WHAT TO DO WHEN SOMETHING GOES WRONG
Something has happened.
You clicked a suspicious link.
You sent money to the wrong account.
You gave someone an OTP.
Your account suddenly looks different.
Your phone has been lost.
Your WhatsApp account may have been taken over.
Your email may be compromised.
Your cryptocurrency may have moved.
You entered your password on a website you now suspect was fake.
A transaction failed but your account was debited.
Someone contacted you claiming to be support.
Whatever happened, the first thing you should know is:
DO NOT PANIC.
Panic creates urgency.
Urgency creates mistakes.
Mistakes can make an incident worse.
The correct response is to slow the situation down, preserve what happened, secure what you still control, report through legitimate channels, verify information independently, and then recover.
The core incident-response sequence is:
STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE
Not every incident will require every step.
But this sequence gives you a safe starting point when you are unsure what to do.
1. FIRST: STOP
The first response to a suspected security incident is to stop the activity that may be causing further harm.
If you are on a suspicious website:
Stop entering information.
If someone is pressuring you to send money:
Do not send more money.
If someone is asking for an OTP:
Do not provide it.
If you are about to approve a suspicious transaction:
Stop before authorising it.
If someone is telling you to install software:
Do not install it until you have independently verified the request.
The purpose of STOP is containment.
You are creating a pause between the incident and your next decision.
2. DO NOT TRY TO FIX EVERYTHING IMMEDIATELY
When people realise something has gone wrong, they often begin taking random actions.
They may:
- Change several passwords at once.
- Delete messages.
- Delete suspicious applications.
- Factory-reset a device.
- Send more money.
- Contact random people online.
- Search for “recovery agents.”
- Post details publicly.
- Give strangers remote access.
- Attempt unfamiliar technical fixes.
Some of these actions may destroy useful evidence or create additional risk.
Before doing something irreversible, ask:
“Will this make the situation safer, or could it make the situation harder to understand?”
3. PRESERVE EVIDENCE
Evidence can help you understand what happened and can become important when reporting the incident.
Where appropriate, preserve:
- Screenshots
- Messages
- Emails
- Phone numbers
- Usernames
- URLs
- Transaction references
- Payment receipts
- Wallet addresses
- Transaction hashes
- Account notifications
- Dates and times
- Names used by the person contacting you
- Relevant account activity
Do not immediately delete everything simply because it looks suspicious.
The evidence may help establish:
What happened?
When did it happen?
Who contacted you?
What information was requested?
What action was taken?
Where did the money go?
What account or device was involved?
4. PRESERVE THE ORIGINAL CONTEXT
A screenshot can be useful, but preserve the original conversation or message where possible.
For example, if you receive a suspicious WhatsApp message:
Do not rely only on a cropped screenshot.
Keep the original conversation if it is safe to do so.
The surrounding messages may provide information about:
- The sender
- The timing
- The request
- The link
- The account used
- What happened before the suspicious message
Evidence is more useful when its context is preserved.
5. DO NOT FORWARD SENSITIVE INFORMATION CARELESSLY
Preserving evidence does not mean publicly sharing everything.
Be careful with:
- Passwords
- OTPs
- PINs
- Recovery codes
- Recovery phrases
- Private keys
- Full card information
- Personal identity documents
If you need to provide evidence to a legitimate organisation, follow its official process.
Do not upload sensitive credentials to public websites simply because someone says they are investigating the incident.
6. IDENTIFY WHAT WAS ACTUALLY EXPOSED
Not every incident exposes the same thing.
Ask:
What did I provide?
What did I click?
What did I approve?
What did I download?
What did I send?
What account was involved?
What device was involved?
What money was involved?
What information may now be accessible?
Clicking a suspicious link is not automatically the same as entering a password.
Entering a password is not automatically the same as giving away an OTP.
Giving away an OTP is not automatically the same as exposing a cryptocurrency recovery phrase.
The response should match the actual exposure.
7. IF YOU GAVE AWAY A PASSWORD
Treat the password as compromised.
Change it through the legitimate service.
If you reused the same password elsewhere, change it on those services too.
Password reuse can turn one incident into multiple account compromises.
After changing the password, review:
- Active sessions
- Logged-in devices
- Recovery email
- Recovery phone
- MFA methods
- Connected applications
- Recent security activity
Changing the password is only the beginning.
8. IF YOU GAVE AWAY AN OTP
An OTP may have been generated for:
- Login
- Password reset
- Payment
- Device registration
- Account changes
- Transaction approval
Determine what the code was intended for.
Then secure the affected account or transaction through the official service.
Do not assume:
“It was only a six-digit code.”
