United States · scam response guide · 31 min read
How to Get Money Back After a Scam in the United States
Getting money back after a scam is not one process. The strongest first move is to identify exactly how each payment left, tell the relevant provider immediately, preserve the transaction trail and describe truthfully who initiated the transfer. A card billing-error notice, an unauthorized electronic-fund-transfer claim, a wire recall and an IC3 crypto report are separate tools with different purposes. None guarantees repayment, but delay and inaccurate wording can close practical options that still exist.
Sources for the introduction, figures and summary
- FTC — What To Do if You Were Scammed28.07.2026
- GAO-24-107107 — Payment Scams: Information on Financial Industry Efforts28.07.2026
- FBI Internet Crime Complaint Center — Domestic Financial Fraud Kill Chain, 2025 results28.07.2026
- FTC — IdentityTheft.gov Recovery Steps28.07.2026
- CFPB — Electronic Fund Transfers FAQs, version updated 15 January 202528.07.2026
- CFPB — Regulation Z § 1026.12, Special credit card provisions28.07.2026
- CFPB — Regulation Z § 1026.13, Billing error resolution28.07.2026
- CFPB — How to fix mistakes in your credit card bill, modified 4 June 202528.07.2026
- CFPB — Regulation E § 1005.11, Procedures for resolving errors28.07.2026
- CFPB — Regulation E § 1005.6, consumer liability for unauthorized transfersChecked 29 July 2026
- FBI Internet Crime Complaint Center — File a complaint28.07.2026
- FBI Internet Crime Complaint Center — Complaint FAQ28.07.2026
- GAO-25-107088 — Consumer Protection: Actions Needed to Counter Scams28.07.2026
- FTC — Refund and Recovery Scams28.07.2026
- FBI Internet Crime Complaint Center — Cryptocurrency guidance28.07.2026
- FTC — ReportFraud.gov28.07.2026
- CFPB — Learn how the complaint process works, modified 28 May 202628.07.2026
Can you get money back after a scam? Start with the payment rail
Direct answer: You may be able to recover money after a scam, but the correct route depends first on the payment method and who initiated it: call the card issuer, bank, wire company, payment app, gift-card issuer or crypto platform now, ask for the specific reversal or investigation available, and record the case number.
There is no single federal form that reverses every scam payment. A stolen card charge, a transfer pushed from an account by an intruder, a wire the customer approved after a fake-invoice email and USDT sent to an investment wallet may all arise from fraud, yet they do not enter the same dispute system. Separate mixed losses into one row per transaction before choosing language or attaching evidence.
The Federal Trade Commission advises contacting the company used to send the money and asking whether the transaction can be reversed. That is sound triage, not a refund guarantee. The Government Accountability Office reported in April 2024 that financial institutions generally are not required by federal law to reimburse a fraudulently induced payment when a person with payment authority authorized it. Provider policies, network protections, state law and the exact facts may still create another route, so ask for a written classification instead of accepting a one-line answer.
Run the actions in parallel where possible. A bank recall tries to reach money; an FTC report supplies consumer-protection intelligence; an IC3 complaint supplies internet-crime and transaction data. Waiting for one agency to reply before calling the bank misunderstands their roles. Secure the account and preserve evidence at the same time, because the next loss may be an account takeover or a fake recovery service targeting the same victim.
Use the table as a first routing tool. It is deliberately cautious: ‘ask’ means submit a fact-matched request, not claim a right that the record cannot support. If one scam used three payment methods, create three workstreams and keep their reference numbers in the same chronology.
| How money left | First contact and request | Evidence to have ready | Core limitation |
|---|---|---|---|
| Credit card | Issuer: report unauthorized use or send a billing-error notice that matches the facts | Statement, merchant descriptor, receipt, promised delivery, contact record | A purchase willingly made is not automatically unauthorized use |
| Debit card or consumer ACH | Account-holding bank: assert the specific EFT error and request Regulation E handling if applicable | Statement date, amount, account, device or login facts, notice timestamp | A consumer-initiated scam payment may be treated differently from an intruder-initiated EFT |
| Bank wire | Originating bank: request recall or reversal and a fraud notification; file IC3 promptly | Wire confirmation, beneficiary, receiving bank, time, communications | A recall is a request; settlement and onward movement can defeat it |
| Zelle or another payment app | App and linked bank or card: report to every provider in the funding chain | App transaction ID, recipient profile, funding instrument, login history | No universal federal reimbursement rule covers every scam-induced payment |
| Gift card | Issuer: report scam use and request a freeze or refund; retain card and receipt | Card number, PIN exposure time, purchase receipt, redemption details | Value may be spent quickly and policies differ |
| Cash or check | Carrier, bank and law enforcement: ask about intercept, stop-payment or fraud steps | Tracking, check number, payee, deposit status, delivery address | A posted counterfeit check can be reversed after provisional availability |
| Cryptocurrency or USDT | Sending platform and any identifiable receiving service; file a detailed IC3 complaint | Network, asset, TXID, addresses, amount, timestamp, exchange records | Blockchain transfers typically are not reversible by the sender |
Source: FTC — What To Do if You Were Scammed28.07.2026
Source: GAO-24-107107 — Payment Scams: Information on Financial Industry Efforts28.07.2026
What to do in the first hour after discovering the scam
Direct answer: Stop new payments, call the sending provider through a verified channel, lock exposed accounts, preserve messages before blocking contacts and start a timestamped incident log; these actions protect both recovery options and the evidence needed to use them.
