What should I ask a victim to preserve?¶
Ask the victim to retain the original device, account and records through which the incident was experienced, while avoiding interaction that increases harm or changes evidence unnecessarily.
Preserve the original sources and context¶
Relevant material may include messages, emails, calls, voicemails, files, applications, transaction records, account alerts, password-reset notices, receipts and provider case numbers. Record the services, account names, contact identifiers, profile links, dates and times involved. Screenshots already taken should be retained, but they may not contain the metadata or quality of the source.
Ask what the victim saw, what actions they took and whether anyone else could access the device or account. Do not ask them to open attachments, follow links, revisit harmful content, confront another user or investigate on your behalf.
Make preservation safe and practical¶
Disappearing content, remote control, threats and account compromise may require urgent specialist or safeguarding advice. If credentials or settings must change to stop harm, preserve the visible state first where safe and document every action.
Provide an approved, secure route for supplying material; indiscriminate forwarding through ordinary messaging can lose context or expose sensitive content. Clear advice should reduce repeated viewing and keep welfare, access to support and communication needs in view.
Key takeaway
Help the victim retain original devices, accounts and records without turning them into an investigator or requiring unsafe exposure, and document any protective change that cannot wait.