← Back to Knowledge Center
KNOWLEDGE CENTER

What To Do When Something Goes Wrong

Incident Responseen-NG
BEFORE YOU BEGIN

Understand the issue before you decide what to do.

This lesson is designed to explain the subject in practical terms so that you can understand not only what the risk is, but why it matters, how it can appear in real situations and what you can do to reduce your exposure.

Read the explanation carefully before acting on a suspicious message, request, transaction, account notification or other security-related situation.

FULL LESSON

Understanding the subject

Take your time with this explanation. The goal is not simply to recognise a warning sign, but to understand what is happening and make a safer decision when you encounter it.

WHAT TO DO WHEN SOMETHING GOES WRONG

Something has happened.

You clicked a suspicious link.

You sent money to the wrong account.

You gave someone an OTP.

Your account suddenly looks different.

Your phone has been lost.

Your WhatsApp account may have been taken over.

Your email may be compromised.

Your cryptocurrency may have moved.

You entered your password on a website you now suspect was fake.

A transaction failed but your account was debited.

Someone contacted you claiming to be support.

Whatever happened, the first thing you should know is:

DO NOT PANIC.

Panic creates urgency.

Urgency creates mistakes.

Mistakes can make an incident worse.

The correct response is to slow the situation down, preserve what happened, secure what you still control, report through legitimate channels, verify information independently, and then recover.

The core incident-response sequence is:

STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE

Not every incident will require every step.

But this sequence gives you a safe starting point when you are unsure what to do.

1. FIRST: STOP

The first response to a suspected security incident is to stop the activity that may be causing further harm.

If you are on a suspicious website:

Stop entering information.

If someone is pressuring you to send money:

Do not send more money.

If someone is asking for an OTP:

Do not provide it.

If you are about to approve a suspicious transaction:

Stop before authorising it.

If someone is telling you to install software:

Do not install it until you have independently verified the request.

The purpose of STOP is containment.

You are creating a pause between the incident and your next decision.

2. DO NOT TRY TO FIX EVERYTHING IMMEDIATELY

When people realise something has gone wrong, they often begin taking random actions.

They may:

  • Change several passwords at once.
  • Delete messages.
  • Delete suspicious applications.
  • Factory-reset a device.
  • Send more money.
  • Contact random people online.
  • Search for “recovery agents.”
  • Post details publicly.
  • Give strangers remote access.
  • Attempt unfamiliar technical fixes.

Some of these actions may destroy useful evidence or create additional risk.

Before doing something irreversible, ask:

“Will this make the situation safer, or could it make the situation harder to understand?”

3. PRESERVE EVIDENCE

Evidence can help you understand what happened and can become important when reporting the incident.

Where appropriate, preserve:

  • Screenshots
  • Messages
  • Emails
  • Phone numbers
  • Usernames
  • URLs
  • Transaction references
  • Payment receipts
  • Wallet addresses
  • Transaction hashes
  • Account notifications
  • Dates and times
  • Names used by the person contacting you
  • Relevant account activity

Do not immediately delete everything simply because it looks suspicious.

The evidence may help establish:

What happened?

When did it happen?

Who contacted you?

What information was requested?

What action was taken?

Where did the money go?

What account or device was involved?

4. PRESERVE THE ORIGINAL CONTEXT

A screenshot can be useful, but preserve the original conversation or message where possible.

For example, if you receive a suspicious WhatsApp message:

Do not rely only on a cropped screenshot.

Keep the original conversation if it is safe to do so.

The surrounding messages may provide information about:

  • The sender
  • The timing
  • The request
  • The link
  • The account used
  • What happened before the suspicious message

Evidence is more useful when its context is preserved.

5. DO NOT FORWARD SENSITIVE INFORMATION CARELESSLY

Preserving evidence does not mean publicly sharing everything.

Be careful with:

  • Passwords
  • OTPs
  • PINs
  • Recovery codes
  • Recovery phrases
  • Private keys
  • Full card information
  • Personal identity documents

If you need to provide evidence to a legitimate organisation, follow its official process.

Do not upload sensitive credentials to public websites simply because someone says they are investigating the incident.

6. IDENTIFY WHAT WAS ACTUALLY EXPOSED

Not every incident exposes the same thing.

Ask:

What did I provide?

What did I click?

What did I approve?

