Social Engineering Scams
First steps after a suspicious interaction
Start with what you actually shared, approved, installed or paid.
Choose the exposure
| What happened | Your first priority | Continue reading |
|---|---|---|
| You received a message only | Do not use the sender’s link or number; inspect the real account independently | Bank-call guide |
| You shared a code or password | Use official account recovery; review sessions and security changes | Verification-code guide |
| You installed remote access | End the connection; secure important accounts from another trusted device | Fake support guide |
| You sent money | Contact the payment provider immediately and explain exactly what happened | Recovery-scam guide |
| You paid to unlock a job | Stop further deposits; preserve records and contact the provider | Task-job guide |
Write down facts, not a perfect story
Note the time, the account involved, the action you took and the destination of any payment. Keep existing messages and transaction references. A short accurate account is more useful than guessing how an attacker obtained your details. Do not delay a bank call while trying to complete a report.
Ask what the institution can do
The FTC’s recovery guidance distinguishes payment methods and types of exposed information. Ask the relevant provider about reversal, recall, account restrictions and evidence requirements. None of these options guarantees recovery. For a work account or device, follow your organization’s incident process.
Be alert to the second approach
An unexpected “recovery specialist” who knows your loss amount is not necessarily legitimate. Do not pay an advance fee, disclose a wallet recovery phrase or grant remote access because a stranger promises a refund. Use our official reporting directory and keep public posts free of private records.