For U.S. consumers, report the exact scam page, not only the domain. First contact the payment provider and secure any exposed accounts; a website report won't stop a payment that is already moving. Then send each part of the incident to the channel that handles it: the FTC for consumer fraud, IC3 for cyber-enabled crime, Google Safe Browsing for harmful URLs, and a registrar or host for an abuse review.
A report can help agencies identify patterns, help browsers warn users, or support an investigation. It doesn't guarantee a refund, a personal response, or removal of the domain.
Protect your money and accounts first
Take these steps before or while you prepare a report:
- Contact the payment provider immediately. Call the number on your card or use the bank's official app. Explain that you paid a suspected scammer and ask which dispute, recall, freeze, or recovery options apply to that payment method. The FTC's guidance on what to do after a scam recommends promptly contacting a bank or credit union for debit-card payments, a gift-card issuer for gift-card scams, and a cryptocurrency exchange for crypto payments.
- Change exposed passwords. If you entered a password on the site, change it from a trusted device anywhere else you reused it. Turn on multifactor authentication and contact the real company if the scam involved one of your accounts.
- Stop communicating with the scammer. Don't pay a supposed recovery fee, provide another verification code, or use a phone number supplied by the website.
- Preserve the site safely. Save the URL from your browser history and take screenshots without logging in again. If the site downloaded software or your device behaves strangely, disconnect it from the internet and seek trusted technical help.
Build an evidence packet
A report that only says "this website is a scam" gives reviewers little to assess. Gather:
- Exact web address: Copy the full URL, including the page path, such as a fake login or checkout page. Record the domain exactly; one altered character can identify a different site.
- How you found it: Say whether you reached the page through an email, text, social-media post, search result, advertisement, or another website.
- Timeline: Include dates, approximate times, and your time zone for visits, messages, payments, account changes, and any promised delivery.
- Payment details: Record the amount and currency, payment rail, merchant or recipient name, transaction or order number, and the account, wallet, or phone number shown to you. Don't include a full card number or online-banking password.
- Screenshots and messages: Capture the address bar, product or login page, checkout screen, confirmation page, emails, text messages, and receipts. Keep original messages and sender details where possible.
- What happened afterward: Describe non-delivery, unauthorized charges, account access, requests for more money, redirects, malware warnings, or other conduct.
Redact passwords, one-time codes, recovery phrases, full financial-account numbers, and unnecessary identity documents before uploading evidence. Keep an unredacted copy in a secure location in case a verified payment provider or law-enforcement form later requests specific information.
Common mistakes when reporting scam websites
1. Reporting only the domain
A domain such as example-shop.com may host many pages. The harmful content could be at a specific login, payment, or redirect URL. Include the full page address and say whether it redirected you elsewhere.
2. Using vague or emotional language
Anger is understandable, but labels and speculation can make a report harder to assess. Replace "These criminals stole everything" with a factual sequence:
On [date] at [time and time zone], I visited [full URL] after seeing [email, advertisement, or message]. The page requested [information or payment]. I paid [amount and currency] by [payment method] to [recipient]. The transaction reference is [ID]. Afterward, [describe what occurred]. I have screenshots, messages, and receipts.
Say "I suspect this is a phishing page" when you haven't confirmed who operates it. Avoid threats, unsupported accusations, or claims about the operator's identity.
3. Sending the complaint to the wrong place
A browser-safety report, consumer-fraud report, criminal complaint, and payment dispute serve different purposes. Sending a URL to Google won't replace a bank dispute, and filing with the FTC won't automatically create a browser warning.
4. Searching for a form through the suspicious site
Scammers sometimes imitate government agencies, banks, brands, and complaint services. Open the official site by typing its address yourself or using a trusted bookmark. Don't give a second scammer your documents or payment information because an unsolicited message promises to "file the report for you."
5. Waiting until the site disappears
A live page, email, advertisement, and payment receipt can be valuable evidence. Save what you can promptly. Don't delay contacting the bank while you assemble a perfect complaint. Submit an accurate report with the evidence available and add details later if the official channel allows it.
6. Expecting every report to produce a response
The IC3 FAQ says analysts review complaints and may forward information to law-enforcement or partner agencies. IC3 doesn't conduct investigations and can't provide the investigative status of a complaint. A lack of follow-up doesn't necessarily mean the report was ignored.
7. Filing inconsistent reports
Reporting the same incident to more than one appropriate channel is reasonable, but use the same URL, dates, amounts, and transaction details each time. Don't inflate the loss or change the story to make it sound more serious.