What did I download?

What did I send?

What account was involved?

What device was involved?

What money was involved?

What information may now be accessible?

EXAMPLE

Clicking a suspicious link is not automatically the same as entering a password.

Entering a password is not automatically the same as giving away an OTP.

Giving away an OTP is not automatically the same as exposing a cryptocurrency recovery phrase.

The response should match the actual exposure.

7. IF YOU GAVE AWAY A PASSWORD

Treat the password as compromised.

Change it through the legitimate service.

If you reused the same password elsewhere, change it on those services too.

Password reuse can turn one incident into multiple account compromises.

After changing the password, review:

  • Active sessions
  • Logged-in devices
  • Recovery email
  • Recovery phone
  • MFA methods
  • Connected applications
  • Recent security activity

Changing the password is only the beginning.

8. IF YOU GAVE AWAY AN OTP

An OTP may have been generated for:

  • Login
  • Password reset
  • Payment
  • Device registration
  • Account changes
  • Transaction approval

Determine what the code was intended for.

Then secure the affected account or transaction through the official service.

Do not assume:

“It was only a six-digit code.”

The code may have been the final step required to complete an important action.

9. IF YOU GAVE AWAY YOUR PIN

Treat the PIN as compromised.

Contact the relevant financial institution or service through its official channel.

Follow its security instructions.

Do not continue using the compromised credential simply because no suspicious transaction has appeared yet.

A credential can be compromised before it is used.

10. IF YOU GAVE AWAY A RECOVERY CODE

A recovery code may provide a way to bypass part of your normal authentication process.

Treat it as highly sensitive.

If you believe a recovery code was exposed:

  • Secure the account.
  • Review authentication settings.
  • Revoke or replace the affected recovery method where the service supports it.
  • Review active sessions.
  • Follow the official security process.

Do not assume that changing your normal password automatically invalidates every recovery method.

11. IF YOU EXPOSED A CRYPTOCURRENCY RECOVERY PHRASE

This is a particularly serious situation.

A recovery phrase can potentially allow a person to restore or control a self-custody wallet.

If you believe it has been exposed:

Do not send it to another person for “verification.”

Do not give it to fake support.

Do not wait for a stranger to tell you what to do.

Preserve relevant information and use trusted official documentation or qualified assistance appropriate to the situation.

If assets remain at risk, the response may need to be treated as an urgent wallet-security incident.

12. IF YOU CLICKED A SUSPICIOUS LINK

Clicking a link does not automatically mean that you have been hacked.

The next question is:

“What happened after I clicked?”

Did the page simply open?

Did you enter a password?

Did you enter an OTP?

Did you download a file?

Did you install software?

Did you approve a browser permission?

Did you connect a wallet?

Did you authorise a transaction?

The answer determines the appropriate response.

13. IF YOU CLICKED BUT ENTERED NOTHING

If you opened a suspicious page but did not provide information, download anything or approve an action, the situation may be less severe.

Still:

  • Close the page.
  • Do not return to it.
  • Do not download anything from it.
  • Do not enter credentials.
  • Review the device if anything unusual occurred.
  • Consider whether the link came from a suspicious message.

Do not assume that every suspicious link automatically compromises a device.

Assess what actually happened.

14. IF YOU ENTERED YOUR PASSWORD ON A SUSPICIOUS WEBSITE

Treat the password as exposed.

Go directly to the legitimate service.

Do not use the suspicious website again.

Change the password through the official application or website.

If the password was reused elsewhere, change it on those services too.

Then review account security.

If MFA was enabled, review unexpected authentication activity as well.

15. IF YOU ENTERED AN OTP ON A SUSPICIOUS WEBSITE

Treat the event seriously.

Determine what service generated the OTP and what the code was intended to authorise.

Then access the legitimate service independently.

Review:

  • Login activity
  • Sessions
  • Devices
  • Password
  • Recovery methods
  • Transactions

Do not wait for an attacker to contact you before acting.

16. IF YOU DOWNLOADED A FILE

Do not automatically open it.

If you have already opened it, consider what happened next.

Did the device show unusual behaviour?

Did the file request permissions?

Did you install software?

Did you enter credentials?

Did you disable security controls?

The appropriate response depends on the situation.

If the device is used for sensitive financial or work activities, consider obtaining appropriate technical assistance rather than experimenting with unfamiliar “cleanup” instructions from strangers.

