If a website took your money or personal information, don't start by arguing with the seller or filling out every complaint form you can find. First stop further contact, protect your accounts, preserve the evidence, and contact the company that handled the payment. Then report the site through the government, browser, platform, and abuse channels that fit what happened.
This article is for U.S. consumers. Payment-dispute rights and deadlines depend on the payment method, so don't wait for the FTC or FBI to respond before calling your bank, card issuer, or payment app. A report can help identify a pattern of abuse, but it won't automatically remove a domain or get your money back.
What to do first
- Stop interacting with the site. Don't enter more information, download files, or reply to messages from the seller. If the page is still open, save the URL without clicking through the site again.
- Contact the payment provider. Use the phone number on your card, bank statement, or the provider's official app. Don't use a number supplied by the website.
- Change reused passwords. Open the legitimate service through its app or a web address you already know. Change the password and turn on two-factor authentication. If your email password was exposed, change it first because email can be used to reset other accounts.
- Review your accounts. Look for unfamiliar charges, new payment recipients, password changes, and account-recovery requests.
- Preserve the trail. Save the URL, messages, receipts, statements, and transaction details before the seller changes or deletes them.
The FTC's guidance on what to do if you were scammed also recommends asking the company involved in the payment to reverse the transaction.
Build an evidence file
A dated sequence of events is easier to check than a long accusation. Gather what you have:
- Exact web address: Save the complete URL, including anything after the domain name. A fake checkout page may have a different address from the homepage.
- Screenshots: Capture the offer, checkout page, contact information, payment instructions, error messages, and any warning banner. Include the device date and time when possible.
- Original messages: Keep emails, text messages, social posts, and advertisements. Preserve sender addresses and email headers if they're available.
- Transaction records: Note the amount, currency, date, payment method, merchant name shown on your statement, confirmation number, and transaction ID.
- A timeline: Write down how you found the site, what it promised, what you paid or entered, and what happened afterward.
- Information exposed: Record whether you entered a password, card number, bank details, government ID, or other sensitive information.
- Seller contact details: Preserve phone numbers, email addresses, shipping addresses, usernames, wallet addresses, and chat logs.
- Technical clues: If you can obtain them safely, note the registrar, registration date, and hosting information. These are leads, not proof that the site is fraudulent.
Keep the original files in a safe offline location. Don't send passwords, one-time codes, or unnecessary full account numbers in a complaint. Redact sensitive information from screenshots unless the receiving organization specifically asks for it.
Describe the payment accurately. If you authorized a purchase but never received it, call it a non-delivery or merchant dispute. If someone else used your card or account, report the charge as unauthorized.
Try to recover the money through the payment method
The FTC and FBI can collect reports, but they don't operate your payment account. Your card issuer, bank, or payment company is the party that can review a reversal or dispute. Contact it immediately and ask which process, documents, and deadlines apply.
Credit card purchase
For a credit-card purchase that wasn't delivered, was materially different from what was promised, or may otherwise qualify as a billing error, ask the issuer which dispute category applies. The FTC's credit-card dispute guidance says written notice should reach the issuer within 60 days after the first statement showing the error if you want to use the law's billing-error procedure.
Send the notice to the billing-dispute address on the statement, not just to the address where you mail payments. Keep a copy of the letter, receipts, screenshots, and proof of delivery. The FTC says the issuer generally must acknowledge a written complaint within 30 days and resolve the dispute within 90 days.
If the card was used without your permission, say that clearly. If you knowingly paid the fake merchant, describe the non-delivery or deception instead of labeling the transaction unauthorized.
Debit card or bank transfer
Call the bank's fraud or dispute department as soon as possible. Ask whether the transaction can be reversed, whether the card or account should be blocked, and whether the bank needs a written statement.
Debit-card and electronic-transfer protections aren't the same as credit-card billing-error protections. The bank may ask when you noticed the transaction and whether you authorized it. Give a precise account and follow its instructions promptly.
PayPal or another money-transfer app
Use the provider's official dispute or resolution process. Include the transaction ID and explain what happened: an unauthorized payment, an item that never arrived, or deceptive information from the seller.
Don't send another payment to a seller who promises a refund after you pay a fee. Keep the in-app case number and the messages connected to it.
Wire transfer
Contact the wire company and your bank immediately. Ask for a reversal or recall, and provide the recipient information, amount, date, and confirmation number. Acting quickly may give the provider more options, but a reversal isn't guaranteed.
Gift card or prepaid card
Contact the card issuer, report the scam, and ask whether the funds can be frozen or returned. Keep the physical card and the receipt. The FTC's scam guidance specifically recommends preserving both.
Cryptocurrency
Contact the exchange or wallet service used to send the funds, if there is one. Provide the transaction hash, recipient address, and screenshots, and ask what reporting or account-security options are available.
Crypto transfers can be difficult or impossible to reverse. Be especially suspicious of anyone who promises guaranteed recovery or asks for an upfront recovery fee.
Report the scam to the FTC
U.S. consumers can file a report through the FTC's ReportFraud form. It accepts reports about scams, fraud, and bad business practices, including a deceptive site you identified before losing money.
Choose the category that best fits the event. Include:
- The exact website address and any seller or brand name
- How you found the site, such as a search result, advertisement, email, or social post
- What the site promised and what it actually did
- The date, amount, and payment method
- Information you entered or believe was stolen
- Names, phone numbers, email addresses, and account details connected to the site
- A short chronological description of your actions and the seller's response
Save the confirmation or report number. An FTC filing isn't a chargeback request, and it doesn't guarantee that the agency will resolve your individual loss. Continue working with your payment provider.
