A safe transfer begins before you open the payment page
Sending money abroad safely involves more than choosing a familiar logo. You need to confirm who is asking, whether the request is genuine, which account will receive the money, and whether the payment service is appropriate for that purpose. A technically secure transaction can still deliver money to a criminal if the recipient details were manipulated.
The most useful habit is to separate verification from payment. First establish the person, purpose and destination through independent information. Then compare the quote and complete the transaction. A request that prevents you from taking this short pause deserves closer scrutiny, particularly when it introduces urgency, secrecy or changed bank details.
This guide is a practical prevention and response checklist. Its scenarios are illustrative, not reports about named customers. For the broader payment process, see the first-time sender's guide. If money has already been sent to a suspected scammer, use the immediate-response section below.
Verify the request through a separate trusted channel
Messages can come from a compromised email or social-media account. Caller ID, a familiar profile picture and a convincing voice do not by themselves prove identity. If a relative asks for emergency funds, call a number already saved from earlier genuine contact, or speak to another trusted family member. Do not use only the new number supplied in the suspicious request.
When paying a school, landlord, supplier or medical institution, verify changed account details with a previously established contact. Retrieve the phone number from an earlier contract, an independently visited official site or a genuine statement. Replying to the same email thread is not independent verification if that email account has been compromised.
The US Federal Trade Commission describes impersonation as a recurring scam pattern, including people posing as trusted organisations or individuals. Its examples support a simple rule: slow down and independently confirm unexpected payment instructions. Source: FTC impersonation-scam guidance.
Check the provider without trusting a logo alone
Find the legal entity that provides the transfer, its official contact details and the relevant authorisation or registration information. Requirements differ by jurisdiction and service, so verify through the appropriate official register rather than assuming that company incorporation equals permission to provide financial services.
A brand may operate through regulated partners. Ask which entity accepts your funds, which entity handles the destination payout and where you can complain. A regulator's logo copied onto a page is not verification. Compare the legal name, domain, address and service permissions with the register's details where those are available.
Read the cancellation, refund, complaint and privacy information before a significant payment. A provider should explain the sender total, recipient amount and applicable conditions. An unusually favourable exchange rate is not evidence of safety; it can be used to attract a rushed payment. Price comparison is covered in the transfer-fees guide.
Recognise high-risk payment requests
- A supposed bank employee asks you to move funds into a “safe account.”
- A person you have never met demands payment to release a prize, parcel, inheritance or investment return.
- A relative's account suddenly provides a new number and insists you must not call.
- A supplier changes bank details immediately before an invoice is due.
- A caller asks for a password, PIN, recovery code or one-time authentication code.
- Someone instructs you to install remote-access software while discussing your money.
- A supposed recovery specialist demands another payment to retrieve previously lost funds.
No single checklist catches every scam. The recurring pattern is an attempt to move your decision away from independent verification and into a channel controlled by the requester. A persuasive story may explain why you must act immediately, keep the transaction secret or ignore normal safeguards. Treat those instructions as reasons to stop, not reasons to hurry.
Use a secure account and device
Use a long, unique password for the transfer account and the email account that can reset it. A password manager can help create and retain different passwords without reusing a memorable one across services. Enable multi-factor authentication where offered. Prefer phishing-resistant options, such as passkeys or security keys, when the service supports them and you can maintain a reliable recovery method.
Keep the operating system, browser and payment app updated. Install apps from legitimate stores or the provider's verified site. Avoid paying from a shared computer where browser extensions, saved sessions or malicious software may expose information. Lock your device and avoid leaving account sessions open for another person to use.
CISA's consumer guidance emphasises stronger passwords, multi-factor authentication, software updates and recognising phishing. These measures reduce account-compromise risk, but they cannot determine whether an invoice or recipient is genuine. You still need the separate verification step. Source: CISA Secure Our World.
Understand what HTTPS does and does not prove
HTTPS protects the connection between your browser and the site you are visiting. A fraudulent website can also have HTTPS. Check the full domain name, not only the padlock, colour scheme or first few words. Misspellings, substituted characters and extra subdomains can make an imitation look plausible.
