The moment you realise you've been scammed is not the moment the scam ends. For a lot of people it's the moment the most expensive part begins, because what you do in the next hour, and who you talk to in the next week, decides whether you lose one amount of money or two.

We've watched this play out more times than we'd like. A trader sends $3,000 to a broker they found through a Telegram channel, watches the account "grow" to $11,000 on a screen the broker controls, tries to withdraw, gets told there's a tax, a fee, a verification deposit. Pays it. Gets told there's another one. Somewhere around the third payment the fog lifts, and the natural instinct kicks in: get angry, fire off messages, then frantically search for how to get the money back. That search is exactly where the second wave of predators is waiting.

So this is a manual on how to report a forex scam, written in the order that actually matters. Not the order most articles use, which starts with "contact the authorities" as though a regulator is going to leap out of bed on a Tuesday and wire your money back. The real order is: stop the bleeding first, preserve evidence second, chase payment reversals third, file reports fourth. And running underneath all of it, one rule you hold onto like a rail: anyone who contacts you offering to recover your funds is almost certainly the next scam.

The first hour: stop the bleeding before you report anything

Reporting feels productive. It is productive, later. But in the first hour it's the wrong job, because the scam may still be live and you may still be losing money while you're filling in forms.

Work through this list in order.

Stop sending money. Completely. Obvious, you'd think. It isn't. The most common way victims deepen their losses is by paying "release fees" after they already suspect fraud, on the logic that they're in for $5,000 so another $800 to unlock it is worth the gamble. It never is. The $800 doesn't unlock anything; it confirms to the scammer that you'll keep paying, which is why the fees never end. There is no legitimate broker anywhere on earth that requires you to deposit new money in order to withdraw old money. None. If you remember one sentence from this article, make it that one.

Cut any access they have to your accounts. If you ever gave the scammer remote access to your computer (AnyDesk, TeamViewer, a "support session" to help you install MetaTrader), assume everything on that machine is compromised. Uninstall the remote software, run a malware scan, and change your banking passwords from a different device. If you gave them your MT4/MT5 credentials, change the master password now. This, incidentally, is why legitimate account management is structured the way it is: in a proper arrangement you keep the master password and the manager gets trading-only access, a distinction we've written about at length in our piece on whether forex account management is safe. If someone has your master password and you didn't set the arrangement up deliberately, that's an emergency.

Call your bank or card issuer, today. Not to file the full dispute yet, just to flag the payments as suspected fraud and ask whether any transfers are still pending and cancellable. Wire transfers sometimes sit in a window of a few hours where a recall request can catch them. Card payments can be flagged immediately even if the formal chargeback comes later. Speed matters here more than paperwork.

Freeze the crypto angle if there is one. If you paid in crypto through an exchange account, contact the exchange's fraud team and report the destination address. They can't claw the coins back, but they can sometimes freeze funds if the scammer cashes out through the same exchange, and your report adds to the pile that gets addresses blacklisted.

Say nothing to the scammer about any of this. Don't announce that you know it's a scam, don't threaten them with the police, don't demand your money back in a blaze of righteous fury. The moment they know you're lost as a paying victim, they delete the channel, kill the website, and vanish, taking your evidence with them. Play dumb for another day or two if you can stomach it. You want them relaxed while you screenshot everything.

Urgency-ordered checklist of first-hour actions after a forex scam
The first hour: stop payments, cut access, flag the bank, freeze crypto, stay quiet

Evidence: capture everything before it disappears

Scam infrastructure is disposable by design. The website is a template that took an afternoon to deploy, the Telegram channel can be deleted in one tap, and the "account dashboard" showing your $11,000 balance exists only as long as the scammer wants it to. Once they burn the operation, every trace you didn't save is gone. So before you file a single report, spend an evening building your evidence file, because every subsequent step (chargeback, police report, regulator complaint) will ask for it.