17. IF YOU INSTALLED UNKNOWN SOFTWARE

This can be more serious because the software may have been given access to the device.

Potential risks can include exposure of:

  • Files
  • Browser sessions
  • Saved credentials
  • Messages
  • Screens
  • Personal information
  • Authentication information

Disconnecting a compromised device from the internet may sometimes help contain ongoing access, depending on the circumstances.

Then seek appropriate technical assistance and follow the relevant service's security procedures.

Do not assume that uninstalling the application automatically removes every possible consequence.

18. IF YOU GAVE REMOTE ACCESS TO SOMEONE

Treat the incident seriously.

Remote access can potentially allow another person to see or control parts of a device.

Depending on the software and permissions involved, the attacker may have had access to:

  • Screen activity
  • Files
  • Applications
  • Browser sessions
  • Messages
  • Settings

Stop the remote session.

Disconnect or disable the remote-access software where appropriate.

Then secure important accounts using a trusted device if necessary.

For serious incidents, obtain qualified technical assistance.

19. IF YOUR EMAIL MAY BE COMPROMISED

Email is often one of the most important accounts to secure because it may be used to reset other accounts.

If you suspect compromise:

  • Change the password through the official provider.
  • Review active sessions.
  • Remove unfamiliar devices.
  • Review recovery methods.
  • Review MFA settings.
  • Check forwarding rules.
  • Check filters.
  • Review recent security activity.
  • Check for password-reset messages you did not request.

Then identify other accounts that use the email address for recovery.

20. WHY EMAIL FORWARDING MATTERS

An attacker who compromises your email may create a forwarding rule.

That rule could secretly send copies of important messages to another address.

EXAMPLE

Your bank sends a security notification.

Your email automatically forwards it to the attacker.

You may not notice.

This is why changing the password alone may not be enough after an email compromise.

Inspect the account's settings.

21. IF YOUR WHATSAPP ACCOUNT MAY BE COMPROMISED

Use the official WhatsApp recovery and security process.

Review linked devices.

Remove devices you do not recognise.

Warn important contacts if necessary.

Be careful about messages sent from the compromised account.

Do not give anyone your WhatsApp verification code.

An attacker may try to convince you that the code is needed to restore your account.

It is an authentication credential.

Keep it private.

22. IF YOUR PHONE IS LOST OR STOLEN

Act quickly.

Depending on your device and circumstances:

  • Use the official device-location or lock function.
  • Lock the device remotely where supported.
  • Contact your mobile network provider.
  • Secure important financial accounts.
  • Secure your primary email.
  • Review active sessions.
  • Remove the lost device from important accounts.
  • Preserve the IMEI and other relevant device information.
  • Report the incident through appropriate channels.

Do not wait for the person who found or stole the device to contact you.

23. IF YOUR BANKING ACCOUNT MAY BE COMPROMISED

Contact the financial institution immediately through an official channel.

Do not use a phone number supplied by a suspicious caller.

Depending on the situation, you may need to:

  • Secure the account.
  • Block or replace a payment instrument.
  • Review transactions.
  • Report unauthorised activity.
  • Change authentication credentials.
  • Follow the institution's fraud procedure.

Time can matter in financial incidents.

24. IF YOU SENT MONEY TO A SCAMMER

Do not send more money.

Do not allow the scammer to convince you that another payment will recover the first one.

Preserve:

  • Transaction reference
  • Recipient information
  • Amount
  • Date
  • Time
  • Messages
  • Phone numbers
  • Screenshots
  • Payment receipts

Contact the relevant financial institution or payment provider immediately through its official channel.

Explain clearly that you believe you were deceived.

Follow the institution's dispute or fraud-reporting process.

25. IF YOU SENT MONEY TO THE WRONG PERSON BY MISTAKE

This is not necessarily a scam.

But you should still act quickly.

Preserve the transaction details.

Contact the financial institution through its official channel.

Explain that the transfer was made to the wrong recipient.

Do not assume that the recipient will voluntarily return the money.

Follow the legitimate recovery or dispute process provided by the institution.

26. IF YOU RECEIVED A FAKE PAYMENT SCREENSHOT

Do not release goods or provide services solely because of the screenshot.

Check your own account.

