Got a Fake Government Call? Here's What to Do Next
Got a Fake Government Call? Here's What to Do Next
Received a fake government call? Learn how to identify scam calls, protect your personal information, report the fraud and avoid becoming a victim.
● Insights
Got a Fake Government Call? Here's What to Do Next
01
How to Tell if the Call Is a Scam
Learn the common warning signs of fake government calls, from unexpected demands and threats to requests for personal or financial information.
02
What You Should Do During and After the Call
Find out the safest way to respond, including when to hang up, how to verify the caller's identity and where to report the incident.
03
How to Protect Yourself from Future Scam Calls
Discover practical steps to reduce your risk, safeguard your personal information and stay one step ahead of increasingly sophisticated fraudsters.
How to Handle a Fake Government Phone Call
The call sounds official. A badge number, a case number, a warning that your Social Security number has been “suspended.” Your pulse jumps. That reaction is exactly what the scammer is counting on, they’ve spent years perfecting every word of the script to produce it. So what should you do if you get a fake government call? Hang up, document, verify, and report, in that order, and without hesitation.
According to the FTC’s Consumer Sentinel Network, government impersonation scams are consistently among the most reported fraud types in the United States. They work because they weaponize urgency and fear, two things that short-circuit rational thinking faster than almost anything else. At The Digital Resistance, we built this guide specifically so you know what to do before, during, and after one of these calls, giving the scammer zero chance to get what they came for.
This article walks you through every step: what to do while you’re still on the call, how to verify whether any government concern is real, where and how to report what happened, and what to do immediately if you accidentally shared information you shouldn’t have.
Why These Calls Feel So Convincing
How Caller ID Spoofing Fools Even Careful People
Scammers use VoIP tools to place outgoing calls while displaying any phone number they choose on your screen. That means your caller ID can show the actual published number for the IRS, the Social Security Administration, or the FBI, and the call is still coming from a fraudster in a call center thousands of miles away. Seeing an official-looking number on your screen is not a credential; it is a costume.
This technique is called caller ID spoofing, and it requires no advanced hacking skills. VoIP-based spoofing services and web interfaces that enable it are widely available to bad actors. Carriers use call-pattern analytics, spam labels, and authentication frameworks like STIR/SHAKEN (a federal call authentication standard) to flag suspicious calls, but these tools are imperfect and far from foolproof. A spoofed government number can still slip through looking completely clean. The most reliable step you can take is understanding that the displayed number proves nothing about who is actually calling, and independently verifying any agency contact using a number from that agency’s official website or a mailed notice.
The Fear Tactics Designed to Short-Circuit Your Judgment
Government impersonation scammers rely on three core psychological levers: urgency, authority, and consequences. In practice, they blend together fast. Urgency sounds like “you must act today or face arrest.” Authority sounds like “This is Agent Thompson, badge number 4471, calling from the Treasury Department.” Consequences sound like “your account will be frozen within the hour.” Rather than deploying these one at a time, callers layer all three inside the first 60 seconds, before you’ve had a moment to question anything.
Here’s what you need to know: no legitimate federal agency will threaten you with immediate arrest, demand same-day payment, or ask you to pay via gift card, wire transfer, cryptocurrency, or prepaid debit card. These are the tells. Any call that includes these demands is a fake government phone call, regardless of how convincing the caller sounds or what number appeared on your screen.
The Agencies They Most Commonly Impersonate
The IRS and Social Security Administration are the most frequently impersonated federal agencies, and FTC Consumer Sentinel Network data consistently puts them at the top of the list year after year. Medicare, U.S. Customs and Border Protection, and the FBI round out the most common targets. Knowing which agencies get impersonated most often helps you recognize the pattern instantly, because the script rarely changes much between callers.
What Should I Do If I Get a Fake Government Call, Immediate Steps
Hang Up Without Explaining Yourself
The single most important action you can take is also the simplest: end the call. You don’t owe the caller an explanation, a polite goodbye, or a chance to respond. Simply hang up. Engaging the caller, even to challenge their claims or call them out as a fraud, keeps you on the line and gives them more opportunities to pressure you.
According to IRS and SSA guidance, legitimate government agencies will not penalize you for hanging up and verifying a call through official channels. If there is a real issue with your taxes or benefits, it will still be there after you hang up. The scam only works if you stay on the line.
What Never to Do During the Call
Do not confirm your name, date of birth, or the last four digits of your Social Security number, even if the caller frames it as “just verifying your identity.” Do not agree to call them back at a number they provide, and do not stay on the line while you “look something up” or “check your records.” Scammers are skilled at using small confirmations to build a partial profile or to establish just enough trust to push for payment or more sensitive data.
Any caller who resists letting you hang up and verify through official channels is telling you exactly who they are. A real government employee will direct you to the agency’s official contact information; a scammer will insist you stay on the line or call only the number they gave you. That resistance is the tell.
Document Everything Immediately After Hanging Up
As soon as the call ends, write down everything you remember before doing anything else. Memory degrades fast under stress, and you’ll need these details for every report you file. Capture the date and time of the call, the number shown on your caller ID, any name or badge number the caller gave, the agency they claimed to represent, the exact demands they made, and any consequences they threatened.
Keep this documentation somewhere accessible. You’ll reference it when you file with the FTC, when you call a relevant agency’s watchdog, and potentially when you contact local law enforcement. Five minutes of note-taking now saves hours of frustration later.
How to Verify If the Call Could Actually Be Real
The One Rule: Find the Number Yourself
Real government contact is verifiable, but only through contact information you locate independently. Go to the agency’s official .gov website or look at any paper notice you already received in the mail, then call that number directly. For the IRS, the main line for individual taxpayers is 800-829-1040; you can also log in to your IRS Online Account at IRS.gov to check whether any notices or account issues are actually on file. For Social Security inquiries, use the contact information listed at SSA.gov.
Never call back a number the suspicious caller gave you, and never use a number from a text or email they referenced. If you need to look something up online, go directly to the agency’s official .gov site, not a search result that could surface fraudulent pages. The only numbers worth trusting are ones you found through a .gov website or a mailed government notice.
What Real Government Contact Actually Looks Like
The IRS almost always contacts taxpayers first by mail, not phone. The SSA may call, but will never threaten arrest or demand immediate payment. No federal agency will ask you to pay a debt using gift cards, wire transfers, cryptocurrency, or prepaid debit cards, and that rule holds without exception. If the caller’s story doesn’t hold up against even one of these benchmarks, the call was a government impersonation scam.
How to Report the Fake Call to the Right Agencies
Start With the FTC at ReportFraud.ftc.gov
Go to ReportFraud.ftc.gov, click “Report Now,” and select “Impersonator” as the scam category. Enter the details you documented: the caller ID number, any callback number they gave you, the agency they claimed to represent, the exact demands made, and whether any money or personal information was shared. Save the confirmation number you receive when the report is submitted. The FTC uses these reports to identify fraud patterns and pursue enforcement, so your report has real value beyond your own situation. Learning how to report a scam call correctly ensures your information actually reaches investigators.
Report to the Agency-Specific Watchdog
For IRS impersonation calls, report to TIGTA, the Treasury Inspector General for Tax Administration, which specifically investigates IRS impersonation fraud. You can reach TIGTA’s hotline at 800-366-4484. For Social Security impersonation calls, the correct reporting body is the SSA Office of Inspector General fraud hotline at 1-800-269-0271, staffed Monday through Friday from 10 a.m. to 2 p.m. ET; you can also file online through the SSA OIG’s fraud reporting form.
Have your documented call details ready when filing either report: the name the caller used, the number displayed on your caller ID, the date and time, and exactly what was demanded. These specifics are what allow investigators to connect your report to patterns they’re already tracking.
When to Also File With the FBI’s IC3
If you lost money or were coerced into making a payment, file a complaint at IC3.gov, the FBI’s Internet Crime Complaint Center. The IC3 handles financial fraud tied to phone scams, and a report there creates a federal fraud record that can support recovery efforts. Contact your local law enforcement as well if threats were made or if you need an official police report for insurance or banking purposes.
If You Already Gave Them Something, Do This Right Now
If You Shared Info: Call Your Bank and Card Issuers First
If you shared any account numbers, routing numbers, or card details, call your financial institution immediately. Use the number printed on the back of your card or on a prior statement, both are safe options. Avoid using a number from a search result, since fraudulent pages can surface for even major banks; stick to your physical card or a prior statement you already have on hand. Report the contact as fraud, ask the institution to flag the account, and request that any unauthorized transactions be reversed. Ask whether the account or card number needs to be replaced entirely. Minutes matter here.
Freeze Your Credit With All Three Bureaus
If you shared your Social Security number, date of birth, or other identity details, place a credit freeze with all three major bureaus right away. A freeze is free and blocks new credit from being opened in your name. Contact Equifax at 1-888-378-4329, Experian at 1-888-397-3742, and TransUnion at 1-888-909-8872. You must contact each bureau separately, and online or phone requests are typically processed within one business day.
According to FTC guidance, a credit freeze is one of the most effective single actions you can take against identity theft after a data exposure. Save the confirmation PIN or account login each bureau provides so you can lift the freeze later if you need to apply for legitimate credit. Set up fraud alerts as a secondary layer of protection on top of the freeze.
File an Identity Theft Report at IdentityTheft.gov
The FTC’s IdentityTheft.gov walks victims through a personalized recovery plan based specifically on what information was exposed. It generates an official Identity Theft Report that banks, credit bureaus, and other agencies will recognize and act on. If passwords were shared in the call, change them immediately across every account that uses the same credentials, and enable two-factor authentication wherever possible. Don’t wait on this step, credential reuse means one exposed password can unlock multiple accounts fast.
Keep This Phone Scam Checklist Ready Before the Next Call Comes
Download The Digital Resistance Government Scam Response Checklist
The Digital Resistance has put together a free downloadable Government Scam Response Checklist, a single-page reference covering exactly what to do in the first five minutes, what to document, and which agencies to contact. Keep it somewhere you can find it in seconds: print it, screenshot it, or drop it in your notes app. You don’t need to memorize this entire guide; you just need to know where that checklist lives when the call comes in.
Set Up Your Phone to Screen Suspicious Calls Before They Reach You
Enable built-in spam filtering on your phone. Both Android and iPhone have built-in options to label or silence calls from unknown numbers, and your carrier likely offers a call-labeling or blocking service as well. Setting unknown callers to go directly to voicemail is one of the most underused and effective filters available. According to FCC consumer guidance, legitimate agencies leave messages with callback information and reference numbers, scammers typically don’t, because a voicemail gives you time to think, and time is exactly what they don’t want you to have.
