Security Scams that go straight for your money
Reporting a scam: who to tell and what it achieves
Where to report a scam in the US, the UK and the EU, what each body can and cannot do, and how to write a report that is actually useful.
The short answer
- Tell your bank or payment provider first and the national fraud reporting body second, because only the bank can move money back and only it is on a clock.
- Banks treat an unauthorized transaction and a payment you were tricked into making as different cases, so use the right words when you call.
- The US routes are the FTC and the FBI internet crime center, the UK route is Action Fraud or Police Scotland, and the EU has national routes rather than one body.
- The platform where the scam ran is the fastest takedown available, and often the only way the other listings get removed.
- If identity documents were exposed, freeze or flag your credit file as a separate step from reporting the money.
- Most reports do not produce an investigation, but they are what turn scattered complaints into a cluster that gets blocked.
Report a scam in two places first: the bank or payment provider that moved the money, and the national fraud reporting body for your country. Everything else, the platform, the phone network, the credit bureaus, comes after those two. The split matters because only one of those tracks can get money back, and it is the one with a clock running on it. The reporting body almost never recovers anything for you. It collects patterns, and patterns are what close the accounts and websites being used on everybody else.
The four tracks and what each one does
People imagine a single place to report a scam that handles everything. No country has one. There are parallel tracks with different powers, and you may need three of them.
| Who you tell | What they can actually do | How time sensitive |
|---|---|---|
| Your bank, card issuer or payment app | Freeze the card, attempt recall of a transfer, raise a chargeback, refund an unauthorized transaction | Extremely: hours for transfers, days to weeks for card disputes |
| National fraud reporting body | Build intelligence, refer clusters for investigation, occasionally trigger a takedown | Low, but report while you still have the evidence |
| The platform or website | Suspend the account, remove listings, sometimes reverse an in platform payment | High, because scam accounts are abandoned fast |
| Credit bureaus | Freeze your credit file, add a fraud alert, remove accounts opened in your name | High if identity documents or a national ID number were exposed |
| Phone network or email provider | Block sending numbers, feed network level filtering, take down a phishing mailbox | Low, and it is a thirty second job |
The bank comes first, and the wording matters
Before you pick up the phone, work out which of two categories your loss falls into, because banks treat them very differently.
An unauthorized transaction is one you did not make: a cloned card, a payment from an account someone took over. In the EU and the UK, your bank must refund an unauthorized payment promptly unless it can show you acted fraudulently or with gross negligence. In the US, card rules limit your liability sharply if you report quickly, and debit card protection weakens the longer you wait.
An authorized push payment is one you made yourself because you were deceived, and it is the harder case. The UK runs a mandatory reimbursement scheme for these, with caps and exceptions. In the US and most of the EU there is no general right to a refund, and recovery depends on the receiving bank freezing what remains before it moves on.
So say the right thing. For a card: this transaction is fraudulent and I want to dispute it. For a transfer: I was deceived into authorizing this payment, please attempt an immediate recall and record it as fraud. Ask for a case reference. With a transfer, minutes matter, and the sequence to follow in the first hour is worth reading before you call. With a card, the mechanics are set out in how chargebacks and refunds actually work.
If the bank refuses and you think it was wrong, there is a second stage: the Financial Ombudsman Service in the UK, a national financial ombudsman or dispute resolution scheme in EU countries, and in the US the Consumer Financial Protection Bureau or your state banking regulator.
Where to file the national report
This is the track that feels pointless and is not. It is also the one where the route depends on where you live.
In the United States, the Federal Trade Commission takes consumer fraud reports online, into a database shared with law enforcement. For anything involving the internet, including wire transfers and investment fraud, the FBI runs the Internet Crime Complaint Center, usually written as IC3. Large domestic wires reported there very quickly can sometimes be frozen through a recovery process, which is a real reason not to wait a week. If a Social Security number or identity documents were involved, the FTC runs a separate identity theft service that produces a recovery plan and the letters you will need. Your state attorney general has a consumer protection division, and a local police report is mainly a paper trail that banks and insurers ask for.
In the United Kingdom, Action Fraud is the national reporting center for England, Wales and Northern Ireland, and its reports feed the National Fraud Intelligence Bureau, which looks for clusters big enough to assign to a force. Scotland is different: report to Police Scotland directly. Scam texts can be forwarded free to the short code 7726, which spells SPAM on a keypad, and the National Cyber Security Centre runs a mailbox for phishing emails.
In the European Union, there is no single body. Reporting is national: most member states run an online police or cybercrime portal, and every country has a consumer protection authority for trader fraud. For a purchase from a business in another member state, the European Consumer Centres Network handles cross border disputes in your own language. If a company leaked your data rather than defrauding you, that goes to your national data protection authority under the GDPR. Europol coordinates between countries but takes no reports from individuals.
