GuideOnline fraud

How to report an online scam: where to report it, what evidence you need and how to certify it first

The bank, the platform and the police each do a different job after an online scam, and each one needs evidence captured before the scammer deletes it.

TrueScreen editorial teamPublished 13 min read

To report an online scam, act on three fronts on the same day: your bank or card issuer, the platform where the scam happened, and the police or the national fraud reporting center of your country. In the United States that means ReportFraud.ftc.gov and, for internet crime, the FBI’s IC3. In England, Wales and Northern Ireland it is Report Fraud, run by the City of London Police since December 2025. In the EU, Europol points you to each member state’s own reporting website. Before any of those reports, save the evidence at the source: the listing, the website, the chats, the emails and the payment receipts. Scammers delete profiles and pages within hours, and a screenshot taken after the original has gone cannot be checked against anything.

Key takeaways

  • In the US, scams are reported at ReportFraud.ftc.gov and internet crime to the FBI’s IC3; in England, Wales and Northern Ireland, Report Fraud replaced Action Fraud on 4 December 2025 (City of London Police).
  • Europol does not take complaints: it points EU victims to their national reporting website or, where none exists, to the local police station (Europol, Report Cybercrime online).
  • In the EU, an unauthorized payment must be refunded by the end of the following business day, if reported within 13 months of the debit (PSD2, Articles 71 and 73).
  • A transfer you were tricked into making counts as authorized under PSD2 Article 64; since 9 October 2025, a euro-area bank that fails to run the verification of payee correctly is liable to the payer (Regulation (EU) 2024/886, Article 5c).
  • Every hosting service, marketplaces and social networks included, must offer an easy electronic way to flag illegal content (Digital Services Act, Article 16), so capture the evidence before the report takes it down.

Being scammed online leaves you with two jobs at once: getting the money back while there is still a chance, and filing an online scam report that someone can act on. The usual first reactions, writing to the scammer, arguing, or deleting the chat out of embarrassment, make both harder. What works is a short sequence done in the right order, with evidence that keeps its value when the other side claims it was edited.

How to report an online scam: what to do in the first hours

In the first hours after an online scam, contact your bank, stop any further payments and save the evidence, before you do anything else. Money still moving between accounts can sometimes be held back, while money that has reached the scammer rarely returns. Reports to the platform and the police follow on the same day.

The US Federal Trade Commission gives the same order in its guidance for people who have been scammed: after a bank transfer, “report it to your bank or credit union immediately” and ask them to reverse the payment; after a card payment, call the card issuer straight away. Cryptocurrency payments, the FTC warns, “don’t have the same legal protections”.

If the scam began with someone taking over your email or social media account, record the login alerts and the messages sent in your name before resetting your password, because a reset can wipe that trail; the guide on unauthorized account access lists what to keep. Keep quiet with the scammer, too. Once warned, they delete the listing and move the money on faster.

Where to report an online scam

Report an online scam in three places, because each one does a different job: the bank can freeze or recover money, the platform can remove the account and the content, and the police record the crime and connect it with other cases.

The police and national reporting centers

In the United States, scam reports go to the FTC at ReportFraud.ftc.gov, and internet-enabled crime, from fake investment sites to business email compromise, can also go to the FBI’s Internet Crime Complaint Center (IC3).

In England, Wales and Northern Ireland, Action Fraud no longer exists. Since 4 December 2025 the national service has been Report Fraud, run by the City of London Police, which completed its public launch in January 2026. You can report online or on 0300 123 2040; in Scotland, call Police Scotland on 101.

The European Union has no single reporting desk. Europol’s cybercrime reporting page sends you to your country’s reporting website or, where there is none, to your local police station. For cross-border purchases, eConsumer.gov, run by the International Consumer Protection and Enforcement Network (ICPEN), collects reports and shares them with participating authorities, though it does not resolve individual cases.

