Where to report ransomware, scams and cybercrime: US, UK, Canada, Australia and the EU
Report cybercrime to the national service for where you live: IC3 in the US, Report Fraud in the UK, the CAFC in Canada, ReportCyber in Australia, and your national police in EU countries. Businesses have extra duties with fixed deadlines, such as notifying a personal data breach within 72 hours under the GDPR.
Why report, and what to do first
Few individual reports lead to an arrest, but they still matter. A report gives you a reference number that banks, card issuers and insurers often ask for. It lets police connect your case to others from the same group, and reports have helped recover decryption keys and freeze stolen money. For businesses, some reports are a legal duty with a deadline.
If you lost money, contact your bank, card issuer or payment service before anything else. Use the number on your card or on the official website, not a number from an e-mail or a pop-up. Recall requests for transfers and card disputes are time-sensitive. What else to do after a payment: What to do after paying a scammer.
If someone is in immediate danger, call the emergency number for your country: 911 in the US and Canada, 999 in the UK, 000 in Australia and 112 in the EU.
What to collect before you report
Every service asks for broadly the same information. Collect it once, on a clean device if the PC is infected, and keep a copy for your bank and insurer.
- Dates and times of each event: the first contact, the attack, each payment.
- Money: amounts, currency, payment method, transaction IDs, the receiving bank account, crypto wallet addresses and transaction hashes.
- The criminals' contact details: e-mail addresses, phone numbers, Telegram or other messenger accounts, website addresses, social media profiles.
- The messages themselves: screenshots of chats and pages, e-mails saved with their full headers, text messages with the sender number.
- For ransomware: the ransom note as a file, the new file extension, a photo of any lock screen, the victim ID, and the names of the programs installed shortly before the attack.
- For fake alerts and tech support scams: the web address of the pop-up, the phone number shown, and the name of any remote access program you were asked to install.
Do not delete the evidence after reporting. Police may ask for more detail later, and a decryptor or refund process can need the same records.
United States
- FBI Internet Crime Complaint Center (IC3) at ic3.gov: the main federal intake for ransomware, extortion, hacking and online fraud, whether or not you lost money. Use File a Complaint.
- Federal Trade Commission at ReportFraud.ftc.gov: scams, fake shops, tech support scams and other fraud. The FTC shares reports with law enforcement but does not resolve individual cases.
- IdentityTheft.gov at identitytheft.gov if someone used your personal data to open accounts, file taxes or take out loans. It produces a recovery plan.
- CISA through its incident reporting form, for organisations hit by ransomware or another cyber incident. CISA says a victim needs to report ransomware only once, to the FBI, CISA or the Secret Service, and the other agencies are informed.
- Phishing: forward phishing e-mails to reportphishing@apwg.org and scam text messages to 7726.
The step-by-step version for US residents is in Report a cyber attack or scam to the authorities. If your Social Security number was exposed, also consider Freeze your credit after a breach.
United Kingdom
- Report Fraud at reportfraud.police.uk, the national service run by the City of London Police for England, Wales and Northern Ireland. It replaced Action Fraud. The online tool is open day and night; the phone line is 0300 123 2040. A business, charity or other organisation under a live cyber attack can call that number 24 hours a day.
- Scotland: report to Police Scotland on 101.
- National Cyber Security Centre: organisations can report a significant cyber incident at report.ncsc.gov.uk. If you are not sure who to contact, the government signposting service at gov.uk/report-cyber points to the right place.
- Phishing: forward suspicious e-mails to report@phishing.gov.uk, the NCSC's Suspicious Email Reporting Service, and suspicious text messages to 7726. Scam websites can be reported to the NCSC as well. Details: Report a phishing e-mail.
Keep the crime reference number Report Fraud gives you. Your bank will usually ask for it when you claim a refund for a scam payment.
Canada
- National Cybercrime and Fraud Reporting System at reportcyberandfraud.canada.ca, run by the RCMP's National Cybercrime Coordination Centre (NC3) and the Canadian Anti-Fraud Centre (CAFC). You can report as a victim, a target or a witness, and anonymously if you prefer.
- By phone: the CAFC on 1-888-495-8501, Monday to Friday, 10 am to 4:45 pm Eastern time, excluding holidays.
- Local police: report to your local police service as well, which can open a file and give you a reference number.
