An FAQ scam website is a fake help or support page made to look trustworthy while stealing information, money, or account access. It may copy a company's branding, answer ordinary questions, and then send you to a fake login form, refund page, remote-access request, or cryptocurrency address.

If the page is open now, close it. Don't call a number displayed there, download a file, or enter more information. If you paid or shared account details, contact the bank, card issuer, or payment service through an official channel as soon as possible. Whether you authorized the payment, how quickly you act, and the evidence you have can affect what the provider is able to do. This guidance is for U.S. consumers.

Red flags on fake FAQ websites

Leave the page if you notice several of these warning signs:

  1. A misleading web address
    Look for misspellings, extra words, unusual domain endings, or a domain that uses a brand name as part of a longer address. For example, example.com.security-check.net is controlled by security-check.net, not example.com.

  2. An unexpected link brought you there
    Be cautious with FAQ pages reached through an unsolicited email, text message, pop-up, social media post, or online advertisement. Scammers can buy ads or use copied search content to put fake support pages where people are looking for help.

  3. Pressure to act immediately
    Countdown clocks, threats of account closure, claims that a refund will expire, and warnings about criminal penalties are designed to stop you from checking the story. Genuine support generally gives you a way to verify a request.

  4. Unusual payment instructions
    Gift cards, cryptocurrency, gold, cash sent by courier, or transfers to a personal account are major warning signs. Don't pay a supposed technician, government agent, bank representative, or refund department through these methods.

  5. A request for remote access
    A stranger who asks you to install AnyDesk, TeamViewer, or another remote-access tool may be trying to view passwords, move money, or install malware. A page's claim that your device is infected isn't a reason to grant access.

  6. A login or verification request that doesn't fit
    Be suspicious if an FAQ page asks for your password, one-time security code, Social Security number, full card details, wallet recovery phrase, or a photo of an identity document to answer a basic question.

  7. Alarming browser messages
    A web page can display a fake virus warning or make your device beep. These messages don't prove that your device is infected. Don't call a phone number shown in the alert or download software at the page's direction.

  8. Inconsistent contact details
    The phone number, email address, privacy policy, or company name may not match the organization's official website. Fake chat agents may refuse to identify the business or insist that you stay on the page.

  9. Manipulative cookie and download prompts
    A page that makes “accept” easy but hides “reject,” repeatedly asks for notifications, or pushes an unexpected browser extension may be seeking more access or data than the FAQ requires.

HTTPS and a padlock only show that the connection is encrypted. They don't prove that the site operator is legitimate.

How to check an FAQ page safely

Don't use the suspicious page to verify itself. Instead:

A search result isn't automatically safe. Ads and compromised pages can appear above an organization's genuine support page.

If you entered information or paid a scam website

Take these steps in order. Use a device you trust if you think the original device was accessed remotely or infected.

1. Stop communicating with the scammer

Don't send another payment to “unlock” a refund, fix an account, pay a tax, or recover money. A second demand is often another attempt to exploit someone who has already lost money.

2. Preserve evidence

Before deleting messages or resetting a device, save:

Don't click the links again just to collect evidence. A screenshot or saved message is usually enough.

3. Contact the financial institution that sent the money

Use the phone number on your card or statement, or the institution's official app. Tell the representative that you were targeted by a scam. Ask which fraud claim, payment dispute, stop-payment, or recall procedure applies, and explain accurately whether you entered or approved the payment yourself after being deceived.

For a wire transfer, request a recall immediately. A recall is a request, not a guaranteed reversal. If the funds have already moved, recovery may depend on the receiving bank, the recipient's agreement, and whether the money is still available.

For a card or electronic transfer, ask whether the account, card number, or online-banking credentials should be replaced. Follow the institution's instructions and note any deadline for submitting a written dispute.

4. Secure your accounts

Change reused passwords, starting with your email account, from a device you trust. Then:

If a scammer had remote access, disconnect the device from the internet while the session is active. Contact your employer's IT team for a work device. For a personal device, remove unauthorized software and run a reputable security check before changing passwords from that device.

5. Protect your identity

If you shared a Social Security number or identity documents, consider placing a credit freeze with Equifax, Experian, and TransUnion. A fraud alert can also warn businesses to take extra steps before opening credit. Report identity theft through IdentityTheft.gov and follow its recovery checklist.

Report the fake FAQ website

Reporting won't automatically return your money, but it can help connect related complaints and may help get the page removed.

Include the original message and transaction details. Don't exaggerate or guess; a clear timeline is more useful than a long description.

Recovery options depend on how you paid

The word “FAQ” doesn't determine your refund rights. The payment rail, authorization, timing, account agreement, and applicable consumer-protection rules do.

Payment method What to do first Important limitation
Credit card Contact the card issuer and ask how to dispute the charge or report fraud. A transaction you authorized after being deceived may be handled differently from a charge you didn't authorize. The issuer may require a written dispute by a stated deadline.
Debit card Call the bank promptly, report the transaction, and ask whether the card and account should be replaced. Timing and protection can differ depending on whether the transfer was unauthorized or you approved it.
ACH or other electronic bank transfer Contact the bank's fraud department and ask about a stop, reversal, or claim. The bank's procedures and applicable deadlines depend on the transfer and account type.
Wire transfer Call the sending bank and request an immediate recall and fraud investigation. A completed wire may be difficult to reverse, especially after the funds have moved to another account.
Peer-to-peer payment app Report the transaction in the app and contact the linked bank or card issuer. App policies often distinguish between unauthorized payments and payments the account holder approved.
Gift card Call the gift card issuer using its official number and provide the card and purchase details. Keep the card and receipt. Never buy more cards to recover the balance.
Cryptocurrency Notify the exchange or service involved and provide the wallet address and transaction hash. Blockchain transactions are generally irreversible. Never share a recovery phrase or private key with a supposed recovery agent.

If the scammer obtained your wallet recovery phrase or private key, treat that wallet as compromised. Create a new wallet using a trusted device and move any remaining assets if it's safe to do so. If only a token approval was granted and the wallet itself remains secure, use a trusted wallet interface or blockchain tool to review and revoke that approval.

Be wary of “fund recovery” companies that promise a guaranteed refund, request an upfront cryptocurrency payment, or claim to have special access to law enforcement or banks. Those are common signs of a follow-up scam.

What doesn't prove that an FAQ page is legitimate?

These features can appear on both real and fraudulent sites:

Verify the organization through a separate, trusted route. A polished design, familiar logo, or reassuring chat agent isn't a substitute for that check.

Frequently asked questions

Is an FAQ page with HTTPS safe?

Not necessarily. HTTPS protects the connection between your browser and the site, but it doesn't verify who operates the site. Check the exact domain and confirm the page through the organization's official app or website.

Can my bank reverse money sent to a scammer?

Sometimes, but there's no universal refund guarantee. Contact the bank immediately and ask about the procedure for your payment type. A card dispute, ACH reversal, wire recall, and cryptocurrency recovery follow different processes.

Should I call the phone number on a fake support page?

No. Use a number from your card, statement, product documentation, or a website you reached independently. A scam page may route you directly to the person trying to steal from you.

What if I visited the page but didn't pay?

Close it, avoid downloading anything, and change any password you entered. If you provided sensitive identity or account information, monitor those accounts and consider a credit freeze. You can still report the page to the FTC and the impersonated company.

If you only visited the page, closing it is the next step. If you entered information or sent money, make the call to your bank, card issuer, or payment service through an official channel before responding to anyone who contacts you about recovery.