Build the Four Basic Defenses First
Cybersecurity awareness should produce repeatable behavior, not fear of every unfamiliar message. CISA's Secure Our World campaign emphasizes four actions: recognize and report phishing, use strong passwords, turn on multifactor authentication, and install software updates. Individuals and small businesses can make those actions operational with a password manager, unique credentials, automatic updates, MFA on email and financial accounts, and a known process for reporting suspicious messages.
Businesses should also identify who can change payment instructions, reset accounts, add administrators, export customer data, or approve remote access. Require a second channel or second person for high-risk changes. Maintain current vendor and employee contact information outside the email thread being verified. Backups should be protected from the same credentials and systems they are intended to recover.
Verify Requests Outside the Message That Created Urgency
Do not treat a familiar display name, phone number, writing style, photograph, or voice as identity proof. Attackers can compromise accounts, spoof sender information, reuse public details, and generate convincing audio or text. The FBI has warned that malicious actors use text messages and AI-generated voice messages for impersonation, often trying to move a target to another platform or obtain account access.
Pause before paying, disclosing credentials, installing software, changing banking details, buying gift cards, or sharing verification codes. Call the claimed person using a number already known or independently retrieved—not a number in the suspicious message. For a business payment change, verify through an established vendor contact and internal approval process. The FTC's voice-cloning scam guidance similarly recommends contacting the person through a known number.
Contain an Incident Without Destroying the Record
If compromise is suspected, protect money and access first. Contact the bank or payment provider about unauthorized transactions, use a known-clean device to change the affected account's password, revoke unknown sessions and recovery methods, enable MFA, and notify the appropriate internal security or IT contact. Follow incident-response advice from a qualified cybersecurity professional where systems, regulated data, or business operations are involved.
Preserve what happened while containment proceeds. Save original emails where possible, full message headers, text threads, voicemail files, account alerts, login notifications, URLs, usernames, telephone numbers, transaction identifiers, receipts, wallet addresses, remote-access tool names, dates, times, and steps already taken. Avoid editing originals or relying only on cropped screenshots. Do not continue communicating merely to “catch” the actor if doing so risks more loss, retaliation, or contamination.
Route Fraud, Identity Theft, and Cybercrime Correctly
Immediate danger and active crimes require the appropriate emergency or law-enforcement route. Identity-theft victims can create a recovery plan at IdentityTheft.gov. Consumer fraud can be reported at ReportFraud.ftc.gov. Internet-enabled crime can be reported to the FBI's Internet Crime Complaint Center. Also use the reporting channel supplied by the bank, platform, employer, insurer, or affected service.
A private investigation should not delay those reports or promise recovery. Preserve confirmation numbers and copies of submissions so later work can avoid duplication. Notify affected people or organizations only through an authorized plan; premature public accusations can create safety, privacy, legal, and evidence problems.
Know Which Professional Role You Actually Need
A cybersecurity provider can contain systems, review logs, eradicate malware, restore operations, harden controls, and address notification or compliance duties. Law enforcement investigates crimes with government authority. Banks and platforms can freeze, reverse, restore, or disclose through their own processes. Counsel provides legal advice, directs preservation and privilege strategy, and evaluates compulsory process.
A licensed PI may help build a chronology, preserve public-facing evidence, resolve identities, trace business or account leads through lawful sources, interview witnesses, or coordinate factual reporting. A PI license does not authorize hacking, access to private accounts, interception, or recovery guarantees. Define the missing fact and choose the professional with the authority and technical capability to address it.
For an account-specific checklist, see how to respond to a suspected hacked account. For AI impersonation evidence, continue with the AI scam verification workflow.
Related Services
