What to Do After You’ve Given a Scammer Remote Access
A caller claims to be from Microsoft, your bank, an internet provider or a security company. They say your computer has been hacked, your broadband has been compromised or a payment needs to be cancelled.
They ask you to install a remote-support application, read out a connection code and approve access.
Only afterwards do you realise it was a scam.
At that point, you should assume the scammer may have been able to:
- View anything displayed on the screen
- Control the keyboard and mouse
- Open files and applications
- Watch you sign in to accounts
- Copy information from the computer
- Install additional software
- Change security settings
- Create a way to reconnect later
- Access email, shopping or banking sessions already open
Microsoft warns that criminals use remote access to steal information and install malware while pretending to repair a problem. The National Cyber Security Centre also states that genuine NCSC representatives will never ask for remote access to your computer.
Do not panic, but do act quickly.
The immediate priorities are:
- End the scammer’s connection.
- Protect your money.
- Secure your online accounts from a different trusted device.
- Determine whether the computer can be safely cleaned or must be rebuilt.
- Report the incident and preserve useful evidence.
Immediate Action: Disconnect the Computer
End the call and do not respond to further messages from the scammer.
Disconnect the affected computer from every network:
- Turn off Wi-Fi.
- Unplug the Ethernet cable.
- Disconnect it from a docking station if the dock supplies networking.
- Disconnect mobile tethering.
- Do not reconnect it until it has been assessed.
This prevents the scammer from continuing to issue commands through the existing connection and can help limit further access.
For a personal computer, disconnecting it from the internet is normally the quickest practical action.
For a business computer, contact your IT provider or internal security team immediately. Do not start deleting applications, wiping logs or restarting systems unless directed. Current NCSC guidance notes that disconnecting a system can prevent further commands, restrict spread and preserve evidence, while powering it off may cause valuable investigative evidence to be lost.
Do Not Continue Using the Affected PC
Do not use the potentially compromised computer to:
- Change passwords
- Access online banking
- Check email
- Buy anything
- Speak to your bank through online chat
- Download security tools
- Sign in to your password manager
- Contact your IT provider through stored email accounts
The scammer may have installed monitoring software or retained access.
Use a different trusted device instead, such as:
- Another computer
- A phone or tablet
- A work device confirmed as safe
- A family member’s device that you trust
If no other trusted device is available, call your bank and IT provider by telephone.
Protect Your Money Immediately
Contact your bank or card provider as soon as possible when:
- You entered banking credentials
- Online banking was open during the session
- You showed the scammer a bank balance or statement
- They asked you to move money
- You made a card, bank-transfer, cryptocurrency or gift-card payment
- You gave them card details, a PIN or security code
- They claimed to issue a refund
- They moved money between your accounts
Use the number printed on the back of your card, the bank’s official application on a safe device or 159 where your bank participates.
The 159 service connects customers of participating banks directly to their bank when they believe someone is attempting to scam them. Stop Scams UK advises people to stop the conversation, hang up and call 159.
Tell the bank clearly:
“I gave a scammer remote access to my computer. They may have viewed or captured my banking information.”
Ask the bank to:
- Review recent activity
- Stop or recall suspicious payments where possible
- Freeze or replace affected cards
- Secure telephone and online banking
- Check for new payment recipients
- Review changes to contact information
- Add an alert to the account
- Explain what evidence it needs
Do not call a number supplied by the scammer, displayed in a pop-up or sent in a follow-up message.
Do Not Move Money to a “Safe Account”
A genuine bank or police officer will not need you to protect money by moving it into an account controlled by somebody else.
Scammers frequently continue the incident after remote access by claiming that:
- Your account remains at risk
- A payment must be reversed
- The bank’s fraud team needs your help
- You must transfer money for investigation
- You should not speak to anybody else
- Your IT provider or bank cannot be trusted
End the contact and call the organisation independently.
Change Passwords From a Safe Device
Assume any password typed, displayed, copied or stored during the remote session could have been exposed.
Begin with the accounts that can be used to take control of other accounts.
1. Secure Your Email First
Your email account is usually the most important account to protect because it can be used to:
- Reset other passwords
- Receive security codes
- Impersonate you
- Access invoices and private conversations
- Find information about your bank, employer and suppliers
Change the email password from a safe device.