You Now Have a Plan
Now you know what to do if you get a fake government call: hang up immediately, document everything while the details are fresh, verify through official .gov numbers you find yourself, and report to the FTC at ReportFraud.ftc.gov plus the relevant agency watchdog. If anything was shared, call your bank, freeze your credit, and file at IdentityTheft.gov without delay. Government impersonation scams count on panic, and a plan is what takes panic off the table.
The scam works on fear. The fix is a plan.
Grab The Digital Resistance Government Scam Response Checklist and keep it somewhere you can find it in 10 seconds. Because the next call is coming, and now you’re ready for it.
Headquarter
12 Belmont, Bath
United Kingdom
Telephone
+447707329924
How to Spot a Social Security Scam
How to Spot a Social Security Scam Before It's Too Late
Social Security scams often use urgent calls, threatening messages and requests for personal information or immediate payment.
● Insights
How to Spot a Social Security Scam Before It's Too Late
01
Recognise the Most Common Social Security Scam Tactics
Fraudsters often impersonate government officials, claiming there's a problem with your Social Security number, benefits or identity. Learn the warning signs that immediately indicate a scam.
02
Red Flags That Should Never Be Ignored
From demands for gift card payments to threats of arrest or benefit suspension, discover the tactics scammers use to create panic and pressure victims into acting quickly.
03
What to Do If You Receive a Suspicious Call or Message
Knowing how to respond can make all the difference. Find out how to verify legitimate communications, report suspected fraud and protect your personal and financial information.
How Social Security Scams Actually Work
Why scammers target Social Security specifically
Most adults in the United States either hold a Social Security number or are connected to someone who receives benefits. Whether you receive payments yourself, hold an SSN, or have a parent or spouse who depends on monthly checks, the SSA touches your life in some way. Scammers exploit that near-universal connection to create instant relevance. The goal is to make the threat feel personal before you have time to question it.
The emotional trigger is precise: a threat to your benefits or your freedom. The combination of a benefit threat and an arrest warning is not accidental, it is a tested script designed to bypass critical thinking and push you into compliance within seconds of answering the phone. That combination works because most people don’t know what the SSA is and isn’t permitted to do.
The multi-channel playbook fraudsters are running in 2026
The scam rarely arrives through one channel anymore. Victims often receive a text or WhatsApp message first, followed by a phone call, and sometimes a follow-up letter that appears to be official correspondence. Each channel reinforces the others, building a false sense of legitimacy through repetition. Researchers note that this cross-channel reinforcement wears down skepticism in a way that a single cold call never could.
Fraudulent emails in 2026 campaigns have included HTML attachments that open fake SSA portals asking for login credentials. Fake postal letters have claimed data breaches requiring recipients to email sensitive documents to “update” their records. Social media direct messages impersonating the SSA have requested payment information outright. The delivery method changes; the underlying pressure does not.
The Three Tactics Fraudsters Rely On Most
Benefit suspension threats and fake arrest warnings
The most common script goes something like this: a caller identifying themselves as an SSA agent tells you that your Social Security number has been “suspended” due to suspicious activity or an unpaid debt, and that law enforcement will arrest you unless you act immediately. Real scam call transcripts include phrases like “your Social Security number has been suspended for suspicion of illegal activity” and “if you do not contact us, your account will be deactivated.” That language is designed to terrify, not inform.
This script targets two fears at once, financial loss and legal jeopardy. It works because most people don’t know what the SSA is and isn’t permitted to do. Here’s the reality: the real SSA will never threaten arrest over the phone, and Social Security numbers cannot be suspended. When a caller says otherwise, you are speaking to a fraudster.
Fake SSA agent calls with spoofed caller ID
SSA impersonator scams use Voice over Internet Protocol systems to display any number they choose on your caller ID, including the real SSA customer service line at 1-800-772-1213. When that number appears on your screen, it looks like a legitimate government call. According to SSA guidance, fraudsters may also use real SSA employee names to add another layer of credibility, which is exactly why caller ID and a name alone cannot confirm the identity of the person on the line.
Federal programs like STIR/SHAKEN work to reduce caller ID spoofing, but they don’t eliminate it, especially through less-regulated VoIP paths. The practical takeaway is straightforward: a convincing caller ID proves nothing. Your response to any unsolicited SSA call should always be to hang up and verify through a number you look up yourself.
Gift cards, cryptocurrency, and wire transfers as payment demands
When a scammer asks for payment, they push specific methods: gift cards from major retailers, cryptocurrency transfers, wire transfers, prepaid debit cards, and mailed cash. These methods share one critical characteristic, they are nearly impossible to trace or reverse once completed. That is not a coincidence. It is the reason scammers insist on them even when a target pushes back.
The real SSA will never, under any circumstances, ask you to pay a debt, resolve a problem, or restore benefits using gift cards or cryptocurrency. If a caller directs you to purchase gift cards and read the numbers over the phone, you are being robbed in real time. Hang up immediately.
Red Flags That Give Every Social Security Scammer Away
The exact phrases and pressure tactics that reveal fraud
Scam calls and messages use a recognizable set of linguistic tells. Watch for phrases like “your benefits will be suspended today,” “you must act before 5 p.m.,” “do not hang up,” and “this is your final notice.” The urgency is manufactured, because a real government agency sends written notices and gives you time to respond through official channels.
A practical rule worth memorizing: any contact that presents a problem, sets a hard deadline, and demands an unusual payment method should be treated as a scam until proven otherwise. That three-part pattern is the clearest signal a contact is fraudulent. No legitimate government communication requires you to buy gift cards to fix your account.
What the real SSA will never do
These are the SSA’s own stated policies, not opinions. The SSA will not demand immediate payment, threaten arrest or legal action for nonpayment, or ask for payment by gift card, cryptocurrency, wire transfer, prepaid debit card, or mailed cash. It will not send unsolicited emails with attachments asking for login credentials. It will not contact you through WhatsApp, social media direct messages, or personal text threads.
If a caller claims to be from the SSA and does any of those things, the call is fraudulent. Knowing this removes the uncertainty that scammers depend on. You no longer have to wonder whether to comply, the answer is always no.
How to Verify Whether an SSA Contact Is Actually Real
Simple steps to confirm a legitimate SSA communication
Hang up or ignore the message. Do not click any link and do not call back any number given to you by the suspicious contact. Go directly to ssa.gov or call the real SSA hotline at 1-800-772-1213, using the number you look up independently, and ask whether there is any issue with your account. If a message claims there’s an urgent problem, contacting the SSA directly will quickly confirm whether that’s true.
Initiating the contact yourself through a verified channel breaks the scam, because fraudsters depend entirely on keeping you inside their pipeline. The moment you hang up and verify through official sources, their leverage disappears.
Where The Digital Resistance fits in
The Digital Resistance is a resource hub for Americans who want clear answers about scams and digital threats without wading through technical jargon. The site includes plain-language guides on government impersonation scams, including SSA and IRS fraud, along with resources on how to flag and report suspicious contacts. It functions as a community-driven safety net, not a product, because protecting people from fraud works better when communities share knowledge together.
What to Do Right Now If You Were Targeted or Shared Your Information
If you haven’t shared anything yet
If you recognized the scam before giving anything up, hang up or delete the message, block the number or sender, and don’t respond. No personal data was exchanged at this stage, but reporting the attempt still matters. The FTC and SSA OIG use data from even failed scam reports to track active campaigns, identify patterns, and issue public Social Security scam alerts.
If you already gave out your SSN or financial details
Act within the first 24 to 48 hours. Speed matters here, the faster you move, the more limited the damage. Work through these steps in order:
- Freeze your credit with all three major bureaus separately. Equifax: 1-800-525-6285 orequifax.com. Experian: 1-888-397-3742 orexperian.com. TransUnion: 1-800-680-7289 ortransunion.com. A freeze blocks most new credit accounts from being opened in your name and is free by law.
- Visit IdentityTheft.govto file an identity theft report and receive a personalized recovery plan, including the letters and forms needed to dispute any fraudulent accounts.
- Call the IRS Identity Protection Hotline at 1-800-908-4490 if your Social Security number could be used to file a fraudulent tax return.
- Contact your bank and financial institutions to flag potentially compromised accounts.
- Change passwords on your email and financial accounts from a clean device.
Where and How to Report a Social Security Scam
Reporting to the SSA OIG and the FTC
The SSA Office of Inspector General is the primary agency for reporting Social Security fraud. File a report online at oig.ssa.gov or call the OIG fraud hotline at 1-800-269-0271 (Monday through Friday, 10 a.m. to 2 p.m. Eastern). When you report, include the source of the contact, the content of the message, any phone numbers or website links involved, and screenshots or copies of any text, email, or mail you received. The more detail you provide, the more useful your report is to investigators.
The FTC handles broader fraud reports at ReportFraud.ftc.gov. Even if you didn’t lose money, submitting a report matters. The FTC’s Consumer Sentinel database pulls data from millions of individual reports to identify patterns, map scam campaigns, and support law enforcement actions. A report you file today may protect someone else next week.
Local law enforcement and follow-up steps
If money was lost or accounts were opened fraudulently in your name, file a report with your local police department. Some credit dispute and identity recovery processes require a police report or FTC report as supporting documentation. Keep copies of everything, confirmation numbers from credit bureaus, agency reference numbers, and any correspondence with financial institutions.
Reporting is not just about your individual case. When communities share information about scam attempts, including ones that didn’t succeed, they build a collective defense. That’s the core principle behind The Digital Resistance: protecting people from fraud works better as a shared effort than as a solo one.
You Now Have the Advantage
Social Security scams are built on a simple assumption: that you don’t know the SSA’s actual policies. Now you do. The real SSA never threatens arrest, never demands gift cards or cryptocurrency, and never contacts you through WhatsApp or personal text messages. When something feels off, hang up and verify through official channels. That single habit dismantles the scam before it can cause harm.
Staying informed is your most effective defense against this kind of fraud. Visit The Digital Resistance for ongoing plain-language guides on how to protect Social Security benefits, recognize government impersonation scams, and navigate the full range of digital threats targeting everyday Americans. Use them. Sharing what you know is one of the most effective things you can do.
Frequently Asked Questions About Social Security Scams
What is a Social Security scam alert and how do I recognize one?
A Social Security scam alert is an official warning issued by the SSA or FTC about active fraud campaigns targeting Americans. You can check for current alerts at ssa.gov/antifraud. In general, any unsolicited contact, by phone, text, email, or mail, claiming your benefits are suspended or that you face arrest is a scam. The real SSA contacts you primarily by mail and never demands immediate payment.
How do I report a Social Security scam?