The code may have been the final step required to complete an important action.
9. IF YOU GAVE AWAY YOUR PIN
Treat the PIN as compromised.
Contact the relevant financial institution or service through its official channel.
Follow its security instructions.
Do not continue using the compromised credential simply because no suspicious transaction has appeared yet.
A credential can be compromised before it is used.
10. IF YOU GAVE AWAY A RECOVERY CODE
A recovery code may provide a way to bypass part of your normal authentication process.
Treat it as highly sensitive.
If you believe a recovery code was exposed:
- Secure the account.
- Review authentication settings.
- Revoke or replace the affected recovery method where the service supports it.
- Review active sessions.
- Follow the official security process.
Do not assume that changing your normal password automatically invalidates every recovery method.
11. IF YOU EXPOSED A CRYPTOCURRENCY RECOVERY PHRASE
This is a particularly serious situation.
A recovery phrase can potentially allow a person to restore or control a self-custody wallet.
If you believe it has been exposed:
Do not send it to another person for “verification.”
Do not give it to fake support.
Do not wait for a stranger to tell you what to do.
Preserve relevant information and use trusted official documentation or qualified assistance appropriate to the situation.
If assets remain at risk, the response may need to be treated as an urgent wallet-security incident.
12. IF YOU CLICKED A SUSPICIOUS LINK
Clicking a link does not automatically mean that you have been hacked.
The next question is:
“What happened after I clicked?”
Did the page simply open?
Did you enter a password?
Did you enter an OTP?
Did you download a file?
Did you install software?
Did you approve a browser permission?
Did you connect a wallet?
Did you authorise a transaction?
The answer determines the appropriate response.
13. IF YOU CLICKED BUT ENTERED NOTHING
If you opened a suspicious page but did not provide information, download anything or approve an action, the situation may be less severe.
Still:
- Close the page.
- Do not return to it.
- Do not download anything from it.
- Do not enter credentials.
- Review the device if anything unusual occurred.
- Consider whether the link came from a suspicious message.
Do not assume that every suspicious link automatically compromises a device.
Assess what actually happened.
14. IF YOU ENTERED YOUR PASSWORD ON A SUSPICIOUS WEBSITE
Treat the password as exposed.
Go directly to the legitimate service.
Do not use the suspicious website again.
Change the password through the official application or website.
If the password was reused elsewhere, change it on those services too.
Then review account security.
If MFA was enabled, review unexpected authentication activity as well.
15. IF YOU ENTERED AN OTP ON A SUSPICIOUS WEBSITE
Treat the event seriously.
Determine what service generated the OTP and what the code was intended to authorise.
Then access the legitimate service independently.
Review:
- Login activity
- Sessions
- Devices
- Password
- Recovery methods
- Transactions
Do not wait for an attacker to contact you before acting.
16. IF YOU DOWNLOADED A FILE
Do not automatically open it.
If you have already opened it, consider what happened next.
Did the device show unusual behaviour?
Did the file request permissions?
Did you install software?
Did you enter credentials?
Did you disable security controls?
The appropriate response depends on the situation.
If the device is used for sensitive financial or work activities, consider obtaining appropriate technical assistance rather than experimenting with unfamiliar “cleanup” instructions from strangers.
17. IF YOU INSTALLED UNKNOWN SOFTWARE
This can be more serious because the software may have been given access to the device.
Potential risks can include exposure of:
- Files
- Browser sessions
- Saved credentials
- Messages
- Screens
- Personal information
- Authentication information
Disconnecting a compromised device from the internet may sometimes help contain ongoing access, depending on the circumstances.
Then seek appropriate technical assistance and follow the relevant service's security procedures.
Do not assume that uninstalling the application automatically removes every possible consequence.
18. IF YOU GAVE REMOTE ACCESS TO SOMEONE
Treat the incident seriously.
Remote access can potentially allow another person to see or control parts of a device.
Depending on the software and permissions involved, the attacker may have had access to:
- Screen activity
- Files
- Applications
- Browser sessions
- Messages
- Settings
Stop the remote session.
Disconnect or disable the remote-access software where appropriate.
Then secure important accounts using a trusted device if necessary.
For serious incidents, obtain qualified technical assistance.
19. IF YOUR EMAIL MAY BE COMPROMISED
Email is often one of the most important accounts to secure because it may be used to reset other accounts.
If you suspect compromise:
- Change the password through the official provider.
- Review active sessions.
- Remove unfamiliar devices.
- Review recovery methods.
- Review MFA settings.
- Check forwarding rules.
- Check filters.
- Review recent security activity.
- Check for password-reset messages you did not request.
Then identify other accounts that use the email address for recovery.
