You think you have been defrauded. The next thirty minutes matter—but panic is not a plan.
The objective is not to solve the entire case immediately. It is to stop additional loss, protect access, preserve evidence and create a reliable record.
CLAIM
A short, ordered response can reduce avoidable damage and make the later account easier for a bank, reporting body or investigator to understand.
EVIDENCE
The National Cyber Security Centre advises anyone who has lost money following a suspicious message to tell their bank and report the matter as a crime. Its wider phishing guidance emphasises breaking contact, avoiding suspicious links and using recognised reporting routes.
The Payment Systems Regulator’s authorised push payment reimbursement framework also makes prompt reporting and a coherent account practically important. It does not guarantee reimbursement in every case, but it establishes protections for many in-scope UK payments.
TEST
Use the sequence below. Do not spend the first half-hour arguing with the suspected fraudster, investigating social-media profiles or producing a polished narrative. Secure the position first.
VERDICT
The best immediate response is disciplined rather than dramatic: stop, secure, preserve, report and record.
ACTION — THE FIRST 30 MINUTES
Minutes 0–5: stop the movement
- Do not send further money, codes, documents or credentials.
- Break contact. Do not announce that you are collecting evidence.
- If a payment has been made, contact the bank or payment provider through its official app or a trusted number.
- Ask whether the payment can be stopped, recalled or flagged.
Minutes 5–15: secure access
- Change affected passwords from a trusted device.
- Start with the email account controlling password resets.
- Enable multi-factor authentication where available.
- Check for changed recovery details, forwarding rules and unfamiliar sessions.
- Tell the bank immediately if card, account or security information was disclosed.
Minutes 15–25: preserve the evidence
- Keep original messages and emails. Do not rely only on cropped screenshots.
- Record telephone numbers, usernames, account details, URLs and transaction references.
- Save confirmation emails and bank notifications.
- Write down what was said while the memory is fresh, clearly labelling it as your recollection.
Minutes 25–30: report and open a chronology
- Use the appropriate official reporting route for your location and incident.
- Record the date, time, organisation, contact method, reference number and advice received.
- Begin a single chronology. Add later events; do not rewrite the earlier entry.
DO NOT
- Delete accounts or conversations before preserving what is needed.
- Use contact details supplied by the suspected fraudster to “verify” the story.
- Pay a recovery agent who makes an unsolicited approach or guarantees success.
- Send identity documents to anyone claiming they need them to release recovered funds.
Official sources
The Verification Desk distinguishes verified fact, evidence-led inference and unresolved uncertainty. This publication provides general information, not legal, financial, regulatory or emergency advice. Findings reflect the evidence available at publication and may be updated if material evidence changes.

Leave a Reply