Use a bookmark you previously verified or type the address carefully. Do not follow a payment link in an unsolicited text merely because it contains your name. Search advertisements can also point to impersonation pages. If you are unsure, leave the page and reach the provider through an independently verified channel.
Avoid entering payment details on untrusted devices or networks. A mobile-data connection you control can be preferable to unfamiliar public Wi-Fi. Network choice is only one safeguard: a secure connection to a fake site is still a connection to a fake site.
Verify recipient details at the final review screen
For a bank payment, compare the account name, number, bank and any required routing details with the verified instructions. If a name-checking service displays a mismatch, do not dismiss it automatically. Ask the recipient or provider to explain it before proceeding. A valid account number is not proof that it belongs to the intended recipient.
For mobile money, confirm the correct country, wallet brand, registered name and complete number. A phone number used for ordinary calls does not prove an eligible wallet exists. For cash pickup, use the name on the accepted identity document and confirm the authorised collection location. Share the pickup reference privately with the intended recipient only.
If someone else is helping with the transaction, keep control of the payment and credentials. Assistance should not require handing over a PIN or approving an unknown authentication prompt. Read the amount and merchant information displayed by your bank before you authorise it.
Practical scenarios: where verification changes the outcome
A family emergency from a new number
A message claims a sibling has lost their phone and needs urgent money. The sender calls the sibling's previously known number and checks with another family member. If the emergency is genuine, those checks help identify an accessible payout method. If it is fraudulent, the pause prevents a transfer to an impostor. The aim is to verify the request, not dismiss real emergencies.
A school invoice with changed bank instructions
A parent receives an email appearing to come from a school finance office. The account number differs from the previous invoice. Before paying, the parent contacts the finance office using the number already on the enrolment documents. The email may be legitimate, but the change must be confirmed independently. Payment to the wrong account can leave the genuine school invoice unpaid.
A caller offering to reverse a wallet transfer
A caller says money was accidentally sent to the recipient and asks them to return it to another number. The recipient checks the actual wallet ledger rather than an SMS screenshot, then contacts the wallet provider. They do not send a separate payment to an unverified account. A legitimate error should be handled through the authorised process.
A recovery agent after an earlier loss
After posting online about a scam, a victim receives an offer of guaranteed recovery for an upfront fee. The person may be exploiting publicly shared information. The victim avoids further payment, preserves the messages and continues through their bank, provider and appropriate reporting authorities. No stranger can guarantee recovery simply because they know the transaction story.
If you think you have been scammed: act promptly
Contact the transfer provider immediately through its official channel. State clearly that fraud is suspected and ask whether the transaction can be stopped, held, recalled or traced. Contact the bank or card issuer that funded it as well. The available action depends on the payment method and status, so do not assume recovery is impossible or guaranteed.
Secure affected accounts using a trusted device. Change compromised passwords, review active sessions and enable or reset authentication protections. If your phone service unexpectedly stops and you suspect SIM compromise, contact the mobile operator promptly through an independent channel and inform relevant financial providers.
Preserve receipts, references, messages, usernames, web addresses and timestamps. Report to the appropriate local police, cybercrime or consumer-protection authority. The FTC's response guide advises contacting the relevant payment company quickly and asking about reversal where possible; its US reporting route is not a substitute for the correct authority in another country. Source: FTC guidance after a scam.
Protect evidence without exposing more information
Keep an organised private timeline: initial request, verification attempts, payment confirmation, discovery of the problem and support contact. Save original messages where possible rather than only rewritten summaries. Avoid editing evidence in ways that remove sender information or timestamps.
When sending evidence to verified support, provide what is needed for the investigation. Redact unrelated account balances and third-party personal data where appropriate. Never publish full identity documents, card numbers, wallet credentials or transaction references in a social-media complaint. Public disclosure can invite further impersonation and recovery scams.
If remote-access software was installed at a caller's direction, stop using that device for banking until it has been checked and secured. Disconnect it from the network if an attacker may still have access, and contact financial institutions from a trusted device. A password reset on a still-compromised device may not resolve the risk.