Here's what goes in the file:

  • The full conversation history. Every Telegram, WhatsApp, email and SMS exchange, exported properly, not just screenshotted. Telegram has an export function on desktop; use it. Include the parts where you look naive. Investigators need the grooming phase, not just the ending.
  • Screenshots of the platform. Your dashboard, your balance, the trade history they showed you, the deposit page, the withdrawal page with its rejection message or fee demand. Capture the URL in every shot.
  • The website itself. Save the pages as PDFs and run the URL through a web archive service so there's a timestamped third-party copy. Scam sites vanish fast; archives don't.
  • Every payment record. Bank statements showing the transfers, card statements, crypto transaction hashes, the exact wallet addresses you sent to, receipts, invoices, anything with an amount and a date on it.
  • Identity fragments. Names they used, phone numbers, email addresses, the beneficiary name on the bank account you wired to, any company registration numbers on their site (usually fake, still useful), profile photos (often stolen, and a reverse image search sometimes tells you from whom).
  • A timeline, written by you. One page. Date of first contact, how they found you, each deposit with amount and method, the date you first tried to withdraw, each fee demand. Write it while it's fresh. Six weeks from now the details blur, and a clean timeline is the single most useful document you can hand an investigator or a bank fraud team.

A note on the balance screenshots, because this trips people up emotionally: the $11,000 was never real. The scam platform is a video game rendering numbers; no trades were placed anywhere. Your loss, for reporting purposes, is what you deposited, not what the screen said you'd grown it to. Report the deposits. Claiming the fictional profits as losses muddies your case and makes fraud teams take you less seriously.

Chargebacks and payment reversals, method by method

Here's the uncomfortable truth that sits under everything else in this article: how you paid matters more than who you report to. The realistic routes to actually seeing money again mostly run through the payment system, not through law enforcement, and each payment method has a different window and a different set of odds.

Payment methodReversal mechanismTypical windowHonest odds
Credit cardChargeback (services not rendered / fraud)Usually 120 days from transaction, sometimes from expected deliveryBest of the lot, worth pursuing hard
Debit cardChargeback via card scheme rulesSimilar to credit, often weaker protectionModerate, varies by bank
Bank wireRecall request / fraud claimHours to days for recall; APP fraud claims vary by countryLow once funds have moved on
PayPal / e-walletsInternal dispute processTypically 180 daysPatchy; "investment" often excluded
CryptoNone (exchange freeze at best)Effectively immediateVery low, near zero for off-exchange wallets
Cash / gift cardsNoneNoneZero

Card payments are your strongest hand. Phone the number on the back of the card, say the words "I want to dispute transactions as fraud", and be specific: dates, amounts, the merchant descriptor as it appears on your statement. The bank may push back with "you authorised the payment", which is true but not the end of the argument. You authorised a payment to what you believed was a regulated brokerage for genuine trading services. That's a service not rendered, procured by deception. Say so, in writing if the phone call goes nowhere, and escalate to your country's financial ombudsman if the bank refuses without properly investigating. Persistence changes outcomes here more than people expect.

Wires are harder. Once the receiving account has forwarded the money on, which professional scam operations do within hours through a chain of mule accounts, a recall finds an empty account. Still file the recall and the fraud claim; some countries now have reimbursement schemes for authorised push payment fraud, and banks that ignored obvious red flags on the receiving account can carry liability. In the UK in particular, mandatory reimbursement rules for APP fraud have shifted real money back to victims. Don't assume you're out of luck until your bank has actually said so in writing.

Crypto, we have to be blunt about. If you sent USDT to a wallet address, that money has almost certainly gone through a mixer or a chain-hop and out through an exchange in a jurisdiction that doesn't answer emails. Report the transaction hashes to the exchange you sent from and include them in your police report, because blockchain analysis does occasionally trace funds in large coordinated cases. But plan your finances around not seeing it again. Anyone who tells you otherwise wants something from you, which brings us to a section we'll get to shortly.

