When something has already gone wrong.
STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE.
A security incident can create fear and urgency. That is exactly when people are most likely to make another mistake. An attacker may pressure you to act immediately, while a legitimate recovery process may require you to slow down and establish what actually happened.
Your first objective is not to solve everything immediately. Your first objective is to stop the situation from getting worse.
Stop additional payments or transfers. Stop communicating with suspicious people. Do not provide more information simply because someone claims they are helping you. Preserve useful evidence before deleting messages, resetting devices or changing things you may later need to investigate.
Then use an independently verified official channel to secure the affected account, payment method, device or service.
What does STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE mean?
STOP means interrupt the activity that may be causing further loss. Do not continue a suspicious conversation, payment, login or transaction simply because someone says it is urgent.
PRESERVE means keep useful evidence such as messages, email headers, transaction references, receipts, account notifications, usernames, phone numbers, URLs and screenshots where appropriate.
SECURE means use the legitimate security controls of the affected service to reduce further access or damage.
REPORT means notify the relevant bank, payment provider, platform, service provider or other appropriate authority through an independently verified channel.
VERIFY means independently establish what actually happened and verify anyone offering assistance.
RECOVER means restore account access, replace compromised credentials, recover devices or take other appropriate recovery steps.
ESCALATE means seek professional, institutional or appropriate law-enforcement assistance when the situation involves significant financial loss, identity theft, serious compromise or circumstances that cannot safely be handled alone.
What happened?
Choose the situation that comes closest to what you are experiencing. Start with the section that best matches the immediate problem; you can read the deeper explanations afterward.
My account may be compromised
My email is compromised
My WhatsApp is compromised
My phone is lost or stolen
OTP or password exposed
I clicked a suspicious link
Crypto wallet concern
I think I've been scammed
A scam is not only a situation where money has already been lost. You may also have been deceived into revealing information, approving an action, installing software, sharing an account recovery code or communicating with someone who is impersonating another person or organisation.
The first mistake to avoid is assuming that because the first transaction or interaction has ended, the danger has ended too. Scammers may continue contacting victims and may use information obtained during the first interaction to make the next deception more convincing.
What to do first
Stop communicating with the suspicious person or organisation. Do not send additional money to "unlock", "reverse", "verify" or "recover" an earlier payment unless the request has been independently verified through a legitimate channel.
Preserve the evidence. Keep screenshots, transaction references, payment receipts, phone numbers, usernames, email addresses, website addresses and relevant messages.
If money was involved, contact the bank, payment provider or financial institution using contact information obtained independently from its official website, application, card or statement.
Why scammers may contact you again
Once someone knows that you have already suffered a loss, you may become a target for a second scam. Someone may claim to be a recovery specialist, investigator, lawyer, bank employee, government official or cybersecurity expert.
The person may know real details about the original incident. That does not prove that they are legitimate. Information can be copied, shared or obtained from the original scam.
Treat unexpected recovery offers with the same caution as the original incident. Verify the organisation independently before communicating further.
What you should never do after being scammed
Never give a supposed recovery agent your password, OTP, PIN, recovery phrase, private key or other authentication secret.
Never install remote-access software simply because someone claims it is necessary to recover your money.
Never assume that paying another fee guarantees recovery.
My account may be compromised
An account is potentially compromised when another person may have gained access to it or may be able to act as you. This can happen through stolen passwords, phishing, malware, exposed sessions, compromised recovery methods or social engineering.
Do not focus only on whether the attacker changed your password. An attacker may already have created a session, changed recovery information, added another authentication method or changed settings that allow continued access.
What to check
Use a trusted device and access the service through its official application or a website address you obtained independently. Review active sessions, logged-in devices, recovery email addresses, phone numbers, authentication methods and recent security activity.
Change the password if appropriate and unique it to that service. If the same password was used elsewhere, those other accounts should also be reviewed.
Why changing only the password may not be enough
Account security is not always controlled by one password. Sessions, recovery methods, trusted devices, authentication applications and other account settings can influence who is able to access an account.
That is why a proper response should include reviewing the account's security settings rather than assuming that changing one password automatically removes every possible form of access.
My email is compromised
Email deserves special attention because it is often connected to other accounts. Password-reset messages, security alerts, verification links and sensitive communications may all pass through the email account.
If an attacker controls your email, they may attempt to reset passwords for other services or impersonate you when contacting people who trust your email address.
Secure the email account first
Access the account through the provider's official application or independently verified website. Review recent sign-ins, connected devices, recovery methods, forwarding rules, filters and unfamiliar applications or integrations.
Change the password and strengthen authentication according to the provider's official security guidance. Then review important accounts that depend on that email address.
Why forwarding rules matter
Email accounts can sometimes contain rules that automatically forward, hide or move messages. An attacker who creates such a rule may try to make security notifications less visible to the account owner.
That is why checking only the inbox is not enough when an email account may have been compromised.
My WhatsApp is compromised
A WhatsApp account can become a target for impersonation and account takeover. An attacker who gains access may attempt to contact your friends, family, customers or colleagues while pretending to be you.
This makes the incident both a security problem and a trust problem. People who know you may believe the attacker because the message appears to come from your account.