The platform where the scam happened (notice and action)

Under Article 16 of the EU Digital Services Act, every hosting service, marketplaces and social networks included, must let anyone flag content they consider illegal through an electronic mechanism that is “easy to access and user-friendly”. Use the report button on the listing, profile or ad and keep the confirmation. For a fake shop or a phishing or clone site, report the scam website to the host and the domain registrar too. A successful report takes the page down, and with it the evidence the police need, so capture it before you press the button.

Your bank or card issuer: stopping payments and getting money back

Whether your bank has to refund an online scam depends on one question: did you authorize the payment? Under Article 64 of the EU’s second Payment Services Directive (PSD2), a payment is authorized only if the payer consented to it. For an unauthorized payment, such as a card used after a phishing page stole your details, you must notify the bank without undue delay and no later than 13 months after the debit date (Article 71). The bank must then refund you immediately, and in any event by the end of the following business day (Article 73), unless it has reasonable grounds to suspect fraud and reports them in writing to the national authority. Your own loss for a lost or stolen payment instrument is capped at EUR 50, unless you acted fraudulently or with gross negligence (Article 74).

A transfer you made yourself because you were deceived counts as authorized, so the automatic refund does not apply. For card payments, ask the issuer for a chargeback, which rests on the card network’s rules rather than on payment law. For transfers in the euro area, ask whether your bank ran the verification of payee required from 9 October 2025 by Regulation (EU) 2024/886: under Article 5c, a bank that fails to carry out the name and IBAN check correctly is liable to the payer.

What evidence you need to report an online scam

The evidence for an online scam report is whatever shows who you dealt with, what they promised and what you paid: the listing or website, the conversation, the emails and the payment records. The mix changes with the type of scam, and so does the item that vanishes first, which is the one to secure before anything else.

Evidence to collect for each type of online scam, where it disappears first and the guide for each case
Type of scam Evidence to collect Where it disappears Guide
Marketplace purchase or fake shop Listing and URL, seller profile, chat, receipt The listing, removed after the sale Marketplace listing scams
Romance scam Profile, dated conversation, every request for money Profile and chat, deleted when payments stop Romance scam evidence
Trading or investment scam Broker site, account dashboard, deposit receipts The dashboard, offline once you ask to withdraw Online trading scam
Vacation rental scam Listing, messages with the “owner”, deposit receipt The listing, pulled within days Vacation rental scam
Phishing and clone websites The message, the link, the cloned page The cloned page, moved to a new domain Phishing and clone sites
Supplier bank details changed on an invoice Original email with headers, invoices, transfer The email thread, when the mailbox is cleaned Invoice IBAN fraud
Payment request from a hacked account Request message, account profile, transfer The messages, deleted by the intruder Payment request from a compromised account
Fake surety bond or guarantee The document, the issuer’s website, the covering email The fake issuer’s website Fake surety bond

Collecting the evidence in this order protects the pieces that disappear first.

  1. Block your cards and alert your bank

    Block any exposed card and ask for pending transfers to be stopped or recalled. Note the time of the call and the reference number.

  2. Certify the listing or website before it disappears

    Capture the listing, the seller’s profile or the broker site while it is online, with its full address and time of capture. Certify the page rather than photographing the screen.

  3. Certify the chats and emails

    Capture WhatsApp chats, Telegram threads and text messages in full, and keep emails with their headers. For screen recordings, see how to submit video evidence with a police report.

  4. Save receipts and statements with the transaction details

    Keep receipts and statements showing the IBAN or account number, amount, date and transaction ID; for cryptocurrency, the wallet addresses and transaction hashes.

  5. Write a dated timeline of what happened

    List each step, from first contact to the moment the other side went silent, and tie each one to the evidence that supports it.

Why screenshots taken later weaken your report

A screenshot taken days after the fact weakens a scam report because the original page or chat may no longer exist, so nobody can compare the image with its source. It shows what was on a screen, not where it came from, when it was captured, or whether anything changed in between.