- Canadian Centre for Cyber Security at cyber.gc.ca: for incidents affecting large organisations, critical infrastructure or government institutions.
- Spam: non-criminal spam e-mail goes to the Spam Reporting Centre; spam text messages can be forwarded to 7726.
If your identity was used, also contact the credit bureaus Equifax Canada and TransUnion Canada to place a fraud alert on your file.
Australia
- ReportCyber at cyber.gov.au/report, run by the Australian Signals Directorate's Australian Cyber Security Centre as a national policing initiative. Choose whether you report as an individual, a business or a government agency. Reports are passed to police.
- ASD hotline: 1300 CYBER1 (1300 292 371), for urgent help with a cyber security incident.
- Scamwatch at scamwatch.gov.au, run by the National Anti-Scam Centre, for scams, so warnings can reach other people.
- IDCARE at idcare.org, the national identity and cyber support service, if your identity documents or personal details were stolen.
- Police Assistance Line: 131 444 for non-urgent police matters.
If you lost money, ask your bank whether the payment can be stopped or recalled, using the number on its official website or your card.
European Union
Each EU country runs its own police reporting channel. Europol's Report cybercrime online page lists them: choose your country to reach the national police website or address. Where no online option exists, report at a local police station.
Europol's list is not always current, and a link may point to an old address. If it does not work, go to your national police website directly. Keep the reference number you receive.
For ransomware, the No More Ransom project, run by Europol, national police and security companies, also links to reporting pages and lists free decryptors: see free ransomware decryptors.
Reporting deadlines for businesses
Organisations hit by ransomware or a data breach can have legal reporting duties on top of a police report. The main deadlines are below. They depend on your sector and size, so check them with your data protection officer or legal adviser.
European Union
- GDPR, Article 33: notify the data protection authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to people. Article 34 adds that affected people must be told without undue delay when the risk is high. The European Data Protection Board lists every national authority.
- NIS2 Directive: essential and important entities send an early warning of a significant incident to their CSIRT or competent authority within 24 hours, an incident notification within 72 hours, and a final report within one month.
United Kingdom
- UK GDPR: report a notifiable personal data breach to the Information Commissioner's Office without undue delay and within 72 hours of becoming aware of it. The ICO's breach advice line is 0303 123 1113.
United States
- SEC: public companies disclose a cybersecurity incident they determine to be material on Form 8-K, Item 1.05, generally within four business days of that determination.
- CIRCIA: the law will require covered critical infrastructure entities to report significant incidents to CISA within 72 hours and ransom payments within 24 hours, but only once CISA's final rule takes effect. As of 4 October 2026, CISA's page says the final rule is still being prepared.
- States and sectors have their own breach notification laws and deadlines, for example for health data.
Canada
- PIPEDA: a breach of security safeguards that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner and to affected people as soon as feasible. Records of all such breaches must be kept for two years.
Australia
- Ransomware payments: under the Cyber Security Act 2024, businesses with an annual turnover of 3 million Australian dollars or more, and responsible entities for critical infrastructure, must report a ransomware or cyber extortion payment to the ASD within 72 hours.
- Notifiable Data Breaches scheme: an organisation that suspects an eligible data breach must assess it within 30 days and, once it has reasonable grounds to believe one occurred, notify the OAIC and affected people as soon as practicable.
What happens after you report, and the scams that follow
Most services do not reply to every report personally. IC3, for example, passes complaints to FBI field offices and other agencies and will not contact you itself in most cases. Report Fraud assesses reports and sends them to a police force when there are lines of enquiry. Silence does not mean the report was ignored.
Criminals know that victims are waiting for news, and they pretend to be the agencies above. Be suspicious of anyone who contacts you about your case and:
- asks for a fee, tax or deposit to release recovered money or decryption keys,
- offers to recover lost crypto or funds for an upfront payment,
- asks you to install remote access software or move money to a safe account,
- claims to be from IC3, the FTC, Report Fraud, the CAFC or a police force and contacts you first through social media or a messenger.
Government agencies do not charge victims and do not work with paid recovery services. Report such contacts the same way as the original crime. To secure your accounts after a scam or infection: securing your accounts after malware or phishing.
Frequently asked questions
Where do I report ransomware?