Start with the money still at risk. Cancel scheduled transfers, revoke unfamiliar devices and app sessions, replace exposed passwords from a clean device and tell the provider if the scammer had remote access. If a payment is pending, say so explicitly. If it has posted, still ask what recall, reversal, charge dispute or recipient-bank notification can be initiated. Record the exact answer and reference number.
Do not keep negotiating for a withdrawal, prize, refund or investment balance. A demand for tax, insurance, gas, verification funds or a refundable security deposit is often the next extraction step. Paying a small amount to ‘unlock’ a larger balance creates another transaction to chase. Preserve the demand, but do not warn the sender that a report is coming; that may encourage deletion of accounts or movement of funds.
Save evidence before it changes. Export the full chat if the platform allows it, download bank and exchange records, capture complete URLs and profile identifiers, and keep original email files with headers. Screenshots are useful, but a cropped image of a balance is weaker than a statement, transfer confirmation or blockchain transaction identifier. Keep originals unedited and work from copies when adding notes.
Create a one-page control sheet with transaction, amount, date and time, destination, provider contacted, requested action, case number and next follow-up date. This reduces a common failure: telling three institutions three slightly different stories because the victim is exhausted. The core chronology should remain consistent while each submission answers the rules of its own payment rail.
- 01Stop
End further payments, scheduled transfers, wallet approvals and remote access.
- 02Notify
Use the number on the card, the official app or an independently typed official website; ask for a reference.
- 03Secure
Change email and financial credentials, enable strong multifactor authentication and review logged-in devices.
- 04Preserve
Export communications and download transaction records before blocking the scam contact.
- 05Report
Use FTC and IC3 channels for their distinct purposes, without postponing payment-provider action.
Source: FTC — What To Do if You Were Scammed28.07.2026
Source: FBI Internet Crime Complaint Center — Domestic Financial Fraud Kill Chain, 2025 results28.07.2026
Source: FTC — IdentityTheft.gov Recovery Steps28.07.2026
Related steps:Investment scam recovery: bank, regulator and legal routes · Crypto scam recovery: evidence, tracing and reporting
Credit card scam disputes: use the correct federal track
Direct answer: For a credit card, promptly report unauthorized use by another person and separately consider a written Regulation Z billing-error notice when the statement shows a qualifying error, such as a transaction you did not make or goods or services not delivered as agreed.
Unauthorized use and billing-error resolution overlap, but they are not interchangeable slogans. Regulation Z section 1026.12 defines unauthorized use around use by a person without actual, implied or apparent authority and limits a cardholder’s liability to the lesser of $50 or the value obtained before notice, when the regulation’s conditions for imposing liability are satisfied. An issuer may provide more generous zero-liability terms, but those private terms should not be presented as the federal minimum for every case.
Section 1026.13 defines several billing errors. They include an extension of credit not made to the consumer or an authorized person and, in specified circumstances, property or services not accepted or not delivered as agreed. The official interpretation says this latter category does not cover a dispute only about the quality of accepted goods or services. A card purchase of crypto that the exchange delivered may therefore be different from a direct card charge by a fake seller that delivered nothing.
To invoke the formal billing-error procedure, the creditor must receive a written notice at the billing-inquiries address no later than 60 days after transmitting the first periodic statement that reflects the alleged error. The notice should identify the consumer and account, the disputed amount and why an error exists. The regulation generally requires written acknowledgment within 30 days unless the matter was already resolved and resolution within two complete billing cycles, never later than 90 days. These are procedure markers, not promised refund dates.
Keep paying undisputed amounts on time. The CFPB consumer guide says the disputed charge and related charges need not be paid while the issuer investigates under the qualifying billing-error process, but correct charges remain due. Use the address and submission method on the statement, retain proof of delivery and keep a copy. A phone report may secure the account quickly; it does not necessarily replace the written notice required for the statutory billing-error procedure.
- 01Lock and report
Tell the issuer immediately if the card or account may still be used and request replacement credentials.
- 02Classify
State whether another person used the card, or whether your dispute concerns non-delivery or another listed billing error.
- 03Write
Send the notice to the billing-dispute address using the statement’s instructions and preserve proof of receipt.
- 04Track
Log acknowledgment, requested documents, investigation result and the rule or policy cited.
