After a Scam: Steps to Take When You Think You've Been Targeted
Photo credit: Telecom360.net | Connecting You To The Latest In Telecom
In this article
Acting quickly limits the damage. This step-by-step guide covers what to do immediately after a suspected phishing click, fraudulent charge, or data leak.
Key Takeaways
- Disconnect affected devices immediately to prevent further unauthorized access or data transmission.
- Change passwords starting with your email account, which is the master key to most other logins.
- Contact your bank or card issuer within minutes of spotting a fraudulent charge.
- Report the scam to the FTC and your state attorney general to help others avoid the same attack.
- Monitor your credit reports for weeks after an incident — some identity theft surfaces slowly.
Understanding What You're Up Against
Scams take many forms — a phishing email that harvested your login credentials, a fraudulent charge from a compromised card number, a vishing (voice phishing) call that tricked you into sharing account details, or malware delivered through a deceptive download. The specific attack type shapes which steps matter most, but the underlying response framework is consistent: contain, secure, report, and monitor.
For a deeper look at how one common attack type is engineered to manipulate victims, see our breakdown of how tech support scams work. Understanding the playbook scammers follow helps you recognize when you're mid-attack rather than only after the fact.
It is also worth knowing that a stolen phone creates compounding risks similar to a successful phishing attack — your accounts, saved passwords, and authenticator apps can all become accessible to the wrong person. The response steps overlap significantly.
What you will need
What You'll Need Before You Start
Before working through the steps below, gather the tools and access that will make the process faster and less stressful. Having these ready on a separate, trusted device is strongly recommended — if your primary device was compromised, do not use it for recovery actions.
AnnualCreditReport.com
Pull free credit reports from all three major bureaus to check for unauthorized accounts or inquiries.
FTC IdentityTheft.gov
File an identity theft report and receive a personalized recovery plan from the Federal Trade Commission.
Have I Been Pwned
Check whether your email address or phone number appears in known data breach databases.
Password manager (any major provider)
Generate and store unique, strong passwords for every account to prevent credential-stuffing attacks.
Act Within the First Hour
The window immediately following a suspected scam is the most critical. Fraudsters often move quickly to drain accounts, lock you out of email, or sell your credentials. Do not wait until you are certain something is wrong — take protective action first, investigate second.
Step-by-Step Recovery Process
Work through these steps in order. Some can be done in parallel — for example, a family member can call your bank while you change passwords — but do not skip steps or reorder them without good reason. The sequence is designed to stop active damage before addressing longer-term remediation.
Disconnect the affected device from the internet
If you clicked a malicious link or downloaded an unexpected file, take the device offline immediately. Turn off Wi-Fi and disable mobile data. This severs any live connection a remote attacker may have established and stops malware from phoning home or transmitting stored data.
Change your email password first
Your email account is the recovery key for nearly every other login you own. Change its password on a trusted device before touching anything else. Enable two-factor authentication (2FA) if it is not already active — use an authenticator app rather than SMS where possible, since phone-number-based 2FA carries its own vulnerabilities. See our guide to SIM swap fraud for details on why SMS 2FA can be bypassed.
Contact your bank and card issuers
Call the number on the back of each card. Report any suspicious transactions and ask the representative to flag your account for fraud monitoring. Request a new card number if your details may have been exposed. For bank accounts, ask whether a temporary hold or additional verification layer can be applied while you assess the full scope of the incident.
Scan the device for malware
Reconnect the device to the internet only long enough to run a full scan using reputable security software. If your operating system has a built-in security tool (such as Windows Defender or macOS's XProtect), run a full-system scan. For persistent concerns — especially if you downloaded an unknown file — consider a factory reset as the most thorough remediation, then restore only from a backup dated before the suspected incident.
Place a fraud alert or credit freeze
Contact one of the three major credit bureaus — Equifax, Experian, or TransUnion — and request a fraud alert. By law, that bureau must notify the other two. A fraud alert asks lenders to verify your identity before extending credit. For stronger protection, place a credit freeze with all three bureaus individually, which blocks new credit inquiries entirely until you lift it. Both services are free under federal law.
File official reports
Report the scam to the Federal Trade Commission at ReportFraud.ftc.gov and, if identity theft occurred, follow up at IdentityTheft.gov for a personalized recovery plan. You can also report to the FBI's Internet Crime Complaint Center (IC3) and your state attorney general's office. If money was transferred, contact your local police department and file a report — you may need that report number when disputing charges or applying for victim assistance programs.
Monitor accounts and credit for the following weeks
Many consequences of a scam surface gradually. Set up transaction alerts on all financial accounts so unusual activity triggers an immediate notification. Check your free credit reports at AnnualCreditReport.com at staggered intervals across the three bureaus. Watch for unexpected password-reset emails, new accounts you did not open, or unfamiliar addresses appearing on correspondence — these are indicators that identity misuse is ongoing.
Use a Password Manager Going Forward
If credential reuse was part of what made this incident worse, a password manager removes that risk permanently. It generates and stores a unique, complex password for every account so a single breach cannot cascade into multiple compromised logins.
Do Not Call Numbers from Suspicious Messages
If you received a fraudulent email or text with a callback number, do not dial it. Scammers staff these lines specifically to extract more information from victims who call back. Use official numbers found on the back of your card or on verified government websites.
Your broader online privacy posture matters here too. If the scam succeeded partly because your personal details were already widely exposed — through data brokers, public social media, or previous breaches — addressing those data sources reduces your vulnerability to future targeting.
