Who to Report a Hacked Crypto Account To — If You're Not in the US
Search for what to do about a hacked crypto account and you'll be told, within about two clicks, to file with the FBI's IC3. That's sound advice in Ohio. In Manchester, Melbourne or Manitoba it's a form submitted to a jurisdiction with no reach over your case, and filling it in costs you the one thing you can't get back: the first few hours. This piece covers what to do before you report anything, and where the report actually goes if you're in the UK, Canada, Australia or elsewhere in the English-speaking world.
- The first hour belongs to the account, not the form
- United Kingdom: Report Fraud — unless you're in Scotland
- Canada: the CAFC, and the regulator nobody mentions
- Australia: ReportCyber, and ASIC
- If your phone number moved, that's a separate report
- The second wave: the people who ring to help
- Anywhere else: how to find the right desk
- What a report actually does
- FAQ
The first hour belongs to the account, not the form
Reporting is not containment. No police force and no fraud centre can freeze your exchange account, revoke a login session or cancel an API key — the platform can, your bank can, and you can. So the order is: shut the doors first, gather evidence second, file third. Filing first because it feels like doing something is how people spend the live window watching a progress bar.
From a device you trust — not the one you suspect — work through this quickly:
- Change the password and log every session out, then check the device list and kick off anything you don't recognise. Device management and suspicious logins walks the screens.
- Kill the API keys. This is the one people skip. A key with trading or withdrawal permission survives a password change and keeps working — see API key security.
- Check the withdrawal whitelist. If an attacker added an address, it may already be sitting there waiting out the cooling-off period. Whitelist setup covers where to look.
- Check your email account, not just the exchange. A forwarding rule that shunts every message containing the word Binance into the archive means you never see the alerts. Reset the email password too.
- Tell the platform, in writing, through its own support channel. Not through a link someone sent you.
- Ring your bank if any card, transfer or fiat rail was involved. Banks work on hours, not weeks, and they have their own process that a police report does not replace.
The full sequence is in the first ten minutes after an account is stolen; if you're too rattled to hold an order in your head, the hacked-account response decision tree asks one question at a time.
United Kingdom: Report Fraud — unless you're in Scotland
Report Fraud (formerly Action Fraud) is the national reporting centre for fraud and cybercrime covering England, Wales and Northern Ireland, run by the City of London Police. The change took effect on 4 December 2025 and the service went fully public in January 2026, which is why nearly every guide still names the old one — searches and the old address redirect to the new service either way. You report online at reportfraud.police.uk, which is open around the clock, or by phone on 0300 123 2040 — the number didn't change — staffed Monday to Friday, 08:00–20:00. If you've just watched your balance go at three in the morning, the online form is the one that's awake.
A local police station is not the route for this in those three nations. Walking in with a crypto theft generally gets you pointed back at Report Fraud, which wastes an afternoon.
Canada: the CAFC, and the regulator nobody mentions
The Canadian Anti-Fraud Centre (CAFC) is the national collection point, and the report goes in online at reportcyberandfraud.canada.ca. That much most people find on their own.
What gets left out of the English-language write-ups is the second and third stop. If what happened to you has an investment flavour — a fake trading platform, a broker who wasn't one, a scheme that promised returns rather than simply draining a wallet — you're also directed to report it to the securities regulator for your province or territory, and to your local police. Three reports, not one.
Securities regulation in Canada sits at the provincial and territorial level, so the body you want depends on where you live rather than on a national desk. Look up your own province's regulator instead of assuming a federal equivalent catches it.
Local police still matter, and not as a formality: some processes downstream — an insurer, a bank, a platform's escalation — ask for a police file number specifically, and the CAFC report is a different animal.
Australia: ReportCyber, and ASIC
Cybercrime is reported through ReportCyber, the national portal, at cyber.gov.au/report-and-recover/report. If you go looking for ACORN — the name still turns up in older articles and forum posts, which is how you can date them — it's been replaced by ReportCyber.
There's a second desk worth knowing about. Where the conduct involves crypto assets and looks like financial misconduct rather than a straightforward break-in, it can also go to ASIC. Two reports serve different purposes: the ReportCyber submission is about the crime against you, and the ASIC one is about conduct that a regulator can act on more broadly. Sending it to one doesn't send it to the other.
If your phone number moved, that's a separate report
If your phone lost signal shortly before the account went, that's probably not a password leak — it's your number re-issued onto someone else's SIM, with every SMS code following it there. Why SMS is the weakest 2FA covers the mechanism; what it changes here is who else needs to hear from you: the carrier is a party to what happened, not a bystander.
This is worth pressing on, because in Australia it isn't a matter of goodwill. Telecommunications rules in force since 30 June 2022 require multi-factor identity verification before high-risk actions such as a SIM swap or a change to account details go through. There's enforcement behind it: Exetel was fined A$695,000 after transferring 73 numbers to cybercriminals without verifying identity — the largest penalty issued under the number-porting rules so far.
You can't recite Australian telco rules at a carrier in Cardiff or Calgary. But the request travels anywhere: ask, in writing, when the SIM change was requested, through which channel, and what identity check was performed — as a record you can attach to your report. Asking on day one is a different exercise from asking in month three.
The second wave: the people who ring to help
Australia's National Anti-Scam Centre has warned about a pattern that deserves naming here, because the timing is what makes it work. In an account compromise scam, someone contacts you claiming your account has been hacked, and frightens you into moving your money or your crypto somewhere — to a safe account, to a new wallet, to an address they'll happily supply.
