How To Preserve Scam Evidence
Good evidence helps your bank, the police, and platforms act — capture it before anything disappears.
Last reviewed: 1 August 2026
First 10 minutes
- Screenshot conversations, profiles, and any platform/dashboard
- Save payment receipts, references, and wallet addresses
- Don't delete messages yet — capture them first
First 24 hours
- Organise evidence by date and source
- Back it up somewhere secure (and a second location)
- Export emails with full headers where possible
Contact your bank or payment provider
- Provide transaction references and a clear timeline to your bank
- Keep copies of everything you send them and note who you spoke to
Evidence to preserve
- Screenshots of all messages, including dates and usernames
- Sender numbers, emails, and profile URLs
- Links (recorded as text, not clicked)
- Payment records: amounts, references, accounts, wallet addresses
- Any documents, contracts, or 'invoices' received
Secure your accounts and devices
- After capturing evidence, block the scammer and secure accounts
- Don't factory-reset or delete accounts until evidence is safely backed up
Report it
- Report to your national fraud/cybercrime service
- Report to the platform, bank, or provider involved
- Keep any reference numbers you're given
Evidence is what turns 'I think I was scammed' into something your bank, the police, and platforms can act on. The catch is that much of it can vanish quickly: scammers delete profiles and messages the moment they think they've been detected, platforms remove reported accounts (taking the chat history with them), and many victims — understandably wanting the whole thing gone — block and delete everything before anyone official has seen it. So the golden rule is: capture first, clean up second. Nothing about preserving evidence requires you to keep talking to the scammer; you're simply photographing the scene before it disappears.
Start with the conversations. Screenshot the full chat history, not just the worst messages — context matters, and the early friendly messages are often what proves deception. Scroll to the beginning and work forward, making sure each screenshot shows the contact's name or username and, where possible, dates and times. If the conversation is long, don't worry about capturing every routine exchange; prioritise the beginning, anything about money or personal information, and the final messages. Some apps let you export a chat as a file — do that as well as screenshots if the option exists, but never rely on the app keeping the history for you.
Next, capture identities. Screenshot the scammer's profile pages on every platform involved: profile photos, usernames, handles, bios, follower counts, and the profile URL. Save phone numbers and email addresses as text somewhere separate, and copy any website addresses you were sent — as text, written down or pasted into a document, never by revisiting the link. Clicking scam links again risks malware or reinfecting a cleaned device; you only need the address itself.
Then capture the money trail, which is what your bank will care about most. Save payment receipts and confirmations, transaction reference numbers, the exact amounts and dates, the account names and numbers you paid, and — for cryptocurrency — the wallet addresses and transaction hashes, copied precisely as text. If you were shown a fake trading platform, investment dashboard, or 'account balance', screenshot it: fabricated dashboards are strong evidence of how the fraud worked. Keep any documents you were sent too — contracts, invoices, ID photos, 'certificates' — however obviously fake they now look.
Emails deserve one extra step. As well as screenshots, use your mail app's option to view or download the original message (sometimes called 'show original' or 'view source') so the full headers are preserved — headers can reveal where a message really came from, and investigators may ask for them. If you can't find the option, simply keeping the email unread and un-deleted in a separate folder is fine.
Now organise it. Create one folder — on your computer, or printed into a physical file if that's easier — and give files names that mean something, like the date and what they show. Write a short timeline while your memory is fresh: when contact started, what was said, when each payment happened, when you realised. It doesn't need to be polished; a plain list of dates and events is exactly what fraud teams and police ask for, and writing it now, once, spares you retelling the story from scratch to every organisation you report to.
Back the folder up in a second place — a cloud drive, an email to yourself, or a USB stick kept somewhere safe. Evidence that exists only on one phone is one lost or compromised phone away from being gone. If your device itself may be compromised (for example after a remote-access scam), copy the evidence off it, but do the organising from a clean device.
Only when everything is captured and backed up should you block the scammer, report their accounts to the platform, and tidy up. From then on, treat the folder as the single source of truth: every reference number from your bank, the police, and platforms goes into it, along with notes of who you spoke to and when. Well-organised evidence doesn't just support a possible reimbursement claim — it shortens every phone call you're about to make.
Frequently asked questions
Should I block the scammer right away?
Capture your evidence first — screenshots of chats, profiles, links, and payments. Once that's safely saved and backed up, blocking and reporting the scammer is the right move. Blocking first often means losing the chat history you'll later need.
The scammer already deleted their account — is it too late?
No. Capture whatever remains: your side of the conversation, payment records, emails, phone numbers, and anything you saved earlier. Banks and platforms keep their own records too, so report anyway — your reference numbers, amounts, and timeline are still valuable evidence.
Do I need to keep the scam links and fake websites?
Keep the addresses as text — written down or pasted into a document — but don't revisit them. Clicking scam links again risks malware and adds nothing; investigators only need the URL itself, plus screenshots if you already have them.