A screenshot is a copy of what a display showed, stripped of the context that makes digital evidence verifiable: the full web address, the source it was loaded from, the time of capture and a way to prove the file has not been altered since. ISO/IEC 27037, the international guideline for the identification, collection, acquisition and preservation of digital evidence, treats those steps as part of handling evidence properly. Once a listing has been removed or a chat deleted, the screenshot becomes the only version left, and the person you accuse can argue that it was edited, cropped or taken out of context. With the original gone, there is nothing to set against that claim. Screenshots are still how many reports begin, but they are the weakest form of evidence at the moment you need the strongest.

Courts weighing screenshot evidence keep coming back to integrity, and a defense built on edited screenshots is easy to raise and hard to rebut afterwards. Capturing content at the source, while it is live, fixes its digital provenance: what was captured, from where, when and on which device. If you still have evidence to collect, TrueScreen lets you certify it before you file, so the report rests on certified captures rather than on screenshots the other side can dispute.

Certified digital evidence for litigation

Use case

Certified digital evidence for litigation

Listings, chats and emails acquired at the source with a digital seal and a qualified timestamp, ready for your report and any later claim.

Discover more →

How do you certify online scam evidence before you report it?

TrueScreen, the Data Authenticity Platform, captures the listing, the website, the chats and the emails of a scam at the source with a forensic methodology, so the evidence stays verifiable even after the scammer deletes everything. You certify first and report second, and every report carries the same checkable package.

TrueScreen captures content in a controlled environment, following ISO/IEC 27037, and records the source, the date and time and the device. During the acquisition the content cannot be altered; afterwards any change is detectable, because each file has a cryptographic hash and the package is closed with an official digital seal and a qualified timestamp, recognized internationally. Under Article 41 of the eIDAS Regulation, a qualified electronic timestamp enjoys a presumption of the accuracy of its date and time and of the integrity of the data it is bound to. Each certification produces a package with the original files and PDF, JSON and XML reports, which anyone can verify without TrueScreen.

Each type of evidence has its own tool:

  • Chats on WhatsApp, Telegram or SMS: with the TrueScreen app you record the screen while you scroll the conversation. On a computer, WhatsApp Web opened in the Forensic Browser also records the network traffic.
  • Listings, websites and webmail: the Forensic Browser, a desktop application for macOS and Windows, certifies pages as you browse them.
  • Emails: mail certification from the TrueScreen Web Portal certifies the message with its headers and attachments.

Take a deposit paid for a vacation rental that does not exist. Before reporting the listing, you certify it and the host profile with the Forensic Browser, record the chat with the app and certify the transfer receipt. When the listing vanishes two days later, your package still shows it, with the time of capture, ready for the police and your bank.

A small business meets the same problem in another form: the accounts team pays a regular supplier’s invoice after an email announcing new bank details. When the real supplier chases payment, the business certifies that email with its headers, and the earlier invoices, before the mailbox is cleaned up. One package then supports the bank complaint, the verification of payee question and the police report: certified digital evidence prepared through forensic certification before the dispute starts.

Conclusion

Reporting an online scam works best in a fixed order: stop the money with your bank, capture the listing, the chats and the emails at the source, then file with the platform and the police. Certifying the evidence before you report means every report rests on the same verifiable package, even after the scammer deletes the originals. For the details of each case, see the guides on online trading scams, romance scams, holiday rental scams and marketplace listing scams.

FAQ: reporting an online scam

Is it worth reporting an online scammer?

Yes. Reporting an online scam creates the official record that banks and platforms often ask for, and lets investigators link your case with others using the same accounts or websites. In the US you report at ReportFraud.ftc.gov and to the FBI’s IC3; in England, Wales and Northern Ireland, to Report Fraud, which replaced Action Fraud in December 2025.

How do I get my money back after an online scam?