Then check:
- Recovery email addresses
- Recovery phone numbers
- Recent sign-ins
- Connected applications
- Trusted devices
- Automatic forwarding
- Inbox rules
- Delegated access
- Sent and deleted messages
- Two-factor authentication methods
Remove anything you do not recognise.
2. Secure Financial and Shopping Accounts
Change credentials for:
- Online banking
- Credit cards
- PayPal and payment services
- Amazon and other retailers
- Investment or pension services
- Cryptocurrency accounts
Contact the provider directly if the account shows unfamiliar activity.
3. Secure Your Main Technology Accounts
Review:
- Microsoft account
- Google account
- Apple Account
- Password manager
- Cloud-storage accounts
- Mobile-phone provider
- Social-media accounts
Change any password that was reused on another service.
The NCSC advises changing compromised passwords, replacing reused passwords on other accounts and enabling two-step verification. It also recommends a strong, separate password for email because criminals can use email access to compromise other services.
4. Use Unique Passwords
Do not create one new password and apply it everywhere.
A password manager can generate and store a separate strong password for each service. The NCSC recommends unique passwords and notes that password managers make this practical.
5. Enable Multi-Factor Authentication
Turn on multi-factor or two-step authentication wherever available.
Prefer:
- A passkey
- An authenticator application
- A physical security key
- Another strong provider-supported option
Review existing authentication methods before adding a new one. A scammer may have registered their own telephone number, authenticator or recovery address.
Sign Out Other Sessions
Changing a password does not always terminate every active session immediately.
Use each service’s security settings to:
- Sign out all other devices
- Revoke active sessions
- Remove unfamiliar trusted devices
- Revoke suspicious application access
- Remove unknown app passwords
- Regenerate recovery codes where appropriate
For business Microsoft 365, Google Workspace and other managed accounts, administrators should revoke active sessions and review authentication logs centrally.
Record What Happened
Write down the timeline while it is still fresh.
Record:
- Date and time of the call
- Telephone number used
- Name and organisation claimed
- Website you visited
- Remote-access software installed
- Connection code or session ID
- Duration of remote access
- Accounts that were open
- Passwords or codes you entered
- Payments made
- Files the scammer opened
- Commands or applications you saw
- Any names, email addresses or payment details supplied
- What actions you have taken since
Preserve:
- Emails
- Text messages
- Screenshots
- Call logs
- Payment receipts
- Bank-transfer references
- Cryptocurrency wallet addresses
- Remote-support session emails
- Downloaded filenames
Do not contact the scammer to obtain additional evidence.
For organisations, create a formal incident log containing the known facts, potential effects and actions taken. The ICO advises organisations to begin documenting an incident immediately, even when they have not yet determined whether it needs to be reported.
Identify the Remote-Access Software
Scammers often use legitimate remote-support tools because these applications are designed to let another person see and control a computer.
Check:
Settings > Apps > Installed apps
Sort by installation date and look for software installed during the incident.
Also review:
- Start menu
- Downloads folder
- Desktop
- Browser download history
- Task Manager
- Startup applications
- Browser extensions
- System tray
The application could have been:
- Installed normally
- Run as a portable application
- Added as a browser extension
- Configured to start automatically
- Set up for unattended access
- Renamed to look less suspicious
Do not assume that uninstalling the visible application proves the computer is safe. The scammer may have installed additional software or changed settings separately.
Microsoft recommends uninstalling applications the scammer asked you to install and considering a device reset after giving a scammer access.
Check for Unattended Access
Some remote-support applications allow a computer to be controlled again without the user approving each session.
The scammer may have configured:
- Unattended-access passwords
- Automatic startup
- A background service
- Trusted remote devices
- Permanent access permissions
- A newly created remote-support account
Before removing the application, an experienced technician may want to record:
- Its exact name and version
- Installation date
- Configuration
- Recent connection history
- Associated account or device IDs
For a personal computer where forensic evidence is not required, uninstall the remote application after recording its identity.
For a company device, leave this process to the incident-response team so evidence is not unintentionally destroyed.
Check for New Windows Accounts
A scammer with administrative access could create another user or add an existing account to the Administrators group.
Open:
Settings > Accounts > Other users
Look for accounts you do not recognise.