Verify whether the money actually arrived.

Preserve the screenshot and the communication if you believe fraud was attempted.

If appropriate, report the incident through the relevant platform or institution.

27. IF A TRANSACTION FAILED BUT YOUR ACCOUNT WAS DEBITED

Do not immediately repeat the transaction.

First:

  • Check your account.
  • Preserve the transaction reference.
  • Keep the receipt.
  • Record the date and time.
  • Contact the financial institution through its official channel.
  • Follow the dispute process.

Repeating the transaction without understanding the first transaction can create duplicate payments.

28. IF YOUR CRYPTOCURRENCY WAS MOVED WITHOUT AUTHORISATION

Record the blockchain information.

Where available, preserve:

  • Wallet address
  • Transaction hash
  • Destination address
  • Asset
  • Amount
  • Network
  • Date and time

Do not send additional cryptocurrency to someone promising to reverse the transaction unless the person and service have been independently verified.

Blockchain transactions may be difficult or impossible to reverse.

29. IF YOUR CRYPTO WALLET SHOWS A ZERO BALANCE

Do not immediately conclude that the assets are gone.

Check:

  • Correct wallet account
  • Correct network
  • Wallet address
  • Blockchain explorer
  • Token visibility
  • Token contract address
  • Transaction history

The wallet interface may not display an asset even when the blockchain record still contains it.

Do not give your recovery phrase to someone claiming they can “restore” the balance.

30. DO NOT CONFUSE A TECHNICAL PROBLEM WITH A SECURITY INCIDENT

A website may fail.

A banking application may experience downtime.

A wallet may display an incorrect balance.

A transaction may be delayed.

A device may crash.

These events do not automatically mean that you have been hacked.

Start with evidence.

Ask:

What actually changed?

What does the official service report?

What does the account activity show?

What does the transaction record show?

What does the blockchain record show?

Do not let fear turn an unknown technical problem into an assumption of compromise.

31. VERIFY INFORMATION BEFORE ACTING

During an incident, you may receive conflicting information.

One person says:

“Your account is safe.”

Another says:

“Your account has been hacked.”

A message says:

“Your payment failed.”

Your banking application says:

“Payment successful.”

A stranger says:

“I can recover your funds.”

The correct response is not to choose the most convincing story.

Look for independently verifiable evidence.

Use official applications.

Use official websites.

Use official support channels.

Use transaction records.

Use trusted account activity.

32. DO NOT SEARCH FOR RANDOM RECOVERY AGENTS

After an incident, you may search online for:

“Recover hacked account.”

“Recover stolen crypto.”

“Recover bank transfer.”

“Fix compromised WhatsApp.”

This can expose you to another layer of scammers.

Attackers know that victims search for help after an incident.

They may create:

  • Fake recovery websites
  • Fake support accounts
  • Fake investigators
  • Fake cybersecurity experts
  • Fake legal services
  • Fake blockchain recovery services

Do not assume that someone offering help after an incident is trustworthy.

33. RECOVERY SCAMS TARGET VICTIMS TWICE

The first scam may cause the financial or account loss.

The second scam promises to fix it.

EXAMPLE

“You were scammed? We can recover your money.”

“Send us a processing fee.”

“Give us your OTP.”

“Give us your recovery phrase.”

“Install this application.”

The emotional state of the victim makes this especially dangerous.

You are allowed to pause.

Verify the recovery service independently.

34. REPORTING IS PART OF RECOVERY

Reporting an incident may help:

  • Protect your account.
  • Document the event.
  • Start a dispute.
  • Alert a financial institution.
  • Warn other users.
  • Support investigation.
  • Establish a record of what happened.

The correct reporting channel depends on the incident.

Examples may include:

  • Bank or financial institution
  • Payment provider
  • Mobile network provider
  • Platform's official support
  • Employer or IT/security team
  • Relevant law-enforcement or regulatory channel
  • Cryptocurrency service provider
  • Appropriate cybersecurity organisation

Always verify the reporting channel independently.

35. WHAT INFORMATION SHOULD YOU INCLUDE IN A REPORT?

A useful incident report should explain:

WHAT happened?

WHEN did it happen?

HOW did it happen?

WHO contacted you?

WHAT information was exposed?

WHAT action did you take?

HOW much money was involved?

WHERE did the money go?

WHAT evidence do you have?

