What to Do After a Remote Access Scam

If a stranger controlled your computer through a support app, focus on containing access, protecting important accounts, checking the device, and limiting payment or identity harm.

Illustrated laptop with a disconnected remote-access link and a protective shield

Quick answer

If the remote session may still be open

  1. Disconnect the computer from Wi-Fi or Ethernet and end the remote-control session.
  2. From a different, trusted device, change passwords for email, banking, and any account used or displayed during the session.
  3. Remove unneeded remote-access software, update security software, and run a full scan.
  4. Contact your bank or payment provider using an official number if you paid or exposed financial information.
  5. Preserve evidence and report the incident to the FTC.

A remote-access tool is not automatically malicious. IT teams and people helping relatives use legitimate tools every day. The risk is that the same software can let a scammer view the screen, type, transfer files, or return later if unattended access was enabled. CISA specifically warns that threat actors can co-opt remote-access software to reach victim systems. Your response should therefore address both the device and anything the scammer may have seen or used.

1. Contain the remote connection

If someone is still controlling the pointer or typing, stop the connection before investigating.

  • Disconnect the computer from the internet. Turn off Wi-Fi and unplug Ethernet. If you cannot do that quickly, power the computer down.
  • End the session. Close the remote-support app if you can do so safely. Do not follow the caller's instructions or reconnect for a supposed refund or cleanup.
  • Use another trusted device for recovery. A phone, tablet, or computer that was not part of the session is a safer place to change passwords and contact providers.

Do not rush to delete messages or receipts. Preserve them before cleanup because they can help a bank, platform, or investigator understand what happened.

2. Secure accounts from a trusted device

Prioritize accounts that can unlock other accounts or move money.

  1. Email first: change its password, review recovery addresses and phone numbers, sign out unfamiliar sessions, and inspect forwarding rules. Follow the full email security checklist.
  2. Password manager and primary sign-in accounts: change the master or account password if it was typed, displayed, or stored on the affected computer.
  3. Banking and payment accounts: use the institution's official app, bookmarked site, statement, or card number—not a link or number supplied by the caller.
  4. Other exposed accounts: replace reused passwords with unique ones and enable a passkey, authenticator app, or security key where available.

Changing a password is not enough if an intruder added a recovery method, created an app password, or left an active session. Review those settings too. The site's broader account security guide explains the control points to check.

3. Remove unneeded remote software and check the device

The FTC advises people who gave a scammer remote access to update security software, run a scan, and delete anything the scan identifies as a problem.

  • Write down the name of the remote-access program before removing it.
  • Uninstall remote-control software you do not knowingly need. If it is a legitimate work tool, contact your organization's real IT team before removing or changing it.
  • Check installed apps, browser extensions, startup items, and user accounts for additions you do not recognize.
  • Install operating-system, browser, and security updates, then run a full scan with trusted security software.
  • If warnings, unknown accounts, or remote access return, keep the device offline and seek help from a reputable local technician or the device maker through a contact route you find independently.

A factory reset is not the automatic first step. It may be appropriate when malicious persistence is confirmed or you cannot regain confidence in the system, but backup and recovery choices depend on the device and what was changed.

4. Protect money and personal information

What you do next depends on what the scammer obtained.

If this happenedRespond this way
You paid by card, bank transfer, payment app, gift card, or cryptocurrencyContact the card issuer, bank, app, gift-card company, or exchange immediately through an official channel. Ask whether the transfer can be reversed or the account protected. The FTC's payment-specific recovery guide explains the available route for each payment type.
Banking was open or credentials were enteredTell the financial institution that a scammer remotely accessed the device. Change credentials, review transactions and payees, and follow the institution's fraud instructions.
A Social Security number or other identity data was exposedUse IdentityTheft.gov for a situation-specific recovery plan. Consider a credit freeze when the exposed information could support new-account fraud.
Files or photos may have been copiedDocument what was accessible and watch for follow-up extortion or impersonation. Do not pay a new demand solely because the caller claims to have copied files.

Review relevant statements and alerts, but do not assume that monitoring alone prevents misuse. If you later receive a breach or exposure notice, match the response to the data involved using the data breach response guide.

5. Preserve evidence and report the scam

Keep a short incident record before details disappear:

  • the caller's phone number, email address, website, and claimed company;
  • the remote-access app and any session or support ID;
  • screenshots, messages, receipts, transaction IDs, and the time of the session;
  • accounts that were open, passwords entered, and files that may have been visible.

Report the tech support scam at ReportFraud.ftc.gov. If someone used your personal information, IdentityTheft.gov can generate a recovery plan and an FTC Identity Theft Report. Also report fraudulent transactions directly to the company that moved or received the money.

6. Reduce the chance of a repeat

  • Treat unsolicited support contact as unverified. The FTC says legitimate technology companies will not call, email, or text to say there is a problem with your computer.
  • Do not call a number in a pop-up. Real security warnings do not ask you to call a phone number for help, according to the FTC.
  • Find support independently. Type the vendor's known address yourself or use contact information in the product or account.
  • Remove unattended access you do not need. If you keep a remote tool, update it and review its sign-in and access settings.
  • Expect a second approach. A caller who promises a refund, recovery, or investigation may be the same scammer or someone using the leaked details.

For a general method to slow down urgent requests and verify who is contacting you, use the scam prevention guide.

Common questions

Can the scammer return after I close the app?

Possibly. Some tools can be configured for unattended access. Disconnect the device, remove unneeded remote software, review installed apps and accounts, update the system, and scan it before treating the incident as contained.

Should I change every password?

Start with email, financial, password-manager, and primary sign-in accounts. Change any password entered, displayed, stored in a browser, or reused elsewhere. Use a trusted device and review sessions and recovery settings as well as the password.

Do I need to wipe the computer?

Not automatically. A full reset may be warranted if malicious access persists or a qualified technician cannot establish confidence in the system. Keep it offline while you decide, and make sure backups do not reintroduce suspicious software.

What if I already paid?

Contact the payment provider immediately using a verified number or app. The possible remedy depends on how you paid, so use the FTC's payment-specific instructions rather than paying anyone who promises recovery.

Authoritative sources

Source note: This guide summarizes public consumer and cybersecurity guidance available on September 14, 2026. Product menus and recovery options change, so confirm steps through the official provider for your device, account, or payment method.