If you think a website scammed you, stop using it and contact the company that handled your payment as soon as possible. Then secure any affected accounts or device, preserve evidence without returning to the site, and report the conduct through the appropriate official channels. Reports can help investigators connect cases and platforms assess warnings or policy violations, but they don't guarantee a takedown, refund, or personal response.
This article is for U.S. consumers. The best next step depends on whether you paid, what information you shared, and whether the site involved phishing, malware, impersonation, or an online purchase.
What to do first
- Stop interacting with the site or scammer. Don't click more links, download files, enter additional information, or pay a "verification," "tax," or "recovery" fee.
- Contact the payment provider. Use the number on your card or bank statement, or the provider's official app. Don't use contact information displayed on the suspicious site. Ask about fraud review, a payment recall, a stop payment, or a dispute. Do this even if you haven't yet gathered perfect evidence.
- Secure compromised accounts. From a trusted device, change any reused passwords, starting with your email and financial accounts. Turn on multifactor authentication, review recent sign-ins and recovery details, and sign out unfamiliar sessions.
- Check the device and identity information you exposed. If you installed software or gave someone remote access, disconnect the device from the internet and contact a trusted technician or your employer's IT team. If you shared your Social Security number or other identity data, consider a fraud alert or credit freeze through the official credit bureaus.
- Save evidence before deleting anything. Keep original messages, receipts, transaction records, and downloaded files in a secure location.
- File the relevant reports. ReportFraud.ftc.gov is a starting point for consumer fraud. Use the FBI's Internet Crime Complaint Center for internet-enabled crime, and report a phishing or malware URL through Google Safe Browsing.
If the site involved investments, commodities, or a trading platform, the CFTC's fraud-response guidance also recommends acting quickly, keeping records, contacting financial institutions, and reporting suspected fraud.
Choose the right reporting route
| Reporting route | Best use | What it does not do |
|---|---|---|
| FTC ReportFraud | Consumer fraud, impersonation, deceptive business practices, and online purchases that went wrong | It doesn't itself reverse a payment or guarantee an individual refund |
| Internet Crime Complaint Center | Phishing, stolen credentials, account takeovers, online financial fraud, cryptocurrency scams, and other cyber-enabled crimes | IC3 says it can't respond directly to every submission |
| Google Safe Browsing | A URL that appears to be phishing or distributing malware | It isn't a financial recovery or general legal complaint process |
| Bank, card issuer, payment app, or wire provider | A payment you made or an account that may have been compromised | Available recovery options depend on the payment method, timing, and provider rules |
| State consumer protection office or local police | Significant losses, identity theft, threats, or a local business connection | A report doesn't guarantee prosecution or repayment |
These routes serve different purposes, so you may use more than one. A payment dispute asks a provider to review a transaction. An FTC or IC3 report gives information to agencies that may identify patterns or investigate conduct.
Save evidence without revisiting the scam site
Don't keep logging in or returning to the website just to gather proof. Use information already stored in your browser history, email, text messages, bank records, and downloads folder.
Record:
- The complete website address, including the domain, page path, and any redirect you saw
- Screenshots showing the address bar, offer, checkout page, error message, or fake login screen
- The date and time of each interaction
- How you found the site, such as a search result, advertisement, email, text, social media post, or QR code
- The name the site used, along with its phone number, email address, physical address, and claimed business affiliation
- Payment confirmations, statements, receipts, invoices, wire details, and transaction IDs
- The amount lost and the payment rail used, such as a credit card, debit card, ACH transfer, wire, cryptocurrency, or peer-to-peer app
- Messages, emails, and caller details, including email headers if you know how to preserve them
- Personal information or account credentials you shared
Keep original files unchanged and make a working copy if you need to redact sensitive details. Don't include passwords, Social Security numbers, full bank account numbers, or unnecessary identity documents in a general complaint.
A short timeline can make the report easier to review:
Website: [exact URL]
First contact: [date and source]
What the site promised: [short description]
What happened: [steps you took and what went wrong]
Payment: [date, amount, method, recipient, and transaction ID]
Information shared: [type of information, without the actual secret]
Actions taken: [bank call, password change, and report numbers]
Report the website to the FTC
Use ReportFraud.ftc.gov and choose the category that best matches what happened. The FTC accepts reports about scams, fraud, and bad business practices, including impersonation and online purchases that went wrong.
Include as much of the following as you can:
- The exact website URL and any related domains
- How you encountered the site
- What it claimed to sell or represent
- The misleading statement, demand, or event that made you suspect fraud
- Dates, amounts, and payment method
- Contact details used by the scammer
- The type of personal or financial information you provided
- Any bank, card, marketplace, or police report number
The FTC's reporting demonstration shows the information the form requests. After submitting, save the report number and any instructions shown. The FTC explains in its Why Report Fraud guidance that reports help investigators identify patterns, build cases, and share information with other law enforcement agencies.
An FTC report isn't a chargeback request. Contact your bank or card issuer separately, and don't assume that filing with the FTC requires a company to contact you within a particular period.
Report internet-enabled crime to IC3
The FBI's IC3 complaint system is designed for internet-enabled crime. It is especially relevant when a scam website involves phishing, stolen credentials, an account takeover, online investment fraud, cryptocurrency, a fake marketplace, or a payment sent after online contact.