WHAT have you already done to secure the situation?

Clear information makes it easier for the receiving organisation to understand the incident.

36. INCIDENT TIMELINES ARE USEFUL

If an incident is complicated, create a simple timeline.

EXAMPLE

10:15 — Received WhatsApp message.

10:18 — Clicked link.

10:20 — Entered password.

10:21 — Received OTP.

10:22 — Entered OTP.

10:25 — Account security notification received.

10:30 — Contacted bank.

This can help you and the relevant institution understand the sequence of events.

Write down times while the information is still fresh.

37. SECURE YOUR OTHER ACCOUNTS

One compromised account may affect other accounts.

EXAMPLE

Your email is compromised.

Your email is the recovery address for your social-media account.

Your social-media account is connected to your payment account.

Therefore, after a major incident, ask:

“What other accounts depend on this account?”

Prioritise those accounts.

38. PRIORITISE THE MOST IMPORTANT ACCOUNTS

A useful priority order may include:

  1. Primary email
  2. Banking and financial accounts
  3. Cryptocurrency accounts and wallets
  4. Work accounts
  5. Cloud storage
  6. Social media
  7. Shopping and marketplace accounts
  8. Other services

The exact order depends on your circumstances.

The principle is:

SECURE THE ACCOUNTS THAT CAN CAUSE THE MOST DAMAGE IF COMPROMISED.

39. USE A TRUSTED DEVICE WHEN NECESSARY

If you suspect that your device itself has been compromised, consider using another trusted device to secure important accounts.

EXAMPLE

Your laptop may have unknown software installed.

Instead of changing your banking password on that laptop, use a trusted device if appropriate.

The goal is to avoid exposing the new credential to the same potentially compromised environment.

40. DO NOT DESTROY EVIDENCE UNNECESSARILY

A factory reset may sometimes be appropriate.

Deleting suspicious messages may sometimes feel necessary.

Uninstalling software may seem helpful.

But before taking irreversible steps, consider whether evidence needs to be preserved.

If the incident is serious, seek appropriate technical or investigative guidance before wiping the device.

41. WHEN TO ESCALATE

Some incidents are simple enough to handle using the service's normal security process.

Others require additional help.

Consider escalation when:

  • Significant money is involved.
  • Multiple accounts are compromised.
  • Identity information was exposed.
  • A device may be infected.
  • Cryptocurrency was stolen.
  • A business account was compromised.
  • Sensitive customer information was exposed.
  • You cannot determine what happened.
  • The attacker still appears to have access.
  • You are being targeted repeatedly.

42. DO NOT BE ASHAMED TO REPORT

People sometimes avoid reporting because they feel embarrassed.

They may think:

“I should have known better.”

“I can't tell anyone.”

“People will laugh at me.”

That reaction can delay recovery.

Cybersecurity incidents happen to people with different levels of technical knowledge.

Reporting quickly is more important than protecting your pride.

The goal is to reduce further harm.

43. WHAT NOT TO DO AFTER AN INCIDENT

Do not:

  • Send additional money to the attacker.
  • Give your password to a “helper.”
  • Give away an OTP.
  • Give away a recovery phrase.
  • Give away a private key.
  • Install unknown remote-access software.
  • Click more suspicious links.
  • Trust unsolicited recovery agents.
  • Publicly expose sensitive information.
  • Destroy evidence without considering its value.
  • Assume the first person who offers help is legitimate.

44. A GENERAL EMERGENCY DECISION TREE

If something has gone wrong, ask:

DID MONEY MOVE?

If yes: Contact the relevant financial institution immediately and preserve transaction evidence.

DID AN AUTHENTICATION SECRET LEAK?

If yes: Secure the affected account and replace or revoke the exposed credential where possible.

DID A DEVICE BECOME SUSPICIOUS?

If yes: Stop sensitive activity on that device and consider appropriate technical assistance.

DID A CRYPTO WALLET LOSE ASSETS?

If yes: Preserve blockchain evidence and treat the incident as potentially urgent.

DID YOU ONLY CLICK A LINK?

If yes: Determine what happened after the click before assuming compromise.

DID SOMEONE CONTACT YOU CLAIMING TO BE SUPPORT?

If yes: Stop the interaction and verify the organisation independently.

