SECURITY EMERGENCY CENTER

When something has already gone wrong.

STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE.

First rule: do not panic.

A security incident can create fear and urgency. That is exactly when people are most likely to make another mistake. An attacker may pressure you to act immediately, while a legitimate recovery process may require you to slow down and establish what actually happened.

Your first objective is not to solve everything immediately. Your first objective is to stop the situation from getting worse.

Stop additional payments or transfers. Stop communicating with suspicious people. Do not provide more information simply because someone claims they are helping you. Preserve useful evidence before deleting messages, resetting devices or changing things you may later need to investigate.

Then use an independently verified official channel to secure the affected account, payment method, device or service.

What does STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE mean?

STOP means interrupt the activity that may be causing further loss. Do not continue a suspicious conversation, payment, login or transaction simply because someone says it is urgent.

PRESERVE means keep useful evidence such as messages, email headers, transaction references, receipts, account notifications, usernames, phone numbers, URLs and screenshots where appropriate.

SECURE means use the legitimate security controls of the affected service to reduce further access or damage.

REPORT means notify the relevant bank, payment provider, platform, service provider or other appropriate authority through an independently verified channel.

VERIFY means independently establish what actually happened and verify anyone offering assistance.

RECOVER means restore account access, replace compromised credentials, recover devices or take other appropriate recovery steps.

ESCALATE means seek professional, institutional or appropriate law-enforcement assistance when the situation involves significant financial loss, identity theft, serious compromise or circumstances that cannot safely be handled alone.

CHOOSE YOUR SITUATION

What happened?

Choose the situation that comes closest to what you are experiencing. Start with the section that best matches the immediate problem; you can read the deeper explanations afterward.

I think I've been scammed

If money, personal information or account access may have been taken through deception, stop the interaction and begin preserving evidence before taking further action.
Open →

My account may be compromised

If someone may have gained access to an account, treat the account as potentially compromised and secure it through its official recovery and security controls.
Open →

My email is compromised

Email accounts are often connected to password resets, financial services and other important accounts. Securing the email account should therefore be a priority.
Open →

My WhatsApp is compromised

If someone may have gained access to your WhatsApp account or linked device, secure the account through official recovery and warn contacts about possible impersonation.
Open →

My phone is lost or stolen

A lost phone can expose communication, authentication, financial and identity information. Begin with device protection and then secure important accounts.
Open →

OTP or password exposed

If a password, OTP, PIN or other authentication information has been exposed, assume it may be compromised and act through the affected service's official security process.
Open →

I clicked a suspicious link

Clicking a link does not automatically mean your device or account has been compromised. What matters next is what the link did and what information or action followed.
Open →

Crypto wallet concern

Crypto transactions can be irreversible. Never give anyone your recovery phrase or private key, and independently verify addresses, networks and transaction records.
Open →
EMERGENCY GUIDE

I think I've been scammed

A scam is not only a situation where money has already been lost. You may also have been deceived into revealing information, approving an action, installing software, sharing an account recovery code or communicating with someone who is impersonating another person or organisation.

The first mistake to avoid is assuming that because the first transaction or interaction has ended, the danger has ended too. Scammers may continue contacting victims and may use information obtained during the first interaction to make the next deception more convincing.

What to do first

Stop communicating with the suspicious person or organisation. Do not send additional money to "unlock", "reverse", "verify" or "recover" an earlier payment unless the request has been independently verified through a legitimate channel.

Preserve the evidence. Keep screenshots, transaction references, payment receipts, phone numbers, usernames, email addresses, website addresses and relevant messages.

If money was involved, contact the bank, payment provider or financial institution using contact information obtained independently from its official website, application, card or statement.

Why scammers may contact you again

Once someone knows that you have already suffered a loss, you may become a target for a second scam. Someone may claim to be a recovery specialist, investigator, lawyer, bank employee, government official or cybersecurity expert.

