Finding out you’ve been scammed online triggers a specific kind of panic — but the response that actually helps is calm and orderly, not frantic. What you do in the next hour matters more than how you feel about it. This guide is a clear, step-by-step checklist for right now, followed by extra steps for the most common scam types, so you can act fast without missing something important.
Do this first, before anything else
Skip straight to whichever step applies right now — this checklist is ordered by urgency, not by importance of feelings.
1. Stop all further contact and payment
The moment you suspect a scam, stop. Stop replying to the message, stop the call, stop sending any more money, and stop providing any more information. If you’re mid-conversation, end it now. There’s no version of “let me see what they say next” that helps you, and continuing to engage only gives a scammer more material to work with or more time to push you further.
2. Document everything — before you delete anything
Before you block, delete, or close anything, capture the evidence:
- Screenshot the messages, profile, listing, or email.
- Save the sender’s username, email address, phone number, or payment account details.
- Write down the exact amount, date, and payment method used.
- Note anything you told them — this matters for step 5 if you shared a password or personal details.
This record is what your bank, any report you file, and your own memory a week from now will need. It’s much easier to gather in the first ten minutes than to reconstruct later.
3. Contact your bank or card issuer immediately
If any money moved, call the fraud or dispute line on the back of your physical card, or reach your bank through its official app or the number on its real website — never a number or link the scammer gave you, even if it looked official. Ask them to:
- Freeze or replace the card if card details were involved.
- Open a dispute or chargeback for the transaction.
- Flag the account for monitoring.
Card payments generally have the strongest dispute protections and the best odds of reversal — and only if you act quickly. Bank transfers, wire transfers, gift cards, and cryptocurrency payments are far harder to reverse once sent, which is exactly why scammers steer people toward those methods. If that’s how you paid, still report it (next step), but be realistic that recovery is less likely.
4. Report the scam to the appropriate authority
File a report with your country’s official consumer-fraud or cybercrime reporting body. **** Reporting takes a few minutes, helps authorities and platforms track patterns, and is worth doing even for a small loss or a near-miss you caught in time.
If the scam happened through a specific platform — a marketplace, social app, or dating app — also report it directly through that platform’s own reporting tool, separate from the government report.
5. Change any password you reused — starting with email
If you entered a password on a scam site, or suspect any account was compromised, change that password immediately. Then change it everywhere else you used the same one, and start with your email — it’s the account that can reset almost everything else, so securing it first limits how much further a scammer can go.
A password manager makes “change it everywhere” tractable instead of a guessing game, since it can show you exactly where you’ve reused a password and generate a unique one for each account:
1Password
Shows you where passwords are reused across your accounts and generates unique ones for each — the practical way to actually finish the 'change every reused password' step instead of abandoning it halfway through.
If you’d rather start free, Bitwarden covers the same core need — unique, generated passwords stored securely — without a subscription:
Bitwarden
Free, open-source password manager with the same core reuse-fixing capability, if you want to start without paying.
6. Turn on two-factor authentication
Add app-based two-factor authentication to your email and to any account involved in the scam. With it on, a password alone — even one the scammer already obtained — isn’t enough to get back in; they’d also need a code from your device or a passkey. Prefer an authenticator app or a passkey over SMS codes where it’s offered, since SMS can be intercepted through SIM-swap attacks.
7. Monitor for identity theft in the weeks after
The immediate cleanup is done, but stay alert for a while longer:
- Check bank and card statements regularly for unfamiliar charges, not just once.
- Watch your credit report for new accounts you didn’t open.
- Expect follow-up phishing. Scammers sometimes sell or share what they collected, and a scam attempt can be followed by a second one referencing real details from the first, which makes it more convincing, not less risky.
If the scam exposed identity-level information — a government ID number, date of birth, or full financial details — a credit freeze is worth doing on top of the steps above; see our guide on what to do if your data was leaked for that fuller process. For ongoing peace of mind rather than a one-time check, an identity-monitoring service can watch for misuse across more sources than you’d realistically check by hand:
Aura
Monitors for signs of identity theft and account misuse after an incident like this, so you're not relying on manually checking every statement and report yourself for months.
Extra steps by scam type
The checklist above covers every scenario, but a few common scam types have specific extra steps worth calling out.
If it was a payment or purchase scam
You paid for something — a product, a service, a fake listing — that never arrived or wasn’t real.
- Prioritize the bank/card dispute step above all else; this is the scenario where a fast chargeback has the best odds.
- If you paid through a marketplace or platform with its own buyer protection, file a claim there too, separately from your bank dispute.
- Save the listing or ad itself, not just the payment confirmation — platforms often want to see what was advertised.
If your account was taken over
You clicked a phishing link, entered a password on a fake site, or noticed a login, post, or message you didn’t make.
- Change that account’s password immediately from a device you trust, and check its recovery email/phone for anything the attacker may have changed.
- Log out of all other active sessions/devices if the account offers that option — most major platforms do.
- Warn your contacts if the account was used to message people you know; account-takeover scams frequently pivot to scamming your contacts next using your identity.
- Check our guide on how to check if your email was breached if you’re unsure whether this ties back to a broader data breach.
If it was a romance or relationship scam
You built a relationship online with someone who asked for money, gifts, or personal/financial information — often over weeks or months.
- This scenario carries real emotional weight on top of the financial one; that’s normal, and it doesn’t make the fraud less real or less worth reporting.
- Save the entire conversation history before blocking, since the pattern of requests over time is often the clearest evidence.
- Be extra cautious of a “recovery” contact who reaches out afterward claiming they can get your money back for a fee — this is a well-documented follow-up scam that targets people who already lost money once.
- If you shared photos, financial details, or documents, treat those as compromised the same way you would in an account-takeover scenario, and take the password and monitoring steps above.
What not to do
- Don’t pay anyone who contacts you promising to “recover” your lost funds for a fee. This is a common secondary scam targeting people who already lost money.
- Don’t confront or continue engaging with the scammer looking for answers or an apology — there’s no upside and some risk of escalation.
- Don’t wait to see if it “resolves itself.” Time works against you for payment disputes and account security alike.
- Don’t skip reporting because the amount was small or because you feel embarrassed — reports help regardless of size, and the embarrassment fades faster than people expect.
The bottom line
Being scammed online is unsettling, but the response that actually helps is short and ordered: stop contact and payment, document everything, call your bank or card issuer, report it, change reused passwords starting with email, add two-factor authentication, and monitor for a while afterward. Match any extra steps to the type of scam it was, skip the shame spiral, and skip anyone who contacts you afterward promising to fix it for a fee.
This guide is part of the Privacy & Security Kit. If the scam involved a data exposure rather than a direct payment, see what to do if your data was leaked; if you’re not sure whether your email or a password has been exposed at all, start with how to check if your email was breached. And if you’re dealing with unwanted contact because your phone number or home address are too easy to find, see how to remove your phone number and how to remove your home address from the internet.