EVIDENCE PRESERVATION VERIFICATION

Verify what happened before you delete, wipe or change the record.

Good incident records help you understand what happened, communicate accurately with a bank or service provider and support legitimate investigation. This guide helps you preserve useful information without exposing secrets, repeatedly interacting with an attacker or destroying important context.

Preserve evidence without preserving the threat.

The goal is not to collect everything. The goal is to keep the information that can establish what happened while stopping the activity that may cause further harm.

STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE

Should I delete a suspicious message immediately?
Not always. If it is safe, preserve the original message and its context before deleting or reporting it. But do not continue interacting with the sender simply to collect evidence. Immediate containment takes priority when the interaction itself creates ongoing risk.
Is a screenshot enough?
A screenshot can be useful, but it may be incomplete or altered. Where practical, preserve the original conversation, email, notification or account record as well. Important claims should be independently verified through the appropriate official system.
Can I send evidence to someone online for help?
Only use a legitimate, independently verified process. Do not send passwords, OTPs, PINs, recovery codes, recovery phrases or private keys. An unsolicited person offering investigation or recovery is not trustworthy simply because they know details about your incident.
STRUCTURED VERIFICATION

Work through the evidence-preservation checks.

Use these checks before deleting messages, wiping devices, disputing transactions or reporting a significant incident.

STEP 01

Stop the risky activity first

Do not continue interacting with the suspected attacker just to collect more evidence.

How do I verify it?
Stop entering credentials, sending money, approving transactions, opening suspicious files or following recovery instructions. If an active threat requires immediate containment, secure the situation first and preserve whatever information can safely be retained.
STEP 02

Record what actually happened

Build your record from observations rather than assumptions.

How do I verify it?
Write down what you clicked, entered, sent, approved, downloaded or noticed. Separate what you directly observed from what someone told you and what you merely suspect.
STEP 03

Preserve the original context

A screenshot alone may not contain enough information to understand the incident.

How do I verify it?
Where safe, retain the original conversation, email thread, notification or account record. Note the sender, timing, exact request, URL, attachment and surrounding messages rather than relying only on a cropped screenshot.
STEP 04

Build a timeline

A simple sequence of events can make a confusing incident easier to understand.

How do I verify it?
Record approximate dates and times for messages, clicks, credential entry, transactions, alerts and reports. Do not invent precision you do not have. A clear approximate timeline is better than false exactness.
STEP 05

Preserve transaction and account records

Financial and account incidents often depend on identifiers that may be needed later.

How do I verify it?
Keep transaction references, receipts, account notifications, login alerts, device information and relevant security events. For crypto incidents, preserve wallet addresses, destination addresses, asset, amount, network and transaction hashes. Never include a recovery phrase or private key.
STEP 06

Protect sensitive information while preserving evidence

Evidence can itself contain credentials and personal information.

How do I verify it?
Never publicly share passwords, OTPs, PINs, recovery codes, recovery phrases, private keys or full payment-card information. Use the legitimate submission process of the relevant organisation when sensitive evidence is genuinely required.
STEP 07

Verify important claims independently

A screenshot, receipt or message can be misleading or fabricated.

How do I verify it?
Check important claims against the official account, application, transaction record or independently verified service. A screenshot of payment is not the same as verified payment. A message claiming to be support is not proof of identity.
STEP 08

Preserve, report and escalate appropriately

Evidence is useful when it reaches the right organisation through a trusted route.

How do I verify it?
Report through the affected bank, platform, payment provider, mobile operator, employer, cryptocurrency service or appropriate authority using an independently verified channel. Escalate when significant money, crypto, sensitive data, multiple accounts or a potentially compromised device is involved.
REAL-WORLD EXAMPLES

Recognize what should be preserved in context.

The safest evidence process protects both the record and the person handling it.

Example 1: A suspicious WhatsApp message

Instead of deleting it immediately, preserve the original conversation where safe, record the sender, time, wording and link, and avoid interacting further. Do not forward the message to random people for investigation.

Example 2: A fake payment screenshot

Keep the screenshot and surrounding conversation if appropriate, but verify the payment in your own account. A screenshot is evidence of what someone displayed, not proof that money actually arrived.

Example 3: An unexpected bank transfer

Record the transaction reference, amount, date, time and relevant notifications. Then contact the bank through its official channel. Do not use a suspicious caller's explanation as your source of truth.

Example 4: A crypto transaction you did not authorise

Preserve the wallet address, destination address, asset, amount, network and transaction hash. Do not send another transaction to 'reverse' it and never provide your recovery phrase or private key.

Example 5: You entered a password on a suspicious website

Record the URL, approximate time and what happened. Do not revisit the site to collect more evidence. Secure the affected account through its official service and preserve the relevant security alerts.

Example 6: A suspicious APK was installed

Do not repeatedly open the application to investigate it. Preserve useful information about the app, permissions and installation, stop sensitive activity if appropriate, and seek legitimate technical assistance if the device may be compromised.

Example 7: A suspicious email attachment

Keep the original email and relevant metadata where practical, but do not repeatedly open the attachment or upload it to random analysis websites. Use an appropriate security or professional process if analysis is required.

Example 8: An account-security alert

Record the date, time, device information and action described by the alert. Do not automatically click the alert's link. Open the official service independently and verify the security event there.

Example 9: Someone claims to be an investigator

The person says they need your screenshots and OTP to investigate. Preserve the evidence yourself and verify the organisation independently. Never surrender authentication secrets merely because someone claims to be investigating.

Example 10: You are tempted to factory-reset your phone

If there is no immediate active threat requiring a wipe, pause before resetting. Consider what evidence may be lost and obtain appropriate guidance. If immediate containment is necessary, prioritise safety and document what you can first.

Example 11: You sent money to a scammer

Preserve transaction references, receipts, messages, numbers and timestamps. Do not pay another person who promises recovery. Contact the financial institution through its official fraud or dispute channel.

Example 12: You only clicked a suspicious link

Record the link and context if safe, then determine what happened after the click. Do not claim that the device was definitely compromised unless the evidence supports that conclusion.

Use the eight-question Evidence Test.

1. WHAT happened, based on what I actually observed?

2. WHEN did each important event happen?

3. WHO or WHAT was involved?

4. WHAT evidence can I preserve without creating another risk?

5. HAVE I preserved the original context?

6. HAVE I protected passwords, OTPs, PINs and recovery secrets?

7. CAN I verify the important facts through an independent official source?

8. WHO is the correct organisation to report this to?

WHAT A GOOD INCIDENT RECORD CONTAINS

Keep facts, context and actions together.

01

Incident description

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

02

Date and approximate time

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

03

Account or device involved

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

04

What was observed

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

05

What information was exposed

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

06

Messages, alerts or screenshots preserved

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

07

Transaction references or hashes

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

08

Actions already taken

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

09

Organisation contacted

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

10

Current status and next step

Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.

Remember the rule.

Preserve useful information. Protect sensitive information. Verify important facts. Report through legitimate channels.

VERIFY BEFORE YOU TRUST.

CONTINUE YOUR LEARNING PATH

Put this guidance into practice.

Return to Preserve Evidence and Report to practise evidence-preservation decisions, complete the assessment and continue through the security-improvement loop.

Return to Preserve Evidence and Report →