Report Social Security scams to the SSA Office of Inspector General at oig.ssa.gov or by calling 1-800-269-0271. Also file a report with the FTC at ReportFraud.ftc.gov. If you lost money or your identity was compromised, contact local law enforcement and visit IdentityTheft.gov for a step-by-step recovery plan.
Can a Social Security scam affect my benefits if I don’t respond?
No. Ignoring a scam call, text, or email has no effect on your actual Social Security benefits. Your benefits are managed exclusively through the SSA’s official systems, and a scammer has no ability to alter or suspend them. If you’re concerned, call the SSA directly at 1-800-772-1213 to confirm your account status.
Headquarter
12 Belmont, Bath
United Kingdom
Telephone
+447707329924
Phishing, smishing, and vishing: know the difference
Phishing, smishing, and vishing: know the difference
Learn the difference between phishing, smishing and vishing, how each scam works, the warning signs to watch for and the best ways to protect yourself from fraud.
● Insights
Phishing, smishing, and vishing: know the difference
01
What Are Phishing, Smishing and Vishing?
Understand the key differences between email phishing, text message scams (smishing) and fraudulent phone calls (vishing), and how each is used by cybercriminals.
02
How to Recognise the Warning Signs
Learn the common tactics scammers use, including urgent requests, fake links, impersonation and attempts to steal passwords or financial information.
03
How to Protect Yourself from Every Type of Scam
Discover practical steps to avoid phishing, smishing and vishing attacks, including verifying communications, using multi-factor authentication and reporting suspicious activity.
Don't Get Caught Out: Understanding Phishing, Smishing and Vishing
What is the difference between phishing, smishing, and vishing? Picture this: you get an email at 2 PM saying your work password expires in 24 hours. At 3 PM, a text arrives saying your USPS package couldn’t be delivered. At 4 PM, your phone rings and a man named “Alex from the Help Desk” says there’s been suspicious activity on your account. Are all three scams? Almost certainly yes. Are they the same scam? No, and that distinction matters more than most people realize.
Many people recognize “phishing” by name but are far less familiar with smishing or vishing. That gap in awareness is exactly what attackers count on. These three social engineering scams are the leading entry points for identity theft, financial fraud, and account takeover in 2026, and they work because the tactics feel different enough that people don’t recognize the same playbook running across all three channels. This guide from The Digital Resistance breaks each one down so you can name what you’re looking at, spot the red flags fast, and know what to do next.
What is the difference between phishing, smishing, and vishing?
The channel is the clearest dividing line. Phishing comes by email, smishing by SMS, and vishing by voice call. The manipulation tactics running underneath all three are nearly identical: authority, urgency, a simple action, and just enough legitimacy to get you moving before you think. The delivery medium is what changes the name and determines how you should verify and respond.
It’s worth knowing two emerging variants. Quishing is phishing delivered via QR code; the URL is hidden inside an image, bypassing link-scanning tools entirely. AI-generated voice cloning is making vishing harder to detect by removing the “that doesn’t sound right” instinct that used to serve as a natural filter. Knowing these vectors exist keeps you from being caught off guard by a new delivery format.
Your personal risk profile also shapes which vector is most likely to reach you. Email phishing hits employees and business account holders hardest. Smishing disproportionately targets mobile-heavy consumers and seniors expecting deliveries or benefits. Vishing is increasingly used against small business owners, IT staff, and older Americans through Medicare and Social Security impersonation. Knowing where you fit helps you stay alert to the channel most likely to come for you.
What phishing is and why email scams still fool millions
Phishing is a fraudulent email designed to look like it’s from a trusted source, engineered to steal your credentials, money, or system access. The core mechanic is simple: attackers spoof sender addresses, mirror real branding, and use professional-sounding language so the message passes a quick visual scan. Many recipients overlook subtle indicators that something is off.
Spear-phishing takes this a step further. Instead of sending a generic mass email, the attacker uses personal details: your name, your company, your manager’s name, even a recent project you’re working on. That specificity makes the message feel routine and expected, which is what makes it dangerous. When an email looks like it came from someone you work with, your guard drops before you’ve finished reading the subject line.
The red flags hiding in a typical phishing email
The IT password expiry email is one of the most common phishing templates in circulation. The subject line creates urgency (“Action Required: Password Expires Today”), the body uses a generic but professional greeting, and a link points to a credential-harvesting page dressed up to look like a real login portal. The sign-off says “IT Support,” which sounds authoritative enough that most people don’t question it.
Watch specifically for these red flags: a sender domain that doesn’t match the organization it claims to be from, a link URL that shows something different when you hover over it versus what the display text says, a generic greeting instead of your actual name, and pressure to act within a tight window. If an unexpected email asks you to click, log in, or confirm anything urgent, verify through a separate channel before you do anything. Look up the official number yourself and call directly.
Smishing: the text message scam with a surprisingly high success rate
Smishing is phishing carried out over SMS. A fake text pushes you toward a malicious link, a credential entry page, or a malware download. The reason smishing outperforms email phishing comes down to one structural reality: SMS carries far less sophisticated spam filtering than email and fewer automated client-side protections, and a text feels personal in a way that an email doesn’t. According to security industry benchmarking data, click rates on SMS phishing campaigns run as high as 25 to 36 percent, compared to roughly 2 to 4 percent for email. That’s not a small difference; it’s a structural advantage for the attacker.
The most common smishing impersonations targeting Americans right now are package delivery failures from USPS, UPS, and FedEx; bank fraud alerts; unpaid toll notices; and government benefit messages. The delivery scam is especially effective because so many people are genuinely expecting packages, which makes the message feel plausible before they’ve read the second line.
How to read a smishing text critically
A typical smishing text looks like this: “[USPS]: Your package could not be delivered today. Reschedule here to avoid return to sender: [link].” Notice the structure. It frames urgency as loss prevention, borrows a trusted brand name, and gives you one action to take. The link is shortened or slightly misspelled, but most people tap before they check.
The red flags are: an unknown or spoofed number, a shortened URL, no personalized greeting, and a request to click or verify within a short time window. The safest habit is to never tap a link in a text about an account or package. Close the message, go directly to the brand’s official app or website, and look up your account or tracking number there. If there’s a real problem, it will show up without you clicking anything.
Vishing: why a phone call can be the most dangerous attack of all
Vishing is voice phishing: a caller poses as a bank representative, tech support agent, government official, or IT help desk employee to extract personal data, passwords, or one-time authentication codes. A real human voice triggers social pressure that a text or email simply can’t replicate. Industry data puts vishing success rates at roughly three times those of email phishing, and the average loss per successful organizational incident runs around $1.35 million (based on 2026 attack-cost estimates from cybersecurity industry reports). For individuals, the average loss lands near $1,400 per incident (a fast-growing trend in 2026), which is still life-disrupting for most people.
The most common vishing scripts targeting Americans include IRS and Social Security impersonation, bank fraud department calls, Medicare and insurance calls, and internal IT help desk impersonation. AI voice cloning is making this worse. Attackers now need only a few seconds of public audio to generate a convincing synthetic voice, which means a call can sound like your actual boss, a family member, or a government official you’ve heard before.
Breaking down a real vishing call script
Here’s how a help desk vishing call actually runs. The caller says: “Hi, this is Alex from the Help Desk. We detected unusual sign-in activity on your account and need to verify your identity right away. I’m going to send a code to your phone. Please read it back to me so we can keep your account from being locked.” Every element of that script is calculated. Authority (“Help Desk”), urgency (“right away”), fear of loss (“account locked”), and a request for the one-time code that bypasses your two-factor authentication entirely.
No legitimate bank, government agency, or IT department will ever ask you to read back a one-time code over the phone. That code is a key that unlocks your account. The moment you say it aloud, the attacker is in. End the call, look up the official number yourself, and call back to verify whether the contact was real.
Comparing the three attacks: phishing vs. smishing vs. vishing
Understanding what is the difference between phishing, smishing, and vishing in practice means looking at how each attack unfolds across three dimensions: channel, red flags, and the right defensive response.
| Attack Type | Channel | Primary Red Flags | Best Defense |
|---|---|---|---|
| Phishing | Mismatched sender domain, hover-revealed URLs, generic greeting, urgent deadline | Hover before clicking; verify via official channel | |
| Smishing | SMS | Unknown number, shortened link, no personalization, time pressure | Never tap links in texts; go directly to the official app or site |
| Vishing | Voice call | Unsolicited call, request for one-time code, artificial urgency | Hang up; call back using a number you looked up yourself |
What to do immediately if you’ve been targeted
Early action limits the damage. The window right after a phishing, smishing, or vishing attempt matters most, so move through these steps in order. Speed counts, but staying methodical prevents additional mistakes.
- Stop all interaction immediately. End the call, don’t reply to the text, don’t click anything else in the email.
- Disconnect the device from the network if you clicked a link or entered information anywhere. This limits how far any malware can spread.
- Change passwords right away for any account that may be compromised, starting with email, banking, and anything sharing the same password.
- Contact your bank or card issuer immediately if financial details were shared. Request a freeze or card replacement before any fraudulent charges can clear.
- Preserve evidence. Screenshot the message, note the caller ID or sender address, and save timestamps. You’ll need this for reports.
For reporting, use these official U.S. channels. Forward smishing texts to 7726 (SPAM), which works on all major U.S. carriers. Report phishing emails using the built-in “report phishing” button in your email client. File a report with the FTC at ReportFraud.ftc.gov for any scam involving financial loss, identity theft, or government impersonation. For more serious incidents involving business fraud or significant financial loss, file with the FBI’s IC3 at ic3.gov. If the caller impersonated the IRS, Social Security Administration, or Medicare, those agencies each have inspector general offices with their own reporting channels in addition to the FTC.
Simple habits that make you a much harder target
Attackers count on you staying reactive. These four habits shift you into a proactive posture that breaks the playbook across all three attack types.
- Verify unexpected contact independently. Look up the official number or website yourself and reach out directly, never through a link, number, or attachment from the incoming message.
- Enable multi-factor authentication (MFA) on every account that offers it. MFA significantly reduces your exposure, even when a password is stolen through phishing, it raises a meaningful barrier that most attackers cannot easily clear. Note that certain advanced attacks (such as MFA prompt acceptance fraud) can still bypass it, so MFA works best as one layer in a broader defense, not a standalone fix.
- Pause before acting. Urgency is the weapon; a 30-second pause before clicking, calling back, or entering credentials disarms it completely.
- Never share a one-time code with anyone who contacts you first, regardless of who they claim to be.
