After a possible tech support scam

A scammer remotely accessed your computer. What should you do now?

Gave a scammer remote access to your computer? Follow safe first steps for the device, passwords, payments, accounts, and official reports.

Prepared and reviewed by South Bay Tech Rescue
Published

Stop the contact first. You do not need to keep talking to the person or follow another instruction. The next steps depend on what they saw, what you shared, and whether money or account information was involved.

End the contact and stop sharing

Hang up. If the other person still has control of the device, turn the device off. Do not send another payment, install another program, or sign in to an account for them.

Use a different phone or computer that the scammer did not access for the next steps. Do not call a number from the pop-up, email, text message, or remote support window.

Protect money and important accounts

If you paid or shared financial information, contact the bank, card company, or payment provider through its official app, the number on your card, or the number on a statement. Tell them that a possible scammer remotely accessed your device.

From a different trusted device, change the password for your main email account and any other account that may have been exposed. Turn on two-step verification where the provider offers it. Do not reuse a password that the scammer may know.

If a Social Security number or other identity information was exposed, use IdentityTheft.gov from a trusted device for a personal recovery plan.

Have the device checked by a trusted source

Removing a remote access app does not prove that every unwanted change is gone. A trusted support provider or the device manufacturer can help identify the remote program, install available updates, run appropriate security checks, and explain whether another recovery step is needed.

If this is a business device, or if it contains regulated or highly sensitive information, stop using it and contact an appropriate security specialist before making more changes.

Save the details and make official reports

Write down the date, time, caller name, phone number, website, remote access app, payment method, and the information you remember sharing. Keep messages, receipts, and transaction records.

Report the incident to the FTC. The FBI also accepts internet crime reports. California residents can review the state Attorney General's tech support scam guidance. A report does not promise recovery, but it gives the appropriate agency a record of what happened.

Be cautious if someone contacts you later and promises a refund or says they can recover the money for a fee. Do not pay them or give them more access. Contact the bank, payment provider, or agency through an official address you found yourself.

Questions about this problem

Use these answers as a starting point, not a diagnosis.

Should I keep using the computer?
If someone still had remote control, or if banking, passwords, or sensitive files were visible, leave the device off until you can get trusted guidance. Use a different device for financial and account-protection steps.
Should I change passwords on the affected computer?
Use a different trusted device when possible. Begin with the main email account, because email is often used to reset other passwords, then address other accounts that may have been exposed.
Is uninstalling the remote access app enough?
Not necessarily. It can stop that app from being used again, but it does not show whether other settings, programs, files, or accounts were changed.

Worried about remote access or a possible scam?

Call from a different phone if possible. Tell us which device was involved, what the person asked you to do, and whether any account or payment information was shared.