File an IC3 complaint for internet-enabled crime
The FBI's Internet Crime Complaint Center, or IC3, focuses on cyber-enabled crime. A fake online store, phishing page, account takeover, or internet-based payment fraud can fit that route. Use the IC3 complaint form and follow the form's instructions.
Keep the narrative short and factual. Include the full URL, a dated timeline, payment details, account or identity information exposed, email addresses, phone numbers, and transaction or wallet identifiers. Keep your original evidence even if the form doesn't request every file.
IC3 says it receives a large number of complaints and can't respond directly to every submission. It shares reports with FBI offices and law-enforcement partners, where they may be compared with other complaints.
An IC3 form isn't an emergency-response channel. For an active threat, threat to life, or national-security concern, use the reporting options described in the FBI's cyber guidance, including a local FBI field office or the appropriate emergency channel.
Report phishing or malware to Google Safe Browsing
If the site tries to steal logins, install malware, impersonate a trusted service, or pressure you to reveal sensitive information, submit it through Google Safe Browsing.
This report helps browsers and other services evaluate dangerous web pages. It isn't a payment dispute or police report, and it doesn't guarantee that the domain will be taken down. Don't bypass a browser warning just to collect more screenshots; use the evidence you already saved.
Contact the registrar, host, platform, and impersonated brand
The site may also be visible to a registrar, hosting provider, search engine, social network, advertising platform, marketplace, or the real company being impersonated. Send a factual report to the channels that apply:
- Domain registrar: Use the registrar's abuse channel if the domain is impersonating a brand, collecting payment, or hosting phishing content.
- Hosting provider: If you can identify the host, send its abuse team the same evidence. The registrar and host may be different companies.
- Search engine, social network, or advertising platform: Report the specific ad, profile, post, or search result that led you to the site.
- Impersonated company: Tell the real bank, retailer, government agency, or other copied brand. It may have its own phishing or brand-abuse process.
- Marketplace: If the seller appeared on a marketplace, open a case through the marketplace as well as reporting the seller or listing.
Give each recipient the exact page address, screenshots, the date you saw it, and a brief description of the deceptive conduct. Stick to facts you can support. A registrar or host makes its own decision under its policies, and it may not reply.
Complaint outline you can adapt
Use the outline below for an FTC, IC3, platform, registrar, or hosting report. Change it to match the form's questions.
- Subject: Suspected scam website: [exact website address]
- Date and time: [include your time zone]
- How I found it: [search result, advertisement, email, social media, or referral]
- What the site claimed: [product, service, brand, discount, account alert, or other promise]
- What happened: [purchase not delivered, credentials collected, unauthorized charge, malware, or other conduct]
- Payment details: [amount, date, method, merchant name, and transaction ID]
- Information exposed: [password, card details, bank information, or identity documents]
- People or entities involved: [seller name, email, phone, payment recipient, and impersonated brand]
- Evidence available: [screenshots, original messages, receipts, statements, and chat records]
- Action requested: [investigation, browser warning, review under the site's abuse policy, or help securing the account]
Remove passwords, one-time codes, and unnecessary full financial or identity numbers before submitting. Always start from the organization's official website or app.
Which report should you file?
| Goal | Best first route | What it can and cannot do |
|---|---|---|
| Stop or dispute a payment | Bank, card issuer, or payment provider | Reviews a reversal or dispute under its rules; deadlines and outcomes vary |
| Create a federal fraud record | FTC | Collects reports that can support enforcement and pattern analysis; it isn't a refund service |
| Report cyber-enabled crime | IC3 | Shares internet-crime reports with FBI offices and law-enforcement partners; an individual reply isn't guaranteed |
| Warn browser users | Google Safe Browsing | Evaluates dangerous web pages for warning systems; it doesn't recover money |
| Request action against a domain or page | Registrar, host, platform, or impersonated brand | Reviews the complaint under its own policies; removal isn't automatic |
Filing with more than one relevant organization is reasonable. Use the same dates, amounts, URLs, and payment details in every report so the records don't conflict.
Avoid a second scam during recovery
People who have already lost money are often targeted again. Be wary of anyone who:
- Contacts you unexpectedly while claiming to be from the FBI, IC3, a bank, or another government agency
- Demands an upfront fee, gift card, cryptocurrency payment, or remote access
- Requests your password, one-time code, or complete bank details
- Says a refund is guaranteed if you act immediately
- Asks you to leave an official support channel and continue elsewhere
The FBI's IC3 site warns about scammers impersonating IC3. Start from the official IC3 website rather than from a link sent by a stranger. Never pay someone simply to file a complaint.
Common questions
Should I report a site if I'm not completely sure it's a scam?
Yes, if you can describe specific warning signs or deceptive conduct. Report facts such as a copied brand, a payment request, a false delivery promise, or credential harvesting. Don't present an unverified suspicion as a proven criminal finding.
Should I contact my bank before filing an FTC or IC3 report?
Yes, when money or payment information is involved. The bank or payment provider controls the dispute process and may impose a deadline. File the agency reports afterward or in parallel.
Will reporting to Google shut down the website?
Not necessarily. Safe Browsing reports help identify dangerous pages and support warning systems. The domain may remain online, and Google doesn't decide whether your payment should be refunded.
Can the FTC or IC3 get my money back?
Neither report guarantees repayment. Pursue a reversal through the payment provider first. Keep the agency confirmation numbers because they can help document what happened and connect your complaint with related reports.
What if the scammer used my password or identity information?
Secure the legitimate account immediately, change reused passwords, turn on two-factor authentication, and monitor financial and email activity. Tell the bank or affected service exactly what was exposed. Include the same information in your FTC and IC3 reports.
After each submission, log the date, confirmation number, payment-dispute case, and any follow-up request. Keep that log with your evidence so you can answer the bank, platform, or agency without having to revisit the scam site.