Source: CFPB — Regulation Z § 1026.12, Special credit card provisions28.07.2026
Source: CFPB — Regulation Z § 1026.13, Billing error resolution28.07.2026
Source: CFPB — How to fix mistakes in your credit card bill, modified 4 June 202528.07.2026
Source: FTC — What To Do if You Were Scammed28.07.2026
Debit card and ACH fraud: what Regulation E does and does not cover
Direct answer: Regulation E can require an investigation of a qualifying error involving a consumer account, including an unauthorized EFT, but coverage and liability turn on the transaction, authorization facts and timely notice—not simply on the fact that a scam occurred.
Regulation E covers electronic fund transfers that debit or credit a consumer asset account, including many debit-card, ACH and P2P transactions. It is not the rule for every wire, business account or credit transaction. Start with the account type, transfer mechanism and person who initiated the instruction. If the fraudster used stolen credentials, say that. If you pressed send, say that too and ask what non-Regulation-E protections the institution offers.
For the section 1005.11 error-resolution procedure, notice generally must reach the institution no later than 60 days after it sends the periodic statement on which the alleged error first appears. The notice must enable identification of the consumer and account and indicate why an error is believed to exist, including the type, date and amount as far as possible. A bank may request written confirmation within 10 business days after oral notice, but the official interpretation says it must begin promptly and may not delay the investigation while waiting for that confirmation.
Section 1005.6 has a separate liability ladder for unauthorized EFTs. Where a lost or stolen access device is involved, notice within two business days after learning of the loss or theft generally limits liability to the lesser of $50 or the unauthorized transfers before notice. A later report can produce a maximum of up to $500 under the regulation’s formula. If an unauthorized transfer appears on a periodic statement and is not reported within 60 days after the statement was sent, exposure to qualifying subsequent transfers can become unlimited. These are conditional maximum-liability rules, not a flat fee and not proof that a personally initiated scam payment was unauthorized.
The general investigation period is 10 business days. If the institution cannot finish then, section 1005.11 allows up to 45 days when it provisionally credits the alleged error within 10 business days and follows the rule’s conditions. The rule contains modified periods for certain transactions and accounts, including a possible 90-day investigation period in specified cases. Do not quote ‘ten days’ as a guaranteed final refund or ‘forty-five days’ without checking whether provisional-credit and exception provisions apply.
The CFPB FAQ also states that a financial institution cannot require a police report as a condition to begin a Regulation E investigation and cannot require the consumer to contact the merchant first before initiating an investigation of a reported unauthorized EFT. A police or IC3 report can still strengthen the factual record. If the bank says ‘the network is final,’ ask how that private rule affects its statutory analysis; CFPB says private network rules cannot reduce Regulation E protections.
| Marker | General rule | What it does not mean |
|---|---|---|
| Consumer notice | No later than 60 days after the institution sends the statement first showing the alleged error | Every late claim is impossible or every scam is a covered error |
| Lost or stolen access device | Report within two business days to preserve the basic up-to-$50 tier where § 1005.6 applies | Every unauthorized EFT automatically costs the consumer $50 |
| Later access-device report | Potential liability can rise to a maximum of $500 under the regulation’s loss-and-timing formula | $500 is automatic or applies to a consumer-authorized transfer |
| Initial investigation | Generally determine within 10 business days | Money must permanently remain credited by day ten |
| Extended investigation | Up to 45 days if provisional-credit and other conditions are met | Every institution may wait 45 days without provisional credit |
| Specified exceptions | Certain accounts or transactions can have modified periods, including up to 90 days | Ninety days is the standard for all debit or ACH claims |
Source: CFPB — Regulation E § 1005.11, Procedures for resolving errors28.07.2026
Source: CFPB — Regulation E § 1005.6, consumer liability for unauthorized transfersChecked 29 July 2026
Source: CFPB — Electronic Fund Transfers FAQs, version updated 15 January 202528.07.2026
Wire transfer scam recovery: request the recall immediately
Direct answer: After a fraudulent wire, contact the originating bank at once, request a recall or reversal plus a fraud notice to the receiving bank, ask whether a hold-harmless or indemnity communication is appropriate, and file a detailed IC3 complaint without waiting for the bank’s final decision.
A wire recall is an urgent attempt to reach funds, not a legal undo button. The sending bank may contact the receiving institution, but money can be withdrawn, moved onward or subject to another institution’s process. Give the bank the wire reference, date and time, amount, beneficiary, beneficiary account, receiving bank, and a compact explanation of the deception. If the wire is only scheduled or pending, state that before discussing the completed-payment route.
The FBI IC3 Domestic Financial Fraud Kill Chain brochure tells victims to contact the originating financial institution as soon as fraud is recognized to request a recall or reversal, as well as a Hold Harmless Letter or Letter of Indemnity, and to file a detailed IC3 complaint with banking information. These documents are communications between institutions; a consumer should ask the bank whether they are suitable rather than attempting to create a supposed bank indemnity letter independently.
