STOP the activity that may be causing further harm
Create a pause before the incident turns into a larger loss.
A security incident creates pressure to act quickly, but the safest response is usually deliberate. This guide turns the incident-response lesson into practical verification checks: stop further harm, preserve useful evidence, secure what you still control, report through legitimate channels, verify what you are being told, then recover and escalate when necessary.
A suspicious link, wrong transfer, exposed password, lost phone, compromised account or crypto incident can create a second wave of mistakes if you act without understanding what happened.
The core response sequence is: STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE.
Not every incident needs every step, but the sequence provides a safe starting point when you are unsure what to do.
Use these checks whenever something unusual happens and you are deciding what to do next.
Create a pause before the incident turns into a larger loss.
Do not treat every unusual event as proof that you have been hacked.
Evidence can help you understand the incident and report it accurately.
Incident evidence should never become another source of exposure.
Once you understand the exposure, use the legitimate security controls available to you.
Reporting is part of containment and recovery.
During an incident, conflicting stories and fake helpers are common.
Some incidents can be handled through normal account recovery; others need specialist or institutional help.
The incident may look different, but the principle remains: understand the exposure before choosing the response.
Stop using the suspicious page and do not enter the OTP that follows. Open your bank's official app or independently verified website, change the exposed password, review account activity and contact the bank through its official channel if appropriate.
Do not assume it was only a six-digit code. Determine what the OTP was intended to authorise, then access the legitimate service independently and review sessions, devices, password, recovery methods and transactions.
Do not wait for someone to contact you. Use the manufacturer's official device-location or lock tools where available, contact your mobile provider, secure important accounts, review active sessions and preserve the device's IMEI and other relevant information.
Use the official WhatsApp recovery and security process, review linked devices and remove unfamiliar ones. Warn important contacts if necessary, and never give anyone your WhatsApp verification code.
Secure the email account through the official provider, review sessions, devices, recovery methods and MFA, and check forwarding rules and filters. Then identify other accounts that depend on that email for recovery.
Do not assume uninstalling the application solves everything. Stop sensitive activity if appropriate, preserve useful evidence, review what permissions the app received, secure affected accounts and obtain qualified technical help if the device may be compromised.
Do not send another payment because someone promises to recover the first one. Preserve the transaction reference, recipient information, amount, date, time and messages, then contact the financial institution or payment provider through its official fraud or dispute channel.
Do not automatically classify the incident as a scam or attempt a risky recovery yourself. Preserve the transaction details and contact the financial institution through its official channel to explain that the transfer was made to the wrong recipient and follow its legitimate recovery process.
Do not immediately give your recovery phrase to someone offering to restore the wallet. Check the correct wallet account, network, address, blockchain record, token visibility, contract address and transaction history through trusted sources before concluding that the assets are gone.
The person may know that you lost crypto, but that does not prove they are legitimate. Preserve the blockchain evidence, verify the organisation independently and never provide your recovery phrase, private key or other authentication secret.
Do not immediately repeat the transaction. Check your account, preserve the transaction reference and receipt, record the date and time, and contact the financial institution through its official channel to avoid creating a duplicate payment.
Do not assume that clicking alone proves compromise. Determine what happened after the click: whether you entered credentials, downloaded a file, installed software, granted permission, connected a wallet or authorised a transaction. Then take the response appropriate to the actual exposure.
1. WHAT exactly happened?
2. WHAT information, credential, device or money was exposed?
3. WHAT should I stop doing right now?
4. WHAT evidence can I safely preserve?
5. WHICH official organisation or service should I contact?
6. HOW can I independently verify what I am being told?
7. WHAT other accounts, devices or services could be affected?
8. DO I need specialist help or escalation?
Escalation may be appropriate when significant money, multiple accounts, identity information, cryptocurrency, business systems, sensitive data or a potentially infected device is involved, or when the situation remains unclear.
Contact the relevant bank or payment provider immediately through its official fraud or dispute channel.
Secure the account, review sessions and recovery methods, and follow the service's official security process.
Stop sensitive activity and consider qualified technical assistance rather than experimenting with unfamiliar cleanup instructions.
Preserve wallet and transaction evidence and use independently verified wallet or service guidance.
Follow the organisation's incident process and involve the appropriate security, management or professional resources.
Do not guess. Preserve what you can and seek legitimate, independently verified assistance.
Victims can be targeted again by fake investigators, fake support accounts, fake cybersecurity experts and fake recovery services.
Never give a helper your password, OTP, PIN, recovery code, recovery phrase or private key merely because they know about your incident.
VERIFY BEFORE YOU TRUST.
Return to First Response When Something Goes Wrongto practise realistic incident decisions, complete the assessment and continue through the security-improvement loop.
Return to First Response When Something Goes Wrong →