You gave a scammer remote access to your computer: what to do now
You let a "tech support" or "refund" caller control your screen, and now you are afraid of what they saw or did. Don't panic — this is recoverable, and the steps are free. Here is exactly what to do, in order, to cut them off, clean your device, and protect your accounts and money.
A caller convinced you there was a problem — a virus, a refund, a charge you didn’t make — and talked you into letting them control your computer. Now the call is over and you’re left with the worst feeling: a stranger was inside your machine, and you don’t know what they saw, installed, or changed. Take a breath. This is recoverable, the steps are free, and the order below is what makes it work.
1. Cut the connection first
Before anything else, disconnect the device from the internet — turn off Wi-Fi or unplug the network cable. That immediately ends any live remote session, so they can no longer see or control the screen. Then close or uninstall the remote-access program they had you install (common names: AnyDesk, TeamViewer, or a generic “support” tool).
This is the step that actually stops the bleeding. Everything after it is cleanup.
2. Clean the device
A remote session can leave software behind, so clean the machine before you trust it again. The FTC says to “update your computer’s security software, run a scan, and delete anything it identifies as a problem.” Then restart the machine so the changes take effect. Until it’s clean, follow the FTC’s other rule: “stop shopping, banking, and entering passwords online” on that device.
If the computer is part of a home or office network, it’s worth checking the other devices on it too.
3. Change your passwords — from a different device
If they watched you log in anywhere, or if you handed over a username and password, treat those credentials as known. Using a different device you trust (your phone, another computer), change your passwords — starting with email and banking, the keys to everything else. The FTC’s guidance after malware is to “change the password you’ve been using for your bank accounts, your email accounts, and all your other important accounts.” If you reused a password anywhere, change it there too, and turn on two-factor authentication so a stolen password alone isn’t enough.
4. Protect your money
If your banking was open during the session, or you paid the “technician”:
- Call your bank and card companies on official numbers — the back of your card or your statement, never a number the caller gave you — explain what happened, and ask them to watch for or reverse unauthorized transfers.
- If you paid by gift card, follow the FTC’s advice: “Contact the company that issued the gift card. Tell them it was used in a scam and ask them to refund your money. Keep the gift card itself, and the gift card receipt.”
- If you paid by credit or debit card, call the issuer immediately and ask them to reverse the charge.
This is where the tech-support refund / overpayment trick usually plays out — knowing the pattern helps you tell the bank exactly what to look for.
5. Report it — and if your bank login was exposed, treat it as identity theft
Report the scam at ReportFraud.ftc.gov. If the scammer saw your bank credentials or personal details, assume that information is now out and follow the same playbook as any breach: this is a Freeze & Report moment. Consider a free credit freeze, and use the personalized recovery plan at IdentityTheft.gov.
The lures that lead here — a pop-up warning, a live “support” call, or a fake subscription-renewal invoice — all rely on the same move: getting you to grant access. Now you know the move, and the way out. For more, see the defense library or test your eye on the 60-second quiz.
- You installed software like AnyDesk, TeamViewer, or "support" tools so someone could see or control your screen.
- While connected, they opened your banking, asked you to log in, or showed you "proof" of a problem on your computer.
- They asked you not to move the mouse, not to hang up, or not to tell your bank what you were doing.
- Afterward you are unsure what they installed, saw, or changed — and whether your accounts are still safe.
- Disconnect the device from the internet now (turn off Wi-Fi or unplug it) to end the remote session.
- Clean the device: the FTC says to update your security software, run a scan, delete anything it flags, and restart. Until then, stop banking and entering passwords on it.
- Change passwords from a different, clean device — starting with email and banking — and turn on two-factor authentication. If you reused a password anywhere, change it there too.
- Protect your money: call your bank and card companies on official numbers, watch for unauthorized transfers, and if a gift card was involved, contact the company that issued it right away and ask them to refund it.
- Report it at ReportFraud.ftc.gov, and if your bank login was exposed, treat it as identity theft — freeze your credit and follow the recovery plan at IdentityTheft.gov.
The feeling people describe after this is a specific kind of dread — a stranger was inside their machine, and they don’t know what it means. So the first thing worth saying is that it is recoverable, and you don’t need to buy anything or call anyone’s ’support‘ line to fix it. The order is what matters: disconnect first so they’re out, then clean the device, then change passwords from a phone or another computer, then call your bank. The scam’s whole power was the live connection and your panic; the moment you pull the plug and work the list, you have it back.
Sources
Frequently asked
They had access for a few minutes. Is my computer ruined?
No — almost certainly not, and this is fixable for free. The risk from a short remote session is mostly two things: software they may have left behind, and information they may have seen. You address both directly. The FTC's guidance is to "update your computer's security software, run a scan, and delete anything it identifies as a problem." Then restart the machine so the changes take effect. Until the device is cleaned, the FTC says to "stop shopping, banking, and entering passwords online" on it. That handles the device; changing your passwords from a clean device handles the rest.
What's the very first thing I should do?
Cut the connection. Disconnect the computer from the internet — turn off Wi-Fi or unplug the network cable — which immediately ends any active remote session. Then close or uninstall the remote-access program they had you install (names like AnyDesk, TeamViewer, or a "support" app). Only after you're disconnected should you start cleaning the device and changing passwords, and do the password changes from a different device you know is safe.
They saw me log into my bank. What now?
Treat your bank credentials as compromised. Call your bank and card companies on a number you know is real — from the back of your card or your statement, not one the caller gave you — tell them what happened, and ask them to watch for or reverse unauthorized transfers. Change your banking password from a clean device and turn on two-factor authentication. Because your login was exposed, also handle it like identity theft: consider a free credit freeze and use the recovery plan at IdentityTheft.gov.
I paid them with a gift card or card. Can I get it back?
Maybe — if you act fast. The FTC's advice for gift-card payments: "Contact the company that issued the gift card. Tell them it was used in a scam and ask them to refund your money. Keep the gift card itself, and the gift card receipt." If you paid by credit or debit card, call your card company or bank immediately, explain it was a scam, and ask them to reverse the charge. Speed matters, so make these calls before anything else once your device is disconnected.