Make any future attempt much harder — and check related identity exposure.
What to do
- Switch the fund and linked email to authenticator-app 2FA (avoid SMS where possible)
- Change the linked email and phone if they were the entry point
- Set 'verbal password' / 'no transactions over the phone' rules on the fund where supported
- Place a credit freeze and report identity theft to your national authority (IDCARE / FTC / Action Fraud)
- Notify the tax authority — pension-fund compromise often pairs with tax-refund fraud
Was this guide helpful?
Know someone who needs this? Send them the guide.
JD
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers