Table of Contents
- The containment sequence, in order
- What you actually shared changes what happens next
- Why "no money is missing yet" doesn't mean you're safe
- The next few hours: three things worth doing even if the bank says you're fine
- What this does not mean
- Reporting it, once your accounts are secured
- A note on how to use this
- Frequently asked questions
If you just realized you shared a card number, an online banking login, or a one-time code with someone who was not who they claimed to be, do this now: call your bank or card issuer using the number on your card (not any number the caller gave you), tell them what happened, and ask them to lock the account or card. Then change the password on that account and any other account using the same password. Do this before you finish reading, if you can. The rest of this page explains why each step matters and what comes after the first call.
This page is for the moment before money has visibly gone missing: you shared something, but nothing is confirmed stolen yet. If money has already left your account, the sequence is different and time matters even more; see our companion guide on what recovery actually looks like after money is sent.
The containment sequence, in order
Work through this in order. Each step closes a door the next step can't close for you.
- Stop giving out anything else. If you are still on a call or in a chat, end it. Do not confirm any more details, even to "cancel" or "verify" the first ones.
- Call your bank or card issuer directly, using the number on the back of your card, your statement, or the bank's official app, never a number given to you during the contact that raised the alarm.
- Tell them plainly: you believe you shared account details, a password, or a one-time code with someone who was not genuinely your bank.
- Ask them to lock the card or freeze the account, and to watch for unusual activity in the meantime.
- Change the password on the affected account, and on any other account where you reused that password.
- Turn on transaction alerts if you haven't already, so you see movement the moment it happens.
What you actually shared changes what happens next
Not every detail carries the same risk, so it helps to know exactly what you gave up.
- A card number alone (no PIN, no online banking password) is the least exposed case. The card issuer can usually cancel and reissue it before it's used, and most card fraud is reversible through a dispute process.
- An online banking username and password is more serious, because it can allow someone to view your accounts or attempt transfers, not just make a card purchase. This is the case where changing the password immediately, and everywhere else it was reused, matters most.
- A one-time passcode (OTP) is the most urgent. A code is only useful to an attacker in the few minutes after it's issued, which means if you read one out loud or entered it somewhere you shouldn't have, your bank needs to know within that same window, not after.
If you're not sure which of these applies, tell your bank everything you can remember. They would rather hear more detail than less.
Why "no money is missing yet" doesn't mean you're safe
A detail shared but not yet used is not the same as a detail that will never be used. Attackers sometimes wait, testing a card with a small charge first, or holding a stolen login until they can act on several accounts at once. This is exactly why the sequence above starts with locking the door rather than waiting to see if anything happens. Acting now, while nothing is confirmed lost, is the version of this situation with the best odds. Waiting to "see if it's really a problem" gives the window more time to close in the attacker's favor, not yours.
The next few hours: three things worth doing even if the bank says you're fine
Your bank locking the card or account handles the most urgent exposure. A few follow-up steps reduce the damage if anything was missed.
- Place a fraud alert or credit freeze on your credit file, especially if you shared anything beyond a card number, such as a password, a national ID number, or answers to security questions. This tells lenders to verify your identity more carefully before opening new credit in your name.
- Change any other password built the same way. If the exposed password was reused, or followed a pattern you use elsewhere ("Bank2024!", "Bank2025!"), change those too. This is the moment a password manager earns its keep, because it removes the temptation to reuse a password in the first place.
- Watch your statement daily for a week, not just once. Small test charges before a larger one are a known pattern, and catching them early is what keeps a bank's fraud recall option open.
What this does not mean
Sharing your details with a scammer does not mean you did something careless or unusual. Convincing operations are built specifically to feel routine: a call that mirrors your bank's real hold music, a text that references an order you actually placed, a caller who already knows your name and the last four digits of your card. The response that matters is speed, not self-blame. If you want the full pattern behind how these approaches are engineered to feel normal, our guide on the six levers behind almost every scam covers it in depth.
If the contact that led to this specifically impersonated your bank by phone, text, or email, our dedicated guide on bank impersonation scams walks through how to recognize that exact pattern before it happens again.
Reporting it, once your accounts are secured
Once your card is locked or your password is changed, it's worth filing an official report, not because it will necessarily recover anything, but because reports feed the fraud-pattern data that protects the next person, and in some cases opens a path to a refund. Which body you report to depends on your country; our guide on how to report financial fraud breaks this down by jurisdiction, and our own reporting resource page lists the specific channels.
A note on how to use this
This page describes general containment steps, not personalized advice for your specific account or bank. Every bank's fraud process differs slightly, and your bank's fraud team is the authority on what happens to your specific account from here. Please also read our full Disclaimer. FinMateMastery does not sell identity-protection products and is not affiliated with any bank named for illustration.
Frequently asked questions
I gave a scammer my card number but not my PIN or online password. How worried should I be?
Less worried than if you'd shared a password or a one-time code, but still act now. A card number alone is generally the most recoverable case. Call your card issuer, have the card cancelled and reissued, and watch your statement for a week. Most card networks have a dispute process for unauthorized charges.
Should I close my bank account entirely?
Usually not, and your bank will tell you if that's the right call for your situation. Locking the card and changing the password addresses most exposure without the disruption of closing an account, which can complicate direct deposits and automatic payments.
What if I already gave them a one-time passcode?
Call your bank immediately and say so specifically: a one-time code is only useful to an attacker for a short window, so your bank needs to know that detail right away, not as part of a general "I think I was scammed" report.
Do I need to report this to the police, or is calling my bank enough?
Calling your bank first is the urgent step because they can act on your account immediately. A police or national fraud-agency report afterward is still worth doing; see our guide on how to report financial fraud for where that report actually goes in your country.
Is it too late if some time has already passed since I shared the details?
It's not too late to act, and calling your bank remains the right first step regardless of how much time has passed. The odds simply improve the sooner you call, so the priority is doing it now rather than waiting for a reason to be more certain.