You can also open an elevated Terminal and run:
net user
To review local administrators:
net localgroup administrators
Do not remove standard Windows service accounts simply because their names are unfamiliar.
Record anything suspicious and ask an experienced technician to verify it.
Check Startup Applications
Press:
Ctrl + Shift + Esc
Open:
Startup apps
Look for unfamiliar software enabled to start automatically.
Also review:
Settings > Apps > Startup
Be particularly cautious of:
- Remote-support tools
- Unknown update agents
- Applications with no recognised publisher
- Programs installed at the time of the scam
- Entries running from temporary or user-profile folders
Disabling a suspicious startup item may stop it from launching automatically, but does not remove it or establish what else has changed.
Check Browser Extensions
The scammer may have installed or enabled an extension that can:
- Read website content
- Redirect searches
- Change the home page
- Inject adverts
- Access clipboard data
- Modify downloads
Review extensions in every installed browser.
Remove anything:
- Installed during the incident
- You did not approve
- With an unfamiliar publisher
- Claiming to provide security, support or refunds
- Requesting unusually broad permissions
Also check:
- Default search engine
- Home page
- Proxy settings
- Saved passwords
- Payment methods
- Notifications
- Website permissions
Run a Full Security Scan
Once the immediate financial and account protections are complete, the computer needs to be examined.
On Windows, open:
Windows Security > Virus & threat protection > Scan options
Run:
- Full scan
- Microsoft Defender Offline scan, where appropriate
A full scan examines available files and applications. An offline scan restarts the PC and checks it in a more isolated environment, which can help with malware that attempts to hide while Windows is running.
The NCSC advises updating the computer and applications, running an antivirus scan and following the security product’s recommendations. If the antivirus cannot clean the computer, the NCSC advises wiping it and reinstalling the operating system.
Do not reconnect the PC to normal business systems simply because one scan reports no threats.
A scan cannot always prove that:
- No password was captured
- No file was copied
- No account session was stolen
- No security setting was altered
- No persistence mechanism remains
- No cloud account was modified
Should You Reset or Reinstall Windows?
This is the most important technical decision.
Because the scammer had interactive control, it may be impossible to prove exactly what they did merely by looking at the visible desktop.
A Scan and Cleanup May Be Reasonable When:
- Access lasted only a few seconds.
- No administrative approval was provided.
- No software was installed.
- The session was terminated before control was established.
- The computer contains no sensitive or business information.
- Security logs and scans show no suspicious changes.
- A competent technician has assessed the risk.
A Reset or Clean Installation Is Strongly Advisable When:
- The scammer had administrative access.
- Remote control lasted several minutes or longer.
- You logged into banking, email or work systems.
- They disabled security tools.
- They installed more than one application.
- They configured unattended access.
- Unknown accounts or services appeared.
- Malware was detected.
- The computer contains customer, financial or sensitive business data.
- You cannot establish what changes were made.
Microsoft recommends considering a reset after a scammer has accessed the device. The NCSC advises wiping and reinstalling when antivirus cannot reliably remove an infection.
Reset This PC vs. Clean Installation
Reset This PC can reinstall Windows while offering options to retain or remove personal files.
A clean installation erases the existing Windows installation and builds the computer again from trusted installation media.
Where there is a significant risk of compromise, a clean installation provides greater assurance than simply uninstalling the visible remote-access software.
Back up irreplaceable personal documents before wiping, but do not blindly copy:
- Executable files
- Scripts
- Unknown installers
- Browser profiles
- Suspicious archives
- Files created during the incident
Restore data from the most recent known-good backup where possible.
Do Not Restore the Infection
After rebuilding the computer:
- Install Windows from a trusted source.
- Install all security updates.
- Install drivers from Windows Update or the computer manufacturer.
- Ensure Microsoft Defender or the approved security product is active.
- Restore documents from a known-good backup.
- Scan restored files.
- Reinstall applications from their official publishers.
- Do not reinstall the scammer’s remote-access tool unless it is genuinely required and properly secured.
The NCSC advises restoring from the last known-good backup because trying to recover data from an infected installation can carry the infection into the rebuilt system.
Business Computers Require an Incident Response
Giving a scammer access to a work device is not only a PC problem.
