What happened?
Pick the closest option — each one gives you a step-by-step emergency plan.
- Call your bank's fraud line NOW — the number on the back of your card, not any number the scammer gave you. Say: "I've been scammed and sent money. Please recall the payment and freeze my accounts."
- If you paid by debit card, ask for a chargeback (120-day limit). If bank transfer, ask for a Faster Payment recall and mention APP fraud reimbursement (mandatory since Oct 2024, up to £85,000).
- If PayPal — log in and report the transaction as fraud immediately; ask them to freeze the recipient's account.
- Note the exact transaction reference, amount, date and time — your bank will ask for these.
- If the money was sent to a crypto address or gift card, tell the bank — recovery routes differ.
- Keep the conversation with the scammer (screenshots) — it's evidence.
- Your bank — fraud line (back of card) — first priority
- Action Fraud: 0300 123 2040 or actionfraud.police.uk — get a crime reference number
- PayPal / payment provider if used — report the transaction
- Financial Ombudsman (if the bank refuses to reimburse): financial-ombudsman.org.uk
- Bank statements / transaction confirmations (screenshots)
- Adverts, websites, or messages from the scammer
- Payment reference numbers and the recipient's account name
- Any email addresses, phone numbers or crypto wallets used
- Don't contact the scammer or threaten them — they'll just vanish
- Don't pay any "release fee", "tax" or "recovery fee" to get your money back — it's a second scam
- Don't wait — every hour reduces the chance of recovery
- Don't feel ashamed — this happens to millions of people
- APP fraud reimbursement — banks must refund up to £85,000 (unless gross negligence)
- Chargeback — debit/credit card purchases (120 days, some 540)
- Section 75 — credit card purchases over £100, the card company is jointly liable
- PayPal buyer protection — if you paid "Goods & Services"
- Call your bank's fraud line NOW (back of card). Tell them exactly what you shared — card number, sort code/account, or a one-time code.
- Ask them to block the card and check for any unauthorised payments.
- If you shared a one-time code, say so — it can be used to approve a payment or log into your account instantly.
- Watch for small test charges (e.g. £1) — scammers test cards before big purchases
- Check for new direct debits set up with your account number
- Set up transaction alerts in your banking app
- Your bank — fraud line, first priority
- Action Fraud: 0300 123 2040
- Cifas (0330 100 0180) — Protective Registration flags your identity (£25, 2 years)
- What details you shared, when, and with whom
- Screenshots of the conversation or call details
- Any reference numbers from the scammer
- Don't ignore it because "nothing happened yet" — act now
- Don't share any more codes or passwords with anyone who calls
- Don't pay anyone who offers to "protect" your account
- New card issued by the bank — old one cancelled
- Unauthorised payments reversed by the bank
- Monitor your credit file for identity fraud attempts
- Change your email password FIRST — if they control your email, they can reset every other account.
- Then change banking, PayPal, social media, and any account where you reused that password.
- Log out of all devices and enable two-factor authentication (use an authenticator app, not SMS).
- Check account settings for email forwarding rules (scammers hide your emails there)
- Check recovery email/phone hasn't been changed
- Check logged-in devices and remove unknown ones
- Your bank — if banking credentials were shared
- The platform (email provider, social network) — report the compromise
- Action Fraud: 0300 123 2040
- Which account, what password (don't reuse it), when you shared it
- Screenshots of the phishing page or message
- Login alerts or security notifications from the platform
- Don't reuse the old password anywhere — ever
- Don't use the same new password for multiple accounts
- Don't ignore security emails from the platform — read and act on them
- Password reset on all affected accounts
- 2FA via authenticator app on email + banking
- Password manager (Bitwarden, 1Password) so every account gets a unique password
- Did you enter anything? If you typed a password, card number or a code → treat it as compromised and follow the password/bank-details plans above.
- Change your email password now (from a different device if possible).
- Run a full antivirus scan on the device you used (Malwarebytes, Windows Defender).
- If the page is still open — close it, don't interact
- Enable 2FA on email and banking
- Watch for unexpected login alerts over the next days
- Your bank — only if you entered card/bank details
- Action Fraud: 0300 123 2040
- NCSC — [email protected] for the phishing email
- The link itself (copy the URL)
- Screenshot of the message and the page it opened
- Date/time and device used
- Don't click it again "to check"
- Don't install anything the page suggested
- Don't call any number shown on the page
- Password changes + 2FA on anything you entered
- Malware scan and removal
- If nothing was entered — you're likely fine; just stay alert
- Cut the connection NOW — end the session in AnyDesk/TeamViewer, or disconnect the internet / turn the device off.
- Uninstall the remote-access software.
- From a different device, change your email password first, then banking.
- Call your bank — the scammer may have watched you log in or taken screenshots.
- Run antivirus on the affected device
- Check for new browser extensions or apps the "helper" may have installed
- If banking was accessed, ask the bank to check for transfers and change your login
- Your bank — fraud line, immediately
- Action Fraud: 0300 123 2040
- Your device manufacturer / IT support if work device
- The remote-access session ID and any codes you read out
- What the caller claimed (company name, reference)
- Phone number they called from
- Don't reconnect the remote session "to check"
- Don't use the affected device to log into banking until it's been scanned
- Don't pay any "refund" or "security" fee — it's a second scam
- Full password reset from a clean device + 2FA
- Malware scan; factory reset if anything suspicious was installed
- Bank monitoring for unauthorised activity
- Move any remaining crypto NOW to a brand-new wallet the scammer has never seen.