20. WHY EMAIL FORWARDING MATTERS
An attacker who compromises your email may create a forwarding rule.
That rule could secretly send copies of important messages to another address.
Your bank sends a security notification.
Your email automatically forwards it to the attacker.
You may not notice.
This is why changing the password alone may not be enough after an email compromise.
Inspect the account's settings.
21. IF YOUR WHATSAPP ACCOUNT MAY BE COMPROMISED
Use the official WhatsApp recovery and security process.
Review linked devices.
Remove devices you do not recognise.
Warn important contacts if necessary.
Be careful about messages sent from the compromised account.
Do not give anyone your WhatsApp verification code.
An attacker may try to convince you that the code is needed to restore your account.
It is an authentication credential.
Keep it private.
22. IF YOUR PHONE IS LOST OR STOLEN
Act quickly.
Depending on your device and circumstances:
- Use the official device-location or lock function.
- Lock the device remotely where supported.
- Contact your mobile network provider.
- Secure important financial accounts.
- Secure your primary email.
- Review active sessions.
- Remove the lost device from important accounts.
- Preserve the IMEI and other relevant device information.
- Report the incident through appropriate channels.
Do not wait for the person who found or stole the device to contact you.
23. IF YOUR BANKING ACCOUNT MAY BE COMPROMISED
Contact the financial institution immediately through an official channel.
Do not use a phone number supplied by a suspicious caller.
Depending on the situation, you may need to:
- Secure the account.
- Block or replace a payment instrument.
- Review transactions.
- Report unauthorised activity.
- Change authentication credentials.
- Follow the institution's fraud procedure.
Time can matter in financial incidents.
24. IF YOU SENT MONEY TO A SCAMMER
Do not send more money.
Do not allow the scammer to convince you that another payment will recover the first one.
Preserve:
- Transaction reference
- Recipient information
- Amount
- Date
- Time
- Messages
- Phone numbers
- Screenshots
- Payment receipts
Contact the relevant financial institution or payment provider immediately through its official channel.
Explain clearly that you believe you were deceived.
Follow the institution's dispute or fraud-reporting process.
25. IF YOU SENT MONEY TO THE WRONG PERSON BY MISTAKE
This is not necessarily a scam.
But you should still act quickly.
Preserve the transaction details.
Contact the financial institution through its official channel.
Explain that the transfer was made to the wrong recipient.
Do not assume that the recipient will voluntarily return the money.
Follow the legitimate recovery or dispute process provided by the institution.
26. IF YOU RECEIVED A FAKE PAYMENT SCREENSHOT
Do not release goods or provide services solely because of the screenshot.
Check your own account.
Verify whether the money actually arrived.
Preserve the screenshot and the communication if you believe fraud was attempted.
If appropriate, report the incident through the relevant platform or institution.
27. IF A TRANSACTION FAILED BUT YOUR ACCOUNT WAS DEBITED
Do not immediately repeat the transaction.
First:
- Check your account.
- Preserve the transaction reference.
- Keep the receipt.
- Record the date and time.
- Contact the financial institution through its official channel.
- Follow the dispute process.
Repeating the transaction without understanding the first transaction can create duplicate payments.
28. IF YOUR CRYPTOCURRENCY WAS MOVED WITHOUT AUTHORISATION
Record the blockchain information.
Where available, preserve:
- Wallet address
- Transaction hash
- Destination address
- Asset
- Amount
- Network
- Date and time
Do not send additional cryptocurrency to someone promising to reverse the transaction unless the person and service have been independently verified.
Blockchain transactions may be difficult or impossible to reverse.
29. IF YOUR CRYPTO WALLET SHOWS A ZERO BALANCE
Do not immediately conclude that the assets are gone.
Check:
- Correct wallet account
- Correct network
- Wallet address
- Blockchain explorer
- Token visibility
- Token contract address
- Transaction history
The wallet interface may not display an asset even when the blockchain record still contains it.
Do not give your recovery phrase to someone claiming they can “restore” the balance.
30. DO NOT CONFUSE A TECHNICAL PROBLEM WITH A SECURITY INCIDENT
A website may fail.
A banking application may experience downtime.
A wallet may display an incorrect balance.
A transaction may be delayed.
A device may crash.
These events do not automatically mean that you have been hacked.
Start with evidence.
Ask:
What actually changed?
What does the official service report?
What does the account activity show?
What does the transaction record show?
What does the blockchain record show?
Do not let fear turn an unknown technical problem into an assumption of compromise.
31. VERIFY INFORMATION BEFORE ACTING
During an incident, you may receive conflicting information.
One person says:
“Your account is safe.”
Another says:
“Your account has been hacked.”