The Digital Resistance exists specifically to help non-technical Americans build these habits without needing an IT background. The site offers free downloadable guides on recognizing each scam type, plus a digital safety self-assessment tool you can complete in about five minutes. The self-assessment shows you where your blind spots are before an attacker finds them for you. Knowing the difference between phishing, smishing, and vishing is step one. Knowing your own vulnerabilities is step two.
Put it all together
Phishing targets your inbox, smishing targets your texts, vishing targets your ear. The manipulation tactics running through all three are the same: authority, urgency, a plausible story, and a single action for you to take. Naming the attack type is useful precisely because it gives you a framework for what you’re actually looking at, something more reliable than a gut feeling that something is off.
The most important single action across all three: verify through an independent channel before you click, pay, or share anything. That one habit prevents many of the most common successful attacks before they get started.
Head over to The Digital Resistance to take the free self-assessment and access guides written for real people, not security professionals. Awareness is a skill. The more you practice it, the less likely attackers are to find a way in.
Headquarter
12 Belmont, Bath
United Kingdom
Telephone
+447707329924
10 Ways Seniors Can Protect Themselves From Online Scams
10 Ways Seniors Can Protect Themselves From Online Scams
Staying safe online starts with knowing what to look for. This guide shares 10 essential tips to help seniors spot warning signs, secure their devices, and reduce the risk of becoming a victim of online scams.
● Insights
10 Ways Seniors Can Protect Themselves From Online Scams
01
Recognise the Most Common Online Scams
Scammers use emails, text messages, phone calls, and fake websites to trick people into sharing personal information. Learn how to identify the warning signs and avoid the most common online scams targeting seniors.
02
Build Safer Online Habits
Simple changes can make a big difference. Discover practical ways to create strong passwords, enable two-factor authentication, update your devices, and browse the internet more securely every day
03
Protect Your Personal Information and Finances
Keeping your personal and financial details secure is essential. Explore 10 straightforward tips to help protect your accounts, avoid identity theft, and stay confident when using online services.
Protect Yourself Online: A Senior's Guide to Avoiding Scams
How can seniors protect themselves from online scams? It starts with understanding the scale of the problem. In 2024, adults 60 and older filed 147,127 fraud complaints with the FBI, reporting losses of $4.885 billion, according to the FBI’s Internet Crime Complaint Center (IC3) annual report. Those numbers are not meant to frighten anyone. They are meant to make the threat feel concrete, because it is. Senior online safety has become one of the most urgent consumer protection challenges in the country.
These scams succeed because of surprise, not because older adults are careless or uninformed. Scammers are professionals who spend their days perfecting scripts designed to exploit trust and create panic. Law enforcement and fraud researchers consistently describe elder fraud operations as organized, rehearsed, and psychologically sophisticated. The good news is that recognizing those scripts is the most powerful defense available, and recognition is something anyone can learn.
At The Digital Resistance, this is exactly what we work on every day: giving everyday Americans the practical knowledge to fight back against fraud without needing a technical background. This article delivers 10 concrete steps covering everything from identity theft prevention for seniors to elder financial abuse prevention, a trusted-contact safety plan, and a clear reporting guide so you know exactly what to do if something goes wrong.
The scams targeting seniors right now (and how they get in the door)
Before any protection step makes sense, it helps to know what you are actually protecting against. The FBI and FTC consistently track the same categories at the top of the elder fraud list, and understanding how each one works makes them much easier to spot.
Tech support fraud, phishing scams targeting seniors, and government impersonation
Tech support scams rank among the most widely reported forms of elder fraud in 2024, according to FBI IC3 data. They typically arrive as a pop-up warning claiming your computer is infected, or as a call from someone claiming to be from Microsoft or your antivirus provider. Phishing scams targeting seniors work through email or text, asking you to “verify” your bank account or update your login before your access is suspended. Government impersonation scams pose as IRS, Social Security Administration, or Medicare officials demanding immediate payment or threatening arrest.
Romance scams and grandparent fraud: emotional manipulation at work
These two categories operate differently from the ones above. Instead of creating fear, they build trust. Romance scammers develop relationships over weeks or months through dating sites or social media before making a financial request. Grandparent scams involve a caller pretending to be a grandchild in crisis, often asking for bail money or emergency funds. Both create emotional urgency that bypasses logical thinking, and that manufactured urgency is the whole point.
Why urgency is always the scammer’s most reliable weapon
Nearly every scam script shares one feature: it rushes you. A tax warrant, a frozen account, a grandchild in jail tonight. The pressure is deliberate. Legitimate organizations, including the IRS, your bank, and Social Security, do not demand immediate action over the phone. The moment you feel rushed, that feeling is your signal to stop and verify.
How can seniors protect themselves from online scams: the four security basics that matter most
These four steps form the foundation of account security. None of them require advanced technical knowledge, and each one closes a door that scammers routinely walk through.
Steps 1 & 2: Strong Passwords and a Password Manager
Weak or reused passwords are the easiest entry point for identity theft. Identity theft prevention for seniors starts here: a strong password is long (at least 12 characters, per NIST guidance), unique to each account, and not based on personal information like birthdays or names. The practical problem is that no one can memorize dozens of unique passwords, which is exactly where a password manager helps. Both iPhones (iCloud Keychain) and Android phones (Google Password Manager) include a built-in password manager at no cost. Enabling either one is the simplest starting point and handles the memory problem entirely.
Step 3: Turning on two-factor authentication (2FA)
Two-factor authentication is the single highest-value step you can take for account security. Even if a scammer gets your password, they still cannot access your account without the second code sent to your phone. Start with your three most critical accounts: email, bank, and medical portal. Each account’s security settings will have an option to turn it on, and setup usually takes less than five minutes per account.
Step 4: Keeping devices updated and antivirus active
Outdated software contains known security holes, and scammers actively exploit them. Turning on automatic updates for your phone and computer is a one-time action that keeps those holes closed. Windows computers include built-in antivirus through Windows Security at no charge. iPhones receive security patches through standard iOS updates. Just make sure automatic updates are enabled and stay that way.
How to recognize a scam before it costs you anything
The most valuable protection skill is recognition before action. A mental checklist of red flags means you can identify a scam during the call or message, not after the money is already gone. The FTC and FBI both emphasize that early recognition is the single most effective way to avoid elder financial abuse.
The pressure signals that show up in every scam
Any message, call, or pop-up that creates urgency is using a scripted tactic. “Act now or your account will be closed.” “You owe back taxes and will be arrested.” “Your grandson needs bail money tonight.” The feeling of being rushed is the signal to pause, not to act. Real government agencies send written notices. Real banks call from numbers on your card. Real family members can wait while you verify.
Payment requests that are always a scam
Gift cards, wire transfers, and cryptocurrency are never a legitimate form of payment. No government agency, no legitimate business, and no family member will ever ask you to pay with a gift card. The FTC has documented this pattern across thousands of fraud reports. If anyone makes that request, the conversation is over. This is not a guideline to weigh against other information. It is an absolute rule.
How to verify who is actually contacting you
Hang up and call back using a number you find independently, such as the number on your bank card or the official website of the agency. Never use a number provided inside the message or by the caller. For family emergency calls, establish a code word with your family in advance, a word or phrase only family members would know that confirms the caller is who they say they are. This one habit stops most grandparent scams immediately, according to FTC guidance on elder fraud prevention.
How can seniors protect themselves from online scams through safer payment habits
Steps 5 and 6 focus specifically on what you pay with, because the payment method determines whether you have any chance of getting your money back.
Step 5: What to stop using for unfamiliar transactions
Gift cards and wire transfers work like cash once sent: they are gone. Cryptocurrency payments are irreversible by design. Debit cards pull money directly from your bank account, and recovering those funds after fraud is significantly harder than disputing a credit card charge. Each of these methods gives a scammer exactly what they want: no recourse for you.
Step 6: Safer payment alternatives that give you options
Credit cards offer the strongest fraud dispute rights under federal consumer protection law, as outlined by the CFPB. If a charge is unauthorized, you have the right to dispute it and have it reversed while the investigation takes place. PayPal adds buyer protection and keeps your card number away from sellers. Apple Pay and Google Pay use a technology called tokenization, which means merchants never receive your actual card number. When you are making an online purchase from an unfamiliar source, a credit card is the default safe choice.
Setting up your trusted-contact safety plan
Steps 7 and 8 are about building a human safety net, because no security tool replaces having people who are watching out for you. This is where elder financial abuse prevention moves from technical settings to real relationships.
Step 7: Who goes on your safety plan and what they need to know
A trusted-contact plan means identifying one or two people, a family member, a close friend, or a caregiver, who know to expect a call if something feels off. Share this article with them. Agree on a family code word for verifying emergency calls. No technology is required. It is a conversation that typically takes 10 minutes and can prevent a life-altering financial loss.
Adding a trusted contact through your bank or brokerage
Federal financial regulations, including FINRA Rule 4512, now allow banks and brokers to accept a “trusted contact” designation on your account. This person is not authorized to make transactions or access your funds. They are simply someone the institution can contact if it suspects financial exploitation is occurring. To add one, call the main number on your bank card, say you would like to add a trusted contact, and provide that person’s name and phone number. It takes one phone call.
Step 8: Call blocking to reduce phone scam exposure
Both iPhones and Android phones include built-in spam call filtering that can be turned on in settings. iPhone users can enable “Silence Unknown Callers” to send unrecognized numbers straight to voicemail. Android’s Google Phone app has a “Filter Spam Calls” setting that works similarly. All three major U.S. carriers, T-Mobile (Scam Shield), AT&T (ActiveArmor), and Verizon (Call Filter), also offer free network-level call filtering. Using both your phone’s built-in tools and your carrier’s filtering together can meaningfully cut the number of scam calls that ever ring through.
What to do if you think you’ve been targeted: fraud reporting for older adults
Steps 9 and 10 cover the exact sequence of actions after suspected fraud. Speed matters here: the faster you act, the better your chance of recovering funds.
Step 9: Stop the loss before anything else
Your first call is to your bank or card issuer, not law enforcement. Ask to freeze the account, dispute any unauthorized charges, and request a recall on any wire transfers sent in the last 24 to 72 hours. Acting quickly matters because wire recalls become nearly impossible after a few days.
Save every piece of evidence you have: emails, texts, screenshots, receipts, and any phone numbers or websites the scammer used. That documentation supports every report you file next.