The same FBI brochure reports 3,574 incidents in its domestic FFKC process for calendar year 2025, with about $833 million in reported losses and about $507 million frozen, labeled a 61 percent recovery rate. That percentage belongs only to the reported program population shown in the brochure. It is not a forecast for all wire victims, does not mean every frozen dollar was returned, and should never be used to sell a guaranteed outcome.
Follow up in writing after the urgent call. Confirm the requested recall, describe whether the beneficiary details were substituted or whether you were induced to approve them, attach the payment confirmation and request preservation of related records. Add the IC3 complaint number when available. If a business-email-compromise incident involves a company, preserve the original email with routing headers and notify the real counterpart through a known channel.
Source: FBI Internet Crime Complaint Center — Domestic Financial Fraud Kill Chain, 2025 results28.07.2026
Source: FBI Internet Crime Complaint Center — File a complaint28.07.2026
Source: FBI Internet Crime Complaint Center — Complaint FAQ28.07.2026
Related steps:UK APP scam reimbursement guide
Zelle and payment-app scams: report both the app and funding account
Direct answer: For a Zelle or payment-app loss, report the transaction to the app and the bank or card that funded it, state who initiated it, request the applicable error investigation or provider review, and do not assume that every scam payment is either automatically reimbursable or automatically final.
Begin with the funding chain. A payment-app balance, linked debit card, linked bank account and credit card can trigger different records and potential protections. Download the app receipt, recipient handle, phone or email identifier, transaction ID, funding source, device notices and support conversation. If a stranger used a non-bank P2P provider to pull from your bank account, report the unknown provider as well as the bank entry.
The CFPB FAQ says a credit-push P2P transfer initiated by a third party who fraudulently obtained account access can be an unauthorized EFT. It also says account-holding institutions can have Regulation E error-resolution obligations even when a non-bank P2P provider was involved. That does not turn a transfer personally sent to a scammer into an unauthorized EFT. Who initiated the payment remains the central fact.
GAO’s payment-scam report explains the other side of the boundary: financial institutions generally are not federally required to reimburse fraudulently induced authorized payments. Some institutions and apps may use additional warnings, delays or voluntary programs, and contracts or state law may add protections. Ask the provider to identify the precise policy and transaction classification it used instead of relying on social-media claims that one brand ‘always refunds’ or ‘never refunds.’
If the app points to the bank and the bank points back to the app, send each a short written notice identifying the other case number. Ask which entity holds the consumer account, which initiated the EFT, whether the claim was reviewed under Regulation E, and which records support the authorization decision. Escalate only after preserving both responses; contradictory explanations can be important in a CFPB complaint.
- App transaction ID and recipient profile
- Funding source and corresponding bank or card entry
- Who opened the app, selected the recipient and confirmed payment
- Any credential, one-time-code or remote-access compromise
- Warning screens shown before confirmation
- Reports made to the app and bank, with timestamps and case numbers
Source: CFPB — Electronic Fund Transfers FAQs, version updated 15 January 202528.07.2026
Source: GAO-24-107107 — Payment Scams: Information on Financial Industry Efforts28.07.2026
Source: GAO-25-107088 — Consumer Protection: Actions Needed to Counter Scams28.07.2026
Source: FTC — What To Do if You Were Scammed28.07.2026
Gift cards, mailed cash and checks: contact the issuer or carrier
Direct answer: For gift cards, keep the card and receipt and contact the issuer; for mailed cash, ask the carrier about interception; for a check, contact the bank about stop-payment or fraud steps—then preserve redemption, tracking or deposit records.
Gift-card scams move value through the card number and PIN, so the physical card is evidence even after the code was disclosed. The FTC advises contacting the issuing company, saying the card was used in a scam, requesting a refund and retaining the card and receipt. Use the issuer’s official website or the number printed on the card, not a support number supplied by the person who demanded payment.
For cash sent through the mail, the FTC directs consumers to contact the U.S. Postal Inspection Service and ask whether the package can be intercepted. A tracking number, mailing receipt, destination, package description and time of deposit can matter. Do not attempt to retrieve a package personally from an address linked to a scammer. Report threats or immediate physical danger to emergency services.
A personal check may be stoppable before payment, but status and bank rules matter. Give the bank the check number, payee, amount and date, and ask what action remains possible. Keep images of the front and back if the check posts. An altered payee, forged signature and a check willingly written because of a lie are different fact patterns, so describe what happened rather than choosing a legal label first.
Counterfeit-check scams create a separate trap. Funds may appear available before the bank determines that the deposited check is fake. If the victim sends part of that apparent balance to the scammer, the later return of the counterfeit item can leave the victim owing the bank. Stop onward payments, tell the bank why the check is suspect and preserve the envelope, check image and conversation. Availability on a screen is not final authenticity.
Source: FTC — What To Do if You Were Scammed28.07.2026
Source: FTC — Refund and Recovery Scams28.07.2026
Cryptocurrency and USDT scams: preserve the on-chain identifiers
Direct answer: A crypto or USDT payment is typically not reversible by the sender, but you should immediately secure the wallet, notify the sending platform and any identifiable receiving service, preserve network-specific transaction data and submit a detailed IC3 complaint.
