Cybersecurity

After a Scam: Steps to Take When You Think You've Been Targeted

After a Scam: Steps to Take When You Think You've Been Targeted

Photo credit: Telecom360.net | Connecting You To The Latest In Telecom

Acting quickly limits the damage. This step-by-step guide covers what to do immediately after a suspected phishing click, fraudulent charge, or data leak.

Key Takeaways

  • Disconnect affected devices immediately to prevent further unauthorized access or data transmission.
  • Change passwords starting with your email account, which is the master key to most other logins.
  • Contact your bank or card issuer within minutes of spotting a fraudulent charge.
  • Report the scam to the FTC and your state attorney general to help others avoid the same attack.
  • Monitor your credit reports for weeks after an incident — some identity theft surfaces slowly.

Understanding What You're Up Against

Scams take many forms — a phishing email that harvested your login credentials, a fraudulent charge from a compromised card number, a vishing (voice phishing) call that tricked you into sharing account details, or malware delivered through a deceptive download. The specific attack type shapes which steps matter most, but the underlying response framework is consistent: contain, secure, report, and monitor.

For a deeper look at how one common attack type is engineered to manipulate victims, see our breakdown of how tech support scams work. Understanding the playbook scammers follow helps you recognize when you're mid-attack rather than only after the fact.

It is also worth knowing that a stolen phone creates compounding risks similar to a successful phishing attack — your accounts, saved passwords, and authenticator apps can all become accessible to the wrong person. The response steps overlap significantly.

What you will need

Access to a separate, trusted device (phone or computer) to make changes safely
Login credentials for your email, bank, and key online accounts
Your bank or credit card's customer service phone number
A government-issued ID handy in case identity verification is required

What You'll Need Before You Start

Before working through the steps below, gather the tools and access that will make the process faster and less stressful. Having these ready on a separate, trusted device is strongly recommended — if your primary device was compromised, do not use it for recovery actions.

Required

AnnualCreditReport.com

Pull free credit reports from all three major bureaus to check for unauthorized accounts or inquiries.

Required

FTC IdentityTheft.gov

File an identity theft report and receive a personalized recovery plan from the Federal Trade Commission.

Optional

Have I Been Pwned

Check whether your email address or phone number appears in known data breach databases.

Optional

Password manager (any major provider)

Generate and store unique, strong passwords for every account to prevent credential-stuffing attacks.

Act Within the First Hour

The window immediately following a suspected scam is the most critical. Fraudsters often move quickly to drain accounts, lock you out of email, or sell your credentials. Do not wait until you are certain something is wrong — take protective action first, investigate second.

Step-by-Step Recovery Process

Work through these steps in order. Some can be done in parallel — for example, a family member can call your bank while you change passwords — but do not skip steps or reorder them without good reason. The sequence is designed to stop active damage before addressing longer-term remediation.

1

Disconnect the affected device from the internet

If you clicked a malicious link or downloaded an unexpected file, take the device offline immediately. Turn off Wi-Fi and disable mobile data. This severs any live connection a remote attacker may have established and stops malware from phoning home or transmitting stored data.

Tip: Use a different, clean device — such as a second phone or a family member's laptop — for all subsequent steps in this guide.
2

Change your email password first

Your email account is the recovery key for nearly every other login you own. Change its password on a trusted device before touching anything else. Enable two-factor authentication (2FA) if it is not already active — use an authenticator app rather than SMS where possible, since phone-number-based 2FA carries its own vulnerabilities. See our guide to SIM swap fraud for details on why SMS 2FA can be bypassed.

Tip: After securing email, work outward: change passwords for financial accounts, then social media, then anything else that may have shared a password with the compromised account.
3

Contact your bank and card issuers

Call the number on the back of each card. Report any suspicious transactions and ask the representative to flag your account for fraud monitoring. Request a new card number if your details may have been exposed. For bank accounts, ask whether a temporary hold or additional verification layer can be applied while you assess the full scope of the incident.

Warning: Do not rely on a phone number from a suspicious email or text — always verify contact details through your card or the bank's official website.
4

Scan the device for malware

Reconnect the device to the internet only long enough to run a full scan using reputable security software. If your operating system has a built-in security tool (such as Windows Defender or macOS's XProtect), run a full-system scan. For persistent concerns — especially if you downloaded an unknown file — consider a factory reset as the most thorough remediation, then restore only from a backup dated before the suspected incident.

Tip: Back up important files to an external drive before a factory reset, but scan the backup for malware before trusting it.
5

Place a fraud alert or credit freeze

Contact one of the three major credit bureaus — Equifax, Experian, or TransUnion — and request a fraud alert. By law, that bureau must notify the other two. A fraud alert asks lenders to verify your identity before extending credit. For stronger protection, place a credit freeze with all three bureaus individually, which blocks new credit inquiries entirely until you lift it. Both services are free under federal law.

6

File official reports

Report the scam to the Federal Trade Commission at ReportFraud.ftc.gov and, if identity theft occurred, follow up at IdentityTheft.gov for a personalized recovery plan. You can also report to the FBI's Internet Crime Complaint Center (IC3) and your state attorney general's office. If money was transferred, contact your local police department and file a report — you may need that report number when disputing charges or applying for victim assistance programs.

Tip: Keep copies of every report you file. Reference numbers are often required when disputing fraudulent charges with banks or credit bureaus.
7

Monitor accounts and credit for the following weeks

Many consequences of a scam surface gradually. Set up transaction alerts on all financial accounts so unusual activity triggers an immediate notification. Check your free credit reports at AnnualCreditReport.com at staggered intervals across the three bureaus. Watch for unexpected password-reset emails, new accounts you did not open, or unfamiliar addresses appearing on correspondence — these are indicators that identity misuse is ongoing.

Tip: Spreading your three annual free credit report requests across the year — one bureau every four months — gives you more frequent visibility without paying for a monitoring service.

Use a Password Manager Going Forward

If credential reuse was part of what made this incident worse, a password manager removes that risk permanently. It generates and stores a unique, complex password for every account so a single breach cannot cascade into multiple compromised logins.

Do Not Call Numbers from Suspicious Messages

If you received a fraudulent email or text with a callback number, do not dial it. Scammers staff these lines specifically to extract more information from victims who call back. Use official numbers found on the back of your card or on verified government websites.

Your broader online privacy posture matters here too. If the scam succeeded partly because your personal details were already widely exposed — through data brokers, public social media, or previous breaches — addressing those data sources reduces your vulnerability to future targeting.

Cybersecurity Editorial Team

Author

Cybersecurity Editorial Team

Cybersecurity Editorial Team is the collective byline for our editorial team and contributor network. Articles published under this byline or an editorial pen name are researched, written, and reviewed according to our editorial standards for clarity, consistency, and independence before publication.

View all articles →
The content on this site is for informational purposes only and is not a substitute for professional advice. Always consult a qualified professional for guidance specific to your situation.