If someone is in immediate danger
Call 911 for immediate physical danger, threatened violence, a missing child, a medical emergency, or another situation requiring emergency services. Do not use this page to negotiate with a threatening person, locate someone, perform an investigation, or decide whether a threat is credible.
If a child may be experiencing sexual exploitation, sextortion, online enticement, trafficking, or circulation of sexual images, go to the child safeguarding route below and involve a safe adult now. The child is not responsible for resolving the contact.
First: stop contact, preserve options, and assign one adult lead
Do not send more money, codes, information, images, or access because someone promises to refund a payment, recover a loss, release funds, protect an account, remove content, stop a threat, or conduct an investigation. Recovery scammers may target people known to have lost money and request another fee or more personal information.
Use a separate, known-safe route to contact the real provider. Do not call a number in the suspicious message, a pop-up, or an advertisement. Do not let the suspected scammer transfer the call to a supposed bank, police officer, government agent, lawyer, technician, or recovery service.
Assign one capable adult as the response lead and one backup. Record actions and provider case numbers so several family members do not issue conflicting instructions, reset the same account repeatedly, destroy evidence, or pay a second person. When a child’s account or information is involved, verify who has legal authority to act and protect the child’s privacy.
This guide provides general US educational routing. It cannot determine whether fraud or a crime occurred, interpret account terms or law, perform technical forensics, or promise that money, identity, content, a device, or an account can be recovered.
Make a one-minute consequence inventory
Do not spend the first hour naming the scam. Check what may have happened:
- Was money sent, a check deposited, cash mailed, or a purchase approved?
- Was a card, bank, payment-app, gift-card, wire, cryptocurrency, marketplace, or other transaction involved?
- Was a username, password, security code, recovery key, identity document, Social Security number, financial detail, or health or school information shared?
- Was a sign-in, recovery, multifactor, device-pairing, forwarding, or permission prompt approved?
- Was software installed, an attachment opened, a link followed, a screen shared, or remote access granted?
- Did a phone number, email, cloud, gaming, school, social, creator, shopping, or other account stop working or change?
- Does the incident involve a child, intimate image, sexual request, blackmail, stalking, threat, or planned meeting?
Follow every matching section. More than one provider may need prompt contact.
If the message was received but nobody interacted
Do not reply, click, call, open, download, scan, forward, unsubscribe through the message, or provide information. If the claim could be real, verify through the organization’s normal official app, a saved trusted address, a statement, a known number, or an established in-person route.
Use the message service’s report-spam or report-phishing feature when appropriate. Preserve minimal sender, date, and message information only if a provider or report needs it, then follow the provider’s deletion or blocking guidance. A report label is not an authenticity determination, and blocking one sender does not prevent every future attempt.
If a link, attachment, QR code, or download was opened
Stop interacting. Do not revisit the page to inspect it. Disconnecting a device from a network may sometimes limit communication, but the correct containment step depends on the device, workplace or school system, account, and event. Use a known-safe device to contact the operating-system, device, security-software, school, workplace, or qualified technical support route that controls the system.
FTC recovery guidance recommends updating security software, running a scan, and removing identified problems after remote-access or malicious-software concerns. Follow the current provider’s instructions rather than downloading a “cleaner” recommended by an unexpected caller or search advertisement.
If information was entered, a code was shared, software installed, a prompt approved, remote access granted, or money sent, complete those sections too. A clean scan does not prove that accounts, browser sessions, email forwarding, cloud data, or payment information are unaffected.
If a password, security code, approval, or recovery key was shared
Use a known-safe device and the account provider’s official route. Begin with email if it can reset other accounts, then address financial, carrier, cloud, school, gaming, shopping, social, and other linked accounts based on likely consequence.
Ask the provider to help:
- secure or recover the account
- end unknown sessions and remove unknown devices, apps, forwarding rules, recovery contacts, passkeys, or permissions
- change the password to a long, random, unique one
- change reused passwords on other accounts
- restore provider-supported multifactor authentication and recovery methods
- review purchases, transfers, messages, posts, files, and profile changes
- document the incident and any continuing monitoring step
Do not remove a legitimate caregiver, accessibility support, school administrator, family organizer, or necessary shared access without understanding the effect. A provider may require identity or authority verification. Submit it only through the official process and disclose no more than necessary.
Changing one password is not enough if the email account, phone number, recovery route, device, or another active session remains controlled by someone else.
If a phone number or mobile-carrier account was taken over
Contact the carrier through its official site, app, store, statement, or known support number to regain control of the number and account. Ask about unauthorized SIM, eSIM, port, forwarding, device, PIN, or account changes and how to secure the carrier account.
Then review email, financial, payment, social, cloud, and other accounts that use the phone for recovery or multifactor authentication. Change affected credentials after the carrier route is controlled. FTC guidance also advises checking financial accounts for unauthorized charges or changes and using IdentityTheft.gov when personal information may be misused.
Do not assume that receiving texts again means every account is secure.