Start by naming the network. USDT exists on more than one blockchain, and the same-looking token name does not make addresses interchangeable. Record the asset, network, amount, transaction hash, sending address, destination address, date and time, exchange withdrawal ID, and any destination tag or memo. Copy the values from the wallet or exchange record and verify them against a reputable block explorer for that network.
The FTC says cryptocurrency payments typically are not reversible and usually can be returned only if the recipient sends them back, while still advising the consumer to contact the company used to send the payment and ask whether reversal is possible. The FBI notes that blockchain information can help trace transactions, but movement to services in other jurisdictions can create major investigative challenges. A visible route is evidence; it is not control of the destination wallet.
IC3 asks crypto complainants for transaction addresses, amounts and asset types, transaction hashes, dates and times, plus contextual identifiers such as domains, phone numbers and communication platforms. File even if the wallet has already moved the funds. If an exchange or other hosted service can be identified, use its official fraud or compliance channel, provide the IC3 reference and request preservation of account and transaction records. The service determines what it can disclose or restrain under applicable process.
Never share a seed phrase or private key with a tracer, investigator, lawyer, exchange employee or supposed government agent. Do not connect the wallet to a recovery website or sign a blind transaction to ‘verify ownership.’ A fake recovery operator may show the real transaction on a public explorer, then demand gas, tax or an activation deposit. Knowing a TXID proves that someone read a public ledger, not that they can return the assets.
| Record | Why it matters | Common error |
|---|---|---|
| Network and asset | Identifies the ledger and token actually used | Writing only ‘USDT’ or ‘crypto’ |
| Transaction hash | Locates the exact on-chain transfer | Sending a cropped balance screenshot instead |
| Both addresses | Shows origin and first destination | Assuming an address label proves the owner |
| Exchange withdrawal record | Links the account event to the on-chain transfer | Deleting the account after the scam |
| Communication and domain | Explains inducement and potential attribution | Recording only the display name |
| IC3 and platform references | Connects later evidence to the original reports | Opening unrelated tickets with inconsistent totals |
Source: FTC — What To Do if You Were Scammed28.07.2026
Source: FBI Internet Crime Complaint Center — Cryptocurrency guidance28.07.2026
Source: FBI Internet Crime Complaint Center — Complaint FAQ28.07.2026
FTC report or FBI IC3 complaint: file for the right purpose
Direct answer: Report consumer scams to the FTC for enforcement intelligence and trend detection, and report internet-enabled crime to FBI IC3 with detailed transaction and suspect data; neither filing is a personal refund order, so payment-provider action should continue in parallel.
ReportFraud.gov is the FTC’s intake route for fraud, scams and bad business practices. The FTC explains that reports help it build cases, spot trends, educate the public and share information with law enforcement. A report can create a useful contemporaneous record, but the FTC does not become the victim’s personal recovery representative simply because a confirmation number was issued.
IC3 receives internet-crime complaints. Its FAQ asks for complainant details, financial loss and transaction information, subject identifiers, a clear description and email headers where relevant. The FBI says accuracy and completeness affect its ability to address a complaint and that a complainant may be contacted if additional information is needed. Filing does not guarantee contact, investigation, freezing or reimbursement.
Use both when the facts fit both. A fake online investment platform paid by wire can be reported to the FTC as a consumer scam and to IC3 as internet-enabled financial crime, while the bank receives the urgent recall request. A local police report may be useful for identity theft, threats, insurance or a provider’s evidence file, but it should not be invented or treated as a prerequisite where a federal error rule says the institution must begin without one.
Keep the narrative consistent and tailor the attachments. The bank needs the transaction and disputed authorization or service facts. IC3 needs technical and suspect identifiers. The FTC needs the scam pattern and loss. Save each report before submission if the portal allows it, record the confirmation number and add new evidence through the channel’s stated process rather than assuming an email reply reached the case.
| Route | Primary function | Best information | Not a promise of |
|---|---|---|---|
| Bank, issuer or payment provider | Recall, account protection, dispute or error review | Exact transaction, authorization facts, requested remedy | Approval or recovery |
| FTC ReportFraud.gov | Consumer-protection intelligence and enforcement support | Scam method, business or contact, payment and loss | Individual investigation or refund |
| FBI IC3 | Internet-crime intake and law-enforcement analysis | Transactions, suspect identifiers, domains, headers, crypto data | A freeze or agent contact |
| Local police | Local crime report and immediate safety response | Chronology, identity documents, threats and property evidence | Bank reimbursement |
Source: FTC — ReportFraud.gov28.07.2026
Source: FTC — What To Do if You Were Scammed28.07.2026
Source: FBI Internet Crime Complaint Center — File a complaint28.07.2026
Source: FBI Internet Crime Complaint Center — Complaint FAQ28.07.2026
Source: CFPB — Electronic Fund Transfers FAQs, version updated 15 January 202528.07.2026
What to do when the bank denies the scam or fraud claim
Direct answer: After a denial, obtain the written decision and documents relied on, compare the bank’s classification with the actual initiation facts, submit a concise reconsideration through its formal process and then use the CFPB complaint channel or appropriate regulator without claiming that escalation guarantees reversal.
