The Transfer You Approved May Be Hard to Undo: Seven Checks Before You Pay

An online transfer you authorize may be difficult to recover, even when the request came from a scammer. The practical response is to verify the person, destination and payment terms before approving the transaction—not to assume the bank or app can simply cancel it afterward.
That core warning remains valid, but some older security advice has aged badly. Current guidance favors password managers, multifactor authentication and passkeys over memorizing many complex passwords or changing them on a fixed schedule. The seven checks below combine those account protections with a deliberate review of the transfer itself.
Seven checks to complete before sending money
- Confirm an unexpected request through a separate channel. Call the person using a number already in your contacts, speak face to face, or reach the organization through contact details you found independently. Do not use the phone number, link or callback instructions contained in the request. A familiar name or account can still be involved if someone has impersonated the owner or gained access to the account.
The FTC’s mobile-payment advice warns that app payments can be hard to recover and recommends confirming unexpected requests, checking the recipient’s information, protecting the account with MFA or a PIN, and never giving credentials to an unsolicited contact. - Match the recipient details, not just the story. Compare the displayed name, phone number, email address or account identifier with information supplied through a trusted channel. Read every character before confirming; autocomplete and recently used recipients can make the wrong destination look plausible. For a large first-time payment, consider sending a small test amount and asking the intended recipient to confirm receipt before transferring the balance, provided the extra fee and delay are acceptable.
- Review the final amount, currency and delivery terms. The confirmation screen may include fees, an exchange rate, a delivery estimate or an amount the recipient will actually receive. Check these details against the invoice or agreement rather than concentrating only on the headline amount. If the destination is abroad, establish who is responsible for intermediary charges and whether the recipient expects a specific currency.
- Protect the account with more than a reusable password. Enable MFA or a passkey when the transfer provider offers it. For accounts that still require passwords, use a password manager to generate and store a unique credential; reusing one password allows a compromise elsewhere to threaten the payment account too.
NIST’s updated consumer guidance recommends MFA first, identifies passkeys as resistant to ordinary password phishing, and recommends password managers for accounts that still rely on passwords. It also notes that text-message codes are more vulnerable than some other MFA methods. Never disclose a password, recovery code or one-time code to somebody who contacted you. - Open the service through a trusted route. Launch the official app you previously installed or enter a known web address yourself instead of following a payment link in an email, text, advertisement or search result. A page can imitate a legitimate login screen and capture credentials before redirecting you elsewhere. If a message claims that your account is locked or a transfer is pending, check the account independently rather than responding inside the message.
- Remove urgency from the decision. Pause when someone demands immediate payment, secrecy or a specific hard-to-recover method. A claimed emergency does not prevent you from independently contacting a relative, employer, supplier or government office. Legitimate invoices can also be altered, so businesses should verify any unexpected change of bank details with a known contact before paying.
- Know the cancellation and error process before approval. Check whether the service describes the payment as instant, pending or scheduled, and identify the support route for an incorrect or unauthorized transaction. Do not assume that funding an app with a card gives the transfer the same protections as an ordinary card purchase. Protection depends on the payment product, what happened, the provider’s terms and the law that applies in your jurisdiction.
Why “always use a credit card” is incomplete advice
A card purchase, a bank transfer, an international remittance and a person-to-person app payment are not interchangeable. The distinction between an unauthorized transaction and a payment that the account holder approved after being deceived can also affect the available remedy. That is why the safest choice cannot be reduced to one funding source.
Before choosing a service, compare its fees, exchange-rate information, delivery timing, recipient requirements and stated cancellation process. For US consumers sending qualifying remittances abroad, the Consumer Financial Protection Bureau’s transfer guidance explains that providers generally must disclose specified costs and that covered errors carry investigation rights; it also directs consumers to cancellation, reversal and complaint resources. Other countries and other transfer products may follow different rules.
Likewise, routinely changing a good password every 90 days is not the central safeguard it was once presented as. A unique password stored in a reputable manager, backed by MFA, is more useful than a predictable password that is frequently modified and reused. Account security still cannot correct a payment voluntarily sent to the wrong person, which is why recipient verification remains a separate step.
If the money went to the wrong place
Contact the transfer provider immediately through its official app, website or the number printed on your card or statement. Give the transaction identifier, amount, time and recipient details, state clearly whether the payment was unauthorized, mistaken or induced by fraud, and ask whether it can be stopped, recalled or reversed. Speed matters, but a refund is not guaranteed.
Then notify the bank or card issuer that funded the payment, if one was involved. Preserve messages, invoices, usernames, phone numbers and confirmation screens; do not delete the conversation simply because it is embarrassing or upsetting. These records can help the provider distinguish an account takeover from an authorized payment sent under false pretenses.
If credentials or codes were exposed, change the affected password from a trusted device, end other active sessions where the service permits it, and review recovery email addresses, phone numbers and connected accounts. Monitor statements for unfamiliar activity and use the appropriate national fraud-reporting or police channel when warranted. Ignore anyone who later promises recovery in return for an upfront fee: a second payment does not make the first one easier to retrieve.
The shortest safe routine
For an ordinary transfer, the essential sequence is simple: independently confirm the request, match the recipient identifier, review the amount and terms, and only then authorize. Secure the account with MFA or a passkey, but treat those controls as protection against account access—not as proof that the person asking for money is genuine.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.