How to report a forex scam: the directory by jurisdiction

Now the reports. Understand what reporting achieves before you start: it very rarely gets your individual money back directly. What it does is build the case files that lead to account freezes, warning-list entries, occasional prosecutions and, in aggregate, the compensation events that do sometimes happen years later. It also creates the official paper trail your bank and any future proceedings will demand. So file the reports properly, but file them with sober expectations.

United States. Start with the CFTC, which regulates forex and has an online complaint form for fraud tips. File in parallel with the FBI's Internet Crime Complaint Center (IC3), which is where cyber-enabled fraud reports get aggregated and triaged; include your full timeline and every identifier you collected. The FTC's reportfraud site adds your case to consumer-protection databases. If a supposed securities angle exists (they sold you "managed investment" returns), the SEC takes tips too. File all of them. It costs you an evening.

United Kingdom. Action Fraud is the national reporting centre and the report you'll need a reference number from for your bank. Separately, check the FCA's warning list for the firm that scammed you and report them to the FCA directly, especially if they claimed FCA authorisation, because impersonating a regulated firm is its own offence and the FCA does publish warnings quickly. If your bank mishandles your fraud claim, the Financial Ombudsman Service is the escalation route, and it's free.

European Union. Report to your national police cybercrime unit and your national financial regulator (BaFin in Germany, AMF in France, CONSOB in Italy, CNMV in Spain, and so on). Most EU regulators maintain public warning lists and act on impersonation reports reasonably fast. Europol doesn't take direct public reports, but national reports feed its cross-border casework, which matters because these operations are almost never in your country.

Australia. Scamwatch (run by the competition regulator) for the consumer report, ASIC for the financial-services angle, and ReportCyber for the police report. Australian banks are increasingly held to account on scam reimbursement, so get that police reference.

Everywhere else, and the cross-border reality. If you're outside these jurisdictions, the pattern holds: national police report plus national financial regulator, and check whether your regulator publishes a warning list you can add the firm to. Then accept the awkward truth: the scammer is probably not in your country, the website is registered through a privacy proxy, and the money went through a bank account in a third country. This is precisely why individual reports feel like shouting into a well. They still matter, because cross-border operations get dismantled when enough wells echo at once, but the person your report helps most is probably the next victim, not you.

One more report that punches above its weight: the platforms. Report the Telegram channel to Telegram, the Instagram account to Meta, the ads to Google. Platform takedowns happen in days rather than years, and killing the funnel stops the operation recruiting while the slower wheels turn.

Comparison of scam reporting bodies across major jurisdictions
Who takes the report: regulator, police unit and consumer body by region

Reporting to brokers, banks and platforms: who can actually act

There's a hierarchy of usefulness in who you tell, and it's roughly the reverse of what feels natural. The satisfying reports (police, regulator) are slow. The boring ones (your bank, their bank, the platforms) are where things actually move this month.

Your own bank can flag, dispute, recall and, in some countries, reimburse. Covered above, but it bears repeating that this is your first call, not your fifth.

The receiving bank is a lever most victims never pull. If you wired money, your statement shows the beneficiary bank. Your bank should contact them through the recall process, but you can also report the beneficiary account directly to that bank's fraud department as an account being used for fraud. Banks are obliged in most jurisdictions to investigate money-mule reports, and a frozen mule account occasionally still holds funds. Low odds. Costs one email.

The real broker, if a real broker was involved. Some scams run on top of legitimate infrastructure: a genuine MT4/MT5 server rented from a real broker, or an introducing-broker arrangement gone rotten. If your money actually sat with a regulated broker and the scam was the "manager" churning it or the IB lying about fees, report to that broker's compliance department with your evidence file. Regulated brokers do terminate IB agreements and do cooperate with regulators, because their licence is worth more than one bad partner. This grey zone, where the broker is real but the person driving your account isn't, is exactly the territory covered by a limited power of attorney done properly, and the difference between that structure and "I gave a stranger my password" is the difference between a dispute and a disaster.