The scammer may have reached:
- Microsoft 365
- SharePoint
- OneDrive
- Customer records
- Accounting systems
- Password managers
- VPN connections
- Remote desktops
- Internal file shares
- Supplier portals
- Cloud-management consoles
Notify your IT provider or security team immediately, even when no money appears to have been stolen.
The response may need to include:
- Network isolation
- Endpoint investigation
- Identity-log review
- Session revocation
- Password resets
- MFA-method review
- Email-rule inspection
- Malware analysis
- Cloud audit-log collection
- Review of accessed files
- Supplier and customer risk assessment
- Monitoring other devices for lateral movement
The NCSC recommends a planned incident-management process because fast detection and response can limit financial, operational and reputational damage.
Check Microsoft 365 and Business Email
An administrator should review:
- Recent sign-in activity
- Impossible or unusual locations
- New inbox and forwarding rules
- Changed MFA details
- New application registrations or consents
- Mailbox delegation
- Sent messages
- Deleted messages
- SharePoint and OneDrive access
- Newly created accounts
- Changes to administrator roles
Email access is especially serious because criminals may use a compromised mailbox to:
- Reset other accounts
- Monitor invoices
- Impersonate employees
- Redirect supplier payments
- Target customers and colleagues
Assess Whether Personal Data Was Exposed
Unauthorised access to personal information can constitute a personal data breach.
A business should establish:
- What information was accessible
- Whether the scammer opened or copied it
- Whose information was affected
- How sensitive it was
- Whether the incident is likely to create a risk to those people
- Whether affected people need to be informed
The ICO defines a personal data breach as a security incident affecting the confidentiality, integrity or availability of personal data, including unauthorised third-party access. A notifiable breach must be reported without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it.
Do not wait until the complete technical investigation is finished before starting the assessment and incident log.
Report the Scam
In England, Wales or Northern Ireland, cybercrime and fraud should now be reported to Report Fraud, which replaced the previous Action Fraud reporting service.
You can report online or call:
In Scotland, report fraud to Police Scotland by calling 101.
A business, charity or organisation experiencing a live cyberattack should call Report Fraud immediately on 0300 123 2040; its live-incident service operates 24 hours a day.
Include:
- The scammer’s telephone number
- Email addresses
- Claimed company
- Remote-access software
- Payment details
- Bank accounts
- Cryptocurrency addresses
- Website addresses
- Screenshots
- Timeline
- Amount lost
- Crime reference from any related bank report
Reporting does not guarantee that money will be recovered, but it provides police and fraud analysts with information that can be linked to other cases.
Warn People Who May Be Targeted Next
If the scammer accessed your email, social media or address book, they may contact:
- Friends
- Family
- Employees
- Customers
- Suppliers
Warn relevant people using a trusted communication method.
A useful message is:
“My computer or email may have been accessed by a scammer. Do not trust unexpected payment requests, links, attachments or requests for passwords that appear to come from me. Verify anything unusual by calling me directly.”
For a business, communications should be coordinated with management, the data-protection lead and legal advisers where appropriate.
Watch for Follow-Up Scams
Victims are frequently contacted again.
The follow-up caller may claim to be:
- The bank
- Police
- Report Fraud
- Microsoft
- The NCSC
- A recovery company
- A solicitor
- A cryptocurrency investigator
- Another IT provider
They may know details from the original incident, making the second call appear convincing.
Report Fraud advises people to verify unexpected contact independently and states that legitimate representatives will already have context relating to a submitted report and will not unexpectedly request sensitive information.
Be particularly cautious of anyone promising to recover lost money in exchange for:
- An advance fee
- Remote access
- Cryptocurrency
- Gift cards
- Further bank transfers
Monitor Accounts After the Incident
For the following weeks and months:
- Review bank and card statements
- Enable transaction alerts
- Check email sign-in records
- Review password-reset messages
- Watch for unfamiliar purchases
- Check mobile-phone account changes
- Monitor credit accounts
- Investigate unexpected MFA prompts
- Review Microsoft, Google and Apple security alerts
- Check whether contacts receive unusual messages from you
Do not approve an authentication request you did not initiate.
A surprise MFA prompt can mean somebody already has the correct password and is attempting to complete the sign-in.