Step 10: Report to FTC, FBI IC3, and the Elder Fraud Hotline
Three official channels handle different aspects of fraud reporting for older adults, and filing with all three is worth the effort:
- ReportFraud.ftc.gov, covers most scams and deceptive practices
- IC3.gov, handles any scam that used the internet, including email, social media, and online payments
- National Elder Fraud Hotline: 1-833-372-8311(Monday through Friday, 10 a.m. to 6 p.m. ET), connects you with a live case manager who can walk through the reporting process in plain language, help you file with IC3 and the FTC, and connect you with local resources
When to contact Adult Protective Services and the CFPB
Adult Protective Services handles situations involving coercion or suspected exploitation by a caregiver. Reach them through the Eldercare Locator at 1-800-677-1116. The Consumer Financial Protection Bureau (1-855-411-2372) is the right channel when a bank, lender, or financial product is directly involved. These are not substitutes for the FTC and IC3. They are additional channels for specific situations, and using them in combination gives your report the widest possible reach.
Building protection that actually holds
So, how can seniors protect themselves from online scams in a lasting way? Not by becoming less trusting, but by building habits and systems that make it much harder for scams to land. Strong passwords, two-factor authentication, a firm rule about gift cards, a family code word, a trusted contact on file at your bank, and a clear plan for fraud reporting: these steps stack together into real, durable senior online safety.
The Digital Resistance exists to make this kind of practical knowledge available to every American, at any age and without any technical background. The threat is real, but so is the ability to fight back against it. You do not need to be a cybersecurity expert. You just need to know what to look for and what to do when you see it.
Take one action today: share this article with someone who needs it. A parent, a neighbor, a friend. That one conversation could make all the difference.
Headquarter
12 Belmont, Bath
United Kingdom
Telephone
+447707329924
Top cyber threats for small business owners in 2026
Top cyber threats for small business owners in 2026
Cyber threats are evolving faster than ever, and small businesses remain a prime target. Discover the biggest cyber risks in 2026
● Insights
Top cyber threats for small business owners in 2026
01
The Biggest Cyber Threats Facing Small Businesses
Cybercriminals are constantly evolving their tactics, making small businesses a frequent target. Learn about the most common threats in 2026, including phishing, ransomware, AI-driven scams, and data breaches, so you can better protect your business.
02
Understand the Risks Before They Become a Problem
Recognising today's cyber threats is the first step to preventing them. Explore how hackers exploit weak passwords, unpatched software, and human error, and discover practical ways to reduce your business's exposure.
03
Stay Ahead of Emerging Cyber Threats
The cybersecurity landscape is changing rapidly. Discover the latest risks affecting small businesses in 2026 and the proactive measures you can take to strengthen your defences, protect sensitive data, and maintain customer trust.
The Biggest Cybersecurity Threats Small Businesses Need to Watch in 2026
Small businesses now account for the majority of ransomware victims in the United States, and cyber threats for small business owners have never been more targeted or more costly. According to the 2025 Verizon Data Breach Investigations Report, ransomware was involved in 88% of SMB breach incidents, compared to just 39% for larger organizations. Many small business owners still operate under the assumption that they’re not worth a hacker’s time. That assumption is the vulnerability.
This article breaks down the three attack types doing the most damage to small businesses right now: ransomware, invoice fraud, and credential theft. By the end, you’ll know exactly what you’re up against, which defenses to prioritize this week, and what to do if an attack lands on your doorstep. The team at The Digital Resistance tracks how cyber attacks on small businesses evolve, and the patterns visible in 2026 are clear, specific, and largely preventable based on the threat intelligence we monitor across SMB incidents.
Why small businesses are in the crosshairs
The “I’m too small to target” myth persists because business owners naturally compare themselves to headline-grabbing enterprise breaches. Attackers don’t think that way. They run volume operations, and small businesses offer exactly what they need: fewer controls, faster payouts, and far less scrutiny from law enforcement or internal security teams.
The under-resourced reality attackers count on
Many small businesses have no dedicated IT staff, run outdated software longer than enterprises do, and rely on shared credentials across multiple platforms. These aren’t failures of effort, they’re the reality of running lean with a small team. Attackers know this and build their operations around it. A three-person team typically has no security operations center reviewing alerts at 2 a.m. when ransomware starts encrypting files.
Small businesses as stepping stones to bigger targets
There’s another dynamic that most small business owners don’t consider: they’re connected to larger organizations. A bookkeeper’s email account, a vendor portal login, or a contractor’s remote access credentials can all become the entry point into a larger company’s systems. This is called vendor email compromise, a recognized and growing form of the broader business email compromise problem. When attackers compromise your inbox, they’re sometimes less interested in your money than in the trust your name carries with your clients.
Top cyber threats for small businesses in 2026
These three threats account for the overwhelming majority of SMB breach incidents, according to data from the 2025 Verizon Data Breach Investigations Report and related industry research. Understanding how each one actually unfolds, not in abstract terms but as a sequence of events, is what turns awareness into action.
Ransomware: a top cyber threat for small businesses right now
Here’s how a ransomware incident typically unfolds for a small team. A staff member clicks a link in what looks like a shipping notification. Nothing obvious happens. Overnight, a piece of software quietly begins encrypting every file it can reach across shared drives, cloud syncs, and local storage. By morning, there’s a ransom note on every screen. Recovery costs average $1.53 million even when businesses don’t pay the ransom, and downtime averages 24 days (Sophos State of Ransomware Report). For a three-person shop operating on thin margins, 24 days of downtime isn’t a setback, it’s a business-ending event. The National Cybersecurity Alliance has reported that a substantial share of small businesses that suffer a major cyberattack close permanently within six months, though estimates vary across studies.
Invoice fraud and business email compromise
Invoice fraud works because it exploits something real: an existing business relationship. An attacker monitors a supplier email chain, learns the communication patterns, and then sends a near-perfect duplicate of a legitimate invoice with one change: the bank account number. In a documented 2025 case highlighted by the Better Business Bureau, a Connecticut wholesale food seller shipped nearly $390,000 in product to fraudsters who had stolen a client’s business identity, including invoice documents and logos. Small teams are often especially exposed here because there’s no finance department cross-checking payments and no approval hierarchy slowing down wire transfers. Email is the authoritative channel, and when it looks right, it gets paid.
Credential theft and account takeover
Stolen usernames and passwords are harvested through phishing, then sold in bulk or tested automatically against banking portals, cloud tools, and payroll platforms. This is called credential stuffing, and it works because most people reuse passwords across accounts. Compromised credentials account for roughly 22% of all breaches, and the damage often begins weeks before anyone notices anything wrong. By the time an account takeover becomes visible, an attacker may have already set up forwarding rules, extracted customer data, or initiated fraudulent transactions.
The real cost of a breach for a small team
Financial impact figures for breaches are often cited in ways that make them feel abstract. Here is what those numbers mean in practice for a typical SMB: recovery costs fall in the $120,000 to $1.24 million range, and that money goes toward forensic investigation, system rebuilding, lost revenue during downtime, customer notification, potential legal exposure, and reputation repair. For a business operating on 10, 15% margins, even the low end of that range is existential.
Downtime is often the real killer, not the ransom itself
The ransom demand gets the headlines, but 24 days of average downtime is what actually forces closures. When your point-of-sale system is offline, your project management platform is encrypted, and your customer database is inaccessible, you’re not just losing revenue, you’re losing client relationships that took years to build. Prevention isn’t a technical luxury reserved for businesses with IT budgets. It’s the only financially rational move available to a small business operating in 2026. And the cost of prevention is a fraction of even the low end of small business data breach recovery expenses.
Cyber threats for small business: six defenses to prioritize this week
Most successful attacks against small businesses exploit predictable, closeable gaps. The following defenses are ranked by risk reduction per cost, and several of them cost nothing to implement.
Start with MFA and credential hygiene
Multi-factor authentication is the single highest-impact control available to a small business, and it’s free on most platforms. Microsoft’s research estimates that MFA blocks approximately 99.9% of account compromise attacks. Enable it on email, cloud apps, banking portals, and any remote access tools immediately. Pair it with a password manager so each account gets a unique, strong password. This combination eliminates the credential stuffing risk almost entirely.
Automated patching and tested backups
Most exploits target known vulnerabilities that already have fixes available. Turning on automated patching for operating systems, browsers, and internet-facing software closes that window before attackers can use it. CISA specifically identifies patching as one of the most cost-effective security practices for small organizations. Backups are your recovery insurance: follow the 3-2-1 rule, three copies of your data, on two different media types, with one copy stored offsite or in a separate cloud account. The habit that actually matters is testing restores. A backup that has never been tested is not a backup; it’s a hope.
Email filtering and a basic staff awareness habit
Email filtering reduces phishing delivery at the inbox level before a staff member ever sees a malicious link. Many business email platforms include filtering options that require manual configuration rather than working out of the box, so check your settings. For staff awareness, you don’t need a formal training program. A short monthly team conversation anchored to a real, current scam example can help maintain awareness and reduce the likelihood of a click turning into a crisis. The Digital Resistance publishes plain-language threat updates specifically designed for these conversations, so you’re not building the content from scratch.
What to do the moment an attack hits
When something goes wrong, the first hour matters more than any hour that follows. Staying calm and following a clear sequence is what limits the damage. The steps below apply whether you’re dealing with a phishing incident or active ransomware.
First 60 minutes: isolate, contain, preserve
Disconnect affected devices from the network immediately: unplug the Ethernet cable, turn off Wi-Fi, and disable any VPN connections. For ransomware, isolating infected machines stops lateral spread to shared drives and other devices. Save the phishing email, the ransom note, and any screenshots before deleting anything, that evidence helps authorities track broader patterns. Change compromised passwords from a separate, trusted device, not from the machine you suspect is compromised. Revoke active sessions for affected accounts to cut off any attacker who may still be logged in.
Who to call and how to report the incident
Notify your internal team first using a phone call or secure messaging app. Avoid email entirely, the compromised environment cannot be trusted. If financial fraud is involved, call your business bank immediately to freeze or verify any recent transactions. Contact your cyber insurer if you have coverage. For formal reporting, file a complaint with the FBI’s Internet Crime Complaint Center at IC3.gov. That report costs nothing, takes about 15 minutes, and helps federal authorities track the attack patterns that target other small businesses. CISA’s StopRansomware resources are available at cisa.gov and include step-by-step response guidance built specifically for organizations without dedicated IT staff.
Free tools and resources worth bookmarking
You’re not navigating this alone, and quality help is genuinely free. The following resources are specific and actionable, not just reference pages to skim once and forget.
Government resources that actually help SMBs
CISA Cyber Essentials is a starter guide designed for small-business leaders, with toolkits for both IT and executive teams. CISA’s free Cyber Hygiene vulnerability scanning monitors your publicly reachable systems and sends weekly reports on weaknesses that need fixing. To sign up, email vulnerability@cisa.dhs.gov with the subject line “Requesting Cyber Hygiene Services”, CISA typically starts scanning within three business days, though you can also confirm current enrollment steps at cisa.gov. The CISA Known Exploited Vulnerabilities catalog tells you exactly which vulnerabilities attackers are actively using, so you can prioritize patching intelligently.