What to do
Use WhatsApp's official recovery and account-security procedures. Review linked devices and remove devices you do not recognise. Warn important contacts through another communication channel if you believe someone may be impersonating you.
Never give anyone a WhatsApp verification code simply because they claim to be helping you recover the account.
Why you should warn your contacts
Your contacts may receive convincing requests for money, passwords, codes or other sensitive information from someone pretending to be you.
A short warning through an independent communication channel can prevent the compromise from becoming a second incident affecting people around you.
My phone is lost or stolen
A lost phone is not simply a hardware problem. It may contain messages, photographs, email sessions, financial applications, authentication methods, documents, contacts and other sensitive information.
The response should therefore focus on both the physical device and the digital accounts connected to it.
Start with device protection
Use the device manufacturer's official location, lock or erase tools where available. Contact your mobile network provider if appropriate and protect your SIM and mobile number.
Then review important accounts that were accessible from the device. Pay particular attention to email, banking, payment, messaging and authentication applications.
Why the IMEI may matter
The IMEI is an identifier associated with a mobile device. Keep your IMEI and other relevant device information in a safe place before a device is lost or stolen.
If a device is stolen, the information may be useful when dealing with your network provider or making an appropriate report. Availability and usefulness of tracking or blocking procedures depend on the device, network and relevant authorities.
OTP or password exposed
Treat an exposed authentication secret seriously. A password may remain useful to an attacker after the original conversation has ended, while an OTP may provide a temporary authorization that can be abused within the relevant service's security process.
If your password was exposed
Access the affected service through its official channel and change the password. If the same password was reused elsewhere, those accounts should also be reviewed and secured.
If an OTP was exposed
Do not assume that an OTP is harmless simply because it expires. An OTP can sometimes authorize a login, password reset, transaction or other security action depending on the service.
Contact the affected service through its official security or support channel and explain what happened.
Secrets you should never provide
Never provide passwords, PINs, one-time passwords, recovery phrases or private keys to someone who contacts you claiming to be support, security staff, a recovery specialist or an investigator.
Legitimate support processes should be verified independently and should not require you to hand over the secret that protects your account.
I clicked a suspicious link
Clicking a suspicious link does not automatically mean that your account or device has been compromised. The important question is what happened after the link was opened.
You may have simply viewed a webpage. You may instead have entered a username and password, downloaded a file, installed software, granted permissions, approved a transaction or disclosed other information.
Ask what happened next
Did you enter a password? Did you enter an OTP? Did you download anything? Did you install an application? Did the website ask you to approve a transaction? Did you provide personal or financial information?
The answers determine the appropriate response. Do not randomly reset every account or erase evidence before understanding the situation.
Why clicking and entering information are different
Opening a webpage and giving information to that webpage are two different events. A suspicious page may attempt to persuade you to provide credentials, download something or perform another action.
This distinction is important because the correct recovery response depends on what actually happened rather than simply on the fact that a link was opened.
Crypto wallet concern
Cryptocurrency incidents require particular care because many blockchain transactions cannot simply be reversed through a traditional bank dispute process.
A wallet may also contain multiple assets, networks, tokens and transaction histories. A problem that looks like "my funds are gone" may sometimes involve the wrong network, an unsupported token display, an incorrect address or a transaction that needs to be examined on-chain.
The most important rule
Never give anyone your recovery phrase or private key.
A person who asks for your recovery phrase in order to "recover", "synchronize", "validate", "upgrade" or "unlock" your wallet is asking for the information that can provide control of the wallet.
Verify before taking another transaction
Check the wallet address, network, transaction hash and destination independently. Do not send another transaction merely because someone says that the first transaction can be recovered by paying another fee.
Why a wallet may appear to be missing funds
Not every apparent balance problem means that the assets have disappeared. The wallet application may be displaying the wrong network, may not automatically display a token, or may require the correct token contract information before an asset becomes visible.
On-chain information should therefore be checked independently before concluding that funds have been permanently lost.
Do not let the second incident become worse than the first.
People who have just experienced a security incident are often vulnerable to a second deception. You may be contacted by someone claiming to have detected the attack, recover your funds, trace the attacker or unlock your account.
Some legitimate organisations may provide recovery or investigative assistance, but you should never trust an unsolicited person merely because they know details about your incident.
Obtain the organisation's official contact information independently and verify that you are communicating with the real organisation.
What should I never share with someone helping me?
Never share your password, PIN, OTP, recovery phrase, private key or other authentication secret merely because someone claims that it is necessary for recovery.
You can describe what happened without giving away the secret that protects your account or wallet.
When should I seek additional help?
Consider escalating the situation when there is significant financial loss, suspected identity theft, continuing unauthorized access, threats, serious account compromise or a situation that you cannot safely resolve through the service's official recovery process.
Preserve evidence and use independently verified contact channels when seeking assistance.
If your situation is not covered here, or you need help understanding what to do next, use the consultancy channel for further guidance.
You can explain the situation without providing passwords, OTPs, PINs, recovery phrases, private keys or other authentication secrets.
VERIFY BEFORE YOU TRUST.