Provide details such as:
- The suspicious URL and any spoofed company or government identity
- Email addresses, phone numbers, usernames, wallet addresses, or payment handles
- The sequence of events and the date of each contact
- The amount and currency of the loss
- Bank, card, wire, cryptocurrency, or P2P transaction details
- Screenshots and relevant messages, following the form's instructions for attachments
- Reports already made to a bank, platform, or local law enforcement agency
Save the confirmation after filing. IC3 says it shares complaints through its network of FBI field offices and law enforcement partners, but it can't respond directly to every submission. A lack of follow-up doesn't mean you should stop protecting your accounts or pursuing payment remedies.
The FBI has also warned about scammers impersonating IC3. Use the official IC3 website rather than a link or phone number sent by someone claiming to recover your money.
Report a phishing or malware URL to Google
If the page is designed to steal login or payment information, or appears to distribute malware, submit the exact URL through Google Safe Browsing's report form. Describe briefly what the page did or requested.
A Safe Browsing report can help Google assess whether a browser warning or another protective action is appropriate. It doesn't replace an FTC or IC3 complaint and doesn't start a refund process. If you found the site through an advertisement, search result, email, social media service, or marketplace, use that product's own reporting control too.
Don't enter a password or payment information into the suspicious page while trying to report it. Type the official reporting address into your browser or open it from a trusted bookmark.
Contact the payment provider through an official channel
The payment method affects what remedies may be available. Give the provider a complete, truthful account of what happened.
- Credit card: Ask the issuer how to dispute the charge. Explain whether the charge was unauthorized or whether you authorized it but received nothing, received a materially different item, or were misled.
- Debit card or ACH transfer: Contact the bank's fraud or electronic-transactions department immediately. Ask whether a stop payment, recall, or dispute is available and what notice deadline or documentation applies.
- Peer-to-peer payment app: Report the transaction inside the app and contact the linked bank or card issuer. An in-app report alone may not recover the money.
- Wire transfer: Call the sending bank and request an urgent recall or fraud review. Provide the recipient information, amount, date, and confirmation number.
- Cryptocurrency: Contact the exchange or service used to send the funds. Provide the wallet address, transaction hash, and receiving address. Recovery is uncertain, but delay can reduce the provider's ability to act.
- Marketplace or subscription: Use the marketplace's official dispute process and review the merchant's cancellation or refund procedure. Save the listing and its terms.
Never describe an authorized payment as unauthorized just to improve the chance of a reversal. Ask the provider which dispute category fits the facts.
Notify the impersonated company and other platforms
Use the official support or abuse channel for a company the site pretended to represent. A real bank, retailer, delivery service, or government agency may list a phishing-report address on its own website.
You can also notify:
- The hosting provider or domain registrar, using contact information from its official website
- The advertising, social media, search, or marketplace platform where you saw the scam
- Your state attorney general or consumer protection office
- Local police if there was a substantial loss, identity theft, a threat, or useful local evidence
These notifications have different purposes. A host or platform might review the site under its policies, while a government report can help investigators connect victims and conduct. None guarantees a takedown order.
Public complaint boards and social media posts aren't substitutes for the FTC, IC3, your financial institution, or the relevant platform. If you warn others publicly, don't post private receipts, account numbers, personal addresses, or links that encourage people to visit the scam site.
Can a report take down a scam website?
Not automatically. The FTC and IC3 collect and analyze complaints; they don't promise to remove every reported domain. Google may use a Safe Browsing report to assess a warning, while a host, registrar, payment company, or advertising platform makes decisions under its own policies.
Scammers may use a new domain, mirror site, or shortened URL. Save the exact address for each one and add it to your records. Don't try to force a takedown by attacking the site, contacting its operator, or sending repeated threats.
What to do after filing
Keep a log of:
- The date and channel of each report
- Confirmation or case numbers
- The person or department contacted at your bank
- Dispute, recall, or fraud-review deadlines
- Any new domains, messages, charges, or account activity
Monitor bank and card statements, email, phone accounts, and credit reports for changes. If you gave away a password, review email-forwarding rules and account-recovery settings. Follow up with the payment provider according to its instructions; a government report and a payment dispute are separate processes.
Be suspicious of anyone who contacts you afterward and promises a guaranteed recovery for an upfront fee. Don't send more money or personal information. Add the new contact to the same incident record and report it through the relevant platform or agency.
Common mistakes to avoid
- Waiting for perfect evidence before calling the bank
- Assuming HTTPS proves that a business is legitimate
- Calling a phone number supplied by the suspicious website
- Filing only a Google report when money was lost
- Sending unredacted identity documents with a complaint
- Deleting messages, receipts, or the scam account before saving them
- Paying a second person who claims to be a recovery agent
- Returning to the site to test whether it is still active
Frequently asked questions
Should I report a scam website to the FTC or IC3?
Often, both are appropriate when the website was used for online fraud. The FTC accepts consumer-fraud reports, while IC3 focuses on cyber-enabled crime. Your bank, card issuer, or payment app still needs a separate report if money moved or an account was compromised.
Will the FTC or IC3 get my money back?
Neither complaint guarantees a refund or reverses a transaction. Contact the payment provider immediately and ask about the remedy for your specific payment method. Government reports support broader investigations and may help connect your case to others.
What if I didn't lose money?
Report attempted phishing, impersonation, or malware through the FTC. Use IC3 when the attempt involves cybercrime, and use Google Safe Browsing when the URL is dangerous. An attempted scam can still provide useful information about a larger campaign.
Should I keep visiting the website to collect proof?
No. Save what you already have, record the exact URL from trusted sources, and avoid entering additional information. A clear timeline is more useful than continued contact with the scammer.
If money or credentials were involved, make the payment-provider or account-security call before spending time on additional reports.