Skip to content
FIN-CSIRT
RS
Report an incident

FIN-CSIRT / Practical lesson

What to do first when something goes wrong

Choose the situation that applies. If money is at risk, contact your bank immediately; you do not need to finish this lesson first.

People seeking help after a suspicious actionAbout 4 minutes of reading + 3 questions
Go to response steps Choose what happened

What you will learn

  • Choose the first step for money, an account or a device.
  • Prepare a short description without passwords or codes.
  • Continue with the relevant practical guide.

Choose the first step

If money, your card or banking access is at risk, contact your bank immediately through an official channel. End the suspicious call. Obtain the number from your usual banking app, the back of your card or the bank’s website opened independently.

What happened What to do first
You sent money, shared card details or approved a suspicious payment Call your bank and explain what you sent or approved. Money and card steps.
You entered a password or lost access to an account Open official settings or recovery from a trusted device. Account steps.
Your phone is missing or your number unexpectedly lost service Contact the carrier from another phone to check and protect the number. Notify the bank immediately too if banking is at risk. Phone steps.
Someone controls the device or a ransom demand appears Disconnect Wi-Fi, mobile data and wired networking. Device steps.

If situations overlap, take the urgent measures for each. Notify internal IT or security support immediately for a work account or device.

Money or a card is at risk

  1. Tell the bank you suspect fraud. Give the time, amount and whether you entered card information, a password or a code.
  2. Request protection of the affected payment instrument or access, following the bank’s assessment.
  3. Ask about the procedure for disputing the transaction and the evidence needed.
  4. Record the case number or acknowledgement if provided.

You can begin: “I suspect fraud. It happened at __. I shared __. My account shows __. What measures can you take now?” Do not fill the blanks with a PIN or one-time code. Recovery of money is not guaranteed. More on contacting your bank safely.

A password or account is at risk

  1. Open the instructions for your service. Use another trusted phone or computer if the current one may be compromised.
  2. Change the exposed password, or start official recovery if you cannot sign in.
  3. Check other sign-ins, connected apps and recovery information using that guide.
  4. Replace the same password on any other accounts where you reused it.

If multiple accounts are affected, prioritise the email used to recover the others. Check email forwarding too. Full account recovery sequence.

Your phone is missing or your number has stopped working

Loss of service alone does not prove a number takeover. Your carrier should check outages, SIM status and any change you did not request. Explain whether the phone is missing or still in your possession.

From another trusted device, use a previously configured locating and locking feature: Android or iPhone. Report suspected theft to the police; do not go to an unfamiliar map location yourself. Use the SIM swap guide for further checks.

A device may be under someone else’s control

  1. Disconnect networking if you see active control, extortion or other serious compromise indicators.
  2. Stop entering passwords and using banking on that device.
  3. Contact the bank from another device if banking information was exposed.
  4. Continue with device recovery or your internal IT team’s procedure.

Do not connect a backup drive. Do not reconnect just to download a “cleanup tool”. An installed app alone does not establish infection; the remote-access guide explains the different situations.

Preserve information and report

When this does not delay protection, record the time, website address, displayed number or sender, amount and actions already taken. Keep original messages and receipts. Do not reopen suspicious attachments to gather evidence.

Report a cyber incident to FIN-CSIRT with a short description and relevant evidence. Do not send passwords, PINs, one-time codes or recovery codes. This does not replace urgent contact with the bank, carrier, police or account provider. Keep acknowledgements and follow each relevant recipient’s instructions.

Practice example

You shared a code, then noticed an unfamiliar payment

After speaking to someone claiming to be your bank, you see a transaction in the app that you did not intend to authorise.

  1. 01End the suspicious contact
  2. 02Notify the bank
  3. 03Record the event
Fictional practice example. Do not wait for the quiz result before contacting your bank.
Show the example explanation
End the suspicious contact
Get the bank's number from a known app, your card or its official website.
Notify the bank
Explain what you shared and which transaction you dispute.
Record the event
Keep times, messages and transaction details without delaying urgent measures.

Check your knowledge · 3

Your turn to choose the next step.

Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.

Questions and explanations are also available without JavaScript.

Money was sent after a suspicious call. What comes first?

Why does this matter? Your bank manages the payment instrument and can assess available measures for that transaction.

  1. Wait for a reply to an incident report.

    Waiting delays notifying the bank of possible misuse.

  2. Call the bank immediately using a verified number.Correct answer

    Official contact lets the bank investigate and assess access protection.

  3. Pay someone promising to recover the money.

    Another payment does not establish recovery capability and may be another scam.

Your phone is under active remote control. Where should you change your email password?

Why does this matter? Someone controlling a device may also see new information you enter.

  1. On the same phone while remote control continues.

    The new password could be exposed immediately.

  2. In a form sent by the caller.

    A suspicious contact should not choose your recovery route.

  3. From another trusted device, through the official service.Correct answer

    This separates account protection from the potentially controlled device.

What belongs in an initial report?

Why does this matter? A description and timeline help investigation; secret codes may enable further access.

  1. Time, description and relevant evidence without passwords or codes.Correct answer

    The recipient gets useful context without unnecessary access secrets.

  2. Your password and recovery codes so support can sign in.

    Those credentials are for your own sign-in, not an incident description.

  3. Every photo and document on your phone.

    Unrelated personal information adds exposure and makes review harder.

No registration. Your answers are not sent; the result is just for you.

Protect first, then report

Contact the provider that can limit active harm; a FIN-CSIRT report does not replace your bank, carrier or account provider.

Find the controls for your account

References

Sources and further reading

The National Bank of Serbia explains payment-data protection and immediate notification of misuse. Google’s compromised-account instructions support access and email-setting checks. Lost-phone steps are supported by Google Find Hub and Apple’s stolen-iPhone guide; options depend on prior setup. Isolation of an actively affected system and evidence preservation follow the US cybersecurity agency’s CISA ransomware guide.

Content last reviewed