A message says:
“Your payment failed.”
Your banking application says:
“Payment successful.”
A stranger says:
“I can recover your funds.”
The correct response is not to choose the most convincing story.
Look for independently verifiable evidence.
Use official applications.
Use official websites.
Use official support channels.
Use transaction records.
Use trusted account activity.
32. DO NOT SEARCH FOR RANDOM RECOVERY AGENTS
After an incident, you may search online for:
“Recover hacked account.”
“Recover stolen crypto.”
“Recover bank transfer.”
“Fix compromised WhatsApp.”
This can expose you to another layer of scammers.
Attackers know that victims search for help after an incident.
They may create:
- Fake recovery websites
- Fake support accounts
- Fake investigators
- Fake cybersecurity experts
- Fake legal services
- Fake blockchain recovery services
Do not assume that someone offering help after an incident is trustworthy.
33. RECOVERY SCAMS TARGET VICTIMS TWICE
The first scam may cause the financial or account loss.
The second scam promises to fix it.
“You were scammed? We can recover your money.”
“Send us a processing fee.”
“Give us your OTP.”
“Give us your recovery phrase.”
“Install this application.”
The emotional state of the victim makes this especially dangerous.
You are allowed to pause.
Verify the recovery service independently.
34. REPORTING IS PART OF RECOVERY
Reporting an incident may help:
- Protect your account.
- Document the event.
- Start a dispute.
- Alert a financial institution.
- Warn other users.
- Support investigation.
- Establish a record of what happened.
The correct reporting channel depends on the incident.
Examples may include:
- Bank or financial institution
- Payment provider
- Mobile network provider
- Platform's official support
- Employer or IT/security team
- Relevant law-enforcement or regulatory channel
- Cryptocurrency service provider
- Appropriate cybersecurity organisation
Always verify the reporting channel independently.
35. WHAT INFORMATION SHOULD YOU INCLUDE IN A REPORT?
A useful incident report should explain:
WHAT happened?
WHEN did it happen?
HOW did it happen?
WHO contacted you?
WHAT information was exposed?
WHAT action did you take?
HOW much money was involved?
WHERE did the money go?
WHAT evidence do you have?
WHAT have you already done to secure the situation?
Clear information makes it easier for the receiving organisation to understand the incident.
36. INCIDENT TIMELINES ARE USEFUL
If an incident is complicated, create a simple timeline.
10:15 — Received WhatsApp message.
10:18 — Clicked link.
10:20 — Entered password.
10:21 — Received OTP.
10:22 — Entered OTP.
10:25 — Account security notification received.
10:30 — Contacted bank.
This can help you and the relevant institution understand the sequence of events.
Write down times while the information is still fresh.
37. SECURE YOUR OTHER ACCOUNTS
One compromised account may affect other accounts.
Your email is compromised.
Your email is the recovery address for your social-media account.
Your social-media account is connected to your payment account.
Therefore, after a major incident, ask:
“What other accounts depend on this account?”
Prioritise those accounts.
38. PRIORITISE THE MOST IMPORTANT ACCOUNTS
A useful priority order may include:
- Primary email
- Banking and financial accounts
- Cryptocurrency accounts and wallets
- Work accounts
- Cloud storage
- Social media
- Shopping and marketplace accounts
- Other services
The exact order depends on your circumstances.
The principle is:
SECURE THE ACCOUNTS THAT CAN CAUSE THE MOST DAMAGE IF COMPROMISED.
39. USE A TRUSTED DEVICE WHEN NECESSARY
If you suspect that your device itself has been compromised, consider using another trusted device to secure important accounts.
Your laptop may have unknown software installed.
Instead of changing your banking password on that laptop, use a trusted device if appropriate.
The goal is to avoid exposing the new credential to the same potentially compromised environment.
40. DO NOT DESTROY EVIDENCE UNNECESSARILY
A factory reset may sometimes be appropriate.
Deleting suspicious messages may sometimes feel necessary.
Uninstalling software may seem helpful.
But before taking irreversible steps, consider whether evidence needs to be preserved.
If the incident is serious, seek appropriate technical or investigative guidance before wiping the device.
41. WHEN TO ESCALATE
Some incidents are simple enough to handle using the service's normal security process.
Others require additional help.
Consider escalation when:
- Significant money is involved.
- Multiple accounts are compromised.
- Identity information was exposed.
- A device may be infected.
- Cryptocurrency was stolen.
- A business account was compromised.
- Sensitive customer information was exposed.
- You cannot determine what happened.
- The attacker still appears to have access.
- You are being targeted repeatedly.
42. DO NOT BE ASHAMED TO REPORT
People sometimes avoid reporting because they feel embarrassed.
