You just got scammed. What now?

The hours lost to embarrassment are what turn a bad afternoon into a drained account. Here is the order to work in, and what is actually recoverable.

Share
A young woman with one hand over her forehead, looking down at her phone in a dark room

If you are reading this because it just happened, skip to the list. Come back for the rest later.

This page has a printable version: a two-page card with the four steps and every phone number on it. Print it and put it in a drawer before anything goes wrong. Download the card (PDF). It is part of The Cache, our free library of printable guides.

You did nothing shameful. You met a professional criminal who does this all day and who has practiced the exact script that worked on you. A bad afternoon becomes a drained account in the hours people spend feeling embarrassed before they pick up the phone. So the goal here is speed. Do these in order.

The order

  1. Stop the money.
  2. Lock your email, then everything your email can reset.
  3. Report it.
  4. Expect a second scam offering to get your money back.

Work top to bottom. If you only get through the first two, you've done the most important steps.

What you handed over decides which parts apply: money, information, or access to your computer. Most people gave up more than one, so read the two branches at the bottom as well.

1. Stop the money

Call, do not email. You want a human who can put a hold on something.

If you paid by credit card. Call the number on the back of the card and say the charge was unauthorized. Federal law caps what you can be held responsible for at $50, and that cap does not shrink because you waited a day. Visa and Mastercard both go further and advertise zero liability. You have 60 days from the statement showing the charge to dispute it in writing. Call today anyway.

One catch. This works cleanly when the charge was made without your permission. If a scammer talked you into paying them yourself, the dispute gets harder and the argument shifts to not receiving what you paid for. Make the call regardless and describe exactly what happened.

If you paid by debit card, or money left your checking account. This one has a clock, and it is the reason to call immediately. Your liability is capped at $50 if you report within two business days of finding out. After two business days it rises to $500. Past 60 days from the statement the cap is gone and the loss can be all of it. Once you report, the bank has 10 business days to investigate, or up to 45 days if it puts the money back provisionally while they work.

If you sent a bank wire. Two calls, same hour, and the second one is not paperwork. Call your bank's fraud line and ask them to recall the wire. Then file at ic3.gov, the FBI's Internet Crime Complaint Center. That report is what puts the FBI's Recovery Asset Team on the phone with the receiving bank asking it to freeze the account. In 2025 that team froze $679 million out of $1.16 billion in reported attempted theft. That's about a 58 percent success rate. The rate has been sliding (it was 74 percent in 2023) and it depends almost entirely on how fast the report is filed. The FBI's process is built around a 72-hour window.

If you sent money through Zelle. The words you use matter. If someone got into your account and moved money without you, that is an unauthorized transfer, and federal law says the bank owes it back. If you were tricked into sending it yourself, that protection does not apply. Since June 2023 Zelle's own rules require participating banks to reimburse "qualifying" imposter scams. For example, someone posing as your bank, a government agency, or a utility. Zelle has never published what qualifies, and banks apply it unevenly. Ask your bank in writing for its imposter-scam reimbursement policy and its appeal process, then keep the reply.

Bridging that gap is being fought for as we speak. The Consumer Financial Protection Bureau sued Zelle's owner and three large banks over it in December 2024, then dropped the case in March 2025. New York's attorney general filed her own suit in August 2025, and a judge has let it move forward.

If you bought gift cards. Call the card's company, not the store. Keep the physical card and the receipt, because they will ask for numbers off both. Some issuers can freeze whatever has not been drained yet, and drained-in-minutes is the norm. So this is a first-hour call.

  • Amazon 1-888-280-4331
  • Apple 1-800-275-2273 (say "gift card")
  • Google Play: report it online at support.google.com/googleplay/answer/9057338
  • Best Buy 1-888-237-8289

If you used Western Union, MoneyGram, or Ria. Call and ask them to reverse the transfer.

  • MoneyGram 1-800-926-9400
  • Western Union 1-800-448-1492
  • Ria 1-877-443-1399

If the cash has been picked up on the other end it is gone, but the call takes two minutes.

