Online Fraud: Immediate Steps to Take If Your Money or Personal Data Is Stolen

in

It arrives on your phone one afternoon, just as you’re heading home from work: a text message reading, “Your account has been blocked. Tap here to verify.” Or the phone rings. A calm voice says, “Good evening, this is the security department of your bank. We’ve detected a suspicious transaction and need to cancel it immediately.”

The tone sounds reassuring. The logo looks authentic. The bank’s name is correct. Sometimes the fake SMS even appears in the same chat thread as earlier legitimate messages. Other times, the caller knows your name—or other basic details—that make the story feel credible. Yet within minutes, fraudsters could gain full access to your bank account.

Cyber fraud has evolved. It no longer relies solely on technical tricks—it now exploits human psychology. Scammers aim to trigger urgency, pushing you to act before you pause to think.

The National Cybersecurity Authority warns that attacks have become far more convincing, with some even using artificial intelligence tools to generate messages impersonating government agencies, banks, or well-known companies.

The First Mistake Is Panic

Cybersecurity experts agree on one thing: your immediate actions after falling victim are critical. If you’ve entered your card details, online banking credentials, or approved an unfamiliar transaction, contact your bank right away—using only its official customer service number. Do not reply to the suspicious message or call the number displayed on your screen.

Banks can, depending on how far the fraudulent activity has progressed, block cards, deactivate e-banking access, or initiate chargeback procedures for disputed transactions. If only your login credentials were compromised—and no funds have yet been transferred—every second counts.

Don’t Just Change Your Banking Password

Many people make the same error: they change only their bank password. In reality, if you reuse the same—or a similar—password across email accounts, social media, or other services, you must update all potentially exposed accounts. Enabling two-factor authentication (2FA), wherever available, adds a crucial extra layer of protection and significantly hinders unauthorized access.

Preserve Evidence Before Deleting Anything

Your first instinct may be to delete the suspicious message. Resist that urge. Save screenshots of the SMS or email, note down the sender’s phone number or email address, copy the link you received, and keep any evidence of related transactions. This information can prove invaluable both to your bank and to law enforcement.

Report to the Police

The Hellenic Police urges citizens to file reports for such incidents. Electronic complaints regarding cybercrime can also be submitted via Gov.gr.

Related coverage