Domain registrars and hosts. Every scam website has a registrar, findable through a WHOIS lookup, and registrars accept abuse reports. Takedown success is inconsistent, but it's another ten-minute email that occasionally deletes the trap before the next person steps in it.

The honest summary: nobody on this list works for you. Each of them acts when your report happens to align with their own obligations. Your job is to make acting easy, which is what the evidence file and the one-page timeline are for.

The recovery agent scam: how victims get scammed twice

Now the section this article exists for, because everything above is survivable and this part is where people get destroyed.

Within days of being scammed, sometimes within hours, you will start encountering people offering to get your money back. They'll appear in your Telegram replies. They'll comment under scam-warning posts you read. They'll email you out of nowhere claiming to be a "certified crypto recovery specialist", a "fund recovery law firm", even a government investigator who has "located your funds". Some run polished websites with testimonials from grateful victims who recovered everything.

Every single unsolicited one of them is a scam. Not most. All.

The recovery scam works because it sells the one thing a fresh victim wants more than anything: the chance to make it not have happened.

Think about the mechanics for a second. How did the "recovery agent" find you? Three routes, all bad. Either they trawl public scam-complaint threads for victims, or they bought your details from a broker of victim data (scammers sell lists of people who've paid once, cheerfully labelled), or, in the neatest version, they are the original scammers wearing a new hat, since nobody knows better than them exactly how much you lost and how desperate you are. That last version is common enough to have a name in fraud circles: the double dip.

The script is always structurally identical. They've traced your funds, or they have a legal mechanism, or a contact at the exchange. Recovery is possible, even likely. But there's an upfront cost: a retainer, a filing fee, a tax on the recovered amount that must be paid before release, a "gas fee" to move the located crypto. You pay it. Then there's a complication requiring one more payment. The complication machine runs until you stop feeding it, exactly like the withdrawal-fee machine that got you the first time, because it is the same machine.

Here's how to hold the line:

  1. No legitimate recovery service contacts you first. Real asset-recovery lawyers exist. They are found by you, they have verifiable bar registrations, and they will tell you frankly when a case isn't worth pursuing.
  2. Upfront fees for "recovery" of scam losses are the tell. A genuine lawyer charges for legal work with a proper engagement letter and no promises. Anyone charging a fee to "release" or "unlock" located funds is reading from the scam script.
  3. Nobody can reverse a blockchain transaction. Anyone claiming they'll claw back your USDT with special software is lying to you. There is no special software.
  4. Government investigators don't ask victims for money. Ever. A "CFTC officer" or "Interpol agent" requesting a processing fee is a criminal, and impersonating them is a second offence you can add to your report.
  5. Check the testimonials. Reverse-search the profile photos. The grateful recovered victims are stock photos with names attached, the same way the scam broker's "traders" were.

The cruellest part is timing. The recovery scam lands when you're maximally vulnerable: ashamed, angry, not yet ready to accept the loss, and primed to believe that one more payment fixes everything because that belief is what got you here. If you notice yourself thinking "this one seems different", close the laptop and give it 48 hours. Different is what they all seem.

Anatomy of the recovery-agent second-wave scam from victim list to fee loop
The double dip: how recovery scammers find victims and restart the fee machine

Realistic odds: what recovery actually happens

Let's be adults about the numbers, without inventing any. Most victims of offshore forex scams never recover anything. That's the base case, it's the industry commonplace every honest fraud investigator will confirm, and any plan you make should assume it.

Against that base case, the exceptions cluster in predictable places. Card chargebacks succeed often enough to be worth real effort, especially when filed promptly with clean evidence. Bank reimbursement schemes for authorised push payment fraud, where they exist, pay out meaningful sums to ordinary victims who did nothing more sophisticated than file properly and escalate when fobbed off. Occasionally a regulator action or prosecution years down the line produces a compensation fund, and the victims who filed detailed reports at the time are the ones in the queue. And very occasionally a receiving account gets frozen before it's emptied.