If you paid through Venmo, Cash App, or PayPal. Report it in the app. Then, if the app pulls from a card, call that card issuer and dispute it there too. The card is where the legal protection lives.

If you sent cryptocurrency. Assume it is gone. There is no chargeback, no reversal, and no company to call. File at ic3.gov anyway, because investigators do sometimes trace funds to an exchange that will freeze them, and because the report feeds cases. File it, then read step four twice. Crypto victims get worked for the second scam harder than anyone.

If you mailed cash. Call the U.S. Postal Inspection Service at 877-876-2455 and ask about a package intercept. It only works before delivery, so call as soon as possible.

2. Lock your email first

Email is a master key. Every password reset for your bank, your card, your retirement account and your Amazon account arrives in that inbox. So somebody sitting in your email can undo everything else you do.

Change that password from a different device than the one that was involved. If a scammer had any access to your computer, a keylogger on it can capture the new password while you type it. Use your phone on cellular, or a family member's laptop.

Then, in your email account's security settings:

1. Sign out everywhere. Look for 'Sign out of all sessions' or 'Sign out of all devices'. A new password does not kick out someone who is already logged in.

2. Check your forwarding rules and your filters. People skip this step, and it is the one that keeps bad actors in the account after the password change.

In Gmail:

  • Settings
  • 'See all settings'
  • the 'Forwarding and POP/IMAP' tab
  • the 'Filters and Blocked Addresses' tab

In Outlook:

  • Settings
  • 'Mail'
  • 'Forwarding', and check your rules while you are in there

A forwarding rule survives a password change. So does a filter that deletes your bank's security alerts before you ever see them. CISA has documented this as a standard move, and Barracuda's 2026 email report found inbox-rule changes in 25 percent of account takeovers.

3. Check your recovery email address and recovery phone number. If either one has been changed to something you do not recognize, fix it. That is how someone locks you out tomorrow.

4. Turn on MFA, or multi-factor authentication, sometimes called two-factor or 2FA. If it was already on, remove any device or authenticator app you do not recognize and set it up fresh.

Then work outward in this order: bank and financial accounts. Then anywhere you have a card saved (Amazon and the rest). Then social media, which is what gets used to scam your friends and family next.

If you were reusing that email password anywhere else, every one of those accounts is now on the list too. That is the argument for a password manager, and it is the rebuild step once this is all over.

3. Report it, and know what each report actually does

Each one does a specific job.

  • ic3.gov (FBI). For a wire this is a money-stopping action, not a filing. See step one. Put in every detail you have: dates, amounts, account and routing numbers, the receiving bank, wallet addresses.
  • reportfraud.ftc.gov (FTC). Feeds a database that state and federal investigators actually query. The FTC says plainly that it cannot resolve individual reports, so do not sit waiting on a reply.
  • identitytheft.gov (FTC). If personal information was involved, this one builds you a written recovery plan, generates an official FTC Identity Theft Report, and pre-fills dispute letters.
  • Your local police department. Your bank or your insurer may require a police report number before reimbursing anything. That is the reason to file, even knowing the department is not going to chase an overseas call center.
  • Your state attorney general. This is the office that sues companies over patterns, which is how the Zelle cases above happened.

4. Expect the second scam

The people who got you know one thing about you now: you are a known victim who has money to lose and a reason to want it back. That fact gets sold, and a second crew works the list.

On July 20, 2026 the FBI put out a warning about exactly this. Scammers build fake FBI profiles on social media, reach victims through Facebook Messenger and Telegram, and offer to recover the stolen money. Some of them run AI-generated video of a senior FBI official to promote a spoofed IC3 website that harvests your name, your phone number, and how much you lost. Four rules to hold onto:

  • IC3 will never contact you by phone, email, social media, chat, or a messaging app. If more information is needed, a real FBI employee from a local field office reaches out.
  • IC3 has no social media presence at all. Any account claiming to be IC3 is fake.
  • IC3 will never ask for payment to recover your money, and will never refer you to a company that charges for it.
  • Type ic3.gov into the address bar yourself. Skip the sponsored search results in Google; imitators buy those.

The rule that covers all of it: anyone who contacts you offering to get your money back is the same scam, second act. Real recovery never cold-calls.

