If you’ve been scammed, it can feel impossible to navigate. Online scams result in lost funds, loss of access to important accounts or devices, damage to reputation and other harms. And with the rise of highly sophisticated AI scams, it’s harder than ever to protect yourself.
According to the Pew Research Center, around 73% of adults in the US have experienced an online scam. Once it happens, there are steps you can take to minimize these consequences and reduce the risk of getting scammed again.
What to do if you’ve been scammed
If you’ve been scammed, you can take the following steps to minimize the impact:
1. Freeze affected accounts
If your banking or credit information has been compromised, you’ll want to freeze the related accounts immediately to prevent further damage. Most banks have specialized numbers listed on their websites for this purpose. You may also be able to do it through your online banking app or an identity theft protection service, if you have one.
Freezing your account makes it impossible for fraudsters to make payments or withdrawals using the compromised accounts -- but it'll also make it impossible for you to withdraw money from your account. Automatic payments won’t go through, either, so you’ll need to make alternative arrangements with any companies you make regular payments to.
Depending on the type of account and level of damage, you may be able to regain access once you get a new card. However, your account may be frozen until authorities finish investigating the scam and any other suspicious activity. Contact your bank for advice on this matter to determine whether you need to create a secondary account for processing transactions while you wait for the investigation to conclude.
Representatives from your financial institution may also be able to help you restore any lost funds, or at least let you know how likely it is that you’ll get your money back. However, this may be impossible to determine until you’ve taken the next step.
2. Report the scam to the appropriate authorities
After reporting the scam to your bank or financial institution, you’ll want to inform law enforcement authorities. They'll notify you of any options you have for legal action to protect yourself, prosecute your scammers and/or regain any money lost. They may even directly start some of the processes for taking legal action on your behalf.
In the US, you can turn to the Federal Trade Commission for a full list of offices to contact based on the type of scam you’ve been victimized by. If you’re outside the US, you can search for “where to report scams (country)” to find a similar list for your region.
Note: It’s not always possible to get your money back if you’ve been scammed into making a payment, but it’s still worth reporting. This ensures that government agencies are aware of the scam you’ve encountered, which may help them prevent other people from being victimized.
3. Check your identity theft insurance
You likely have some form of identity theft insurance if you’ve purchased a high-level antivirus suite from a company such as Bitdefender or Malwarebytes. If you have this protection and a scam has compromised your identity, reach out to the company offering your identity theft insurance to find out how it can help you recoup your losses.
4. Change your passwords
Change the passwords for any compromised accounts, as well as for any accounts connected to them. And yes, that does mean you should change all of your passwords if your primary email is compromised.
5. Consider switching to passkeys
This would be a good opportunity to try passkeys, which come in cryptographic pairings: one for the website you’re using and one for your device. When you attempt to log in to a website, it scans the device you’re using and only lets you log in if it recognizes it. You’ll also be asked to enter the device’s PIN (or biometric signals like your fingerprint) to complete your login. This is both more secure and less frustrating than trying to keep track of separate passwords for everything (even with a password manager).
6. Switch email addresses, if you must
If an email account has been compromised -- or even if it’s just become so public that it receives inordinate amounts of scams -- you may want to start using another email address. This makes it more difficult for scammers to contact you. However, switching your primary email address can be a real pain, so I only recommend this if you’re massively overwhelmed by scams or have reason to believe your email is permanently compromised.
Alternatively, you can create a secondary email account for use in conjunction with high-risk third-party accounts. This can minimize the risk that your primary email address will be compromised if a third-party account is compromised. Again, this is a major hassle, so I recommend using it only if there are high-risk websites you absolutely must use to complete your work or other essential activities.
Improve your digital hygiene to protect yourself from scams
With your impacted accounts protected from immediate harm, it’s time to protect yourself from future scams by ensuring that all your accounts use strong login credentials and establishing control over where your data appears -- and what data appears -- online.
Use strong login credentials
Use strong passwords and a password manager to reduce the likelihood of scammers accessing your accounts. As mentioned above, you may even want to switch your most important accounts to passkeys, which act as digital key sets -- one for the website and one for your device -- that must match to allow entry to your accounts.
Alternatively, you can set up two-factor authentication to prevent scammers who gain access to your login credentials from accessing your accounts, since they shouldn't have access to the email or phone used for your secondary factor. Using two-factor authentication also means you’ll be instantly notified if someone other than you attempts to log into one of your accounts.
Clean up your digital footprint
Next, you’ll want more control over where your information appears online. You can use McAfee’s online account cleanup tool to quickly eliminate accounts you’re not using or high-risk accounts, reducing the number of ways scammers can access your personal information. Take special care to delete old accounts that store your financial information.
Additionally, you’ll want to remove your personal information from data brokers and people-finder websites. You can do this manually or use privacy monitoring services from companies such as McAfee and Bitdefender. This reduces the amount of information scammers can access to create personalized scam messages.
Finally, we recommend using a high-quality VPN to keep your browsing habits private. Always pay attention to pop-up alerts and opt out of tracking or targeted ads to reduce the amount of information websites can collect about you. You can also use browser safety tools to block trackers that can be used to gather and sell your data to data brokers or even directly to scammers.
Be careful about where you share your information
The information scammers use isn’t always obtained through malicious means, such as data brokers. Much of it is information you’ve posted publicly online. Think twice before you share something personal online, especially on public social media platforms. There are limitations here, especially if your professional life is largely based on your online presence.
If you want to share personal details on a platform such as Facebook, make sure your privacy settings limit who can see your posts. You may also want to go through old posts and delete -- or modify the privacy settings of -- posts that include personal details scammers could use to trick you.
What about scam detectors?
Some antivirus companies, such as Norton, offer scam detectors that let you submit screenshots of suspicious messages, websites or other content. These detectors analyze the submitted content and tell you whether it’s a scam, offering a breakdown of what makes it seem like one. This worked well when I tested it on an email pulled from my spam folder, giving the following analysis:
You can use scam detectors from antivirus companies and other cybersecurity companies to try identifying scams.
Screenshot/CNETHowever, when I ran more personalized scam messages through the online version of Norton Genie (which uses the same parameters as the desktop version), they were deemed safe. This suggests that scam detectors can’t currently be relied upon alone to identify the highly sophisticated scams AI is capable of generating.
Getting scammed hurts, but you can minimize the damage
If you’ve been scammed, it’s important to keep a level head and focus on practical steps to reduce the damage, such as freezing affected accounts.
And while you can’t 100% guarantee you’ll never be scammed again, you can protect your future self from many scams by cleaning up your digital footprint, learning how scammers are using AI and how to identify scams before your data’s compromised.