They may think:
“I should have known better.”
“I can't tell anyone.”
“People will laugh at me.”
That reaction can delay recovery.
Cybersecurity incidents happen to people with different levels of technical knowledge.
Reporting quickly is more important than protecting your pride.
The goal is to reduce further harm.
43. WHAT NOT TO DO AFTER AN INCIDENT
Do not:
- Send additional money to the attacker.
- Give your password to a “helper.”
- Give away an OTP.
- Give away a recovery phrase.
- Give away a private key.
- Install unknown remote-access software.
- Click more suspicious links.
- Trust unsolicited recovery agents.
- Publicly expose sensitive information.
- Destroy evidence without considering its value.
- Assume the first person who offers help is legitimate.
44. A GENERAL EMERGENCY DECISION TREE
If something has gone wrong, ask:
DID MONEY MOVE?
If yes: Contact the relevant financial institution immediately and preserve transaction evidence.
DID AN AUTHENTICATION SECRET LEAK?
If yes: Secure the affected account and replace or revoke the exposed credential where possible.
DID A DEVICE BECOME SUSPICIOUS?
If yes: Stop sensitive activity on that device and consider appropriate technical assistance.
DID A CRYPTO WALLET LOSE ASSETS?
If yes: Preserve blockchain evidence and treat the incident as potentially urgent.
DID YOU ONLY CLICK A LINK?
If yes: Determine what happened after the click before assuming compromise.
DID SOMEONE CONTACT YOU CLAIMING TO BE SUPPORT?
If yes: Stop the interaction and verify the organisation independently.
45. A PRACTICAL EXAMPLE: SUSPICIOUS BANK CALL
You receive a call:
“Your account is under attack. Read the OTP to me.”
You receive the OTP.
STOP.
Do not read it.
End the call.
Open your official banking application.
Check recent activity.
Contact the bank independently.
If the account shows suspicious activity, follow the bank's security process.
The goal is not to argue with the caller.
The goal is to remove the caller from the verification process.
46. A PRACTICAL EXAMPLE: PHISHING LOGIN
You click a link from an SMS.
A page that looks like your bank appears.
You enter your password.
Then you realise something feels wrong.
STOP.
Do not enter the OTP.
Close the suspicious page.
Open your official banking application or known official website yourself.
Change the exposed password.
Review account activity.
Contact the bank if appropriate.
If you reused that password elsewhere, change it there too.
47. A PRACTICAL EXAMPLE: LOST PHONE
Your phone disappears.
Do not wait.
Use your official device-management tools where available.
Contact your mobile provider.
Secure your primary email.
Review important account sessions.
Secure financial accounts.
Remove the lost device from trusted-device lists where appropriate.
The goal is to prevent the lost device from becoming a gateway into other accounts.
48. A PRACTICAL EXAMPLE: CRYPTO RECOVERY SCAM
You lose cryptocurrency.
Someone messages you:
“We can recover it.”
They request your recovery phrase.
STOP.
Do not send it.
Record the person's information.
Verify the organisation independently.
Review the blockchain transaction.
Seek legitimate assistance if necessary.
The fact that someone knows about your loss does not make them trustworthy.
49. THE INCIDENT-RESPONSE CHECKLIST
When something goes wrong:
□ STOP the suspicious action.
□ Do not send additional money.
□ Do not provide passwords, PINs, OTPs or recovery credentials.
□ PRESERVE messages, screenshots and transaction evidence.
□ Identify exactly what was exposed.
□ SECURE the affected account, device or financial service.
□ Review active sessions and recovery methods.
□ REPORT through legitimate official channels.
□ VERIFY information independently.
□ Recover the affected account or service through the official process.
□ Check whether other accounts may also be affected.
□ ESCALATE when the situation is serious or unclear.
□ Watch for recovery scams after the incident.
50. THE MOST IMPORTANT QUESTION
After something goes wrong, do not immediately ask:
“How do I fix everything?”
Ask:
“What is the next safest action?”
That question prevents panic from controlling the situation.
One safe action at a time.
Stop the damage.
Preserve the evidence.
Secure what you can.
Contact the right organisation.
Verify information.
Then recover.
51. IF YOU REMEMBER ONLY ONE THING
A cybersecurity incident does not become safer because you act quickly.
It becomes safer when you act correctly.
When something goes wrong:
STOP.
PRESERVE.
SECURE.
REPORT.
VERIFY.
RECOVER.
ESCALATE.
Do not let fear choose your next action.
Do not let urgency choose your next action.
Do not let an unknown person choose your next action.
And never allow the person who may have caused the problem to become the person you trust to solve it.
