What to do during the first hour after a phone scam
If you shared details, opened a link, or sent money, follow this first-hour sequence to contain the damage and create a useful record of the fraud.
NoCall Blog
Clear guides to identify calls, prefixes and scams before you answer.
If you have just realised that a call or message was a scam, do not wait until you have reconstructed every detail. The first hour is for cutting off access, alerting the organisations that may be able to stop a transaction, and preserving evidence. The order matters more than having a perfect explanation.
This is a general protocol, not a replacement for your bank, carrier, or local authorities. Use their official channels only—never call the number that contacted you to “fix” the problem.
Minutes 0–10: end the contact and secure the device
- Hang up and stop replying. Do not negotiate, threaten, or confirm what information you have.
- Stop anything still in progress. If you shared your screen or installed remote-access software, cut the connection and revoke its access. Do not delete the evidence yet.
- Do not open more links or enter more codes. Close the suspicious page and do not enter details to “cancel” a transaction.
- Block the contact and report the message from the phone or app after saving screenshots.
If the scammer still has an open session in an account, change that account’s password from a clean device or the official app first. Do not use the link you received.
Minutes 10–25: stop money movement and protect credentials
Contact your bank or payment provider
Call the number on the back of your card, sign in through the official app, or type the organisation’s address yourself. Explain that you were scammed and ask them to:
- block the card or payment method if it was exposed;
- review and flag the related transactions;
- try to stop, reverse, or recover the payment where their process allows;
- give you a case number and record the time of your report.
Do the same with the payment app, transfer platform, money-transfer company, or gift-card issuer you used. Do not assume the money is gone without asking: each provider has different deadlines and processes, and speed improves your options.
Change reused credentials
Start with your primary email and the accounts that control payments, password recovery, or messaging. Use new, unique passwords, sign out sessions you do not recognise, and turn on multi-factor authentication. If you gave away a one-time code, tell the bank and affected service explicitly.
Minutes 25–40: secure the phone line and handset
If you shared mobile-account information, received a SIM-change alert, or suddenly lost service, contact your carrier through its official channel and ask about recent changes to the line. Ask them to protect the account and review any forwarding, SIM replacement, or profile changes you did not authorise.
If you installed software at the scammer’s request:
- Uninstall it if you know which app it is and revoke its permissions.
- Update the operating system and applications.
- Run the security scan available on the device.
- Change passwords from another device if you suspect the first one remains compromised.
Do not factory-reset the phone before preserving evidence or speaking with support if an investigation may be needed.
Minutes 40–55: preserve the evidence
Keep in a private folder:
- screenshots of conversations, pages, and alerts;
- numbers, names used, dates, and times of each contact;
- visible links and email addresses, without opening them again;
- receipts, amounts, destination accounts, and transaction references;
- installed apps, granted permissions, and any changes you remember.
Write a short timeline while the details are fresh. Do not publish personal documents, codes, or full card details when reporting. To check whether the number is already flagged, search it in NoCall’s directory and submit a report without personal information.
Minutes 55–60: open reporting and follow-up channels
Report the fraud to your country’s police, cybercrime authority, or consumer-protection body using its official process. Ask the bank and payment provider what documents they need and when to send the report or complaint.
Set reminders to review transactions, email, recovery accounts, and notifications over the next few days. Scammers may return pretending to be the bank, support, or a supposed recovery company. Anyone promising to recover your money does not need an urgent fee, your password, or more codes.
What not to do afterwards
- Do not pay a second amount to “release” or “recover” the first one.
- Do not delete conversations, emails, or receipts before saving them.
- Do not publish personal data about the person you think is responsible.
- Do not use phone numbers or links supplied by the caller to contact your bank.
- Do not blame yourself or hide the incident: reporting quickly helps contain it.
If you did not send money but shared information
The risk does not disappear because no charge was made. Change exposed passwords, turn on multi-factor authentication, alert the relevant organisation, and review connected accounts. If you shared identity documents, ask your country’s identity or consumer-protection authority about the preventive measures available to you.
In short
During the first hour, end the contact, secure the device, alert your bank or payment provider through an official channel, change credentials, protect the phone line, preserve evidence, and report the scam. Recovery is not guaranteed, but acting quickly prevents further access and creates a useful trail for every organisation that needs to help.
Sources and review
Reviewed:
Numbering, carrier tools, and reporting procedures can change. Verify sensitive steps with the linked primary authority.
Article details
Editorial content reviewed by NoCall with practical context for spotting suspicious calls and messages.
Received a suspicious call?
Look up the number in NoCall before sharing data, calling back, or clicking any link.
Search a phone number or a company name (Bank of America, Verizon and AT&T...) to check if it has been reported as spam.
