Someone remoted into your computer? Here's exactly what to do.
If you — or your parent — let a "technician" take control of a computer, take a breath. This is a calm, ordered response written by computer-forensics analysts who do this for a living. Work through it top to bottom.
1 · The first five minutes
Two goals right now: cut off the remote connection, and stop any more money from leaving.
- Disconnect the computer from the internet. Unplug the network cable or turn off Wi-Fi. A remote-access tool can't do anything if it can't reach the internet. Don't shut the computer off yet if you might report this — but do get it offline.
- Do not send any more money. No more gift cards, no "refund" that requires you to send anything back, no new payments. Real refunds never work that way.
- Stop talking to them. Hang up. Don't let them "finish." Everything after "let me help" is the scam.
2 · How to tell if they still have access
The tool you watched them use is rarely the only one. Common signs the door is still open:
- A new icon or a phone number left on the desktop "in case you have problems."
- Remote-access programs you didn't install (names like AnyDesk, TeamViewer, UltraViewer, Supremo, or "Chrome Remote Desktop").
- Your antivirus is turned off or was uninstalled.
- The cursor moving on its own, or programs opening without you.
Getting offline (step 1) neutralizes all of them immediately. Fully removing them — and being sure you found every one — is where a forensic sweep earns its keep, because these are designed to be missed.
3 · Secure your accounts — email first
Your email is the reset path to everything else, so it's the priority. Use a different, clean device (your phone on cellular, or another computer) — not the one that was controlled.
- Change your email password and turn on two-step verification.
- Then your bank and financial logins, and anything else important. Enable two-step everywhere it's offered.
- Check for sneaky changes: new email forwarding rules, new "app passwords," or unfamiliar recent sign-in locations in your email's security settings — scammers plant these to keep reading your mail after you reset.
4 · Your money: what's recoverable, what isn't
Gift cards are the scammers' favorite because they're nearly impossible to recover once redeemed — but report them anyway (the store and the card brand can occasionally freeze a very recent one). Card or bank charges are different: they're often disputable through your bank and traceable. Call your bank's and card issuer's fraud lines now, dispute unauthorized charges, and ask them to watch for new payees or transfers. Keep every receipt and screenshot.
5 · Should you wipe the computer?
When multiple remote tools were installed and your antivirus was disabled, the honest answer is usually yes — back up your documents only, then wipe and reinstall Windows. It's the one way to be certain nothing was left behind. If there's any chance you'll report it to police, preserve evidence before wiping (or have it preserved for you) — a wipe destroys the proof.
6 · How to report it so it actually counts
- FBI IC3 (ic3.gov) — the federal internet-crime complaint. File for any loss.
- FTC (reportfraud.ftc.gov) — tracks these scams as a named pattern.
- Local police — get a report number; your bank and card issuer will ask for it.
Reports land harder with specifics: dates and times, the remote tools used, any phone number or "customer ID" left behind, and the money trail. That's exactly what a forensic write-up provides — a package investigators and banks can act on, instead of "I think I got scammed."
7 · The callback — the part almost everyone misses
This is the most important warning in the guide. These crews frequently call back — days or weeks later — often posing as a "refund department," "recovery service," your bank, or even law enforcement, to take a second, larger bite. Many leave a callback number and a "customer ID" precisely so the next call feels legitimate.
Anyone who contacts you referencing a prior technician, a customer ID, a refund, or your computer's security is the scam continuing. Hang up. If you want to check on something, look up the company's real number yourself — never use a number they gave you.
That's the exact question we answer. We find every remote-access tool a scammer left, confirm whether any are still active, preserve police- and bank-ready evidence, and lock out the callback — flat pricing, no fear tactics.
Start a free triage8 · When to get professional help
Do it yourself if it was brief, nothing was paid, and you're comfortable. Get help if: money changed hands, they were in your bank or email, it's an elderly parent (the callback risk is highest), or you simply want to know — with evidence — that the door is shut. Reading exactly what happened off the machine is what we do; see a real, anonymized case: Anatomy of a Remote-Access Scam.
Frequently asked questions
Is the scammer still in my computer?
Possibly. These scams usually install several remote tools and often disable antivirus, so the one you watched them use may not be the only one. Get offline now, and have every remote tool and startup entry checked — not just the obvious one.
Can I get my money back?
Gift cards are usually gone once redeemed. Card and bank charges are often disputable and traceable — call your bank and card issuer immediately and file reports.
Should I wipe and reinstall?
Usually yes if multiple tools were installed and antivirus was off. Back up documents only, preserve evidence first if you'll report it, then wipe.
They opened my bank while connected — what now?
Assume anything on screen was seen. Call the bank's fraud line, change banking and email passwords from a clean device, enable two-step, and watch for new payees.
Will they call back?
Very often. Anyone referencing a prior technician, a customer ID, a refund, or your computer's security is the scam continuing — hang up.