Stop the risky activity first
Do not continue interacting with the suspected attacker just to collect more evidence.
Good incident records help you understand what happened, communicate accurately with a bank or service provider and support legitimate investigation. This guide helps you preserve useful information without exposing secrets, repeatedly interacting with an attacker or destroying important context.
The goal is not to collect everything. The goal is to keep the information that can establish what happened while stopping the activity that may cause further harm.
STOP → PRESERVE → SECURE → REPORT → VERIFY → RECOVER → ESCALATE
Use these checks before deleting messages, wiping devices, disputing transactions or reporting a significant incident.
Do not continue interacting with the suspected attacker just to collect more evidence.
Build your record from observations rather than assumptions.
A screenshot alone may not contain enough information to understand the incident.
A simple sequence of events can make a confusing incident easier to understand.
Financial and account incidents often depend on identifiers that may be needed later.
Evidence can itself contain credentials and personal information.
A screenshot, receipt or message can be misleading or fabricated.
Evidence is useful when it reaches the right organisation through a trusted route.
The safest evidence process protects both the record and the person handling it.
Instead of deleting it immediately, preserve the original conversation where safe, record the sender, time, wording and link, and avoid interacting further. Do not forward the message to random people for investigation.
Keep the screenshot and surrounding conversation if appropriate, but verify the payment in your own account. A screenshot is evidence of what someone displayed, not proof that money actually arrived.
Record the transaction reference, amount, date, time and relevant notifications. Then contact the bank through its official channel. Do not use a suspicious caller's explanation as your source of truth.
Preserve the wallet address, destination address, asset, amount, network and transaction hash. Do not send another transaction to 'reverse' it and never provide your recovery phrase or private key.
Record the URL, approximate time and what happened. Do not revisit the site to collect more evidence. Secure the affected account through its official service and preserve the relevant security alerts.
Do not repeatedly open the application to investigate it. Preserve useful information about the app, permissions and installation, stop sensitive activity if appropriate, and seek legitimate technical assistance if the device may be compromised.
Keep the original email and relevant metadata where practical, but do not repeatedly open the attachment or upload it to random analysis websites. Use an appropriate security or professional process if analysis is required.
Record the date, time, device information and action described by the alert. Do not automatically click the alert's link. Open the official service independently and verify the security event there.
The person says they need your screenshots and OTP to investigate. Preserve the evidence yourself and verify the organisation independently. Never surrender authentication secrets merely because someone claims to be investigating.
If there is no immediate active threat requiring a wipe, pause before resetting. Consider what evidence may be lost and obtain appropriate guidance. If immediate containment is necessary, prioritise safety and document what you can first.
Preserve transaction references, receipts, messages, numbers and timestamps. Do not pay another person who promises recovery. Contact the financial institution through its official fraud or dispute channel.
Record the link and context if safe, then determine what happened after the click. Do not claim that the device was definitely compromised unless the evidence supports that conclusion.
1. WHAT happened, based on what I actually observed?
2. WHEN did each important event happen?
3. WHO or WHAT was involved?
4. WHAT evidence can I preserve without creating another risk?
5. HAVE I preserved the original context?
6. HAVE I protected passwords, OTPs, PINs and recovery secrets?
7. CAN I verify the important facts through an independent official source?
8. WHO is the correct organisation to report this to?
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Record only what is relevant, accurate and safe to retain. Separate direct observations from assumptions.
Preserve useful information. Protect sensitive information. Verify important facts. Report through legitimate channels.
VERIFY BEFORE YOU TRUST.
Return to Preserve Evidence and Report to practise evidence-preservation decisions, complete the assessment and continue through the security-improvement loop.
Return to Preserve Evidence and Report →