Choose the right reporting channel
FTC: consumer fraud and deceptive online stores
Use the FTC's consumer-fraud reporting route for:
- A fake online store that accepts payment but doesn't deliver
- A business impersonating a government agency or well-known company
- Deceptive product claims, subscriptions, or online sales practices
- A scam that targeted you even if you didn't lose money
Give the FTC the website, how you encountered it, what was promised, what you paid or shared, and how the business responded. The FTC isn't a substitute for contacting your bank, card issuer, gift-card company, or crypto exchange.
IC3: cyber-enabled crime
File through the official IC3 complaint form when the website or interaction involves online crime, such as:
- Phishing for passwords, payment details, or verification codes
- Account compromise or an attempted takeover
- Malware or a malicious download
- Online fraud involving a website, email account, social platform, or digital payment
- A scam using spoofed domains, search ads, or technical deception
Anyone affected by cyber-enabled crime may file an IC3 complaint, including a person reporting activity involving another country. IC3 analysts review and research submissions before sharing information as appropriate. The service doesn't conduct investigations or provide an investigative status. Use only the official form, not an unofficial site that copies the IC3 name.
Google Safe Browsing: phishing, malware, and harmful URLs
Use Google Safe Browsing to report a URL that appears to host phishing, malware, or other social-engineering content. Include the exact harmful page, not just the brand being impersonated.
This route is intended to help identify risky sites and improve warnings. It isn't a payment-recovery process, a criminal complaint, or a guaranteed takedown request. If you lost money or exposed an account, report that incident separately to your payment provider, the FTC, or IC3 as appropriate.
Registrar, hosting provider, or impersonated brand
A domain registrar or hosting provider may have an abuse channel for phishing, malware, or impersonation. Use the provider's official website and send the exact URL, screenshots, timestamps, and a short factual explanation.
ICANN's contractual compliance complaint page is narrower than a general takedown service. ICANN says it doesn't have contractual authority over country-code domains such as .us or .eu. Its complaint process therefore isn't a universal route for removing a website.
If the site impersonates a bank, marketplace, travel company, or other brand, report the impersonation through that company's verified security or abuse channel too. Don't assume the brand can recover your money or remove a domain it doesn't control.
BBB: an additional business complaint record
A BBB complaint or scam-tracking entry can document a problem involving a business, but it isn't a substitute for a bank dispute, FTC report, IC3 complaint, or browser-safety report. It also doesn't guarantee a refund or domain removal. Reach the BBB through its independently verified website, not through a link in an unexpected email.
Should you report to more than one agency?
Sometimes. Use separate channels when they address different parts of the incident:
- Payment provider: Attempt to stop or dispute the payment.
- FTC: Record consumer fraud or deceptive business conduct.
- IC3: Report the cyber-enabled crime and its technical details.
- Google Safe Browsing: Report a phishing, malware, or harmful URL.
- Registrar or host: Report abuse to the service responsible for the domain or hosting.
- BBB: Add a business complaint record when it is relevant.
Multiple reports don't guarantee a takedown and aren't a reason to submit duplicate or exaggerated forms. Keep one master timeline so every submission remains consistent.
What to do after submitting a report
Save the confirmation page, complaint number, submitted text, and uploaded evidence. Keep the payment provider's case number separately.
Check your bank and affected accounts for new activity. Continue using only official contact details, and be cautious of follow-up messages claiming to be investigators, recovery agents, or agency representatives. A legitimate agency or provider won't need your password or one-time authentication code to verify the original complaint.
For an ongoing crime, threat to life, or national-security concern, don't wait for an online complaint queue. The FBI's cyber reporting guidance directs people to contact a local FBI field office or use the listed reporting route for those situations. The Department of Justice guidance on reporting internet crime also explains other federal and local reporting options.
FAQ
Will reporting a scam website get it taken down?
Not necessarily. The FTC and IC3 collect and share information for consumer-protection or law-enforcement purposes. Google may use a URL report in its Safe Browsing work, while a registrar or host may review an abuse complaint under its policies. None of these routes guarantees removal.
Should I report to the FTC or IC3?
Use the FTC for consumer fraud and deceptive sales practices. Use IC3 when the incident involves cyber-enabled crime such as phishing, account compromise, malware, or online fraud. If both descriptions fit, you can report to both using matching facts.
What if I spotted the website but lost no money?
You can still report the URL and describe what it requested or attempted to do. Google Safe Browsing may be appropriate for phishing or malware, while the FTC or IC3 may be appropriate for a broader fraud or cybercrime report. State clearly that you didn't make a payment.
Can I attach screenshots?
Yes. Screenshots showing the address bar, page content, payment request, and relevant messages can help. Remove passwords, codes, full account numbers, and other information the recipient doesn't need. Keep the original files securely stored.
What if IC3 never contacts me?
IC3 says it can't provide the investigative status of a complaint. Keep the confirmation information, continue working with the payment provider, and submit new evidence through the official channel rather than relying on an unsolicited follow-up message.