What should be preserved from a live banking or payment session?¶
A live banking or payment session may expose volatile account, device and transaction evidence that can disappear when the session ends.
Avoid the dangerous assumption¶
The dangerous assumption is that investigators should immediately browse the account, change security settings or take only a balance screenshot.
Record the device, application or browser, account identifier, displayed name, date, time, network state and whether the session was already authenticated.
Preserve visible balances, recent transactions, beneficiaries, linked funding sources, registered devices, active sessions, security alerts and account changes.
Capture complete transaction details, including identifiers, amounts, statuses, timestamps, references and counterparties.
Record every action taken.
Opening pages, refreshing data or selecting transactions may create new provider logs or alter cached information.
Do not transfer funds, test payment functions, add beneficiaries, revoke devices or change passwords without appropriate authority and a clear operational decision.
Where fraud is ongoing, account security and loss prevention may require urgent action.
That action should still be documented, with the preservation and safeguarding considerations recorded.
Screenshots may assist, but they are not a substitute for provider records or forensic capture.
Where possible, involve digital-forensics or financial-investigation specialists before interacting with a live account.
Preserve relevant notifications, authentication prompts and device-session details before the session expires.
When reporting, distinguish information that was already displayed from information revealed by investigator interaction.
Operational takeaway¶
Preserve live-session identity, transaction, beneficiary, device and security evidence with a complete action log before changing the account or ending the session.