The FCC Small Biz Cyber Planner 2.0 generates a custom cybersecurity plan based on your business type. The SBA’s cybersecurity guidance page ties many of these resources together and is a practical starting point if you’re building a small business cyber security checklist from scratch.
The Digital Resistance: education built for business owners, not IT teams
The Digital Resistance exists specifically because most cybersecurity guidance is written for people with technical backgrounds, and most small business owners don’t have one. The movement translates complex threat intelligence into plain-language guidance you can act on without an IT department. The community-driven model means you’re getting real-world warnings from peers facing the same threats, not just top-down bulletins from agencies. As AI-driven fraud, deepfake scams, and invoice fraud tactics continue to evolve, The Digital Resistance updates its resources to match what’s actually hitting American businesses right now.
Take the threat seriously before it takes your business
The cyber threats facing small businesses in 2026 are serious, specific, and, for the most part, preventable. Most successful attacks exploit the same predictable gaps: no MFA, unpatched software, unverified invoices, untested backups. Closing those gaps doesn’t require an IT team or a large budget. It requires consistent attention and the right habits applied in the right order.
Think of cybersecurity the same way you think about locking the door at closing time or backing up your accounting files before tax season. It’s a business continuity practice, not a technical burden. The businesses that survive attacks in 2026 are the ones that treated prevention as routine, not as a crisis response.
As attack methods shift, especially with AI-generated fraud and voice-cloning scams becoming more accessible to criminals, staying informed is part of the job. Treating cyber threats for small business as a routine business continuity concern, rather than a distant worst-case scenario, is what separates the businesses that recover from the ones that don’t. The Digital Resistance provides resources written for business owners, updated as new fraud tactics emerge, and grounded in the practical reality of running a business without a full security team behind you.
Headquarter
12 Belmont, Bath
United Kingdom
Telephone
+447707329924
Government impersonation fraud: spot it, stop it, report it
Government impersonation fraud: spot it, stop it, report it
Learn how to spot government impersonation fraud, recognise fake calls, emails and text messages, and discover the steps to stop scams and report them safely.
● Insights
Government impersonation fraud: spot it, stop it, report it
01
How Government Impersonation Scams Work
Learn how scammers pose as government agencies through phone calls, emails, text messages and fake websites to steal money and personal information.
02
Warning Signs of a Fake Government Contact
Discover the common red flags, including urgent demands, threats, requests for payment and messages asking for sensitive personal details.
03
What to Do If You're Targeted
Find out how to verify legitimate government communications, report the scam to the appropriate authorities and protect your accounts from further fraud.
The Complete Guide to Government Impersonation Fraud
Americans reported $920 million in losses to government impersonators in 2025 alone, according to FTC Consumer Sentinel data. That number reflects real people who lost real money, often because they received a call that sounded exactly like what they feared most: an official notice of a serious problem. Government impersonation fraud works not because it’s technically sophisticated, but because it targets something deeply human: the instinct to comply with authority and avoid consequences.
Here’s what most people don’t realize: these scams follow a nearly identical script every single time. The agencies change. The names change. The urgency varies slightly. But the structure, the pressure tactics, and the payment demands are predictable. Once you know the pattern, a threatening call from a “federal agent” becomes a transparent con within the first few moments of the call.
At The Digital Resistance, we publish plain-language fraud alerts and guides for everyday Americans who don’t have an IT team or a fraud attorney on speed dial. By the time you finish reading, you’ll know how to recognize government impersonation fraud, shut it down, and report it to the right agency, and if you’ve already been targeted, you’ll know exactly what to do next.
Which agencies scammers impersonate most often
Scammers don’t pick agencies randomly. They pick the ones that carry the most psychological weight: the ones that can threaten your money, your benefits, or your freedom. In 2025 and 2026, the most frequently impersonated agencies, according to FTC and FBI reporting, include the Social Security Administration, the IRS, the FTC itself, Medicare, and Customs and Border Protection.
IRS impersonation: the most reported scheme
The IRS phone and email scam follows a tight script. The caller claims you owe back taxes, warns that an arrest warrant will be issued if you don’t pay immediately, and demands you settle the debt through a method that can’t be traced or reversed. What makes this IRS impersonation scam effective is the fear it triggers, not its accuracy. The IRS initiates contact by mail, not by phone or email. An unsolicited call from someone claiming to be an IRS agent is, by itself, the red flag.
Social Security and Medicare fraud
The Social Security suspension scam tells victims their Social Security number has been “compromised” or linked to criminal activity, and that their benefits are at risk unless they verify their identity or transfer funds to a “secure government account.” Medicare fraud takes a slightly different angle: callers claim to be issuing new Medicare cards and need your personal information to complete the process. Both schemes disproportionately target seniors and retirees, who rely on these benefits and are more likely to take the threat seriously.
FEMA and law enforcement imposters
After major weather events, FEMA disaster relief fraud spikes. Scammers pose as grant administrators and contact disaster survivors with offers of emergency funds, then collect personal information or upfront fees to “process” the application. Fake U.S. Marshals and local police impersonators run a separate scheme, warning victims of outstanding warrants and demanding immediate payment to avoid arrest. Real law enforcement does not call to collect payment over the phone.
How government impersonation fraud works: the psychological pressure playbook
Government impersonation fraud doesn’t succeed through technical skill. It succeeds because it hijacks rational thinking through manufactured fear, artificial urgency, and false authority. Understanding the playbook removes its power.
Fear and artificial urgency
The formula is consistent: claim a serious legal or financial problem, set an impossible deadline (“you must act within the hour”), and warn of severe consequences if the victim hesitates. This manufactured urgency is the point. When your nervous system registers a threat, the part of your brain responsible for critical thinking takes a back seat. Real government agencies do not operate this way. They send written notices, allow time to respond, and provide appeal processes.
Spoofed identity and AI-enabled impersonation
Caller ID spoofing technology lets scammers display real government phone numbers on your screen. They back that up with fake badge numbers, employee IDs, and official-sounding names. In 2026, this form of official impersonation fraud has escalated further: AI voice cloning and deepfake video have been cited in emerging government impersonation cases by federal agencies and cybersecurity researchers. A caller can sound exactly like someone you’ve spoken with before, or display video that appears to show an official in uniform. Authenticity is no longer a reliable indicator of legitimacy.
Untraceable payment demands
When the pressure tactics work, the scammer moves to the demand: payment via gift cards, wire transfer, cryptocurrency, or a cash courier. No legitimate government agency requests payment through any of these methods. This demand is the single clearest red flag in any government impersonation contact. If someone claiming to be from the IRS asks you to buy Google Play cards to settle your tax debt, you are talking to a scammer, full stop.
Spotting government impersonation fraud: key red flags
Every fake government call scam leaves at least one clear tell. Knowing these signals turns a threatening interaction into a recognizable con.
What no real government agency will ever do
These aren’t edge cases or exceptions. They are official agency policies, confirmed in published consumer guidance:
- The IRS will not call you demanding immediate payment by gift card, wire transfer, or cryptocurrency.
- The SSA will not suspend your Social Security number over the phone.
- FEMA does not call unsolicited to offer disaster grants.
- Law enforcement does not demand payment over the phone to prevent an arrest.
- The FTC does not call to tell you that you’ve won a prize or that your account has been flagged.
Contact and communication red flags
Beyond what the caller claims, the way the contact arrives is itself a signal. Watch for any of the following:
- The call or email arrived without prior written notice from the agency.
- The caller refuses to send anything in writing or follow up by mail.
- You’re told not to call back on any number other than the one provided.
- The email domain is slightly off, for example, irs-gov.com instead of irs.gov.
- The “agent” becomes hostile or threatening when you ask questions.
Any single one of these signals is enough to end the interaction and verify independently.
What FTC and FBI data actually show about these scams
The numbers matter because they show the scale of government impersonation fraud, and the individual cases show how the script plays out in real life.
The loss data from 2024 to 2025
FTC Consumer Sentinel data show that reported losses to government impersonators rose from $789 million in 2024 to $920 million in 2025. FBI IC3 data show a parallel increase in complaint volume over the same period. Imposter scams as a broader category generated approximately $3.5 billion in total losses and nearly one million FTC reports in 2025, according to FTC Consumer Sentinel figures, with government impersonators accounting for the largest single share of that total.
How a typical case unfolds
The following composite scenario is drawn from FTC and IC3 case patterns: a caller claiming to be an SSA investigator contacts a retired woman and tells her that her Social Security number was used in a drug trafficking case in Texas. He says her benefits are at risk and her bank accounts may be seized unless she cooperates immediately. He instructs her to withdraw her savings and transfer the funds to a “secure government account” for safekeeping during the investigation, and he stays on the phone the entire time to prevent her from consulting anyone else. At every step, the tactics are deliberate, the fear trigger, the isolation, the false authority, and the urgency that makes calling a family member feel like it will cost her everything. This is not an unusual case. It’s the standard script.
How to verify a contact and protect yourself before you respond
This is the decision framework you need in the moment, not after the fact.
Verification steps for IRS, SSA, and federal contacts
Hang up or close the message. Do not use any phone number, link, or email address provided in the contact itself. Go directly to the agency’s official website, find their published phone number, and call it independently to verify whether the contact was real. For IRS contacts, you can also check your IRS online account at IRS.gov for any pending notices or balances. For SSA, the direct line is 1-800-772-1213. For any law enforcement claim, call your local police department’s non-emergency line and ask whether there is an outstanding warrant in your name.
What to do if you’ve already responded
Stop all contact with the scammer immediately. Call your bank or payment provider right away to attempt a freeze or reversal of any transfer. Preserve every piece of evidence you have: screenshots, call logs, email threads, and transaction records. Then place a fraud alert or credit freeze with each of the three major credit bureaus:
- Equifax: equifax.com or 1-800-685-1111
- Experian: experian.com or 1-888-397-3742
- TransUnion: transunion.com or 1-888-909-8872
A freeze blocks new account openings in your name. After that, visit IdentityTheft.gov for a personalized recovery plan tailored to what information was exposed.
Report government impersonation fraud: exactly what to do
Report the scam through the appropriate channels as soon as possible:
- FTC: ReportFraud.ftc.govor 1-877-382-4357
- FBI IC3: ic3.gov
- SSA Office of Inspector General: 1-800-269-0271
- IRS impersonation (TIGTA): 1-800-366-4484 or forward the email to phishing@irs.gov
- Local law enforcement: Your local non-emergency line for a formal report
The Digital Resistance publishes ongoing community alerts and plain-language breakdowns of new scam variants, including AI voice cloning and deepfake-based impersonation tactics evolving in 2026. It’s a free resource built specifically for non-technical readers who want practical, current information on how these schemes are changing.