The person may know real details about the original incident. That does not prove that they are legitimate. Information can be copied, shared or obtained from the original scam.

Treat unexpected recovery offers with the same caution as the original incident. Verify the organisation independently before communicating further.

What you should never do after being scammed

Never give a supposed recovery agent your password, OTP, PIN, recovery phrase, private key or other authentication secret.

Never install remote-access software simply because someone claims it is necessary to recover your money.

Never assume that paying another fee guarantees recovery.

ACCOUNT SECURITY

My account may be compromised

An account is potentially compromised when another person may have gained access to it or may be able to act as you. This can happen through stolen passwords, phishing, malware, exposed sessions, compromised recovery methods or social engineering.

Do not focus only on whether the attacker changed your password. An attacker may already have created a session, changed recovery information, added another authentication method or changed settings that allow continued access.

What to check

Use a trusted device and access the service through its official application or a website address you obtained independently. Review active sessions, logged-in devices, recovery email addresses, phone numbers, authentication methods and recent security activity.

Change the password if appropriate and unique it to that service. If the same password was used elsewhere, those other accounts should also be reviewed.

Why changing only the password may not be enough

Account security is not always controlled by one password. Sessions, recovery methods, trusted devices, authentication applications and other account settings can influence who is able to access an account.

That is why a proper response should include reviewing the account's security settings rather than assuming that changing one password automatically removes every possible form of access.

HIGH-PRIORITY ACCOUNT

My email is compromised

Email deserves special attention because it is often connected to other accounts. Password-reset messages, security alerts, verification links and sensitive communications may all pass through the email account.

If an attacker controls your email, they may attempt to reset passwords for other services or impersonate you when contacting people who trust your email address.

Secure the email account first

Access the account through the provider's official application or independently verified website. Review recent sign-ins, connected devices, recovery methods, forwarding rules, filters and unfamiliar applications or integrations.

Change the password and strengthen authentication according to the provider's official security guidance. Then review important accounts that depend on that email address.

Why forwarding rules matter

Email accounts can sometimes contain rules that automatically forward, hide or move messages. An attacker who creates such a rule may try to make security notifications less visible to the account owner.

That is why checking only the inbox is not enough when an email account may have been compromised.

MESSAGING SECURITY

My WhatsApp is compromised

A WhatsApp account can become a target for impersonation and account takeover. An attacker who gains access may attempt to contact your friends, family, customers or colleagues while pretending to be you.

This makes the incident both a security problem and a trust problem. People who know you may believe the attacker because the message appears to come from your account.

What to do

Use WhatsApp's official recovery and account-security procedures. Review linked devices and remove devices you do not recognise. Warn important contacts through another communication channel if you believe someone may be impersonating you.

Never give anyone a WhatsApp verification code simply because they claim to be helping you recover the account.

Why you should warn your contacts

Your contacts may receive convincing requests for money, passwords, codes or other sensitive information from someone pretending to be you.

A short warning through an independent communication channel can prevent the compromise from becoming a second incident affecting people around you.

DEVICE SECURITY

My phone is lost or stolen

A lost phone is not simply a hardware problem. It may contain messages, photographs, email sessions, financial applications, authentication methods, documents, contacts and other sensitive information.

The response should therefore focus on both the physical device and the digital accounts connected to it.

Start with device protection

Use the device manufacturer's official location, lock or erase tools where available. Contact your mobile network provider if appropriate and protect your SIM and mobile number.

Then review important accounts that were accessible from the device. Pay particular attention to email, banking, payment, messaging and authentication applications.

Why the IMEI may matter

The IMEI is an identifier associated with a mobile device. Keep your IMEI and other relevant device information in a safe place before a device is lost or stolen.

If a device is stolen, the information may be useful when dealing with your network provider or making an appropriate report. Availability and usefulness of tracking or blocking procedures depend on the device, network and relevant authorities.

