Have You Been Hacked? What to Do in the First Hours After Cyber Fraud
The period immediately after a cyberattack or fraudulent transaction matters. Preserve evidence, contain the compromise, contact the relevant financial institutions through verified channels and avoid making the incident harder to investigate.
Original article date: 20 March 2024
Article type: Practical incident guidance
If you have just discovered fraud, act quickly
Being hacked or defrauded can be disorienting. People often realise something is wrong only after money has moved, an account has been taken over, or a bank tells them that a transaction was authorised using credentials or an authentication code associated with their account.
The first objective is not to reconstruct the entire attack immediately. It is to contain the damage and preserve the evidence.
1. Contact the bank or payment provider through a verified channel
Do not trust a phone number, link, SMS or email contained in the suspicious communication itself.
Open the bank's official application, type the bank's known website address yourself, use the number printed on your card, or use another independently verified contact method.
Tell the bank clearly that you are reporting suspected fraud and ask them to:
freeze or restrict affected cards and accounts where appropriate;
stop or recall transfers if still possible;
block compromised online-banking access;
preserve relevant transaction and authentication records; and
provide you with a case or incident reference number.
Speed matters because some payments may still be interceptable or traceable shortly after the event.
2. Do not delete the evidence
Victims understandably want to remove malicious messages immediately. Before doing so, preserve them.
Useful evidence can include:
screenshots of SMS messages and chat conversations;
email messages, including headers where available;
suspicious URLs;
browser history;
payment confirmations;
transaction references;
phone numbers used by callers;
approximate times of calls and messages;
authentication prompts or one-time codes you received; and
any files you downloaded.
Do not post sensitive evidence publicly. Preserve it for the bank, investigators, lawyers or law-enforcement authorities where appropriate.
3. Change compromised credentials from a trusted device
If you suspect that passwords or credentials were captured, change them using a device you reasonably believe is clean.
Start with the accounts that can be used to reset other accounts:
your primary email account;
your banking and payment accounts;
your mobile-provider account;
password managers; and
other important services.
Do not simply add a number to the old password. Use a new, unique password and enable a stronger form of multi-factor authentication where the service supports it.
4. Think about the attack as a sequence
A useful forensic investigation asks: what had to happen for the attacker to succeed?
For example:
How did the attacker first reach you?
What did you click, install or disclose?
Which credentials were exposed?
Did the attacker also have access to your email or phone number?
How was the transaction authenticated?
Where did the money go?
What happened after the transaction?
This sequence is often more useful than arguing immediately about whether you were "hacked," "phished" or "scammed." The evidence should determine the classification.
Common attack patterns
Financial cyber fraud can take many forms. Common patterns include:
Phishing and fake websites
A victim is directed to a website that mimics a bank, retailer, courier or other trusted service. The site captures credentials, card details or personal information.
Social engineering by telephone
An attacker calls while pretending to be a bank or service provider. The attacker may already possess enough personal information to sound convincing and may attempt to obtain passwords, one-time codes or transaction approval.
Account takeover
An attacker gains access to email, online banking or another account and uses that access to reset credentials or initiate transactions.
Payment-card fraud
Stolen card details are used for online transactions, card-not-present payments or other unauthorised purchases.
Combined attacks
The most effective attacks often use several of these techniques together. A phishing site may collect a password, while a caller simultaneously convinces the victim to provide an authentication code.
Be cautious when someone calls claiming to be your bank
A phone call can be genuine, but the fact that the caller knows your name, account details or recent activity does not prove who they are.
If a call becomes security-sensitive, end the call and reconnect through an independently verified bank channel.
Never approve a transaction merely because a caller tells you that approving it will "cancel," "reverse" or "secure" something. Read the authentication message carefully and verify the action independently.
Disputing fraudulent transactions
The exact legal and contractual position depends on the payment method, bank, jurisdiction and circumstances of the incident.
If you believe a transaction was fraudulent:
dispute it promptly in writing;
ask the bank to explain the authentication evidence it relies upon;
request the relevant transaction and fraud-case references;
keep a chronological record of every interaction; and
seek independent legal advice where the loss is significant or the dispute becomes complex.
Do not assume that the first response from a bank is necessarily the final position. Equally, do not assume that every disputed transaction must legally be refunded. The evidence and the applicable rules matter.
How I may be able to help
I have previously assisted victims by reconstructing the technical sequence of an incident and documenting evidence that could be used in communications with banks or legal advisers.
Where I believe I can add value, I may be able to help with:
reconstructing the attack timeline;
analysing suspicious sites, messages or infrastructure;
identifying likely points of compromise;
organising evidence into a clear incident record;
helping you formulate technical questions for the bank; and
referring you to a suitable legal professional where I know one in the relevant jurisdiction.
I cannot guarantee recovery of funds or a particular legal outcome, and I cannot accept every case.
The most important lesson
Cyber fraud succeeds when attackers create urgency, confusion and misplaced trust.
If something feels wrong, move the interaction onto a channel you control. Verify independently. Preserve the evidence. Document what happened. Then work systematically from facts rather than assumptions.
If you would like Musmato to assess a cyber-fraud incident, contact us with a short description of what happened and the date of the incident.