You already have what it takes to shut this down
Government impersonation fraud is predictable. It follows a script. And the moment you know the script, the scammer loses every advantage they had. Keep these principles front and center: real government agencies contact you in writing first; no legitimate federal agency will ever ask you to pay a debt with gift cards, wire transfer, or cryptocurrency; and verification is always one independent phone call away.
Knowing how this fraud works puts you in control of the interaction instead of the scammer. Sharing that knowledge with the people closest to you compounds that protection into something real. These scammers count on victims staying silent and isolated after the fact. Reporting breaks that pattern and gives investigators the data they need to track and disrupt these operations.
Report what you see at ReportFraud.ftc.gov and follow The Digital Resistance for ongoing updates as these tactics evolve. The scam works by making you feel alone and out of options. You’re neither. You know the script now. Use it.
Headquarter
12 Belmont, Bath
United Kingdom
Telephone
+447707329924
Business Scam Protection: What Every Small Business Must Do
Business Scam Protection: What Every Small Business Must Do
Business scams are evolving, and small businesses are increasingly being targeted. Learn how to identify common fraud tactics, strengthen your security, and take practical steps to protect your finances, data, and reputation from costly scams.
● Insights
Protect Your Business from Scams: Essential Steps Every Small Business Should Take
01
Protect Your Small Business from Scams
Business scams are becoming more sophisticated and more frequent. Learn how to recognise common threats, strengthen your defences, and protect your finances, data, and reputation with practical steps every business owner can take.
02
Stay One Step Ahead of Fraudsters
From phishing emails and invoice fraud to payment scams and cyber attacks, understanding how criminals operate is the first step to preventing costly mistakes. Discover the warning signs and the safeguards that make a difference.
03
Essential Scam Prevention for Every Small Business
No business is too small to be targeted. Explore the key security measures, staff awareness practices, and fraud prevention strategies that can help keep your business secure and resilient.
Business Scam Protection: What Every Small Business Must Do
Business scam protection starts with one uncomfortable fact: sixty percent of fraud losses to small businesses are never recovered. According to AFP survey data, the median loss per incident runs over $4,000, and that figure climbs fast with business email compromise. Most of the businesses that took those hits had no protection plan in place, not because they didn’t care, but because no one handed them a clear, practical starting point.
This guide is that starting point. The Digital Resistance is a movement built around one idea: solid business fraud protection shouldn’t require an IT department or a six-figure security budget. The controls in this checklist are real, affordable, and implementable by anyone who manages a small business. By the end, you’ll have five specific areas of protection you can start acting on today.
Why Small Businesses Keep Losing to Scams
The Numbers Are Worse Than Most Owners Realize
According to AFP survey data, 76% of U.S. organizations reported attempted or actual payment fraud in 2025. For small businesses specifically, 72% reported being hit by fraud, scams, or ransomware in the past year. The median loss per harmed business sits at $4,373, and among businesses that did recover something, almost two-thirds recovered 25% or less of what they lost.
These numbers aren’t meant to scare you. They’re meant to calibrate you. Small businesses are targeted not because attackers are particularly sophisticated, but because small businesses look like the path of least resistance. That gap is closable.
What Makes a Small Business a Preferred Target
The structural vulnerabilities are predictable: no dedicated IT staff, a single person who creates and approves payments, employees handling five jobs at once, and limited time to stop and verify anything. Large enterprises have layered controls, dedicated fraud teams, and vendor security audits. Most small businesses have none of that.
Recognizing this isn’t an indictment of how you run your business. It’s a blueprint for what to fix. Every vulnerability listed above has a practical, low-cost countermeasure.
Internal Vulnerabilities: Where Your Own Team Becomes the Risk
How Phishing Turns Employees into an Open Door
According to cybersecurity industry research, email-based social engineering is the entry point for the majority of business fraud, some estimates place it at 62% or higher. Phishing, spear phishing, and executive impersonation all work the same basic way: they create urgency, mimic someone trusted, and ask for action before the recipient thinks twice. The scenario plays out like this: an employee receives an email that appears to come from the owner, requesting an urgent wire transfer before end of day. No verification step exists. The money moves.
The failure here isn’t technical. It’s behavioral. The attacker didn’t breach a firewall; they bypassed the human in the chair. That’s why training and process matter more than any software you can buy. Small business fraud prevention, at its core, is a people problem with a process solution.
Payroll Diversion, ACH Fraud, and Credential Reuse
Beyond phishing, there are quieter internal exposure points most owners never consider. Payroll diversion happens when an attacker gains access to an employee portal and changes direct-deposit routing to their own account. ACH fraud hits when compromised banking credentials allow unauthorized electronic withdrawals, sometimes days before anyone notices. Password reuse is the fuel for both: when an employee uses the same credentials for payroll, banking, and email, one breach opens all three doors.
These aren’t exotic attacks. They require almost no technical skill from the attacker, just a team with no verification process in place. That’s the gap effective business scam protection is designed to close.
External Threats That Don’t Need an Inside Door
Vendor Impersonation and Fake Invoice Fraud
Vendor impersonation is one of the highest-cost scams for small businesses and one of the most preventable. Attackers spoof a supplier’s domain, or in more sophisticated cases actually compromise the vendor’s email account, then send a message requesting updated payment details or submitting a fraudulent invoice. The request looks completely legitimate because it’s coming from an address you recognize.
The red flags are consistent: last-minute banking changes from a known vendor, invoices for services you don’t remember ordering, and pressure to pay quickly outside your normal process. A single phone call to a known contact at the vendor, using a number you already have on file, stops this attack every time.
Business Email Compromise and Tech Support Scams
Business email compromise (BEC) follows a simple script: an attacker impersonates an executive or trusted contact, then pressures an employee to send money or share credentials. No malware required. The message exploits authority and urgency, and the employee complies because the request appears to come from someone senior.
Tech support scams have evolved alongside this. In 2026, fake IT vendors and software providers are increasingly impersonating AI tool brands and compromised communication platforms to request remote access or credentials. The delivery method changes; the manipulation playbook doesn’t. It’s always urgency plus trust, directed at someone without a clear verification process to stop them.
Business Scam Protection: Technical Controls That Cut Off Fraud Before It Lands
Multi-Factor Authentication and Access Restrictions
Enable MFA on every account that touches money or sensitive data: online banking, email, payroll platforms, and accounting tools. Use an authenticator app over SMS wherever the platform allows it, since SMS codes can be intercepted. Limit admin access to banking and payroll to the fewest people necessary, and make sure every one of those users has a strong, unique password. A password manager makes this feasible even for a solo owner managing dozens of logins.
This is the single highest-return technical control you can implement. Most account takeovers depend on stolen credentials. MFA stops that attack even when the password is compromised.
Dual Approvals, Positive Pay, and Transaction Alerts
These are bank-configurable services designed specifically to stop unauthorized money movement, and most small business owners have never heard of them. Here’s how each one works:
- Dual approval: Configure your business banking so one person creates a payment and a second authorized person approves it before it moves. Essential for wire transfers and ACH batches.
- Positive pay: Upload your issued-check details to your bank. The bank flags any check that doesn’t match your file and holds it for your review before clearing it.
- ACH debit block: Prevents unauthorized electronic withdrawals from accounts that don’t regularly send ACH payments. You can block all debits or create an approved-originator list.
- Transaction alerts: Set real-time SMS or email notifications for new payees, profile changes, large transfers, and account logins. Review them immediately, not at month-end.
Call your business banker and ask specifically for these payment approval controls by name. Many owners don’t know they exist because banks don’t always advertise them. At Chase, for example, ACH Positive Pay is available on Performance, Platinum, and Analysis Business Checking accounts and can be configured directly through Chase Business Online.
Training Your Team to Be Your Strongest Defense
Building a No-Blame Phishing Awareness Program
A practical anti-phishing training program for a small business doesn’t have to be complicated. The format that works: short role-based modules of 20 to 30 minutes, real email examples, a clear reporting process, and a culture where employees feel safe flagging mistakes instead of hiding them. The goal of training is behavior change, not fear. Scared employees hide incidents; empowered employees report them.
Every module should cover the same core content: suspicious sender addresses, urgency cues designed to short-circuit judgment, how to check a link before clicking it, and the verification-before-action rule. If a request involves money, credentials, or sensitive data, verify it through a separate, trusted channel before responding. This single habit eliminates the vast majority of social engineering attacks.
Running Simulated Phishing Tests and Measuring What Matters
Start with a baseline simulation to see where your team stands, then repeat monthly. Track three metrics: click rate, data submission rate, and report rate. That last number matters most. Getting employees to flag suspicious messages is as valuable as getting them not to click, because it creates a real-time early warning system inside your business.
Free and low-cost simulation tools built for small businesses include CanIPhish, which has a perpetual free tier and requires no IT setup, and PhishDrills, which is free for teams up to ten employees. When someone fails a simulation, the response should be targeted coaching and a short refresher, not blame. Repeated public shaming teaches employees to hide mistakes, which is exactly the opposite of what you need.
When a Scam Gets Through: Your Response Workflow
Business Scam Protection, Immediate Containment Steps
Speed is the most important factor in limiting damage. Here’s the 24-hour action list, in order:
- Freeze or change credentials on all affected accounts immediately.
- Call your bank to request a recall on any wire or ACH payment. Same-day contact gives you the best chance of recovery.
- Preserve all evidence: emails, screenshots, transaction records, and timestamps. Do not delete anything.
- Notify your team so the threat doesn’t spread to other employees or accounts.
- Document everything that happened, in sequence, while the details are fresh.
Print this list and post it somewhere accessible. The moment a scam lands is not the time to try to remember what to do first.
Reporting to the FTC, FBI IC3, and Your Bank
Three reporting channels cover most business fraud scenarios. The FTC at ReportFraud.ftc.gov covers scams, impersonation, and deceptive practices. The FBI IC3 at IC3.gov focuses on internet-enabled fraud including BEC and wire fraud. The CFPB covers issues with financial products and services. Before you file, have this information ready: the name, email, phone, and website of who contacted you; a clear narrative of what happened and when; the payment method, amount, and transaction ID; and copies of all evidence including email headers.
Reporting doesn’t guarantee you’ll recover the money, and it’s worth being honest with yourself about that. What it does is feed law enforcement intelligence that can protect other businesses from the same attack. The Digital Resistance community treats reporting as a collective defense act, not just a personal one.