A denial is a document to analyze, not the end of the chronology. Ask which transactions were reviewed, whether the bank treated them as unauthorized EFTs, authorized scam payments, card billing errors or another category, and which rule, account term or network policy controlled. Request the investigation documents the applicable rule or bank process makes available. A generic statement that ‘credentials were used’ may not answer who initiated the EFT.
Build the reconsideration around one or two concrete errors. For example: the denial says the consumer initiated the transfer, while device records show a new session and the consumer only disclosed a code; or the bank measured notice from the transaction date when the cited Regulation E procedure refers to the date the relevant statement was sent. Attach the source and evidence. Do not send a fifty-page emotional narrative without an index or make accusations that the record cannot prove.
The CFPB accepts complaints about consumer financial products and services, routes suitable complaints to companies and may route a matter to another government agency. Its process page, modified 28 May 2026, says companies generally respond in 15 days; in some cases they indicate that work is in progress and provide a final response in 60 days. Those are complaint-process response markers, not deadlines for refunding the underlying loss.
In the CFPB submission, identify the account, disputed transactions, date of the original notice, bank case number, requested correction and the gap in the decision. Upload the denial and a compact exhibit list, removing passwords, complete card numbers, seed phrases and unnecessary identity data. If another regulator is better placed, CFPB says it may forward the complaint and notify the consumer. Preserve that routing notice and continue any separate appeal deadline shown by the bank.
- 01Get the record
Request the denial, reason, classification, investigated transactions and available supporting documents.
- 02Find the mismatch
Compare the decision with who initiated the payment, the account type, notice date and cited rule.
- 03Ask for reconsideration
Use the bank’s formal channel, state the requested correction and attach an indexed evidence set.
- 04Escalate accurately
Submit a CFPB complaint or follow the regulator route given for the institution; retain every reference.
Source: CFPB — Learn how the complaint process works, modified 28 May 202628.07.2026
Source: CFPB — Electronic Fund Transfers FAQs, version updated 15 January 202528.07.2026
Source: CFPB — Regulation E § 1005.11, Procedures for resolving errors28.07.2026
Source: CFPB — Regulation Z § 1026.13, Billing error resolution28.07.2026
Protect identity and credit after sharing personal information
Direct answer: If the scammer received Social Security, identity, bank-login or card information, use IdentityTheft.gov for a tailored recovery plan, secure affected accounts and consider a free credit freeze with each nationwide credit bureau.
Money recovery and identity recovery are separate workstreams. A payment may be final while stolen identity data remains usable for months. Change the email password first if that inbox can reset financial accounts, then replace exposed banking credentials, revoke sessions and ask providers about new account numbers. Tell the mobile carrier if a SIM takeover or number transfer is possible.
IdentityTheft.gov can create an FTC Identity Theft Report and a recovery plan based on the information entered. Save the report and plan as instructed. The site explains that a fraud alert makes a business verify identity before issuing new credit, while a credit freeze limits access to the credit report unless it is lifted or removed. A freeze is free to place and remove and remains until the consumer lifts or removes it.
A freeze must be placed with each of Equifax, Experian and TransUnion. By contrast, the IdentityTheft.gov recovery steps state that contacting one nationwide bureau for an extended fraud alert leads that bureau to notify the other two, subject to the identity-theft documentation described there. Use contact details reached from IdentityTheft.gov or the bureaus’ official sites, not links in an unsolicited ‘credit protection’ message.
Review reports for accounts or inquiries you do not recognize and preserve dispute results. Do not upload an unredacted Social Security card, full bank statement or driver’s license to a general recovery intake unless the recipient’s identity, purpose, security and necessity are established. ScamCompass intake should begin with redacted records; a regulated professional can request specific documents later through a controlled channel.
- Primary email password and recovery settings
- Bank, card, payment-app and exchange sessions
- Mobile-carrier PIN and number-transfer protection
- Credit freeze at all three nationwide bureaus
- IdentityTheft.gov report and tailored plan
- Credit reports, new-account inquiries and collection notices
Source: FTC — IdentityTheft.gov Recovery Steps28.07.2026
Source: FTC — What To Do if You Were Scammed28.07.2026
How to write a bank or provider scam report that can be investigated
Direct answer: Write a short, chronological and transaction-specific report stating who initiated each payment, what false representation caused it, when you discovered the problem, what remedy you request and which exhibit proves each point.
Lead with the action, not the backstory. A useful opening is: ‘I am reporting the three transactions listed below and asking you to determine whether each is an unauthorized EFT under Regulation E; I did not initiate them. I disclosed a one-time code to a caller impersonating the bank, after which a new device initiated the transfers.’ If you pressed send, replace that with the truth: ‘I initiated the payment after the recipient sent a false invoice; please open the institution’s scam review and send a recall.’
