INCIDENT RESPONSE VERIFICATION

Verify the next safest action when something goes wrong.

A security incident creates pressure to act quickly, but the safest response is usually deliberate. This guide turns the incident-response lesson into practical verification checks: stop further harm, preserve useful evidence, secure what you still control, report through legitimate channels, verify what you are being told, then recover and escalate when necessary.

Do not let panic choose your next action.

A suspicious link, wrong transfer, exposed password, lost phone, compromised account or crypto incident can create a second wave of mistakes if you act without understanding what happened.

The core response sequence is: STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE.

Not every incident needs every step, but the sequence provides a safe starting point when you are unsure what to do.

Should I immediately change everything?
Not necessarily. First stop the risky activity and understand what was exposed. Some actions, such as deleting messages, wiping a device or sending more money, can destroy evidence or create additional risk. Make deliberate security changes through official channels.
What if I am not sure whether I was actually hacked?
Do not let fear turn an unexplained technical problem into an assumption of compromise. Check official account activity, transaction records, device behaviour and service notifications. Respond to what you can establish rather than to the most alarming possibility.
Who should I trust after an incident?
Start with the affected organisation's official application, independently verified website or previously trusted contact channel. Do not automatically trust someone who finds you after the incident and offers recovery assistance.
STRUCTURED VERIFICATION

Work through the incident-response checks.

Use these checks whenever something unusual happens and you are deciding what to do next.

STEP 01

STOP the activity that may be causing further harm

Create a pause before the incident turns into a larger loss.

How do I verify it?
Stop entering information, sending money, approving transactions, installing software or responding to suspicious instructions. Do not let the person who may have caused the problem continue directing your next action.
STEP 02

Identify what actually happened

Do not treat every unusual event as proof that you have been hacked.

How do I verify it?
Ask what you clicked, entered, sent, approved, downloaded or installed. Separate a suspicious link that you only opened from a password you entered, an OTP you disclosed, a transaction you approved or software you installed. Match your response to the actual exposure.
STEP 03

PRESERVE the evidence and original context

Evidence can help you understand the incident and report it accurately.

How do I verify it?
Where safe, preserve messages, emails, screenshots, URLs, phone numbers, usernames, transaction references, receipts, wallet addresses, transaction hashes, notifications and dates or times. Keep the original conversation where possible rather than relying only on a cropped screenshot.
STEP 04

Protect sensitive information while preserving evidence

Incident evidence should never become another source of exposure.

How do I verify it?
Do not publicly post passwords, OTPs, PINs, recovery codes, recovery phrases, private keys, full card details or identity documents. If legitimate support needs evidence, use the organisation's official submission process and provide only what is appropriate.
STEP 05

SECURE the affected account, device or financial service

Once you understand the exposure, use the legitimate security controls available to you.

How do I verify it?
Use the official application or website to change exposed credentials, review active sessions, remove unfamiliar devices, review recovery methods and secure affected financial channels. If the device itself may be compromised, consider using a trusted device for important account-security actions.
STEP 06

REPORT through an independently verified channel

Reporting is part of containment and recovery.

How do I verify it?
Contact the relevant bank, payment provider, mobile network, platform, employer or service provider through its official website, application or previously trusted contact route. Do not use phone numbers, links or support accounts supplied by the suspected attacker.
STEP 07

VERIFY the information before taking the next action

During an incident, conflicting stories and fake helpers are common.

How do I verify it?
Compare what people are telling you with official account activity, transaction records, security notifications, trusted applications and other independently verifiable evidence. Do not choose the most convincing explanation simply because it sounds technical or urgent.
STEP 08

RECOVER and ESCALATE when the situation requires it

Some incidents can be handled through normal account recovery; others need specialist or institutional help.

How do I verify it?
Follow the affected service's official recovery process. Escalate when significant money, cryptocurrency, multiple accounts, identity information, business systems, sensitive data or a potentially infected device is involved, or when you cannot determine what happened. Never pay an unverified recovery agent.
REAL-WORLD EXAMPLES

Recognize the safest next move in context.

The incident may look different, but the principle remains: understand the exposure before choosing the response.

Example 1: You entered your bank password on a suspicious page

Stop using the suspicious page and do not enter the OTP that follows. Open your bank's official app or independently verified website, change the exposed password, review account activity and contact the bank through its official channel if appropriate.