- If it was on an exchange — freeze the account, change the password, and contact exchange support immediately.
- Revoke permissions if you approved a wallet connection (e.g. a fake "dApp"): use revoke.cash for EVM wallets.
- Report to Action Fraud and note the transaction hash / wallet address — it's public on the blockchain.
- Check if it was a wallet drain (permissions) vs stolen seed phrase — this determines what to fix
- If you shared a seed phrase, the wallet is compromised forever — move everything out
- Check your email — fake exchange emails often initiate these scams
- Exchange support (Coinbase, Binance, Kraken…) — they can freeze the recipient's account if funds landed there
- Action Fraud: 0300 123 2040
- National Cyber Security Centre — [email protected] if email-linked
- Transaction hash / TXID — the blockchain record
- The receiving wallet address
- Any fake exchange/app screenshots, emails, or links
- Never pay a "recovery service" — 99% are scammers who just take more money
- Don't share your seed phrase with ANYONE who contacts you
- Don't move remaining funds to the same compromised wallet "to consolidate"
- Crypto is largely unrecoverable once moved — but reporting can freeze exchange-bound funds
- Some exchanges freeze wallets flagged for fraud — report the receiving address to them
- Check with your bank: if the crypto was bought via card/bank transfer, you may claim under APP rules
- Report the fake account/profile on the platform where it appears (Facebook, Instagram, X, LinkedIn, WhatsApp — use their impersonation report tools).
- Warn your contacts — post a notice so friends/family don't fall for the fake.
- Check your credit file for accounts opened in your name (Experian, Equifax, TransUnion — free).
- Secure your real accounts — change passwords, enable 2FA
- If they used your photos, report to the platform as impersonation
- If they're contacting people for money, tell those people it's not you
- The platform — impersonation report (first priority)
- Action Fraud: 0300 123 2040 — if used for fraud
- Cifas — Protective Registration if identity theft risk
- Credit agencies — flag any fraudulent applications
- Screenshots of the fake profile (before it's taken down)
- Messages the impersonator sent to you or others
- The profile URL and account creation date if visible
- Don't message the impersonator or pay them to "delete" the account
- Don't delete your real account (you can lock it instead)
- Don't ignore it — impersonation is used to scam people who know you
- Platform takedown of the fake account
- Cifas Protective Registration (£25, 2 years)
- Credit-file monitoring for fraudulent applications
- Stay calm — do NOT blame or punish your child. They are the victim, not the cause.
- Preserve the evidence — screenshot messages, don't delete the conversation or block the account yet.
- Report to CEOP (ceop.police.uk) — the UK's online child safety command — for grooming, sextortion or inappropriate contact.
- If there's immediate danger, call 999 or your local police on 101.
- Talk to your child calmly — find out what happened, what was shared, and who contacted them
- Stop contact: block the account after screenshots are saved
- Check the platform's safety settings and enable parental controls
- If images were shared, contact the Internet Watch Foundation (iwf.org.uk) for removal
- CEOP — ceop.police.uk (grooming, sextortion, online abuse)
- NSPCC — 0808 800 5000 (free, 24/7, confidential)
- Police — 101 (non-emergency) or 999 (immediate danger)
- Internet Watch Foundation — iwf.org.uk (removing images)
- All messages, usernames, and profile links (screenshots)
- Dates, times, and which apps were used
- Any money or gift cards sent, and to where
- Do NOT delete anything until CEOP/police have seen it
- Don't blame, shout, or punish your child — it stops them telling you things
- Don't delete the evidence (even though you'll want to)
- Don't confront the offender yourself
- Don't keep it a secret — tell the police/CEOP
- CEOP safety centre — specialist police support for children
- NSPCC counselling for your child (0808 800 5000)
- Childline — 0800 1111 — free, confidential, for your child
- If money was taken, your bank may refund under APP rules — report quickly
Call your bank using the number on the back of your card — not any number the scammer gave you. Say: "I have been scammed. Please freeze my accounts and help me recover my money."
Change your email password first — if the scammer controls your email, they can reset all your other passwords. Then banking, social media, and any account where you reused the password.
Turn on 2FA on email, banking and social media. Use an authenticator app rather than SMS — scammers intercept SMS codes via SIM swap attacks.
Action Fraud: 0300 123 2040 or actionfraud.police.uk — get a crime reference number
Phishing emails: forward to [email protected]
Scam texts: forward to 7726 (free)
Scam calls: report to Action Fraud and your phone provider
Check Experian, Equifax, and TransUnion — all offer free checks. Look for accounts you didn't open. Consider Cifas Protective Registration (£25, 2 years) to flag your identity.
Run a full antivirus scan on your phone, laptop and any devices you used around the time of the scam. Files or apps the scammer sent may contain malware.
📞 Key Numbers — Save These
💙 You Are Not Alone
Getting scammed is not your fault. Scammers are professionals who trick thousands of people. 4.1 million fraud incidents were reported in the UK in 2024. Help is available — talk to Victim Support, free and confidential, 24/7.