Read that after a real breach and the trap looks obvious. It doesn't arrive as a hypothetical, though. It arrives while you're already scared, already certain your account has been compromised, primed to say yes to anyone who confirms it. The story matches. That's the trick.
So set the rule now, while nothing is happening: nobody legitimate will ever need you to send crypto anywhere to keep it safe. Not the exchange, not the bank, not the police, not the recovery specialist who found your forum post. Urgency plus a destination address is the tell, and it doesn't matter how much they know about you. Hang up, and reach the platform yourself through an app or number you were already using. How to tell whether a Binance message is real covers the verification habit; the phishing check is there for the link you're unsure about.
Anywhere else: how to find the right desk
Ireland, New Zealand, Singapore, South Africa — we won't name bodies we haven't verified, because a confidently wrong agency name is worse than none. The method is the same everywhere and takes about ten minutes:
- Start at your national police service's own website, not a search result, and look for the fraud or cybercrime reporting page. Most English-speaking countries consolidated on a national online portal over the last decade.
- Check whether fraud is split off from ordinary policing. The UK's Report Fraud model — a separate national centre, with a nation-sized exception in Scotland — is not unusual. If your country has one, the local station is a detour.
- Ask whether a financial regulator also wants to know. The Canada and Australia patterns above both have this second door for anything investment-shaped.
- Don't route through a third-party report a crypto scam site. Search results are thick with them, and a fair number are lead generation for recovery scams: you describe exactly how much you lost and how vulnerable you feel, and the calls start. Official portals sit on government domains — check the domain before you type into it.
What a report actually does
What it does: it creates a dated, official record with a reference number. That number has real downstream use — a bank, an insurer or a platform's escalation may want it before their own machinery moves, and you can't obtain one retroactively for a day you never reported. It also feeds a national picture: your case alone is small, but as one of forty submitted the same week pointing at the same addresses, it isn't, and pattern is what makes anything larger possible.
What it does not do: it doesn't start a search for your coins, and it isn't a recovery mechanism. On-chain transfers don't reverse on request. Once funds have moved through several hops and out through a platform, whether anything is traced, frozen or returned rests with law enforcement and whoever holds those funds — not with you, and not with the form. We won't quote a recovery rate or a window; nobody can tell you in advance which side of it your case lands on.
Report anyway: it costs an hour you've already lost the use of, and it's the only route by which anything official can happen. Then keep the reference number somewhere you'll find it in six months, with your notes and screenshots.
FAQ
I'm not in the US — is there any point reporting at all?
There is, but be clear about what the twenty minutes buys you. A report creates a dated official record with a reference number, and that number is often what a bank, an insurer or a platform's own process wants before it will move. It also puts your case into a national pile, where analysts can see that forty other people were hit the same week by the same operation. What it does not do is start a search for your coins. Report because the record is useful to you later, not because you've been promised a recovery.
Do I report to my local police or to the national fraud portal?
It depends where you live, and the two are not interchangeable. In England, Wales and Northern Ireland, fraud and cybercrime go to Report Fraud rather than a local station. In Scotland, Report Fraud is not the route and Police Scotland is, on 101. In Canada the Canadian Anti-Fraud Centre collects the report, and for investment fraud you're also pointed at your provincial or territorial securities regulator and at local police. In Australia, ReportCyber is the national portal. Check your own country's police website rather than assuming the pattern from somewhere else.
Will reporting get my crypto back?
No one can promise you that, and we won't. On-chain transfers don't reverse on request, and once funds have moved through several hops and out through an exchange, whether anything is traced or frozen sits with law enforcement and the platforms holding the funds, not with you. Report anyway, and quickly: it costs an hour and it's the only route by which anything official can happen at all. Treat any service that finds you afterwards and guarantees recovery for an upfront fee as a second attempt on your money.
I'm in Scotland. Do I still use Report Fraud?
No. Report Fraud is the national reporting centre for England, Wales and Northern Ireland. Scotland isn't covered by it, and fraud goes to Police Scotland — call 101, the non-emergency number, or use the reporting route on their own site. Scotland is expected to join the Report Fraud service later in 2026; that hasn't happened yet, so 101 is still the answer today. This trips people up constantly, because guides written for a UK-wide audience name the national centre and stop there.
Someone rang saying my account was compromised and offered to help. Is that real?
Treat it as a scam until you've proved otherwise on your own terms. Australia's National Anti-Scam Centre has warned about exactly this pattern: the caller claims your account has been compromised and frightens you into moving your money or your crypto somewhere they control. It's nastier after a genuine breach, because the story matches what you already know is happening. Hang up, and reach the platform or your bank yourself through a number or an app you were already using. Nobody legitimate needs you to send crypto anywhere to keep it safe.
Sources
- Report Fraud · City of London Police · national fraud and cybercrime reporting centre for England, Wales and Northern Ireland, live since 4 December 2025 (reportfraud.police.uk, go by the current official page)
- Canadian Anti-Fraud Centre · national fraud and cybercrime reporting (reportcyberandfraud.canada.ca)
- ReportCyber · Australian national cybercrime reporting portal (cyber.gov.au/report-and-recover/report)
- Binance Help Center · entries on account security and reporting (binance.com/en/support)