Example 2: You gave someone an OTP

Do not assume it was only a six-digit code. Determine what the OTP was intended to authorise, then access the legitimate service independently and review sessions, devices, password, recovery methods and transactions.

Example 3: Your phone is lost

Do not wait for someone to contact you. Use the manufacturer's official device-location or lock tools where available, contact your mobile provider, secure important accounts, review active sessions and preserve the device's IMEI and other relevant information.

Example 4: Your WhatsApp account may have been taken over

Use the official WhatsApp recovery and security process, review linked devices and remove unfamiliar ones. Warn important contacts if necessary, and never give anyone your WhatsApp verification code.

Example 5: Your email may be compromised

Secure the email account through the official provider, review sessions, devices, recovery methods and MFA, and check forwarding rules and filters. Then identify other accounts that depend on that email for recovery.

Example 6: A suspicious APK was installed

Do not assume uninstalling the application solves everything. Stop sensitive activity if appropriate, preserve useful evidence, review what permissions the app received, secure affected accounts and obtain qualified technical help if the device may be compromised.

Example 7: You sent money to a scammer

Do not send another payment because someone promises to recover the first one. Preserve the transaction reference, recipient information, amount, date, time and messages, then contact the financial institution or payment provider through its official fraud or dispute channel.

Example 8: You sent money to the wrong person

Do not automatically classify the incident as a scam or attempt a risky recovery yourself. Preserve the transaction details and contact the financial institution through its official channel to explain that the transfer was made to the wrong recipient and follow its legitimate recovery process.

Example 9: Your crypto wallet shows a zero balance

Do not immediately give your recovery phrase to someone offering to restore the wallet. Check the correct wallet account, network, address, blockchain record, token visibility, contract address and transaction history through trusted sources before concluding that the assets are gone.

Example 10: Someone offers to recover your stolen crypto

The person may know that you lost crypto, but that does not prove they are legitimate. Preserve the blockchain evidence, verify the organisation independently and never provide your recovery phrase, private key or other authentication secret.

Example 11: A transaction failed but your account was debited

Do not immediately repeat the transaction. Check your account, preserve the transaction reference and receipt, record the date and time, and contact the financial institution through its official channel to avoid creating a duplicate payment.

Example 12: You only clicked a suspicious link

Do not assume that clicking alone proves compromise. Determine what happened after the click: whether you entered credentials, downloaded a file, installed software, granted permission, connected a wallet or authorised a transaction. Then take the response appropriate to the actual exposure.

Use the eight-question Incident Test.

1. WHAT exactly happened?

2. WHAT information, credential, device or money was exposed?

3. WHAT should I stop doing right now?

4. WHAT evidence can I safely preserve?

5. WHICH official organisation or service should I contact?

6. HOW can I independently verify what I am being told?

7. WHAT other accounts, devices or services could be affected?

8. DO I need specialist help or escalation?

WHEN TO ESCALATE

Do not try to handle a serious incident alone.

Escalation may be appropriate when significant money, multiple accounts, identity information, cryptocurrency, business systems, sensitive data or a potentially infected device is involved, or when the situation remains unclear.

01

Financial loss or unauthorised activity

Contact the relevant bank or payment provider immediately through its official fraud or dispute channel.

02

Compromised account

Secure the account, review sessions and recovery methods, and follow the service's official security process.

03

Potentially compromised device

Stop sensitive activity and consider qualified technical assistance rather than experimenting with unfamiliar cleanup instructions.

04

Crypto assets moved or exposed

Preserve wallet and transaction evidence and use independently verified wallet or service guidance.

05

Business or sensitive-data incident

Follow the organisation's incident process and involve the appropriate security, management or professional resources.

06

You cannot determine what happened

Do not guess. Preserve what you can and seek legitimate, independently verified assistance.

Watch for the second scam.

Victims can be targeted again by fake investigators, fake support accounts, fake cybersecurity experts and fake recovery services.

Never give a helper your password, OTP, PIN, recovery code, recovery phrase or private key merely because they know about your incident.

VERIFY BEFORE YOU TRUST.

CONTINUE YOUR LEARNING PATH

Put this guidance into practice.

Return to First Response When Something Goes Wrongto practise realistic incident decisions, complete the assessment and continue through the security-improvement loop.

Return to First Response When Something Goes Wrong →