SCAMSSocial engineering, decoded First steps

Social Engineering Scams

First steps after a suspicious interaction

Start with what you actually shared, approved, installed or paid.

Stop the live interaction first.End the call, remote session or chat. Use a separate trusted route to the bank, platform or employer. You do not need the caller’s permission to check their story.

Choose the exposure

What happened Your first priority Continue reading
You received a message only Do not use the sender’s link or number; inspect the real account independently Bank-call guide
You shared a code or password Use official account recovery; review sessions and security changes Verification-code guide
You installed remote access End the connection; secure important accounts from another trusted device Fake support guide
You sent money Contact the payment provider immediately and explain exactly what happened Recovery-scam guide
You paid to unlock a job Stop further deposits; preserve records and contact the provider Task-job guide

Write down facts, not a perfect story

Note the time, the account involved, the action you took and the destination of any payment. Keep existing messages and transaction references. A short accurate account is more useful than guessing how an attacker obtained your details. Do not delay a bank call while trying to complete a report.

Ask what the institution can do

The FTC’s recovery guidance distinguishes payment methods and types of exposed information. Ask the relevant provider about reversal, recall, account restrictions and evidence requirements. None of these options guarantees recovery. For a work account or device, follow your organization’s incident process.

Be alert to the second approach

An unexpected “recovery specialist” who knows your loss amount is not necessarily legitimate. Do not pay an advance fee, disclose a wallet recovery phrase or grant remote access because a stranger promises a refund. Use our official reporting directory and keep public posts free of private records.