If you paid a scammer or find a payment you did not authorize, report it immediately inside the payment app and to the bank, credit union, debit-card issuer, or credit-card issuer connected to the transaction. Ask whether the payment can be stopped, recalled, reversed, or formally disputed. Save the transaction ID, messages, recipient details, and support case numbers before changing or deleting anything.
What should you do first?
Report the payment first, then secure exposed accounts and devices while preserving the evidence. Do not wait for the scammer to reply or promise a refund.
Start with these steps:
- Open the genuine payment app directly and report the transaction.
- Contact the financial institution that funded it through a verified channel.
- Tell each provider whether you approved the payment or someone initiated it without permission.
- Ask what fraud, dispute, recall, or reversal process applies.
- Record case numbers, names, dates, and promised response times.
- Secure exposed accounts and end unfamiliar sessions.
- Preserve the full conversation and transaction records.
The FTC advises people who paid a scammer to report the transaction to the mobile payment app. Acting quickly improves the chance that a provider can identify an available option, but no recovery method is guaranteed.
Who should you contact about the payment?
Start with the payment service. Use its in-app support, official website, or a phone number you independently verified. Then contact the institution behind the funding source. If the transfer used a debit card, bank account, or credit card, identify that clearly when reporting.
Say:
- the date, time, and amount;
- the recipient’s username, phone number, email, or payment tag;
- the transaction ID;
- how the payment was funded;
- whether you personally tapped Send;
- whether credentials, codes, or device access were stolen;
- when you first noticed the problem.
Do not classify the transaction yourself if you are uncertain. Describe exactly what happened. A payment induced by a false story and a payment initiated after account takeover may be handled differently. Rights and remedies depend on the facts, provider, account type, and funding source.
What evidence should you preserve?
Keep original records when possible, not only cropped screenshots. Export or save the conversation before blocking the account. Do not wipe the phone until you have secured critical accounts and preserved useful evidence, unless ongoing remote access creates an immediate risk.
Save:
- the full payment receipt and transaction ID;
- the recipient profile and account identifier;
- emails, texts, direct messages, voice mail, and call logs;
- the ad, listing, rental, job post, or website;
- URLs and files the scammer sent;
- dates, amounts, and a short timeline;
- support chats and case numbers;
- bank or card statements showing the transaction;
- shipping, pickup, or tracking records, if relevant.
Keep a copy outside the affected phone. Accurate chronology helps providers and law enforcement understand whether the incident involved impersonation, account access, a fake purchase, or another scheme.
When should you change passwords?
Change credentials immediately if you entered them on a suspicious page, shared a password or code, approved an unexpected sign-in, installed a remote-access app, or lost control of the phone. Use another trusted device if someone may still be viewing or controlling the affected one.
Secure the primary email first because it often resets other accounts. Then address the payment service, bank, Google account, mobile-carrier account, social accounts used in the scam, and any other service sharing the same password.
Also:
- end sessions and remove unknown devices;
- replace reused passwords with unique ones;
- enable stronger multifactor authentication;
- review recovery phone numbers and email addresses;
- remove unauthorized linked cards or banks through official support;
- check forwarding rules in the email account;
- review recent payments, transfers, and profile changes.
Applock can add a local PIN or pattern barrier to selected apps on supported devices after the incident. It does not remove an intruder already signed in elsewhere or reverse a transaction.
What if the scammer had remote access to your phone?
Disconnect the phone from Wi-Fi and cellular data if the remote session may still be active. From another trusted device, contact financial providers and secure the email and Google accounts. Tell the bank that screen sharing or remote control was involved.
Record the name of the remote-access app and the permissions it received. After preserving evidence, remove the app and suspicious device-administrator, accessibility, notification, or screen-capture permissions. Run a security scan and update Android before resuming financial activity. If you cannot establish that the device is safe, seek qualified technical help or consider a properly prepared factory reset after protecting evidence and account access.
Where should you report the scam?
Report the incident to the Federal Trade Commission. Internet-enabled fraud may also be reported to the FBI Internet Crime Complaint Center. Depending on the case, you may contact local police or sheriff’s office and your state attorney general.
If a financial company does not address a complaint, the Consumer Financial Protection Bureau accepts complaints about financial products and services. A government report does not itself reverse a payment, so do not delay the provider and bank reports while completing it.
If the scam exposed a Social Security number or other identity data, use IdentityTheft.gov to build a recovery plan. Consider a credit freeze with Equifax, Experian, and TransUnion when identity theft risk warrants it.
How do you avoid a second recovery scam?
Scammers target previous victims with promises to recover lost money, trace a recipient, unlock a frozen transfer, or represent a government agency. They ask for an upfront fee, personal information, remote access, cryptocurrency, gift cards, or another payment-app transfer.
Do not pay. No legitimate recovery process requires sending money to a stranger through a payment app. The FTC warns that anyone requesting financial information or an upfront fee to recover money is a scammer.
Can the money always be recovered?
No. A provider may be able to stop a pending transaction, investigate unauthorized account activity, contact the recipient, or offer a dispute route. The result depends on how the payment happened and whether funds remain available. A report is important even when recovery is uncertain.
Do not let anyone promise a guaranteed refund. Ask each company for its written decision and appeal or escalation options. Keep those records with the original evidence.
PSafe’s analysis of payment-scam recovery
Reporting the payment is only the first part of recovery. The scam may also have exposed your email, phone number, device permissions, identity information, or contacts.
Contact the payment app and funding institution, secure passwords and active sessions, remove unauthorized device access, and preserve receipts, messages, URLs, reports, and case numbers. Finish every step that applies even if the payment provider closes its case.
Frequently asked questions after a payment-app scam
Should I contact the recipient directly?
Do not rely on the recipient or continue a pressured conversation. Report through the app and financial institution. Preserve any reply as evidence.
Should I call a support number from a search result?
Use in-app support, the provider’s official website, or the number on your card or statement. Sponsored results and unofficial listings can lead to fake support.
Does filing a police report return the money?
No. It documents the incident. The payment app and connected financial institution handle transaction reports and available dispute processes.
What if I authorized the payment because I was deceived?
Report it honestly and immediately. State that you approved the transfer after a fraudulent representation. Ask both the app and funding institution what process applies.
What if I did not authorize the transaction?
Say that clearly and identify when you lost access or noticed account changes. Ask the provider and financial institution to investigate unauthorized activity.
Should I erase my phone right away?
First secure accounts from another device and preserve evidence unless active remote access makes delay unsafe. Erasing too early can remove useful records without ending external account sessions.