Build the Plan, Then Work It
Business scam protection isn’t about having perfect technology. It’s about knowing where you’re exposed, putting a few key controls in place, training the people who handle money and communications, and having a plan ready for when something slips through. Use this as your business anti-fraud checklist: most of the controls here cost nothing but time and a conversation with your banker.
The Digital Resistance publishes plain-language updates on new scam tactics, provides free templates for incident response and staff training, and exists specifically to help business owners stay ahead without needing a dedicated security team. This movement is built by practitioners who know what it’s like to run a business without an IT department watching your back.
Pick one section from this checklist and implement it this week. Not next month. This week. Enable MFA on your banking accounts. Call your banker and ask about positive pay. Send your team a phishing red-flags reminder. One step done is worth more than a perfect plan that stays on the drawing board.
Headquarter
12 Belmont, Bath
United Kingdom
Telephone
+447707329924
Scammed? Here's How to File an FTC Complaint Fast
Scammed? Here's How to File an FTC Complaint Fast
If you've been targeted by a scam, knowing how to file an FTC complaint can help protect your identity, support investigations and prevent others from becoming victims. This guide explains the process step by step.
● Insights
Scammed? Here's How to File an FTC Complaint Fast
01
When You Should File an FTC Complaint
Learn which types of scams, fraud and identity theft should be reported to the Federal Trade Commission and why acting quickly matters.
02
How to File an FTC Complaint Step by Step
Follow a simple guide to submitting your complaint, including the information you'll need and what to expect during the process.
03
What Happens After You Submit Your Complaint
Understand how the FTC uses fraud reports, what actions you should take next and how to better protect yourself from future scams.
Everything You Need to Know About Filing an FTC Complaint
Getting scammed hits hard. The confusion, the anger, the second-guessing, it can feel paralyzing. But within the first 24 hours, one of the most concrete actions you can take is filing an FTC complaint scam report with the Federal Trade Commission. It won’t undo what happened, but it puts your experience into a system built to stop the same thing from happening to someone else.
The official starting point is ReportFraud.ftc.gov, the FTC’s primary portal for reporting scams, imposter fraud, and deceptive business practices. The form walks you through a handful of clear steps, category selection, scammer details, payment method, narrative, and the details you provide directly feed law enforcement intelligence used to track down repeat offenders. If you’re reading this before a scam has happened to you, The Digital Resistance publishes plain-language guides specifically designed to help you spot warning signs early. But if you’re already here, this walkthrough covers everything: what to gather, how to file, how to avoid getting scammed again in the process, and what realistically happens after you submit.
What to collect before you open the FTC scam report form
Filing a stronger FTC complaint about a scam starts before you open any browser tab. The more specific your details, the more useful your report becomes for investigators who may be tracking the same scammer across hundreds of complaints.
The documentation that sharpens your report
The FTC recommends pulling together a few core categories of evidence before you begin. You’ll want dates and timelines of every contact, any phone numbers or email addresses the scammer used, website URLs or company names they gave you, and a clear account of how much you paid, when, and through what method. Gift card receipts, wire transfer confirmations, bank statements, and screenshots of text messages or emails are all worth having on hand.
Don’t let incomplete information stop you from filing. If you only have a phone number and a rough date, that still goes into the system. Partial information is worth reporting because your fragment might connect to details from another victim’s report and help build a pattern investigators can act on.
What to leave out of the form
The FTC is explicit on this point: do not include your Social Security number, date of birth, or full bank account numbers in the complaint form. The form exists to document the scammer’s details, not to verify your identity. Keep a separate private file with your complete raw evidence, everything you collected, apart from what you actually type into the submission fields. Think of it as an editorial safeguard: the form gets the scammer’s story, your private file keeps the full record.
How to file an FTC complaint scam report at ReportFraud.ftc.gov
The form is straightforward once you know what to expect at each stage. Access it directly at ReportFraud.ftc.gov, or type ftc.gov/complaint into your browser; both take you to the same place.
Getting started on the FTC fraud report form
After clicking “Report Now,” the form asks you to select a category that describes what happened: an imposter scam, an online purchase that went wrong, identity theft, a deceptive business practice, and so on. Choose the category that fits best, even if it’s not a perfect match. If nothing fits, select “Something else” and describe the situation in the narrative section. The category helps the FTC route your report correctly, but it doesn’t limit what you can write in your own words.
Filling in the scammer’s details and your account of events
The narrative section is where specificity matters most. A report that reads “I was called on July 14, 2026, by someone claiming to be from the IRS who demanded $1,500 in iTunes gift cards” is far more actionable than “someone called and said they were from the government.” Include dates, contact methods, what the scammer said, what they asked for, and exactly how you sent money. The payment section will ask you to select your payment method, gift card, wire transfer, cryptocurrency, credit card, and enter the amount.
Submitting and saving your confirmation
When you hit submit, you’ll receive a reference number. Save it or screenshot it immediately. This number is how the FTC can link any follow-up information you provide to your original report. You’ll also have the option to include your personal contact information. You don’t have to share it, but doing so allows the FTC to reach out if they need additional details as part of a broader investigation.
Reporting by phone and international scams
The online form is the fastest route, but two situations call for a different path. Here’s how to handle each one.
Filing by phone through the FTC Consumer Response Center
If you’re not comfortable with online forms or prefer to speak with someone, call 1-877-FTC-HELP (1-877-382-4357). According to the FTC’s contact page, the Consumer Response Center is staffed Monday through Friday, 9:00 a.m. to 8:00 p.m. Eastern Time. The FTC also provides a TTY line at 1-866-653-4261 for hearing-impaired callers, and interpreter services are available. Phone staff can walk you through the same information captured by the online form.
When to use econsumer.gov instead
If the scam involved someone in another country, or a company based outside the U.S., go to econsumer.gov rather than ReportFraud.ftc.gov. The process is similar: file your complaint through the site’s form, and your report gets shared with a global network of consumer protection agencies that investigate cross-border fraud. The simple rule: international or cross-border scam goes to econsumer.gov; anything involving U.S.-based companies or individuals goes to ReportFraud.ftc.gov.
How to spot an FTC impersonation scam
Before you report a scam to the FTC, you need to know that scammers actively impersonate the agency itself. The FTC received more than 1 million imposter scam reports in 2025, and government impersonation is one of the most common variations. Knowing the red flags protects you from being victimized a second time while you’re in the middle of trying to report the first incident.
What real FTC contact looks like (and what it doesn’t)
The real FTC does not call you out of the blue, demand immediate payment, ask you to move money to “protect it,” or threaten arrest. The agency never requests payment by gift card, wire transfer, cryptocurrency, Bitcoin ATM, or gold. These are all methods scammers use, and no legitimate federal agency asks for them. Caller ID can be spoofed to display official government numbers, so a number that looks real proves nothing.
Warning signs in the message itself
Scammers rely on urgency and secrecy. They pressure you to act immediately, tell you not to mention the call to anyone, and push you to hand over sensitive information, Social Security numbers, bank account details, verification codes, or remote access to your device. Watch for invented department names like “FTC Refund Department” or “Clerk’s Office”; these units don’t exist. If you receive a call, text, or email like this, hang up or delete it, and verify any contact independently using the FTC’s official number you look up yourself, not a number the caller provides.
What the FTC actually does with your complaint
Understanding what happens after you submit sets realistic expectations and explains why filing still matters even when you never hear anything back.
How your report feeds into enforcement
The FTC does not investigate individual complaints or negotiate refunds directly for filers. That’s important to understand upfront so you’re not caught off guard. What the FTC does is add your report to its Consumer Sentinel database, a law enforcement tool used by the FTC and partner agencies to spot patterns, identify repeat offenders, and build cases that result in enforcement actions and court-ordered shutdowns.
Your report could be one of hundreds that tips an investigation over the threshold needed for action. The FTC’s 2025 data recorded 3 million fraud reports and $15.9 billion in consumer losses, and enforcement cases are built from exactly that kind of aggregated data.
What to realistically expect after filing
Most filers receive a confirmation reference number immediately and nothing further unless the FTC needs more information. This is different from agencies like the CFPB, where companies are required to respond within 15 days. The FTC complaint process doesn’t work that way. Think of it as: your report matters at scale, not just individually. That distinction also points you toward the next steps that do have a direct impact on your own situation.
Recovery steps to take alongside your FTC report
Filing an FTC complaint scam report is step one. These are the moves that directly affect your money, your accounts, and your safety going forward.
Other agencies that can escalate your case
Depending on what happened, file with one or more of these agencies in addition to the FTC:
- FBI’s Internet Crime Complaint Center (IC3) at ic3.gov for internet-based fraud and cybercrime involving financial losses
- CFPB (ConsumerFinance.gov) if a bank, lender, or financial institution was involved and you want the company required to respond
- Your state attorney general’s office for state-level consumer protection action, which can move faster than federal agencies in some cases
- Your bank or card issuer immediately if money was transferred, to explore reversal options before the window closes
If the scam involved misuse of your personal information, someone opening accounts in your name, filing taxes using your SSN, or similar identity-based fraud, file a separate report at IdentityTheft.gov. That portal generates a personalized recovery plan, sample dispute letters, and an official FTC Identity Theft Report that can be used with creditors and agencies.
Building your defenses so this doesn’t happen again
The best outcome after filing a complaint is understanding exactly how the scam worked and catching it earlier next time. Scammers are not slowing down. Consumer protection agencies and researchers continue to document growing use of AI-generated voice calls, deepfake impersonations, and increasingly sophisticated social engineering in fraud schemes. That’s precisely the territory The Digital Resistance was built for: helping everyday Americans and small businesses identify scam tactics and AI-driven manipulation before money changes hands. No technical background required. Filing this report was the right call, and using it as a turning point toward sharper digital awareness is the real win here.
You filed. Here’s what’s next.
To recap the process: collect your documentation before you start, go to ReportFraud.ftc.gov, fill in the details specifically and thoroughly, save your confirmation number, and stay alert to FTC impersonation attempts while you’re in the middle of this process. If the scam crossed international borders, use econsumer.gov. If your identity was stolen, add IdentityTheft.gov to your list.
Your FTC complaint scam report may not result in a direct refund, and you may not hear from the agency again. But it feeds a system that has real enforcement power, and it contributes to a larger accountability structure that protects the next person in your position.
The most powerful follow-up to filing is learning how the scam got through your defenses in the first place. The Digital Resistance publishes plain-language scam recognition guides, AI fraud breakdowns, and practical awareness tools built specifically for non-technical Americans. That’s the next step worth taking, understanding the method is how you make sure it doesn’t work twice.
Headquarter
12 Belmont, Bath
United Kingdom
Telephone
+447707329924









