Where to Report Document Fraud: Who Takes the Case
The bank first, within hours, because that is the only step that recovers money. Then the national centres in the US, UK, Canada and Australia — and the four reports almost nobody files that change outcomes most.

The most common outcome after a business discovers document fraud is nothing. Not a cover-up — just an afternoon of phone calls that go nowhere, a growing sense that no single body owns the problem, and a quiet decision to write it off and tighten a process instead.
That instinct is half right. A single report to a single agency will rarely get your money back. But reporting is not really about your case; it is about three things that do work — the bank's recall window, the aggregation that turns forty small reports into one investigation, and the paper trail your insurer and your auditor will want to see. The trick is knowing which door to knock on for which purpose, and in what order.
Key takeaways
- The bank comes first and everything else second, because the recall window is measured in hours.
- Report to the national aggregator even when your own case is small — that is how patterns become cases.
- Preserve the original files before you do anything else. Forwarding an email destroys the evidence in it.
- Reporting is not the same as recovery, and expecting recovery from a report is why most people stop reporting.
Do these three things first
Call the bank. Do not email. If money moved, the only thing that matters in the first hours is whether the receiving account can be frozen. Ask explicitly for a recall, and for the case to be raised with the beneficiary bank's fraud team. Our 72-hour guide covers the sequence in detail, and the single most common reason a recall fails is that the first afternoon was spent emailing the supplier to ask what happened.
Preserve the evidence in its original form. Save the original email as a .eml or .msg file, not a forward and not a screenshot — forwarding rewrites the headers that carry the delivery chain. Keep the attachment exactly as received, without opening and re-saving it, because re-saving can rewrite metadata. Note who received it, when, and what was done. If this ever becomes a dispute, an unbroken record of who held what and when is what makes your evidence usable.
Tell your insurer early. Crime, cyber and professional indemnity policies routinely carry notification deadlines shorter than people assume, and a late notification is a common reason a claim fails on a loss that was otherwise covered.
United States
IC3 — the FBI's Internet Crime Complaint Center, and the right first report for business email compromise, wire fraud and anything with an online component. IC3 operates a Recovery Asset Team that can work with banks on domestic transfers when a report arrives quickly, which is a concrete reason to file within hours rather than days.
ReportFraud.ftc.gov — the Federal Trade Commission's intake. It feeds the Consumer Sentinel database that law-enforcement agencies query, so a report here contributes to pattern-building even when nobody calls you back.
US Postal Inspection Service — the correct route for anything that arrived by post, including forged checks and fraudulent letters. Postal inspectors have real investigative powers and a mail-fraud statute that is broader than most people realise.
Your state Attorney General, for consumer-facing fraud, and the FBI field office directly for large or organised losses.
United Kingdom
Action Fraud — the national reporting centre for England, Wales and Northern Ireland, feeding the National Fraud Intelligence Bureau. Expect aggregation rather than individual investigation; report anyway, because that aggregation is the mechanism.
Police Scotland takes fraud reports directly in Scotland, via 101.
Your bank, under the industry reimbursement rules for authorised push payment fraud, which have changed materially in recent years and are worth understanding before you need them.
Canada
Report Cyber and Fraud — the national online reporting system launched by the RCMP, which routes reports to the Canadian Anti-Fraud Centre and to police. The Canadian Anti-Fraud Centre remains the central intelligence body.
Your local police service for anything needing a report number for insurance.
Australia and New Zealand
Scamwatch, run by the ACCC and now sitting alongside the National Anti-Scam Centre, is the reporting route in Australia. ReportCyber, run by the Australian Signals Directorate, is the door for cyber-enabled crime. In New Zealand, CERT NZ and the police are the equivalents.
European Union
There is no single EU intake. Report to the national police and to the national cybercrime unit — most member states run an online portal — and to the financial regulator if a regulated entity was impersonated. Europol coordinates rather than taking reports from businesses directly.
The reports people forget
These are the ones that actually change outcomes, and almost nobody files them.
The impersonated organisation. If a forged document carries a real company's letterhead, a real bank's logo or a real law firm's name, tell them. Most large institutions have a dedicated address for exactly this, they can often get the hosting or the lookalike domain taken down within a day, and they may already be tracking the campaign.
The registrar and the host. A lookalike domain sending forged invoices can be reported to the registrar for abuse. It works more often than its reputation suggests, particularly when you can show a registration date days before the fraud and a message impersonating your counterparty.
The professional body. If the fraud involved someone claiming a licence — a broker, an accountant, a lawyer, a healthcare provider — the licensing board takes complaints, and unlike the police they have a direct interest in credentials being misused.
The platform. Marketplaces, freight boards, job sites and lending platforms all have fraud teams, and they can act on their own users far faster than any external body.
What to include so the report is usable
Reports get closed for lack of detail more often than for lack of merit. Include:
- What was sent, exactly: the original files, with hashes if you have them.
- The financial detail: amounts, dates, the receiving account and any reference numbers.
- The identifiers: sending addresses, domains, IPs from the email headers, phone numbers, names used.
- The timeline: when it arrived, when it was paid, when it was noticed.
- What you did: recall requested at what time, to whom.
A short factual chronology beats three pages of narrative. Whoever reads it is triaging dozens that day.
About expectations
Be realistic and report anyway.
Most individual business fraud reports do not produce an investigation. The money is usually gone within hours, moved through accounts opened for the purpose, and the people who benefit are frequently outside the reporting country. That is the honest position, and pretending otherwise is why people stop bothering.
What reporting does achieve is real: it starts the only clock that can recover funds, it creates the record your insurer and auditor will ask for, and it adds one more data point to a pattern that eventually reaches the threshold where somebody acts. The cases that get made are made out of dozens of reports that individually looked too small to matter.
Then fix the control. The written control that would have caught it is a cheaper investment than the recovery attempt.
Frequently asked questions
Who do I report document fraud to first?
Your bank, if any money moved, and within hours rather than days — the recall window is the only mechanism that recovers funds. National reporting bodies come immediately after: IC3 in the US, Action Fraud in the UK, Report Cyber and Fraud in Canada, Scamwatch in Australia.
Is it worth reporting fraud if the amount is small?
Yes, for a reason that is not about your case. National centres aggregate reports, and investigations are typically built from many small ones sharing a domain, an account or a template. A small report also creates the record your insurer will want.
What evidence should I preserve?
The original email file rather than a forward or a screenshot, the attachment exactly as received, a note of who received it and when, and the financial detail including any reference numbers. Forwarding an email rewrites the headers, which are often the most useful evidence in the whole package.
Can I report a fake document if no money was lost?
Yes. Attempted fraud is reportable everywhere listed here, and an attempt reported early is more useful to investigators than a loss reported late — the infrastructure is often still live and can be taken down.
Check the PDF you are holding
Run a free PDF X-Ray in your browser — it recovers text from the file’s earlier revisions, so you can see what a value was before it was changed. No account needed.
Keep reading
Wire Fraud: What to Do in the First 72 Hours
Almost everything that works on a fraudulent transfer works in the first day. Almost nothing works after the third. Here is the order to work in when it has already happened.
Fake Proof of Payment: The Screenshot That Buys Three Days
Nobody fakes a payment to steal money. They fake it to buy time — long enough to collect the goods and be somewhere else when the bank tells you nothing arrived.
How to Spot a Fake ID: A Practical Verification Guide
Fake IDs now land in onboarding queues, not just at the bar. A repeatable, six-step way to check identity documents — starting with the barcode most forgers forget.