Situation report active Rev. 2026.4 119 reports 237 source records updated
Real Life After AGI The human survival briefing

What to do after an AI-enabled scam

Follow a first-hour recovery sequence for AI-enabled impersonation, account takeover, identity theft and fraudulent payments, with reporting steps.

Written by
Dwight Ringdahl
Status
Reviewed
Revised
Sources
9 cited
Reading
6 min

Speed matters more than proving it was AI

A cloned voice, convincing message, or synthetic video can make fraud harder to recognize. Once you suspect a scam, do not spend the first hour debating whether the media was generated. The recovery steps depend on what the criminal obtained: money, account access, personal information, control of a phone number, or trust from your contacts.

This U.S.-focused general sequence is not individualized legal, financial, cybersecurity, or law-enforcement advice. Protections and deadlines vary by payment type, facts, institution, and jurisdiction; providers decide claims after reviewing the facts. Use contacts from an official statement, card, app, or independently typed website—not a suspicious message or sponsored search result.

If anyone is in immediate physical danger, contact emergency services. If the scam involved threats, stalking, domestic abuse, child exploitation, or intimate imagery, preserve evidence and seek specialized local help before confronting the suspected offender.

First ten minutes: interrupt the transaction and access

End the call or chat. Do not tell the suspected scammer what you have discovered, install a “refund” tool, share another verification code, or send a second payment to recover the first. Use a different trusted device if you think the current one is remotely controlled or infected.

Call the bank, card issuer, payment app, wire service, cryptocurrency platform, or gift-card company through its official fraud channel. Describe exactly who initiated the transaction, what access or information the criminal obtained, and whether you personally approved a payment. Ask whether it can be stopped, recalled, frozen, reversed, or disputed; request a case number and record the time. Do not guess at a legal label or omit that deception was involved. The Federal Trade Commission’s payment guidance lists different recovery routes because card payments, bank transfers, cash apps, gift cards, wire transfers, and cryptocurrency do not carry the same protections.

If the criminal may control an account, use the provider’s official recovery process. Change the password from a known-clean device, sign out other sessions, revoke unfamiliar devices and app connections, and replace compromised recovery methods. Start with the email account that resets other accounts, then financial, mobile-carrier, cloud, workplace, and social accounts.

Do not delete the suspicious exchange. Screenshots, message headers, transaction identifiers, wallet addresses, phone numbers, usernames, voicemails, and the original media may support recovery and investigation. Preserve them without continuing the conversation.

First thirty minutes: protect identity and phone service

If you disclosed a Social Security number, government ID, answers to security questions, or enough personal data for new-account fraud, begin at the FTC’s IdentityTheft.gov recovery service. It creates a tailored plan and an identity-theft report that businesses may request.

Consider placing a credit freeze separately with Equifax, Experian, and TransUnion. A freeze is free and restricts access to your credit file; it does not protect existing accounts or stop every form of identity fraud. The Consumer Financial Protection Bureau explains freezes and fraud alerts. Keep the confirmation details somewhere secure.

If calls, texts, or mobile service suddenly stopped, contact the carrier’s fraud department from another phone. A criminal may have transferred the number or SIM, allowing interception of codes. Ask the carrier to restore control, add an account PIN or port-out protection, and document the incident. Then replace SMS-based authentication with a passkey, security key, or authenticator app where the service supports it.

If a government ID was exposed, use the issuing agency’s fraud process. The Social Security Administration directs stolen-number reports to the FTC; follow the current SSA identity-theft guidance and review your record through the official SSA site. For a passport, use the State Department’s lost-or-stolen passport channel.

Secure the device without destroying evidence

If you installed remote-access software or granted screen-sharing, disconnect the device from the network. From another device, secure critical accounts and notify any employer security team if work credentials or data were present. Do not rely on closing the remote-control window.

Follow the device maker’s recovery instructions. The FTC advises updating security software, scanning, deleting identified problems, changing exposed passwords, and enabling two-factor authentication. For sensitive data or uncertain compromise, use reputable manufacturer or technician support; refer employer-managed devices to the employer’s incident team. Back up documents carefully before any recommended reset, because restoring malware can recreate the compromise. CISA’s Secure Our World guidance covers passwords, multifactor authentication, updates, and phishing.

