
What to Do After an Online Scam
Immediate steps to protect your accounts, preserve useful digital evidence and avoid making the situation worse.
Clear, practical resources for people dealing with digital incidents, investigations and evidence. Learn what to preserve, what to avoid and when specialist forensic support may help.
Our guides explain the forensic side of common incidents in plain English, with practical steps designed to protect evidence and reduce avoidable mistakes.

Immediate steps to protect your accounts, preserve useful digital evidence and avoid making the situation worse.

A practical introduction to protecting digital material so it remains useful, explainable and defensible.

Contain the incident while preserving the logs and system evidence needed to understand what actually happened.
Printer-friendly, two-page checklists for fast-moving incidents. Keep them, share them internally or use them as a first-response prompt before specialist advice is available.
What to preserve, who to contact and what not to delete after a suspected scam.
Download PDF ↓Immediate actions for invoice diversion, mailbox compromise and executive impersonation.
Download PDF ↓Contain affected systems while protecting logs and evidence needed for investigation.
Download PDF ↓Secure the account while preserving login history, alerts, sessions and account changes.
Download PDF ↓Preserve messages, account identifiers and context without escalating contact.
Download PDF ↓Protect company evidence before devices, logs or accounts are changed.
Download PDF ↓Immediate steps to protect your accounts, preserve useful digital evidence and avoid making the situation worse.
A practical introduction to protecting digital material so it remains useful, explainable and defensible.
Contain the incident while preserving the logs and system evidence needed to understand what actually happened.
What CDR data can show, what it cannot show, and why careful interpretation matters.
Why deletion does not always mean disappearance, and what affects the chances of recovering message evidence.
Why the message body is only part of the evidence and how headers, routing and account activity add context.
What happens during a professional mobile examination and why scope, access and preservation all matter.
How a clear handling record supports confidence in where evidence came from and what happened to it.
What to do - and what not to do - before handing over a computer, phone or storage device.
The key elements that make a forensic report clear, useful and capable of being scrutinised.
How to protect evidence and contain risk when an employee may have copied, removed or misused company information.
Practical steps for preserving posts, profiles and messages with enough context to remain useful later.
If a device, account or digital record may matter, avoid unnecessary changes. Keep the original material available, record what happened and preserve the wider context rather than only isolated screenshots.
We can help you assess what evidence may exist, how it should be preserved and the most appropriate next step.