A repeatable pre-send security checklist
- I verified the requester through a separate trusted channel.
- I understand the purpose and have confirmed any changed details.
- I checked the provider's legal identity and official website.
- I am using a trusted device and protected account.
- I compared the recipient name and destination digit by digit.
- I understand the total cost and the cancellation limitations.
- Nobody has asked for secrecy, remote access, a PIN or an authentication code.
- I will retain the receipt and confirm receipt directly with the recipient.
For recurring transfers, repeat the critical checks whenever a number, account, amount, contact or purpose changes. Familiarity can reduce attention just when a compromised account introduces fraudulent instructions. A saved recipient makes data entry easier, but the current request still needs to be genuine.
Agree a family verification routine before an emergency
Families who regularly send money can agree a simple routine in advance. Keep more than one established contact method for important relatives, agree that changed bank details require a call, and make it acceptable to pause an urgent request. A genuine relative should understand that these checks protect both sides.
Do not rely exclusively on a secret question whose answer is visible on social media. A birthday, school name or pet name may be easy to discover. Use the broader context of a trusted conversation and, where necessary, another known family member. Never place authentication codes or full banking details in a large family group just because the participants appear familiar.
If a recipient changes number, update the contact record through a known channel before the next payment. Keep obsolete beneficiary records clearly labelled or remove them within the official service when appropriate. The goal is to reduce the chance that an old account or a similar contact name is selected during a rushed transfer.
Protect institutional payments with a two-person check
For a substantial school, supplier or association payment, a second trusted person can independently compare the beneficiary instructions and amount before authorisation. The check should use the original verified instructions, not simply glance at the sender's completed form. This is particularly valuable after an account change or when the invoice arrived by email.
If the payment purpose falls outside the provider's supported service, obtain an appropriate route rather than changing the description. A legitimate organisation should be able to explain who receives the funds, what reference is required and how receipt is reconciled. Pressure to pay a personal account for an institutional obligation should be independently investigated, even when an explanation sounds plausible.
Do not treat payment-security procedures as an accusation against the recipient. Present them as a standard routine applied to every substantial payment. Consistency makes it easier to resist a scammer's attempt to frame verification as distrust or a personal insult.
Three situations in which to stop immediately
First, stop if someone asks you to approve a transaction you did not initiate or to reveal an authentication secret. Second, stop if the beneficiary unexpectedly changes during the conversation and cannot be independently confirmed. Third, stop if the requester prevents you from contacting your bank, provider or family while directing the transfer.
A stopped transaction can be resumed after legitimate verification. A completed fraudulent payment may be much harder to recover. This is a practical asymmetry: a short pause usually has a limited cost, while losing control of the destination can have a much larger one. For a genuine emergency, verification and speed can coexist through a quick call to an established contact rather than an extended exchange with the unverified requester.
Frequently asked questions
Does a padlock mean a transfer website is genuine?
No. HTTPS protects the connection, but fraudulent sites can also use it. Verify the full domain and provider identity independently.
Should I share a one-time code with support?
No. Enter authentication codes only in the legitimate flow you initiated. Do not disclose passwords, PINs or recovery codes to callers, messages or chat contacts.
What should I do about suddenly changed bank details?
Confirm the change through a previously established trusted contact before paying. Do not rely only on the message containing the new details.
Can a completed transfer to a scammer be recovered?
Recovery depends on status, method and the institutions involved. Contact the provider and funding institution immediately, but do not assume a guarantee.
Is a familiar social-media account sufficient verification?
No. Accounts can be compromised. Independently confirm unusual, urgent or changed payment requests through a known channel.
Review your available options
Check the current destination, recipient requirements, total price and delivery conditions before confirming.
Explore available servicesSources and further reading
Information notice: General educational information, not individual financial, legal or regulatory advice. Eligibility, fees, exchange rates, limits, products and delivery conditions can change. Confirm the current provider and recipient requirements before payment. Illustrative figures and scenarios are not live quotations or customer case reports.