Avoid companies that contact you promising guaranteed asset recovery. The FTC warns that recovery scams target people whose losses are already public or known to criminals. No legitimate investigator needs a gift card, cryptocurrency payment, remote access, or secrecy to release recovered funds.

Remaining first hour: report through the right channels

After contacting the provider, report at ReportFraud.ftc.gov and, for internet-enabled crime, the FBI’s Internet Crime Complaint Center. For a recent wire, cryptocurrency transfer, or substantial loss, file promptly with transaction details and contact the local FBI field office. IC3 reports can support pattern detection and sometimes fund freezes, but filing does not guarantee investigation, response, or recovery.

File a local police report when an institution requires it, the loss is substantial, or threats and local offenses are involved. Bring a short chronology and copies rather than surrendering your only evidence. Report impersonated accounts and synthetic intimate imagery to the relevant platform using its dedicated process.

Tell affected people through a channel the attacker does not control. A concise notice is enough: which account or identity was compromised, what requests contacts should distrust, and how you will authenticate real communication. Do not publish unnecessary identity details or attacker instructions.

If workplace systems, customer information, health data, or client funds were exposed, notify the appropriate employer contact promptly. Concealment can make containment and legally required notices harder. Let the organization’s incident team decide regulatory and customer obligations.

Match the response to the payment rail

For a credit or debit card, contact the issuer and ask to replace the card and dispute unauthorized charges. Federal protections and notice periods differ by card and transaction, so do not assume a familiar “zero liability” slogan settles the case.

For an electronic fund transfer, notify the financial institution immediately and ask which error-resolution or fraud process applies. Under the CFPB’s official Regulation E FAQ, a transfer the criminal initiates with credentials obtained through fraud can qualify as unauthorized even when the consumer was tricked into disclosing those credentials. A payment the consumer personally instructs or approves because of a scam may be treated differently. Tell the institution precisely who initiated each transfer; do not accept a slogan as the final analysis, and seek qualified advice for a disputed or consequential claim.

For a wire, contact both the sending institution and receiving institution if known. For a payment app, report inside the official app and to the linked bank or card issuer. For gift cards, retain the card and receipt and contact the issuer. For cryptocurrency, contact the exchange used, preserve the address and transaction hash, and be skeptical of anyone claiming they can reverse a blockchain transaction for an advance fee.

Build a clean incident record

Create a simple log with the time, action, contact method, representative, case number, and promised next step. Save confirmations and send important phone discussions through a secure message when possible. Check statements and credit reports rather than assuming the first account was the only target.

Replace passwords that were reused or exposed, but do not rotate every password impulsively from a compromised device. Update recovery codes and trusted contacts after critical accounts are stable. If a biometric voice or face sample was captured, remember that you cannot rotate your voice; strengthen procedures around it instead. A family safe word is only an alarm signal. Verify unusual requests by calling a known number and asking a question grounded in shared context.

Recovery includes the person, not only the accounts

Fraud works by exploiting urgency, authority, fear, affection, and routine—not by measuring intelligence. Shame delays reporting and helps criminals reuse the same technique. The useful family response is calm containment: “You did the right thing by telling us; now we handle the next step.”

After the immediate incident, review which control failed without expecting one perfect defense. Separate email recovery, stronger authentication, transaction alerts, daily transfer limits, a second-person check for large payments, and rehearsed verification calls reduce different parts of the risk.

No checklist guarantees reimbursement. Acting quickly, contacting the real provider, preserving evidence, and using official reporting routes gives a household the best chance to contain loss—and makes the same synthetic impersonation less likely to work twice.

References

  1. Federal Trade Commission's payment guidance consumer.ftc.gov
  2. IdentityTheft.gov recovery service identitytheft.gov
  3. Consumer Financial Protection Bureau explains freezes and fraud alerts consumerfinance.gov
  4. SSA identity-theft guidance ssa.gov
  5. CISA's Secure Our World guidance cisa.gov
  6. recovery scams consumer.ftc.gov
  7. ReportFraud.ftc.gov reportfraud.ftc.gov
  8. Internet Crime Complaint Center ic3.gov
  9. official Regulation E FAQ consumerfinance.gov

The source index also tracks the manual's recurring core sources and expert positions.

Type to search the manual.

navigate open esc close