Notice what's on that list: payment-system mechanisms and official processes, all of them free or nearly free to pursue. Notice what's not on it: paid recovery services, private investigators for hire, and crypto-tracing subscriptions sold to individuals. The correlation between "asks you for money to recover money" and "recovers nothing" is as close to perfect as anything in this business.

What does timing look like when recovery does happen? Chargebacks typically resolve in one to three billing cycles, and the provisional credit can appear sooner while the merchant gets a chance to fight it (scam merchants almost never do, since responding means identifying themselves). Bank fraud claims run weeks to a few months, longer if you have to go through an ombudsman. Regulator-driven compensation, when it happens at all, is measured in years, and usually pays a fraction on the dollar after the liquidators take their cut. Set your expectations to those clocks and you'll waste less energy refreshing your inbox.

There's a decision hiding in here about your own time and sanity. Spend the first two weeks hard on the chargeback, the bank claims and the reports, because that's when the windows are open and the effort has real expected value. After that, put the file in a drawer, set a calendar note to check for regulator news in six months, and stop. The victims who fare worst in the long run aren't the ones who lost the most; they're the ones who spent two years chasing it, feeding recovery scammers, and never rebuilding. The loss is a number. The chase can eat your life.

Withdrawal refused: scam or dispute?

A special case deserves its own section, because "forex withdrawal refused" is the most-searched panic in this whole area and the answer genuinely splits two ways. Sometimes a refused withdrawal is the scam revealing itself. Sometimes it's a legitimate broker enforcing terms you didn't read. The response is completely different, so diagnose before you escalate.

It's almost certainly a scam if: new deposits are required to withdraw (the eternal tell), the "tax" or "release fee" appears from nowhere, the broker is on a regulator warning list, support has gone vague or vanished, or the platform is a web dashboard rather than genuine MT4/MT5. In that world, everything above applies: stop paying, preserve, dispute, report.

It might be a legitimate dispute if: the broker holds a real licence you can verify on the regulator's own register (never trust the certificate JPEG on their website), the withdrawal is delayed rather than refused, and the reason given references something specific: incomplete KYC documents, a bonus with turnover conditions attached, withdrawal to a different payment method than you deposited from, or open trades that need closing first. Bonus terms are the classic one. Accept a "100% deposit bonus" and somewhere in the terms you agreed to trade thirty lots before withdrawing anything, which on a small account is a locked door with paperwork on it. Infuriating, arguably predatory, but contractual rather than criminal.

For the legitimate-dispute path: complete every KYC request precisely, put your withdrawal request and their responses in writing, quote their own published withdrawal timeframes back to them, and if the delay passes a couple of weeks, file a formal complaint with the broker's compliance team, then escalate to the regulator that licenses them. Regulated brokers resolve most genuine disputes at the compliance stage, because a regulator complaint is expensive for them and a stalled $2,000 withdrawal isn't worth it.

And if you're not sure which world you're in? Treat the evidence-preservation steps as mandatory either way. Screenshots and exported chats cost nothing and serve both paths. This whole grey zone is a big part of why we tell people to be paranoid about structure before there's a problem: who holds the master password, whose name is on the account, what happens when you want out. The comparison we wrote between managed accounts and copy trading is really a comparison of exit doors, and you want to have checked the exit before the cinema fills with smoke.

The emotional aftermath, and why it's a fraud-prevention issue

We're a trading desk, not therapists, so we'll keep this short and practical. But it belongs in the manual, because your emotional state after a scam is not a side issue; it's the attack surface for the second scam.

Fraud victims consistently report the same cocktail: shame (worse than the money for many people), self-blame, anger with nowhere to land, and a compulsive need to fix it that overrides normal caution. Scammers know this cocktail intimately. The recovery scam is engineered for it. So treating the emotional side is partly self-defence.