If they got into your computer

If you let someone remote in (AnyDesk, TeamViewer, Quick Assist, "let me just show you the problem"), ran a file, or pasted a command they gave you, treat it as a full compromise even if it was only ten minutes. Ten minutes is enough to copy every password saved in your browser, take the session cookies that keep you logged in to your accounts, and leave something malicious behind that survives a reboot.

Illustration of a masked figure pulling puppet strings attached to a person's hand on a computer mouse, with a password login screen on the laptop
Remote access means someone else is driving. Anything your saved passwords could reach, they could reach too. Illustration: Eva Wahyuni / Unsplash
  1. Disconnect from the internet. Turn the Wi-Fi off or pull the network cable. That ends their session immediately.
  2. From a different device, change your email password. Step two above.
  3. Uninstall the remote-access program. Windows: Settings, then 'Apps', then 'Installed apps'. Remove AnyDesk or whatever they had you install, plus anything else dated today that you did not put there. Do not just delete the folder.
  4. Run a full scan. 'Windows Security', then 'Virus & threat protection', then 'Scan options', then 'Full scan'.

Be straight with yourself about what a scan does. It finds known malware. It does not undo files they already copied, and it cannot promise you a clean machine. If they ran programs you cannot account for, or if this is the computer where you do your banking, the cleanest answer is a full Windows reinstall. A reinstall is easy if you have a backup and miserable if you do not.

If the way in was a fake CAPTCHA or a "press Windows+R and paste this" prompt, that is a specific scam we have covered, and the recovery steps there apply on top of these.

If you gave up your Social Security number

Freeze your credit at all three bureaus. It is free by law, it takes a few minutes online at each one, it does not touch your credit score, and it does not stop your existing cards from working. It is the highest-value move on this page. It also has to be done three separate times, because a freeze at one bureau does not carry to the other two.

  • Equifax 1-888-298-0045
  • Experian 1-888-397-3742
  • TransUnion 1-888-909-8872

One thing to watch. A "lock" is not the same as the free freeze. Equifax will offer you Lock & Alert; the freeze is the one the law makes free, and the freeze is the one you want.

Then get an IRS Identity Protection PIN, or IP PIN. It is a six-digit number that stops anyone else from e-filing a tax return under your Social Security number. Any taxpayer can request one through an IRS online account, and it renews every year. Note that the tool goes offline from roughly November to mid-January, so if you are reading this in December, put it on the January list.

Then let identitytheft.gov build the rest of your plan.

If what leaked was your bank account number rather than your Social Security number, that is a different job. Ask the bank to issue a new account number and watch the statements. A new account number does nothing for an exposed Social Security number, which is why the freeze is the answer there.

Skip the paid monitoring pitch. Monitoring tells you after something happened; a freeze stops it from happening. You can pull all three reports yourself for free at annualcreditreport.com.

One number, for scale

In 2024 people in the United States reported losing $12.5 billion to fraud, up 25 percent in a single year. Adults 60 and over reported $2.4 billion of that, up from about $600 million in 2020. The FTC's own estimate is that the real figure for older adults could run as high as $81.5 billion, because most of it never gets reported at all. Which is the whole reason the top of this page reads the way it does.

You may be thinking this is unlikely to happen to you. But it does happen, every single day. It doesn't just happen to inexperienced users. These scams are so widespread, they count on people being busy, tired, confused, or just careless. I've seen even the most principled security professionals still get caught up in a phishing email. I've done it myself. A lot of the time it's a matter of when, not if. If you respond correctly, often you'll be just fine.

Bookmark this page now, while nothing is wrong. Then send it to whoever in your family would call you first, because the hour they spend being embarrassed is the hour that costs them.

If you are in the middle of it right now and you want a person instead of a page, AARP runs a free fraud helpline at 877-908-3360, weekdays 8am to 8pm Eastern. If the victim is 60 or over, the Justice Department's Elder Fraud Hotline is 833-372-8311.

Sources

[ Free every Tuesday, plus the Cache ]
Tech news without having to be tech savvy.
Subscribe ×