If someone had remote access to a computer or phone
End the session if it is safe and possible without following the caller’s instructions. Contact the device, operating-system, security, workplace, school, or other qualified support provider through a separately obtained route. Tell them exactly what was installed, approved, viewed, typed, transferred, or changed as far as known.
Use another known-safe device for financial or identity response if the affected device may still be controlled. Review related accounts and transactions. Do not let a second unsolicited technician reconnect, and do not pay for a supposed refund or cleanup that begins with unexpected contact.
Technical support can assess whether a scan, removal, backup review, reset, credential change, or other action is appropriate. This page cannot determine that a device is clean or prescribe a universal reset sequence.
If money was sent or a payment was approved
Contact the company used to send the money immediately through its official route. Explain exactly whether the transaction was unauthorized, induced by deception, still pending, or connected to a fake check or compromised account. Those distinctions may affect the provider’s process. Ask what reversal, dispute, recall, interception, account-security, or refund options exist, and keep the case number. Do not misstate what happened.
Credit or debit card
Contact the card issuer. Identify the charge and ask about its current fraud or dispute process. If the card details were exposed, ask how the account should be secured. Card protections and deadlines vary by transaction and circumstance; this guide does not promise a chargeback.
Bank debit, withdrawal, transfer, or check
Contact the bank’s fraud department. State whether you initiated the transaction, someone else made it, or a check was deposited and money sent onward. A displayed balance does not prove a check has finally cleared. Do not spend or forward supposed check funds while the bank investigates. Ask whether accounts, online banking, checks, transfers, or credentials need controls.
Payment app or marketplace
Report the transaction and account to the app or platform. If a bank account or card funded it, contact that provider too. Screenshots, emails, or messages showing payment are not the same as a completed transaction in the official account.
Gift card
Contact the issuer immediately. Keep the physical or electronic card, number information, and purchase receipt secure and ask about its scam-reporting and refund process. Do not send the card or PIN to anyone else. FTC guidance says it is worth asking, but recovery is not guaranteed.
Wire transfer
Contact the bank or wire-transfer company promptly and request its fraud, reversal, or recall process. Preserve the transfer details. A filing with FTC or IC3 does not itself stop the transfer.
Cryptocurrency
Contact the exchange, wallet provider, kiosk operator, or company used to send the transaction and report the fraud. FTC guidance notes that cryptocurrency payments typically cannot be reversed unless the recipient returns them, but the provider may still need the report. Do not pay a tracing or recovery service that contacts you unexpectedly or guarantees retrieval.
Cash or package in transit
Contact the postal or delivery carrier immediately through its official route and ask whether interception is possible. Do not attempt to retrieve a package from an unknown person or location.
If a fake check was deposited
Contact the bank promptly, explain that the check may be fraudulent, and disclose any money already sent or spent. Do not send more money because funds appear available. FTC guidance warns that fake checks can take time to be discovered and that the depositor may be responsible for money sent onward.
Preserve the check, envelope, deposit record, messages, job or marketplace materials, and outgoing transaction details as the bank or reporting authority requests. Do not confront the sender or attempt another deposit.
If identity information was exposed or misused
Use IdentityTheft.gov through a separately entered official address. Its process creates steps based on the information exposed and the type of misuse. Contact the company where known fraud occurred and secure directly affected financial, government, benefits, tax, medical, employment, school, or account records.
Credit reports, fraud alerts, freezes, disputes, replacement documents, and reports serve different purposes. Follow the current official process for the person’s situation rather than buying identity “cleanup.” Keep copies of letters, reports, case numbers, identity documents submitted, and outcomes in a protected response file.
Child identity information
IdentityTheft.gov provides a child-specific route for checking whether a credit file exists, addressing fraudulent accounts, and requesting freezes through each nationwide credit bureau. An authorized parent, guardian, or conservator may need to provide proof of identity and authority. Requirements differ, so use each current official bureau route linked from IdentityTheft.gov.
Do not post the child’s Social Security number, birth certificate, report, or credit information in a family chat or send it to someone who contacted the family. A freeze can reduce some new-credit misuse but does not protect every school, medical, tax, benefit, account, or existing-credit context.
If a child is being threatened, exploited, or blackmailed
Treat the child as a person needing protection, not as the cause of the problem. Say:
I am glad you told me. This is not your fault. Do not send more, pay, or meet anyone. We will get help together.
Stop further contact when safe, but do not delete or redistribute material before receiving guidance. Do not pay, send another image, negotiate, threaten the person, impersonate the child, arrange a meeting, or ask the child to keep the sender engaged. The FBI warns that people committing financial sextortion may distribute images even after payment.
For immediate danger or a planned in-person meeting, call 911. Suspected online child sexual exploitation can be reported to the National Center for Missing & Exploited Children’s CyberTipline. The FBI also provides current reporting through its field offices and tips.fbi.gov.
NCMEC’s Take It Down is a free service for nude, partially nude, or sexually explicit images or videos taken when the depicted person was under 18. It creates a hash on the user’s device for participating platforms; the image does not need to be uploaded to NCMEC. It is one removal-limitation tool, not a guarantee that every copy, encrypted service, private channel, or platform can be found or removed.