Common Mistakes to Avoid
Reconnecting the PC Too Soon
The remote software or malware may reconnect immediately.
Changing Passwords on the Compromised Computer
Monitoring software may capture the replacements.
Only Uninstalling the Remote Tool
The scammer may have created additional access or stolen account sessions.
Assuming a Clean Antivirus Scan Proves Nothing Was Taken
Security software may find malware, but it cannot determine every item the scammer viewed, copied or photographed.
Calling a Number in the Original Pop-Up
Use independently verified contact details.
Hiding the Incident From Your Employer
Delays can increase financial, security, legal and data-protection consequences.
Wiping a Business Computer Immediately
This can destroy evidence needed to establish what happened.
Restoring Every File and Program From the Old PC
You may restore malware or unsafe configuration.
Paying a “Recovery Expert” Who Contacts You Unexpectedly
This may be another stage of the original scam.
An Immediate Remote-Access Scam Checklist
When you realise a scammer had remote control:
- End the telephone call.
- Disconnect the PC from Wi-Fi and Ethernet.
- Do not use it for email, banking or password changes.
- Contact the bank immediately when financial access is possible.
- Call 159 where appropriate.
- Freeze cards and suspicious payments.
- Use a safe device to secure your email.
- Change reused passwords.
- Enable MFA or passkeys.
- Sign out other account sessions.
- Remove unfamiliar recovery methods.
- Record the incident timeline.
- Preserve messages, receipts and remote-session details.
- Notify your employer or IT provider.
- Identify the installed remote-access software.
- Check for unattended access.
- Review Windows accounts, startup items and browser extensions.
- Run full and offline security scans.
- Decide whether Windows should be wiped and reinstalled.
- Restore only from a known-good backup.
- Review business cloud and email logs.
- Assess whether personal data was exposed.
- Report to the ICO within 72 hours when legally required.
- Report the fraud to Report Fraud or Police Scotland.
- Warn contacts who may receive fraudulent messages.
- Monitor financial and online accounts for further activity.
How Hamilton Group Can Help
Giving a scammer remote access should be treated as a potential security incident—not merely an unwanted application installation.
Hamilton Group’s experienced IT team can help determine what happened, contain the incident and return the device or business environment to a trusted state.
Immediate Containment
We can help you:
- Disconnect the affected device safely
- Stop further remote access
- Identify affected users and systems
- Protect other devices on the network
- Preserve evidence where required
Remote-Access and Malware Investigation
Hamilton Group can review:
- Installed applications
- Remote-support configuration
- Unattended-access settings
- Windows accounts
- Services and scheduled tasks
- Browser extensions
- Startup items
- Malware detections
- Security logs
Account and Microsoft 365 Protection
For business customers, we can:
- Reset compromised credentials
- Revoke active sessions
- Review MFA methods
- Check mailbox forwarding and rules
- Examine cloud sign-in logs
- Investigate SharePoint and OneDrive access
- Remove unauthorised application consent
- Monitor for continuing activity
Secure Device Recovery
Depending on the risk, Hamilton Group can:
- Perform controlled malware removal
- Reset Windows
- Complete a clean installation
- Restore verified business data
- Reinstall trusted applications
- Update Windows and drivers
- Confirm endpoint protection is working
Data-Breach and Incident Support
We can help businesses establish:
- What information was accessible
- Which users and customers may be affected
- Whether specialist legal or data-protection advice is needed
- What evidence should be preserved
- Whether regulatory or contractual notifications may apply
- What improvements will prevent a repeat incident
Hamilton Group aims to make first contact on IT support requests within 15 minutes, helping businesses act while there is still an opportunity to limit damage.
Disconnect, Protect and Rebuild Trust
Once a scammer has controlled your computer, simply closing the remote-support window is not enough.
Disconnect the affected PC, protect your money and secure your email and other accounts from a different trusted device. Then have the computer professionally assessed and be prepared to reinstall Windows when the scammer had meaningful administrative access.
The objective is not only to make the computer appear normal again.
It is to establish that the scammer can no longer access your device, accounts, money or business data.
Call 0330 043 0069, book a meeting with one of our experts or visit hgmssp.com for urgent assistance after remote-access scams, account compromise and cyber incidents.