I entered my credit card on a fake website: what to do now.
Call your card issuer right now using the number on the back of the card, not any number from the site or message that led you there. Ask them to lock the card.
This is urgent, but it isn't out of control. The next fifteen minutes matter more than the last fifteen – here's exactly what to do, in order.
Fake checkout pages usually impersonate a real retailer, a delivery company, or a payment processor. They ask for your card number, expiration date, CVV, name, billing address, and sometimes a one-time code sent by text. If you typed any of that into a page you now suspect was fake, the goal is simple: cut off the card's ability to be used, and leave a paper trail while you do it.
1. Call your card issuer right now
Use the number on the back of the physical card, or your bank's official app, not any number or link from the site or message that led you there. Ask them to lock or freeze the card immediately. Most major US card issuers let you do this instantly from their app; use that first, then follow up with a call to make sure a formal fraud flag gets attached to the account.
Under the Fair Credit Billing Act, your liability for unauthorized credit card charges is capped at $50 if you report promptly, and in practice most issuers waive that entirely. Debit cards are less protected the longer you wait, which is exactly why speed matters here more than it would for a credit card.
2. Check pending and recent transactions
Pending charges often show up before a final, posted transaction – don't wait for something to "clear" before flagging it. Write down the amount, the merchant name shown, and the date for anything you don't recognize, even small ones. Small test charges (sometimes $1 or less) are a common way fraudsters confirm a card still works before making a bigger purchase.
3. Don't confirm anything by phone or text after this
Once a card's details are out, a second wave often follows: a call or text pretending to be your bank's "fraud department," asking you to "verify" a transaction by reading back a code. That code is almost always the one-time passcode that would authorize a real transfer or a new card being added to a digital wallet. No legitimate fraud department needs you to read them a code to cancel something. Hang up, and call the number on your card yourself.
4. Save everything before it disappears
Fake pages get taken down fast, sometimes within hours. Before that happens, save:
- The full URL, copied from the address bar, not retyped from memory
- Screenshots of the page, especially any checkout or payment form
- The text message or email that led you there, with the sender's number or address
- Date and time you visited, and what you actually typed in
5. Report it
File a report with the Federal Trade Commission at reportfraud.ftc.gov: this is the FTC's actual consumer fraud intake, and it feeds directly into the database law enforcement uses to spot patterns across victims. If the amount is significant or you suspect organized fraud, also file with the FBI's Internet Crime Complaint Center (IC3) at ic3.gov. Neither of these gets your money back directly – that's your card issuer's job – but they're what actually gets fake storefronts and phishing infrastructure investigated and taken down at scale.
You can also report the page directly to Google Safe Browsing and to Microsoft, which helps get it flagged in Chrome and Edge for other people who click the same link.
6. Change reused passwords
If the fake site also collected your email, a password, or your address, change any password you've reused elsewhere: starting with your email account, since it's usually the recovery path for everything else. Turn on two-factor authentication anywhere you haven't already.
7. Expect a follow-up attempt
Scammers who got real data from you once often try again, using what they learned to sound more credible the second time: a "refund" that requires you to pay a small fee first, a "delivery" that needs address confirmation, a "security alert" with another urgent link. Treat any unexpected follow-up contact about this incident with the same suspicion as the original message.
Variants of the fake checkout page
Knowing how you got there helps you judge how much was exposed and what comes next. The most common route is the fake delivery fee page: a text about a held package leads to a courier-branded form asking for a dollar or two in "redelivery" charges: the fee is bait, the card form is the point. A close second is the too-good-to-be-true storefront: an ad on social media for a brand-name product at a steep discount, leading to a polished shop that takes your payment and ships nothing (or ships a worthless trinket so the seller can contest your dispute with a tracking number).
Subtler variants include the lookalike login-plus-payment page, which imitates a streaming service or subscription site and asks you to "update your billing information" after a supposed failed payment; the fake ticket or booking site that surfaces in search ads for concerts, flights, or vacation rentals; and the cloned checkout, which copies a real small retailer's site down to the product photos, ranked just below the genuine one in search results. In each case the tell isn't the design – modern kits are pixel-accurate – but the route you took to arrive: an unexpected message, an ad, or a search result rather than a bookmark or a typed address.
How it plays out: a realistic example
Consider Dana, a nurse doing holiday shopping on her phone between shifts. She sees an ad for a popular air fryer at half price, taps through to a clean-looking store, and checks out in under two minutes – card number, expiration, CVV, billing address. The confirmation email never arrives. Two days later a $0.83 charge from an unfamiliar merchant appears, which she ignores as a glitch. The day after that: $612 at an electronics retailer three states away, and a text from a "fraud department" asking her to confirm a code to cancel the charge.
This is the moment the incident is won or lost. The small charge was the test; the big one was the real theft; the text is the second wave, hunting for the one-time passcode that would let the thieves add her card to a digital wallet and keep spending after the number is cancelled. Dana almost reads the code back: the caller knows her name and the exact charge amount, because those came from the same fake checkout. Instead she hangs up, calls the number on her card, and the issuer confirms no one from the bank had contacted her. The card is locked, both charges are reversed, and the lesson is the one worth memorizing: the code sent to your phone is the key to your money, and no real bank ever asks you to read it back.
Prevention habits for next time
Once the immediate cleanup is done, a few changes make a repeat far less likely. Use a virtual card number for online shopping if your issuer offers one – many US banks generate per-merchant numbers you can cap or cancel without touching the real card. Turn on transaction alerts for every purchase, not just large ones, so a test charge pings your phone the moment it happens instead of surfacing days later on a statement.
Change how you reach checkout pages. Buy from bookmarks or the retailer's app rather than from ads or search results, and treat any shop you discovered through a social media ad as unverified until you've checked it independently. Prefer credit over debit online: the dispute protections are stronger and the money at risk isn't sitting in your checking account. If a price is dramatically below every other retailer's, let that be the signal it usually is. Finally, brief the household: agree that nobody ever enters a card number on a page reached from a text message, and that any "bank" call asking for a code gets a hang-up and a callback to the number on the card. Those two rules alone would have stopped this scam at either end.
Frequently asked questions
What should I do first if I entered my card on a fake website?
Will my bank refund unauthorized charges from a phishing site?
How do I report a fake checkout website?
Daniel A. and Óscar S. run Breachfolio, a small independent site about security and AI. This article was drafted with AI assistance and reviewed by a person before it went live. We write from documentation, vendor sources and published research rather than from original lab benchmarks, and we link a source in the sentence that relies on it. How we work · About us
