chat apps, consider ending all communication right away. This can give you the space you need to pause and take control of the situation.

If you’re hesitant to hang up or disengage, remember you don’t owe the other person politeness or an explanation.

Continuing the conversation can give the scammer more opportunities to manipulate the situation. Ongoing communication allows them to maintain psychological control, keeping you in a reactive state where decisions are harder to question or reverse.

General advice is to contact your bank or financial institution right away. Use the number printed on the back of your official bank card, on trusted documentation, or by searching for the official website using a secure device.

Calling them without delay typically does two things. First, it allows them to activate protective measures now that they’re aware of a problem. Secondly, they can act on your behalf to try to stop or recover payments, if that is still possible.

This urgency matters. Banks and payment providers often operate within short intervention windows, where funds may still be traceable, frozen, or recalled depending on the payment method used.

It’s also important to understand that you’re not just calling to report the fraud. Reporting is important, but actively asking about recovery options can sometimes improve outcomes. This distinction matters because internal processes for ‘reporting’ and ‘fund recovery’ are often handled separately.

If access was given through downloads or screen sharing, consider disconnecting the device immediately. This may mean switching it off or, at the very least, disconnecting it from Wi-Fi. This is a precaution, not a sign you’ve done something wrong. It reflects how many scams operate.

Remote access tools can allow scammers to continue monitoring activity even after contact ends, including banking activity or password changes. Compromised devices may also be reused as entry points for further targeting or silent data collection.

If you already have antivirus software installed, consider running a full scan to identify and remove any suspicious software. Another option is to seek professional help to check the device. What you want to avoid is any ongoing access or visibility from the scammer’s side.

It can help to assume that anything shared; email addresses, phone numbers, documents, or personal details could be used against you or sold to others. Your data may already be circulating, and that process can continue for months or even years. This can feel overwhelming. But it’s also a point where you still have some control.

For many people, it’s important to lock down accounts by changing passwords using a clean, unrelated device. This might involve securing everything, starting with accounts most likely linked to the scam, such as banking and email accounts.

Email accounts are especially important because they often act as recovery points for other services. If compromised, they can increase wider risks significantly. Once these key accounts are secured, you can move on to others.

Where available, consider enabling two-factor authentication (2FA), ideally using a secure app on a trusted mobile device. This adds an extra layer of protection, even if passwords have been exposed.

Also be aware that scammers may have set up new recovery email addresses or added their own phone numbers. If accounts aren’t fully reset, they may still retain access. This is critical, as recovery channels can sometimes bypass password protections entirely.

Consider taking a moment to pause and ask yourself: have I missed anything? Did you share something sensitive, personal, or potentially useful for accessing other services or accounts?

This step matters because stress and urgency can create memory gaps, meaning important details may be overlooked. This isn’t about guilt or embarrassment; it’s about identifying risks that may still need addressing.

What’s happened has already happened. There’s no need to feel embarrassed. Thousands of people fall victim to scams every day. Scams are designed to work on people. They exploit normal human reactions, not a lack of intelligence. Shame can work against you. It can delay action, reduce reporting, and limit the chances of recovery.

COLLECTION

collection-scaled.png

You’ve acted quickly. You’ve informed your bank and other relevant organisations, and you’ve taken steps to secure your accounts; changing passwords and limiting further access to your device. But now the focus shifts.

This stage can be important because structured information allows banks, fraud teams, and law enforcement to act more efficiently. In turn, this can increase the likelihood of identifying transaction pathways or linked accounts.

Part 2 is about collection. Collecting the facts, establishing a timeline, and understanding how the situation developed. It’s about carefully piecing together what happened.

Depending on your circumstances, consider the following:

Keeping any potentially compromised device off Wi-Fi, meaning not connected to the internet can help prevent further remote access.

When a device is at risk, your information may still be at risk. This precaution matters because remote access tools can remain active in the background, sometimes continuing to transmit data without visible signs to the user.

By ‘evidence’, we mean anything you can bring together to clearly explain and support your situation.

Clear, factual information helps banks and authorities act faster. This matters because structured evidence reduces ambiguity, allowing fraud teams to identify patterns, transaction paths, and potential recovery opportunities more efficiently.

While everything is still fresh in your mind, consider writing a timeline of what happened. It might cover just a few minutes, an hour, or extend over months or even years. However long or short, start making notes. This helps you record events while also highlighting risks you may not yet have identified.

You’re not expected to remember everything perfectly, just capture what you can. Memory under stress is often fragmented, and reconstructing events later becomes significantly less accurate.