Then list transactions exactly as shown on the statement. Include date, amount, recipient or merchant descriptor, transaction ID and status. State the first notice date and case number. Explain the deception in five or six dated sentences: contact, representation, payment instruction, discovery, report and any later demand. This structure lets an investigator compare the account record with the narrative without hunting through chat screenshots.
Index attachments. Exhibit 1 can be the statement entry, Exhibit 2 the transfer confirmation, Exhibit 3 the message that contains the false representation, Exhibit 4 the security alert and Exhibit 5 the prior denial. Name files with dates and neutral descriptions. Keep a hash or original copy where authenticity may later matter. Redact unrelated transactions and sensitive credentials, but do not crop away dates, domains or recipient identifiers.
End with a specific request: recall the wire, open the section 1005.11 error investigation, treat the attached letter as a section 1026.13 billing-error notice, preserve recipient records, or provide the written factual basis for denial. Do not ask the bank to ‘do everything possible’ and stop there. Also do not paste statutes unrelated to the payment; precision is more credible than volume.
| Field | What to write | Why it helps |
|---|---|---|
| Transaction | Exact date, amount, descriptor, recipient and ID | Connects the claim to provider records |
| Initiation | Who logged in, chose the recipient and confirmed | Supports the authorization classification |
| Inducement | The specific false fact and where it appeared | Explains why an authorized payment was scam-induced |
| Discovery and notice | When the issue was found and each provider was told | Preserves timing analysis |
| Requested action | One fact-matched remedy per provider | Makes the report operational |
| Exhibits | Numbered originals or clear copies tied to sentences | Allows reproducible review |
Source: CFPB — Regulation E § 1005.11, Procedures for resolving errors28.07.2026
Source: CFPB — Regulation Z § 1026.13, Billing error resolution28.07.2026
Source: FBI Internet Crime Complaint Center — Complaint FAQ28.07.2026
Source: FBI Internet Crime Complaint Center — Cryptocurrency guidance28.07.2026
Avoid refund and recovery scams after the first loss
Direct answer: Treat an unsolicited promise to recover scam losses for an upfront fee, tax, wallet activation or secret government payment as a new fraud risk; verify every firm independently and reject guarantees, remote access and requests for wallet secrets.
The second approach often sounds more informed than the first because the caller already knows the platform name, amount lost or wallet address. That information may come from the original scam group, a purchased victim list or a public blockchain. It does not prove a court order, frozen account or relationship with a government agency. Call the claimed organization using contact details you locate independently.
The FTC warns that refund and recovery scammers may call an upfront charge a retainer, processing fee, administrative charge, tax or shipping charge. It advises against paying someone who unexpectedly contacts a victim and promises recovery for a fee. The FBI’s crypto guidance likewise warns about recovery services, especially those charging upfront. Neither warning means all legitimate professional work must be free; it means identity, authority, scope, fee structure and claims require independent verification.
Demand a written engagement that identifies the legal entity, jurisdiction, responsible professional, exact work product, fee destination, cancellation terms and complaint route. Verify licenses through the regulator’s own website and call the registered office. Ask what asset or defendant has been identified, what evidence supports that identification, what legal process could reach the asset, and what happens if the attempt fails. A colourful tracing report does not answer those questions.
ScamCompass is an information and intake hub, not a government agency and not a bank. A case submission can be used to organize facts and assess referral to an independent legal or recovery provider; it is not a promise of reimbursement. Do not include wallet secrets, passwords, one-time codes or full payment-card numbers. A careful review may conclude that an urgent provider action exists, that a legal route needs more evidence, or that paid recovery would be uneconomic.
The strongest final action is modest and concrete: stop further loss, send the correct notice, preserve the response and get a scoped review if the value or complexity justifies it. Anyone who guarantees a percentage, says funds are already in a private ‘escrow wallet,’ or requires crypto before showing verifiable authority is selling certainty that the official processes do not provide.
- Unexpected contact that already knows the prior loss
- A guaranteed refund, fixed success rate or secret government channel
- Tax, gas, insurance, bond or activation money paid to release funds
- Payment requested in crypto, gift cards or a personal account
- Seed phrase, private key, wallet connection or remote-access request
- A copied law-firm or agency identity with different contact details
- Pressure to act before a verifiable written scope is provided
Source: FTC — Refund and Recovery Scams28.07.2026
Source: FTC — What To Do if You Were Scammed28.07.2026
Source: FBI Internet Crime Complaint Center — Cryptocurrency guidance28.07.2026
Concise answers
Frequently asked questions
Can my bank refund money I willingly sent to a scammer?
It may, but there is no universal federal reimbursement right for every consumer-initiated scam payment. GAO reported that institutions generally are not federally required to reimburse fraudulently induced payments authorized by a person with payment authority. Report immediately anyway: a recall, provider policy, network program, contract, state rule or fact showing that a third party actually initiated the EFT may change the route.
