What To Do After a Scam

I Gave a Scammer My Information — What Should I Do?

What you should do depends on exactly what you handed over. Find your situation below and work through it in order — the first hour matters most.

By SpamCheck Editorial Team·Updated 2026-09-03·5 min read

Quick answer

Act in this order. Passwords: change them from a trusted device, starting with your email account, and turn on two-factor authentication. Card or bank details: call the number on your card and ask them to block and reissue it. Social Security number: place a free credit freeze with Equifax, Experian, and TransUnion and start a recovery plan at IdentityTheft.gov. A verification code: change that account's password and sign out all sessions immediately, because someone was logging in as you. ID documents: report to the issuing agency and freeze your credit. Then report the incident at reportfraud.ftc.gov.

Warning signs to look for

  • Password-reset emails arriving for accounts you did not touch
  • Small unfamiliar charges, often a dollar or two, on a card
  • Login alerts from cities or devices you do not recognise
  • Mail, statements, or verification texts that stop arriving
  • A new account, loan, or credit inquiry you did not apply for
  • Friends or family receiving messages that appear to come from you

If you gave away a password

Change it now, from a device you trust. Do your email account first — it is the master key that resets everything else. Then change the account that was targeted and every other account where you reused that password or a close variation. While you are in each account's security settings, check for devices you do not recognise, unexpected mail-forwarding rules, and recovery phone numbers or addresses that are not yours; attackers add these so they can return later. Turn on two-factor authentication everywhere it is offered, and prefer an authenticator app over text messages where you have the choice.

If you gave away card or bank details

Call your bank or card issuer using the number printed on the card, not a number from any message. Ask them to block the card, review recent activity, and issue a replacement. Look through your own transactions too, including tiny test charges. In the United States, federal rules limit your liability for unauthorised card charges when you report promptly, and debit-card protections are strongest in the first two business days — so speed genuinely matters. Set up transaction alerts before you hang up.

If you gave away your Social Security number

Place a credit freeze with all three major bureaus — Equifax, Experian, and TransUnion. A freeze is free, can be lifted temporarily whenever you need credit, and is the single most effective step against new accounts being opened in your name. Then go to IdentityTheft.gov, which generates a personalised recovery plan and the letters and affidavits you may need. Consider requesting an Identity Protection PIN from the IRS to stop fraudulent tax filings.

If you gave away a one-time verification code

Someone was almost certainly signing in as you at that moment. Change that account's password, then use the security settings to sign out of all other sessions and revoke connected apps. Check for changes to recovery details and forwarding rules. If it was a mobile carrier code, call your provider and ask about a port-out PIN, because SIM-swap attacks are used to take over bank and crypto accounts.

If you sent copies of ID documents

Photos of a driver's licence, passport, or utility bill are used to open accounts and pass identity checks. Freeze your credit, report to the agency that issued the document, and keep a record of what you sent and when. For a driver's licence, contact your state motor-vehicle agency; for a passport, contact the issuing authority. Keep the original scam messages as evidence.

Tell someone and write it down

Keep a simple log: what you shared, when, with whom, and every call you make about it. Institutions will ask for this repeatedly, and it makes disputes far easier. Tell a family member or trusted friend too — not because you did anything foolish, but because a second person notices follow-up attempts you may miss while you are stressed. Scammers rely on embarrassment to keep people silent.

Then close the door on repeat attempts

You are now on a list. Expect more contact, often more convincing than the first attempt, and often claiming to be from your bank's fraud team. Nobody legitimate will ask you to move money to a 'safe account'. If a new message arrives that you cannot immediately dismiss, forward it to check@spamcheck.com and get a plain-English answer before you act on it.

Frequently asked questions

Is a credit freeze the same as a fraud alert?
No. A fraud alert asks lenders to take extra verification steps and lasts a year. A freeze blocks new credit checks entirely until you lift it. Both are free, and a freeze offers stronger protection.
How long should I keep watching for problems?
Stolen data is often used months later, sometimes years. Check your credit reports periodically at annualcreditreport.com, keep transaction alerts switched on, and stay alert to unexpected account notices.
Can I undo the damage myself, or do I need to pay a service?
Every essential step — freezes, fraud alerts, disputes, IRS PINs, and recovery plans — is free through official channels. IdentityTheft.gov walks you through them. Paid recovery services that contact you first are frequently scams themselves.
I only gave my name and email address. Do I need to do all this?
No. That combination is low risk on its own. Block the sender, report the message, and expect a period of increased phishing attempts aimed at your address.

Sources

SpamCheck provides informational risk assessments and cannot guarantee that any message is completely safe. When money or sensitive information is involved, independently contact the organization using a trusted phone number or website.

About SpamCheck

SpamCheck helps people understand suspicious emails by letting them forward the message to check@spamcheck.com and receive a plain-English analysis. This guide was published by SpamCheck and written and reviewed by the SpamCheck Editorial Team.

Related guides