Skip to content
FRP-174 Fraud & Financial Crime

Should a victim continue using the affected device?

Whether a victim should continue using an affected device depends on the risk of ongoing harm, evidence change and practical necessity.

Avoid this assumption: The device must either be seized immediately or used as normal. Continued use may alter evidence, but removing the device may isolate the victim from support, banking, work, healthcare or emergency contact.

Identify the active risk. Is the device being monitored, remotely controlled, infected, used for fraud or likely to receive further harmful contact?

Record the current state, visible messages, alerts, accounts, network connection, time and any unusual behaviour.

Where serious ongoing harm is credible, seek specialist and safeguarding support quickly.

A safer alternative device or communication route may be needed before the affected device is restricted.

Do not tell the victim to keep using it normally if doing so may expose them or contaminate important evidence.

Likewise, do not take away their only communication method without addressing immediate welfare and support.

If limited continued use is necessary, define what should and should not be done. Avoid opening links, installing software, deleting content, changing settings or communicating with the suspected offender.

Record every unavoidable use after the preservation decision.

Where remote access or malware is suspected, network isolation may be appropriate, but consider loss of messages, synchronisation and location evidence.

Do not promise that leaving the device untouched will preserve everything.

Operational takeaway

Balance evidence with victim safety and practical need, provide a safe alternative where possible and strictly record any continued use of the affected device.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.