Consider noting how contact started, what was said, what actions you took, and where you felt pressure or uncertainty. This can be valuable for any formal investigation and also helps you better understand what happened. Identifying these pressure points can reveal the manipulation techniques used, which in turn helps reduce the risk of it happening again.

Consider storing all collected evidence somewhere safe. This could include text messages, emails, phone numbers, transaction receipts, screenshots of profiles, websites, or wallet addresses if cryptocurrency was involved.

This step can be important because scammers often delete or alter online content once they suspect detection or reporting.

Also remember, if your device is compromised, the scammer may still have access when it reconnects to Wi-Fi. Even logging into accounts linked to the scam could create further risk.

Take time to write down exactly what you shared with the scammer. This could include personal details, documents (such as passports, utility bills, or bank statements), login credentials, addresses, or verification codes. If money was sent, record the amount, method, and timing.

This matters because identity-based fraud can escalate later using previously collected information. Secondary misuse doesn’t always happen instantly. Writing this down can also help you identify risks you may not have considered. Some forms of account compromise are delayed, meaning issues may only appear weeks or months later.

Make a note of anything unusual or unexpected. Have you received notifications about new recovery emails or phone numbers? Unfamiliar text messages? Unexpected login alerts? Are you receiving all your emails as expected? Have you noticed messages relating to debts, services, or recovery offers you didn’t request?

Be especially cautious of follow-up scams. These often pose as authorities, investigators, or recovery agents offering to help. In reality, they are designed to exploit the same situation again, often using urgency or false authority.

PROTECTION

protection.png

You’ve reported the situation, perhaps to your bank, the police, or a scam reporting service. From here, progress can sometimes feel slow, even when you want instant action.

But what you do next remains just as important as what you’ve already done.

Depending on your circumstances, consider the following:

Yet, it can help to recognise that many others are going through similar situations, and that fraud resolution often involves formal processes that take time.

It’s common to receive offers to recover lost money after a scam. In many cases, these are the same or linked scammers testing whether you remain vulnerable. This is why it’s important to continue monitoring your accounts for weeks, or even months, to ensure everything is properly secured.

Stolen data is often circulated or resold, meaning repeated targeting can happen long after the original incident.

After a scam, it’s natural to feel frustrated, embarrassed, or determined to fix what’s happened. This can make offers of help feel more convincing.

Any unexpected contact offering assistance should always be independently verified. Remaining cautious matters because emotional responses can increase susceptibility to urgency-based manipulation.

Ensure you are using strong, unique passwords for each account, and that they are stored securely. If any passwords have been shared or exposed, change them again.

No legitimate bank or law enforcement agency will ever ask for your passwords. If they are known to someone else, treat them as compromised.

Where possible, enable strong two-factor authentication (2FA), ideally through a secure app.

Now is the time to ensure your devices are safe. Consider running a full malware scan, removing suspicious applications, or having the device checked by a professional.

This matters because malicious software can remain hidden and continue collecting data long after installation.

Once you are confident the device is secure, consider backing up important files.

Limit the amount of personal information you share online. Monitor for duplicate or fake profiles and be cautious about where your phone number and email address are listed. Avoid moving conversations or transactions off trusted platforms.

This matters because scammers often use publicly available information to personalise their approach.

Right now, everything may feel obvious and suspicious. Over time, that awareness naturally fades and that’s often when follow-up scams occur.

You may find it helpful to set clear personal rules moving forward. For example, choosing not to act on urgency, always verifying requests through a second channel, and avoiding unexpected links or downloads.

You might also decide not to make financial decisions instantly, instead giving yourself time to step away and think. These rules reduce reliance on emotional decision-making, especially under pressure.

They only work, however, if they are consistently applied. Many people relax too early, something scammers often rely on.

Looking back, can you identify what made the situation convincing? Was it urgency, trust, opportunity, or fear? Understanding this can help you recognise and resist similar tactics in the future.

Scams are rarely random. Targeting is often deliberate, based on factors such as location, behaviour, or perceived likelihood of response. Scammers use tested methods, such as pressure, authority, familiarity, and timing. Often, speed becomes the key factor. Even if it wasn’t immediate, there was likely a moment where you were pushed to act faster than you normally would.

Recognising this isn’t about blame, it’s about awareness.

If you’re a scam victim, it’s usually because the scammer knew how to manipulate you by running tried and tested scripts on human behaviour.

They probably focused on pressure and time constraints, they assumed authority and compliance, or they used friendliness and trust.

They probably used speed as their primary weapon - maybe not at the start, but at some point, there was a panic, a push, a need for you to react sooner than you normally choose to.

That’s why we know playing the scenarios we offer builds practical awareness, helping everyone identify scam risks in everyday situations.