Other countries follow the same shape: a national fraud or cybercrime body, a financial regulator, and local police for a case number. If you are unsure, file with the national body and let it route the case.
The platform is the fastest takedown
If the scam ran through a marketplace, a social network or an email provider, that company can act in hours rather than months, and its abuse team is the only party that can remove the other listings aimed at the next person. Report the profile, not just the message, and include the link.
The same goes for the infrastructure. A phishing site can be reported to its hosting company and to the browser makers, whose warning lists propagate within hours. A scam text can be forwarded to your mobile network. These cost nothing and have visible effects. If it started on a classified site, the evidence worth capturing is covered in how marketplace and ticket scams run from both sides.
Credit files and exposed identity data
Money is one loss and identity data is another. If you handed over a date of birth, a national identity or Social Security number, a passport image, or enough detail to answer security questions, add a fourth track.
In the US, a credit freeze at each of the three major bureaus is free, can be lifted temporarily, and is the most effective single step against new accounts in your name. In the UK, the equivalents are a Cifas protective registration and a note with the credit reference agencies. Most EU countries use a national credit register or a fraud flag through your bank rather than a consumer facing freeze, so ask what is available locally.
Then watch for the quiet symptoms rather than assuming nothing happened, because the early signs of identity theft are usually small pieces of unexpected post. If a company exposed your details rather than you handing them over, the order of work is different and the checklist for a data breach covers it. It is also the moment to check whether an old password is already circulating, using a breach lookup for your email address.
What to keep and how to write it
A useful report is specific. Analysts match on identifiers, not adjectives, so collect these before anything disappears.
- Every payment detail: amount, currency, date, reference, and the account number, wallet address or merchant name that received it.
- The full contact chain: phone numbers, email addresses, profile names and links, and the exact web addresses used.
- Screenshots of the conversation from the beginning, not just the final message, with timestamps visible.
- Original emails saved as files rather than screenshots, because the hidden headers carry routing information.
- Your own timeline in plain sentences: what you were told, what you did, when.
Write the narrative in order, keep it factual, and state the loss as a number. If nothing was lost, report it anyway: an attempted scam with a live phone number and account is as useful to analysts as a successful one. If it began with a link you clicked, note which device, then follow the ten minute response to a clicked phishing link.
What reporting really achieves
Be realistic, because false expectations are why people stop reporting. Your individual report will usually not produce an investigation. Fraud is high volume, often run from another jurisdiction, and forces everywhere triage by scale. The chance of seeing your money again comes almost entirely from the banking track.
What it does do is real, just indirect. Several reports naming the same account, phone number or website are what turn a complaint into a cluster worth acting on. They feed the blocklists your bank uses to stop the next transfer, the takedown requests that kill the site, and the number ranges networks filter. They also shape the rules: reimbursement schemes and payee checking exist because reported volume proved the problem was systemic.
So file it, keep the reference number, then do the part that protects you next time. Change the password on any account touched, turn on a second factor for your email and bank, and tell the people around you what the script sounded like. That last step matters, because the safe account call from a fake fraud team works best on people who are sure they would never fall for anything.
Common questions
Will the police actually investigate my scam report?
Usually not as an individual case. Fraud volumes are enormous and most operations run from other countries, so forces triage by scale and by whether several reports point at the same accounts. Your report is more likely to contribute to a case than to become one. That is still worth twenty minutes, because clusters only form when people file.
Is it worth reporting if I did not lose any money?
Yes, and analysts value these. A near miss still hands over a live phone number, bank account, wallet address or website that is being used on other people right now. Those identifiers are what get blocked and taken down. Near miss reports also arrive earlier in a campaign, when a takedown still prevents losses rather than recording them.
How long do I have to report a fraudulent card payment?
Report the moment you notice, because the protections weaken over time. Card scheme chargeback windows are typically measured in months from the transaction or the expected delivery date, and debit card liability rules in the US tighten sharply after the first days. Waiting never improves your position, so call before you finish gathering evidence.
Where do I report a scam if I live in the EU?
Nationally, in almost all cases. Most member states run an online police or cybercrime reporting portal, and each has a consumer protection authority for trader fraud. For a purchase from a business in another EU country, the European Consumer Centres Network handles cross border disputes in your own language. Europol coordinates between countries but does not take reports from individuals.
Should I report the scammer to the website where it happened?
Yes, and quickly. The platform can suspend the account and remove the other posts within hours, which is faster than any official route. Report the profile rather than only the message, include links to the listing or post, and keep your own screenshots first, because the evidence disappears with the account.