ClearPath PublishingGuides for real life

Guide 05  ·  Outsmart the Scammers

What to Do in the First Hour After Something Goes Wrong

You notice that you cannot sign into your email. Or a friend calls to say she received a strange message from you. Or there is a charge on your statement you know you did not make.

Your stomach drops.

Take a breath, because the next part matters and panic makes it harder. Most of these situations are recoverable, and the first hour is where most of the recovering happens.

Here is what to do, in order. If any step feels beyond you, call a family member and do it together — this is exactly the kind of moment to ask for help, and no one worth knowing will think less of you for it.

1. Start with your email, not the account you are worried about

This surprises people, so it is worth explaining.

Your email is the master key. Nearly every website will let someone reset a password by sending a link to your email address. Whoever controls your email can eventually control everything else, no matter how strong your other passwords are.

So even if the problem appears to be your bank, secure your email first.

Go to your email provider by typing the address into your browser yourself. Do not click a link from any message. Sign in and change the password to something new and unrelated to the old one — a passphrase of a few unrelated words is both stronger and easier to remember than what you probably had.

If you cannot get in because the password has already been changed, use the “forgot password” or account recovery option on the real website. That process usually sends a code to your phone or a second address.

2. Turn on the phone-code step, and check who else is on the list

Once you are back in, turn on the extra step where the account texts a code to your phone.

If it was already turned on, look carefully at which phone numbers and devices are listed. Criminals add their own so they keep getting in after you change the password. Remove anything you do not recognise.

3. Look for the quiet changes

This is the step most people skip, and it is the one that lets a criminal come back.

In your email settings, look for forwarding. Criminals set up a rule that sends a copy of every message you receive to them. You would never notice, and they would see every reset code you request afterwards. Remove any forwarding address that is not yours.

While you are there, check the recovery phone number and backup email address. Make sure both are yours.

If those words mean nothing to you, that is fine and normal. Read this section aloud to whoever is helping you. They will know where to look.

4. Now the accounts with money in them

Call your bank and your credit card company. Use the number on the back of the card, not one from any message.

Tell them plainly what happened. They handle this every day and they will not be surprised or judgemental. Ask them to watch the account and, if a card is involved, to cancel and reissue it.

Report it quickly. Most protections against fraudulent charges depend on you telling them promptly.

5. Change other passwords that were the same

If the stolen password was also used elsewhere, change it there too. The criminals will try it everywhere — that is the first thing they do.

Start with anything holding money or personal information. The rest can wait a few days.

6. Look at what was done while they were in there

Check your sent folder for messages you did not write. Check recent charges. Check your recent posts if it was a social account.

You are not looking to punish yourself. You are looking for anything that needs to be undone or reported.

7. Warn the people in your address book

If the account was used to message others, tell them — a quick note from a secure account, or a phone call to the handful of people most likely to reply to something.

Tell them not to click anything that arrived from you recently. This protects your friends, and it protects your reputation, because it makes clear that whatever they received was not from you.

8. Write down what happened

Dates, times, what you noticed, who you called. If this ever turns into a dispute with a bank or a report to the authorities, having it written down will save you enormous frustration later.

A single sheet of paper is enough.

Two things not to do

Do not let anyone who called you take control of your computer. After a real breach, people are anxious and more willing to accept help — which is exactly the moment these tactics work best. Criminals know this and place calls claiming to be from Microsoft, Apple, or your internet company. Nobody legitimate calls you about a problem with your computer. Ever.

Do not keep it to yourself. Embarrassment is the reason most of this goes unreported, and it is the reason the same criminals come back to the same people. There is nothing shameful here. You were targeted by professionals, which is a statement about them, not about you.

Afterwards

When the immediate work is done, take one quiet look at how it happened. A link in an email? A password used in two places? A step not switched on?

Then fix that one thing. Not everything — one thing. That is how this gets better over time.

And keep the phone number of one family member somewhere obvious. In the hour when something goes wrong, knowing exactly who to call is worth more than any password.

From the book

Outsmart the Scammers

Get the free preview chapter — the introduction plus “Why You, Specifically” — and learn how scammers choose their targets.

Get the free preview