45. A PRACTICAL EXAMPLE: SUSPICIOUS BANK CALL

You receive a call:

“Your account is under attack. Read the OTP to me.”

You receive the OTP.

STOP.

Do not read it.

End the call.

Open your official banking application.

Check recent activity.

Contact the bank independently.

If the account shows suspicious activity, follow the bank's security process.

The goal is not to argue with the caller.

The goal is to remove the caller from the verification process.

46. A PRACTICAL EXAMPLE: PHISHING LOGIN

You click a link from an SMS.

A page that looks like your bank appears.

You enter your password.

Then you realise something feels wrong.

STOP.

Do not enter the OTP.

Close the suspicious page.

Open your official banking application or known official website yourself.

Change the exposed password.

Review account activity.

Contact the bank if appropriate.

If you reused that password elsewhere, change it there too.

47. A PRACTICAL EXAMPLE: LOST PHONE

Your phone disappears.

Do not wait.

Use your official device-management tools where available.

Contact your mobile provider.

Secure your primary email.

Review important account sessions.

Secure financial accounts.

Remove the lost device from trusted-device lists where appropriate.

The goal is to prevent the lost device from becoming a gateway into other accounts.

48. A PRACTICAL EXAMPLE: CRYPTO RECOVERY SCAM

You lose cryptocurrency.

Someone messages you:

“We can recover it.”

They request your recovery phrase.

STOP.

Do not send it.

Record the person's information.

Verify the organisation independently.

Review the blockchain transaction.

Seek legitimate assistance if necessary.

The fact that someone knows about your loss does not make them trustworthy.

49. THE INCIDENT-RESPONSE CHECKLIST

When something goes wrong:

□ STOP the suspicious action.

□ Do not send additional money.

□ Do not provide passwords, PINs, OTPs or recovery credentials.

□ PRESERVE messages, screenshots and transaction evidence.

□ Identify exactly what was exposed.

□ SECURE the affected account, device or financial service.

□ Review active sessions and recovery methods.

□ REPORT through legitimate official channels.

□ VERIFY information independently.

□ Recover the affected account or service through the official process.

□ Check whether other accounts may also be affected.

□ ESCALATE when the situation is serious or unclear.

□ Watch for recovery scams after the incident.

50. THE MOST IMPORTANT QUESTION

After something goes wrong, do not immediately ask:

“How do I fix everything?”

Ask:

“What is the next safest action?”

That question prevents panic from controlling the situation.

One safe action at a time.

Stop the damage.

Preserve the evidence.

Secure what you can.

Contact the right organisation.

Verify information.

Then recover.

51. IF YOU REMEMBER ONLY ONE THING

A cybersecurity incident does not become safer because you act quickly.

It becomes safer when you act correctly.

When something goes wrong:

STOP.

PRESERVE.

SECURE.

REPORT.

VERIFY.

RECOVER.

ESCALATE.

Do not let fear choose your next action.

Do not let urgency choose your next action.

Do not let an unknown person choose your next action.

And never allow the person who may have caused the problem to become the person you trust to solve it.

VERIFY BEFORE YOU TRUST.

APPLY WHAT YOU LEARNED

Turn understanding into a security habit.

Knowing the definition is only the beginning. The real value of cybersecurity education is being able to recognise the situation and make a safer decision when it happens to you.

How should you use what you learned?

Understanding a cybersecurity concept is useful only when it changes how you make decisions. When you encounter a similar situation in real life, slow down and identify what is being requested before you respond.

Ask yourself who is making the request, what they are asking you to do, what information or access is involved, and whether the request can be independently verified.

Do not allow urgency, fear, authority, familiarity or the promise of a reward to replace independent verification.

What if I still do not understand something?

Cybersecurity concepts can sometimes involve technical terms or situations that are difficult to interpret from a single lesson. If something is unclear, do not guess when the decision could affect your money, identity, account access, device or sensitive information.

You can seek further guidance through the consultancy channel. Explain the situation clearly, but never include passwords, OTPs, PINs, recovery phrases, private keys or other authentication secrets.

Use the consultancy form →

THE VERIFY BEFORE YOU TRUST PRINCIPLEVERIFY BEFORE YOU TRUST.

A convincing message, familiar name, professional appearance or urgent request is not proof of legitimacy. Verify the important facts independently before taking an action that could be difficult to reverse.