Do not create, download, resend, or ask someone to send an image in order to use a tool or make a family record. Follow NCMEC, law-enforcement, platform, attorney, and qualified safeguarding guidance about what to preserve and who should handle it.
Ask directly and calmly about the child’s immediate physical and emotional safety. If there is imminent self-harm danger, call 911. In the United States, call or text 988 for crisis support when appropriate, but use 911 when an immediate emergency response is needed. Keep the child with a safe adult and obtain qualified medical or mental-health support as needed.
Preserve minimum necessary evidence without continuing contact
Possible useful records include:
- original messages and email headers
- usernames, profile identifiers, phone numbers, and URLs already visible
- dates, time zones, amounts, transaction identifiers, receipts, checks, gift cards, and shipping records
- account alerts, recovery messages, login records, and provider case numbers
- a factual timeline of what was clicked, shared, approved, installed, paid, or changed
Do not open new links or attachments, revisit harmful content, create screenshots of intimate imagery, forward dangerous material, or prolong contact to make the file “complete.” Preserve only what the provider or authority needs, restrict access, and note who holds each copy. When a child or intimate material is involved, seek safeguarding and law-enforcement guidance promptly.
IC3 advises retaining original evidence because complaint attachments are not collected through its complaint form. Reporting accuracy matters. Keep facts, uncertainties, and interpretations separate.
Use each report for its actual role
- ReportFraud.ftc.gov accepts scam and fraud reports. FTC uses reports to identify patterns, educate the public, and support cases.
- IdentityTheft.gov creates identity-theft reports and situation-specific recovery steps.
- IC3.gov accepts internet-enabled crime complaints.
- NCMEC CyberTipline receives reports of suspected online child sexual exploitation.
- Providers, banks, platforms, carriers, schools, employers, insurers, local law enforcement, state agencies, attorneys, and child-protection authorities may have separate roles.
Submitting one report does not notify every provider, stop a payment, restore an account, freeze credit, remove an image, begin an insurance claim, or guarantee investigation. Ask each organization what it will do, what the family must do next, and how completion will be confirmed.
Expect recovery scams and repeated contact
After a loss or report, someone may claim to know the amount, payment method, or earlier story and offer guaranteed recovery. FTC warns that refund and recovery scammers may use information about prior victims, demand fees, or request financial or identity details.
Use the same rule: stop, leave, and verify through the official provider or authority already handling the case. Government agencies and legitimate investigators do not become authentic because they know details. Do not pay taxes, processing fees, retainers, cryptocurrency, gift cards, or “insurance” to an unexpected recovery contact.
Create a closed-loop response record
For each consequence, record:
- provider or authority contacted through an independently verified route
- date, case number, and factual description supplied
- immediate containment step and who completed it
- remaining account, payment, device, identity, platform, or safety action
- adult owner and backup
- next deadline or monitoring date
- evidence that the action was completed
Continue monitoring only as directed by the relevant provider and the actual risk. Check for new transactions, recovery changes, forwarding, devices, messages, accounts, credit activity, or child-safety concerns where relevant. Avoid endless surveillance that harms a child’s privacy without a defined risk, purpose, review date, and path back to ordinary support.
Protect the person as well as the account
Financial and online exploitation can produce fear, shame, anger, sleep disturbance, withdrawal, repeated checking, secrecy, conflict, or hopelessness. Ask what the person needs, restore normal routines where possible, and avoid public retelling or blame. The first family review should focus on containment and support; later, revise permissions and safeguards transparently.
A loss is not proof of stupidity, dishonesty, or permanent incapacity. A child’s rule-breaking does not remove their right to protection. If distress persists, disrupts daily function, or raises a mental-health concern, involve an appropriate clinician or counselor. Immediate safety danger uses the live emergency route.
What this decision aid cannot promise
Fast action may preserve options, but it cannot guarantee a refund, recall, charge reversal, account restoration, credit correction, device cleanup, investigation, prosecution, content removal, emotional recovery, or prevention of future contact. Provider rules, transaction facts, law, technology, and jurisdiction differ. Record uncertainty honestly and keep following the controlling official source.
Sources
- Federal Trade Commission: What To Do if You Were Scammed
- Federal Trade Commission: How To Recognize and Avoid Phishing Scams
- Federal Trade Commission: How To Spot, Avoid, and Report Fake Check Scams
- Federal Trade Commission: Refund and Recovery Scams
- CISA: Secure Our World
- IdentityTheft.gov: When Information Is Lost or Exposed
- IdentityTheft.gov: Recovery Steps
- FBI Internet Crime Complaint Center
- FBI Internet Crime Complaint Center FAQ
- FBI: Financially Motivated Sextortion
- NCMEC: CyberTipline
- NCMEC: Take It Down
- NCMEC: Take It Down FAQ
- 988 Suicide & Crisis Lifeline
Sources were rechecked on August 9, 2026. This decision aid provides general US educational routing, not technical forensics, legal or financial advice, an authenticity determination, or a guarantee of reversal, restoration, investigation, removal, or recovery.