← Security Awareness Hub Recovery · Bucket 5

I've Been Hit

You can fix this. Start here, breathe, and work down the list for your situation.

Being scammed or hacked is designed to make you panic — panic is what the attacker is counting on. The next hour matters more than the last one. Pick the situation closest to yours and do the steps in order.

TL;DR — the first five minutes, whatever happened
  • Stop talking to them. No more clicks, replies, calls, or payments. The pressure is the attack.
  • Disconnect the affected device from the internet if you think it's compromised (turn off Wi-Fi / unplug), but don't wipe it yet — you may need evidence.
  • Change the password on your email first, from a different, trusted device. Email is the master key.
  • Call your bank if any money or card detail was involved. Speed beats everything.
  • Write down what happened with times. You'll need it to report.

Pick your situation

"I gave away a password / approved a login"

  1. From a clean device, change that account's password and turn on 2FA.
  2. Change the password anywhere you reused it (this is why reuse is dangerous).
  3. Check the account's "active sessions / logged-in devices" and sign all others out.
  4. If it was a bank or LuxTrust approval → the next section, immediately.

"My bank account or card is involved"

  1. Call your bank now — use the number on the back of your card, not from any message.
  2. Ask them to freeze the card/account and flag fraudulent transactions.
  3. File a plainte with the Police Grand-Ducale — banks often require the case reference to process a fraud claim.
  4. Watch for follow-up "we're the fraud department, confirm your details" calls — that's a second scam riding the first.

"My email got taken over"

→ See the dedicated page: Email account compromise. Do that first; it's the account that resets all the others.

"My phone stopped getting signal / texts" (possible SIM swap)

→ See SIM swapping. Call your carrier from another phone immediately and lock the number.

"My device is locked / showing a ransom message"

  1. Disconnect it from the network. Don't pay.
  2. Don't wipe it if it holds anything you need recovered — photograph the screen.
  3. If it's a work device or holds regulated/client data → escalate to your employer/IT or a professional now (data-breach clocks may be running).

"Someone is impersonating me / using my data"

  1. Document everything (screenshots, URLs, dates).
  2. Report the impersonating account to the platform.
  3. If your personal data is being misused, you have GDPR rights to act → see Your GDPR rights.

🇱🇺 In Luxembourg — your reporting map

  • Bank fraud / money moved: your bank first, then a plainte with the Police Grand-Ducale (online pre-declaration available).
  • Phishing email / SMS: SPAMBEE (spambee.lu).
  • Phishing URL / technical incident: CIRCL (circl.lu) — including its anonymous report form and URL-Abuse service.
  • Advice & a human to talk to: BEE SECURE Helpline.
  • Data-protection complaint: CNPD (cnpd.lu).
  • General orientation: cyberfraud.lu, the official Luxembourg anti-cyberfraud platform.

More detail and a decision tree on the Reporting fraud in Luxembourg page.

After the bleeding stops

  • Turn on 2FA everywhere it isn't already (start with email and bank).
  • Move to a password manager so the reuse problem disappears.
  • Watch your accounts and statements closely for 30–60 days.
  • Tell the people in your contacts if the attacker had access — they may be targeted next using your name.
If this was a business device, or you handle client or regulated data, the clock on notification obligations may already be running. That's a situation where professional incident response pays for itself — johlem.net.