Is a transfer unauthorized if I gave the scammer a verification code?
Possibly, depending on who initiated the EFT. CFPB says a third party who obtains account access information through fraudulent inducement and then initiates the transfer can create an unauthorized EFT. If you used the code and personally pressed send, the analysis may differ. Give the bank the exact sequence and ask for a transaction-by-transaction finding.
How long do I have to dispute a credit card scam charge?
For the formal Regulation Z billing-error procedure, the creditor generally must receive written notice at the disclosed billing-inquiries address no later than 60 days after it transmitted the first statement showing the alleged error. Report account compromise immediately as well. Other issuer or network windows may differ, and a scam-induced purchase is not automatically a qualifying billing error.
Does Regulation E cover Zelle, payment apps and ACH scams?
Regulation E can cover qualifying consumer-account EFTs, including many ACH, debit-card and P2P transfers. Its unauthorized-EFT protections depend on who initiated the transfer and other facts. A fraudster’s use of stolen credentials can differ from a payment the consumer personally sent after deception. Report to both the app and the account-holding institution.
What are the $50, $500 and 60-day Regulation E rules?
CFPB § 1005.6 describes conditional liability tiers for unauthorized EFTs. Prompt notice after learning that an access device was lost or stolen can preserve an up-to-$50 tier; later notice can raise the maximum to $500 under a formula. Failure to report an unauthorized transfer shown on a statement within 60 days can expose the consumer to qualifying later transfers. The actual result depends on authorization and timing facts.
Can a bank require a police report before investigating an unauthorized EFT?
The CFPB Regulation E FAQ says a financial institution must begin promptly after oral or written notice of error and may not condition the start of its investigation on receiving a police report or other documentation. A police or IC3 report can still be useful evidence and may be needed for separate purposes.
Can a wire transfer be reversed after it was sent?
Sometimes funds can be stopped, recalled or frozen, but no outcome is guaranteed. Contact the originating bank immediately with the wire details, request a recall or reversal and fraud notification, and file a detailed IC3 complaint. Money may already have moved, and the receiving bank’s process matters.
Can USDT sent to a scammer be recovered?
A USDT transfer normally cannot be reversed by the sender. Preserve the network, transaction hash, both addresses, amount, time and exchange records; notify the sending platform and any identifiable hosted service; and file with IC3. A trace can support an investigation but does not itself reveal every owner, freeze funds or guarantee return.
Will filing with the FTC or FBI IC3 get my money back?
A filing is not a refund order. FTC reports support trend detection and enforcement work; IC3 complaints provide internet-crime data to the FBI and partners. File accurate reports when applicable, but continue bank, issuer, app, exchange and identity-protection actions in parallel.
What should I do if the bank says the transaction was authorized?
Ask for the written factual basis, transaction records and rule or policy applied. Compare the decision with who logged in, selected the recipient and confirmed payment. Submit a focused reconsideration with indexed evidence, then consider the CFPB complaint process or the regulator route identified for the institution. Escalation does not guarantee reversal.
How can I tell whether a recovery company is another scam?
High-risk signs include unsolicited contact, guaranteed results, secret government access, payment in crypto or gift cards, a tax or release fee, cloned professional identities, remote-access demands and requests for a seed phrase. Verify the legal entity and professional independently and require a written, scoped engagement before sharing sensitive documents or paying.
Evidence register
Sources and relevant dates
We link to primary sources whenever available. Sources are grouped under the section they support; the displayed date may be a publication, effective or editorial-review date. A public outcome does not promise the same result in another case.
- FTC — What To Do if You Were Scammed28.07.2026
- GAO-24-107107 — Payment Scams: Information on Financial Industry Efforts28.07.2026
- FBI Internet Crime Complaint Center — Domestic Financial Fraud Kill Chain, 2025 results28.07.2026
- FTC — IdentityTheft.gov Recovery Steps28.07.2026
- CFPB — Electronic Fund Transfers FAQs, version updated 15 January 202528.07.2026
- CFPB — Regulation Z § 1026.12, Special credit card provisions28.07.2026
- CFPB — Regulation Z § 1026.13, Billing error resolution28.07.2026
- CFPB — How to fix mistakes in your credit card bill, modified 4 June 202528.07.2026
- CFPB — Regulation E § 1005.11, Procedures for resolving errors28.07.2026
- CFPB — Regulation E § 1005.6, consumer liability for unauthorized transfersChecked 29 July 2026
- FBI Internet Crime Complaint Center — File a complaint28.07.2026
- FBI Internet Crime Complaint Center — Complaint FAQ28.07.2026
- GAO-25-107088 — Consumer Protection: Actions Needed to Counter Scams28.07.2026
- FTC — Refund and Recovery Scams28.07.2026
- FBI Internet Crime Complaint Center — Cryptocurrency guidance28.07.2026
- FTC — ReportFraud.gov28.07.2026
- CFPB — Learn how the complaint process works, modified 28 May 202628.07.2026