Three things that actually help. First, tell someone. The shame thrives on secrecy, and the people who get scammed twice are disproportionately the ones handling it alone at 2am. You were manipulated by professionals who do this for a living; sophisticated, intelligent people fall for these operations every single day, and the embarrassment you feel is itself part of the scam's design, because silent victims don't warn others. Second, use the victim-support services that exist: many countries have free fraud-victim support lines (Victim Support in the UK, for instance, and equivalents elsewhere), and they've heard your exact story hundreds of times. Third, make a rule that you take no financial decision of any kind for two weeks. No recovery services, no "win it back" trading, no borrowing. The urge to act immediately is the compromised instinct; let it expire.

If the loss is severe enough to threaten your housing or essential bills, say that out loud to your bank when you file the fraud claim. Vulnerability disclosures genuinely change how banks are required to handle cases in several jurisdictions.

Rebuilding: re-entering the market safely, if at all

Some readers will close this article and never touch forex again, and honestly, that's a rational response nobody should talk you out of. Trading leveraged products is high risk even with an honest broker; most retail accounts lose money in the normal course of things, before anyone steals anything. If the scam has spent your risk capital, the correct position size for your next trade is zero until that changes.

But if you do come back, come back with the paranoia you've now paid for. It's the most expensive education in due diligence you'll ever get, so extract full value:

  • Regulated broker, verified on the regulator's register, in a jurisdiction with teeth. Not a certificate image, not a claim in a Telegram bio. The register itself.
  • Your money sits in your account, in your name. Never in a "pooled fund", never wired to an individual, never sent to a wallet address.
  • You keep the master password, always. Anyone who trades for you gets investor or trading access only, with your ability to watch every trade live and pull the plug unilaterally.
  • Every fee is written down before any money moves. Performance fees on realised profit you can see, not promises against fictional balances.
  • Track records are public and include the losses. Any service showing you only winners is showing you marketing.

That last point is a hill we'll die on. It's why every closed signal we've ever issued sits publicly at /signals/history, red ones included, and it's the first thing we tell people to check about anyone, us very much included. We run a gold-only signal service and managed accounts on exactly the structure described above: your own MT4/MT5 account, you keep the master password and the withdrawals, and we get paid only as a flat 50% of realised profit. Fifty percent is at the high end of the industry, and we say so plainly; the trade-off is a $200 minimum advance and no lock-ins, which is deliberately shaped so that we only do well when you actually, verifiably do. If you want to stress-test that structure with hard questions, the FAQ answers the awkward ones and you can put anything else straight to us. Ask us the same questions you'd ask anyone. If any provider bristles at being verified, that's your answer about them.

None of which changes the base risk: gold moves hard, losses are a normal part of any real record, and nobody, including us, can promise you profit. A provider who admits that in plain language on their own about page is displaying the single cheapest honesty signal there is, because scammers structurally cannot copy it. Guarantees are their product.

Your next 48 hours, in order

Let's compress this into the list you can act on tonight, because a victim's manual should end with a checklist, not a flourish.

  1. Stop all payments to them, permanently, whatever they threaten or promise.
  2. Kill any access: remote software off, master password changed, banking passwords changed from a clean device.
  3. Phone your bank: flag fraud, ask about pending transfers and recalls, start the chargeback conversation.
  4. Build the evidence file: exported chats, screenshots with URLs, archived website, payment records, the one-page timeline.
  5. File the reports: police/national fraud centre, financial regulator, plus platform reports to kill the funnel.
  6. Report the receiving accounts: mule account to its bank, wallet address to the exchange.
  7. Block every unsolicited recovery offer on sight, forever. This one is not a step, it's a standing order.
  8. Tell one real person, and take no financial decisions for two weeks.

Then close the file, live your life, and let the slow processes run. You may get some of it back through the chargeback. You may get none of it. Either way, the person who walks out of this intact is the one who refused to pay a single dollar after the moment of realisation, and who treated every voice promising to undo the loss as what it is: the same scam, back for seconds. Don't feed it.