Call your bank or card issuer the same day. In the EU, an unauthorized payment must be refunded by the end of the following business day once reported, within 13 months of the debit (PSD2, Articles 71 and 73). For card payments you made yourself, ask for a chargeback; for transfers, ask for an immediate recall.

Can the police do anything about an online scam?

Yes, although recovering the money is never guaranteed. A police report records the crime, and investigators can link it with reports involving the same accounts, domains or phone numbers. Because many scams cross borders, eConsumer.gov, run by ICPEN, gathers cross-border reports and shares them with authorities in participating countries.

Can you report an online scam without evidence?

Yes, you can report an online scam based on your own account of events and add documents later. Without evidence, though, the bank, the platform and investigators have little to verify. Listings, profiles and chats are often deleted within days, so preserve them at the source, with their address and time of capture, as soon as you suspect a scam.

Will my bank refund a payment I was tricked into making?

Not automatically. Under Article 64 of the EU’s PSD2, a payment you consented to counts as authorized even if you were deceived, so the refund rules for unauthorized payments do not apply. You can still request a card chargeback, and in the euro area a bank that failed to run the verification of payee correctly is liable under Regulation (EU) 2024/886.

How do I preserve evidence of an online scam before reporting it?

Capture it at the source while it is still online. TrueScreen certifies listings and websites with its Forensic Browser, chats with its mobile app and emails through mail certification. Each capture records its source, date and time and is closed with a cryptographic hash, a digital seal and a qualified timestamp, so any later change can be detected.

Sources and verification

Every figure and principle cited here links to its source, listed with type and date. Links checked on the publication date.

Sources cited in this guide to reporting an online scam, with type, date and what each one supports
Source Type Date What it supports
FTC, What To Do if You Were Scammed Document consulted 24/09/2026 First steps with the bank or card issuer; cryptocurrency payments
FTC, ReportFraud.ftc.gov Document consulted 24/09/2026 US scam reporting service
FBI, Internet Crime Complaint Center (IC3) Document consulted 24/09/2026 US reporting of internet-enabled crime
Report Fraud (City of London Police) Document 2025 UK national fraud reporting service since 4 December 2025
City of London Police, Report Fraud launches Document 01/2026 Replacement of Action Fraud and public launch
Europol, Report Cybercrime online Document 03/12/2024 Links to the national reporting websites of EU member states
eConsumer.gov (ICPEN) Document consulted 24/09/2026 Reporting of cross-border scams shared among participating authorities
Regulation (EU) 2022/2065 (Digital Services Act), Article 16 Law 2022 Notice and action mechanism on hosting services
Directive (EU) 2015/2366 (PSD2), Article 64 Law 2015 Consent and authorized versus unauthorized payments
Directive (EU) 2015/2366 (PSD2), Article 71 Law 2015 Notification without undue delay, within 13 months of the debit
Directive (EU) 2015/2366 (PSD2), Article 73 Law 2015 Refund by the end of the following business day
Directive (EU) 2015/2366 (PSD2), Article 74 Law 2015 Payer liability capped at EUR 50
Regulation (EU) 2024/886, Article 5c Law 2024 Verification of payee from 9 October 2025 and bank liability
Regulation (EU) 910/2014 (eIDAS), Article 41 Law consolidated 18/10/2024 Legal effect and presumption of the qualified electronic timestamp
ISO/IEC 27037:2012 Standard 2012 (confirmed 2018) Guidelines for identification, collection, acquisition and preservation of digital evidence

Certify the evidence before you report

Capture listings, websites, chats and emails at the source with a forensic methodology, sealed with a digital seal and a qualified timestamp, so your report rests on evidence anyone can verify.

Start nowRequest a demo

TrueScreen
TS

TrueScreen editorial team

This section is edited by the TrueScreen editorial team, which brings together expertise in digital forensics, the law of digital evidence and regulatory compliance. Every article is checked against primary sources: legislation, published rulings, technical standards and official documentation, always cited in the text.