In the US, report to the FBI's IC3 at ic3.gov; organisations can also use CISA's reporting form, and one report reaches the other agencies. In the UK, use Report Fraud at reportfraud.police.uk or call 0300 123 2040, or Police Scotland on 101. In Canada, use the National Cybercrime and Fraud Reporting System or call the CAFC on 1-888-495-8501. In Australia, use ReportCyber at cyber.gov.au. In EU countries, report to your national police; Europol lists the channels. Include the ransom note, the file extension and any contact addresses.
Do I have to report a ransomware attack?
As a private person, reporting is not mandatory, but it is strongly recommended, and banks and insurers often need the reference number. Businesses can be obliged to report. In the EU and the UK, a personal data breach must normally be notified to the data protection authority within 72 hours. In Australia, larger businesses must report ransomware payments within 72 hours. US public companies disclose material incidents within four business days of deciding they are material. Check your sector's rules with a legal adviser.
What is the GDPR 72-hour rule?
Article 33 of the GDPR says that an organisation must notify its data protection authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. If the notification comes later, it must explain the delay. The duty does not apply when the breach is unlikely to result in a risk to people's rights and freedoms. A ransomware attack that encrypts or copies personal data usually counts as a breach. The UK GDPR has the same 72-hour rule, with reports going to the ICO.
Is Action Fraud still the place to report in the UK?
No. Report Fraud, run by the City of London Police, replaced Action Fraud as the national reporting service for fraud and cybercrime in England, Wales and Northern Ireland. Use reportfraud.police.uk, which is open day and night, or call 0300 123 2040. Organisations under a live cyber attack can call that number at any hour. In Scotland, report to Police Scotland on 101. Older guides and some international lists still point to Action Fraud, so check that you are on the current site.
Will reporting a scam get my money back?
Usually not directly. Police and agencies collect reports to investigate and disrupt criminal groups, and in some cases they freeze stolen funds, but they rarely return individual payments. Your best chance of a refund is your bank, card issuer or payment service, contacted as soon as possible. Card payments can often be disputed, and bank transfers can sometimes be recalled if you act quickly. Keep the report reference number, because the bank may ask for it, and ignore anyone who offers to recover the money for a fee.
Where do I report a phishing e-mail or scam text?
In the US, forward phishing e-mails to reportphishing@apwg.org and scam texts to 7726, and report fraud to the FTC at ReportFraud.ftc.gov. In the UK, forward e-mails to report@phishing.gov.uk and texts to 7726. In Canada, forward spam texts to 7726 and report fraud to the CAFC. In Australia, report scams to Scamwatch. In the EU, use your national police or consumer protection service. If you clicked a link or entered a password, change that password at once and turn on two-step verification for the account.
Sources
- CISA: Report Ransomware (read 4 October 2026)
- FBI Internet Crime Complaint Center (IC3) (read 4 October 2026)
- Report Fraud (City of London Police): Guide to reporting (read 4 October 2026)
- NCSC: Report a Cyber Incident (read 4 October 2026)
- ICO: 72 hours, how to respond to a personal data breach (read 4 October 2026)
- RCMP and CAFC: National Cybercrime and Fraud Reporting System (read 4 October 2026)
- Office of the Privacy Commissioner of Canada: Mandatory reporting of breaches of security safeguards (read 4 October 2026)
- Cyber.gov.au: Report (read 4 October 2026)
- Cyber.gov.au: Cybercrime, getting help (read 4 October 2026)
- Cyber.gov.au: Ransomware payment and cyber extortion payment reporting (read 4 October 2026)
- OAIC: Part 4, Notifiable Data Breach (NDB) Scheme (read 4 October 2026)
- Europol: Report cybercrime online (read 4 October 2026)
- EUR-Lex: Regulation (EU) 2016/679 (GDPR), Articles 33 and 34 (read 4 October 2026)
- EUR-Lex: Directive (EU) 2022/2555 (NIS2), Article 23 (read 4 October 2026)
- SEC: Rules on cybersecurity incident disclosure by public companies (press release 2023-139) (read 4 October 2026)
- CISA: Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) (read 4 October 2026)
Ugnius Kiguolis, Owner and editor of 2-spyware.com. Ugnius Kiguolis owns and edits 2-spyware.com and is responsible for its Windows security guides. Every page he signs is checked against current vendor, law-enforcement and Microsoft sources before it is published and again when the facts change.