Skip to content
FRP-179 Fraud & Financial Crime

What should be preserved from a victim’s account-security alerts?

Account-security alerts may provide early evidence of compromise, access attempts or recovery changes.

Avoid this assumption: The alert text alone is enough. Its value depends on the account, provider, device, timestamp, delivery route and action taken afterwards.

Preserve the original alert in the email, text message, application notification or security page where it was received.

Record the service, account, date, time, time zone, device and delivery channel.

Capture the alert type, location, IP address, device name, browser, session, recovery change, password reset or authentication event where shown.

Preserve any provider-generated reference, button, link text or case number without selecting it unnecessarily.

Record whether the victim recognised the activity and what they did in response.

Do not click “secure account”, “this wasn’t me” or similar options before preserving the original state unless immediate harm makes action necessary.

Those controls may revoke sessions, change credentials or create new audit records.

If protective action is taken, record the exact time, device, account and every resulting notification or session change.

Preserve related emails, text messages, authenticator prompts and linked-device alerts.

Do not assume the displayed location or device label identifies the offender.

Preserve whether the alert was delivered once, repeated, delayed or mirrored across several linked devices. Record any expiry time attached to the warning or approval request.

Record whether the victim approved, rejected or ignored any prompt.

Operational takeaway

Preserve account-security alerts in their original channel with full account, device, time and response context before using any protective control.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.