CREDENTIAL EXPOSURE

OTP or password exposed

Treat an exposed authentication secret seriously. A password may remain useful to an attacker after the original conversation has ended, while an OTP may provide a temporary authorization that can be abused within the relevant service's security process.

If your password was exposed

Access the affected service through its official channel and change the password. If the same password was reused elsewhere, those accounts should also be reviewed and secured.

If an OTP was exposed

Do not assume that an OTP is harmless simply because it expires. An OTP can sometimes authorize a login, password reset, transaction or other security action depending on the service.

Contact the affected service through its official security or support channel and explain what happened.

Secrets you should never provide

Never provide passwords, PINs, one-time passwords, recovery phrases or private keys to someone who contacts you claiming to be support, security staff, a recovery specialist or an investigator.

Legitimate support processes should be verified independently and should not require you to hand over the secret that protects your account.

LINK INCIDENT

I clicked a suspicious link

Clicking a suspicious link does not automatically mean that your account or device has been compromised. The important question is what happened after the link was opened.

You may have simply viewed a webpage. You may instead have entered a username and password, downloaded a file, installed software, granted permissions, approved a transaction or disclosed other information.

Ask what happened next

Did you enter a password? Did you enter an OTP? Did you download anything? Did you install an application? Did the website ask you to approve a transaction? Did you provide personal or financial information?

The answers determine the appropriate response. Do not randomly reset every account or erase evidence before understanding the situation.

Why clicking and entering information are different

Opening a webpage and giving information to that webpage are two different events. A suspicious page may attempt to persuade you to provide credentials, download something or perform another action.

This distinction is important because the correct recovery response depends on what actually happened rather than simply on the fact that a link was opened.

CRYPTO SECURITY

Crypto wallet concern

Cryptocurrency incidents require particular care because many blockchain transactions cannot simply be reversed through a traditional bank dispute process.

A wallet may also contain multiple assets, networks, tokens and transaction histories. A problem that looks like "my funds are gone" may sometimes involve the wrong network, an unsupported token display, an incorrect address or a transaction that needs to be examined on-chain.

The most important rule

Never give anyone your recovery phrase or private key.

A person who asks for your recovery phrase in order to "recover", "synchronize", "validate", "upgrade" or "unlock" your wallet is asking for the information that can provide control of the wallet.

Verify before taking another transaction

Check the wallet address, network, transaction hash and destination independently. Do not send another transaction merely because someone says that the first transaction can be recovered by paying another fee.

Why a wallet may appear to be missing funds

Not every apparent balance problem means that the assets have disappeared. The wallet application may be displaying the wrong network, may not automatically display a token, or may require the correct token contract information before an asset becomes visible.

On-chain information should therefore be checked independently before concluding that funds have been permanently lost.

AFTER THE FIRST RESPONSE

Do not let the second incident become worse than the first.

People who have just experienced a security incident are often vulnerable to a second deception. You may be contacted by someone claiming to have detected the attack, recover your funds, trace the attacker or unlock your account.

Some legitimate organisations may provide recovery or investigative assistance, but you should never trust an unsolicited person merely because they know details about your incident.

Obtain the organisation's official contact information independently and verify that you are communicating with the real organisation.

What should I never share with someone helping me?

Never share your password, PIN, OTP, recovery phrase, private key or other authentication secret merely because someone claims that it is necessary for recovery.

You can describe what happened without giving away the secret that protects your account or wallet.

When should I seek additional help?

Consider escalating the situation when there is significant financial loss, suspected identity theft, continuing unauthorized access, threats, serious account compromise or a situation that you cannot safely resolve through the service's official recovery process.

Preserve evidence and use independently verified contact channels when seeking assistance.

Need further help?

If your situation is not covered here, or you need help understanding what to do next, use the consultancy channel for further guidance.

You can explain the situation without providing passwords, OTPs, PINs, recovery phrases, private keys or other authentication secrets.

Use the consultancy form →

VERIFY BEFORE YOU TRUST.