All guides

Computer Repair

Someone remotely accessed my computer: what to do now

Do this first

Disconnect the affected computer. From a different trusted device, contact the bank or payment provider immediately if money is involved, then secure your most important accounts.

If a stranger controlled your screen, installed a remote-support app, saw an account, or talked you into a payment, act in the right order. Disconnect the affected computer, protect money and important accounts from a separate trusted device, preserve useful clues, and avoid rushed resets that destroy evidence.

A person disconnecting a home router after suspicious remote computer access

Guide updated

Start with simple checks. Get expert help when the fix needs more.

If access may still be active, disconnect the affected computer before using a separate trusted device for account and financial steps.

If the session just happened

Disconnect the affected computer. Use a different trusted device for money and accounts.

A calm sequence matters more than a rushed cleanup. If a financial transaction is happening now, contact the bank, card issuer, or payment provider immediately through a number or app you independently verify. Tech Genie cannot stop or reverse a payment.

  1. Step 1

    End the connection

    Close the remote-support session if you can do so safely, then disconnect only the affected computer from Wi‑Fi or Ethernet. Do not reconnect it to change passwords or check banking.

  2. Step 2

    Protect money from a trusted device

    If banking, cards, payment apps, gift cards, wire transfers, or cryptocurrency were involved, use a different trusted phone or computer to contact the provider through an official number or app.

  3. Step 3

    Secure the accounts that unlock everything else

    From that trusted device, start with primary email and any password manager, then financial and other important accounts. Change reused passwords, review recovery methods, and revoke unfamiliar sessions.

  4. Step 4

    Preserve a simple timeline

    Write down when it happened, how contact began, the remote app used, what was opened, and how payment happened. Save only useful evidence that does not expose more private information.

Triage by exposure

The next step depends on what the person could reach.

Device cleanup is only one part of the response. Financial, identity, account, and business incidents need the appropriate provider, and those actions should not wait for a computer appointment.

Device cleanup path

They controlled the screen, but no account or payment was opened

Keep the computer offline, preserve the basic timeline, and plan a device review before normal use.

Account provider first

A password was typed, saved passwords were visible, or an MFA prompt was approved

Use a trusted device to change the affected credentials, sign out other sessions, and check recovery email, phone, forwarding, and connected-app settings.

Financial provider first

Money, cards, banking, gift cards, a wire, payment app, or cryptocurrency was involved

Contact the bank, card issuer, transfer service, or payment provider immediately through a verified channel. Ask about stopping or disputing the transaction.

Identity recovery path

A Social Security number, driver license, tax form, or other identity document was shared

Use IdentityTheft.gov to build a recovery plan and follow its current instructions for fraud alerts, credit freezes, reports, and affected accounts.

Business incident escalation

The computer belongs to a business or may contain regulated, legal, health, financial, or client data

Stop ordinary cleanup. Notify the authorized owner and the organization’s IT, insurer, legal counsel, or incident-response provider so evidence and reporting duties are not accidentally destroyed.

Preserve useful clues

Keep a small, safe evidence packet.

You do not need to investigate the computer yourself. A short timeline and existing records are usually more useful than hours of clicking through the affected machine.

  • A short written timeline with approximate times and what happened in order
  • The caller’s number, email, text, website address, and the name they claimed to use
  • The remote-access app name and any session or receipt number that is already visible
  • Payment receipts, gift-card receipts, transfer confirmations, and provider case numbers
  • Photos or screenshots only after checking that they do not expose passwords, codes, account numbers, private messages, or personal documents

Stop the second exposure

Do not hand the next helper more secrets.

  • Do not keep talking to the caller, pay a second fee, or accept a promised refund.
  • Do not use the affected computer to log into email, banking, a password manager, or other important accounts.
  • Do not send Tech Genie passwords, MFA codes, recovery keys, card numbers, bank details, identity documents, or private-file contents.
  • Do not factory-reset, wipe, restore, or delete every remote tool before deciding whether evidence or a business escalation matters.
  • Do not assume that uninstalling one app or receiving one clean scan proves what the person saw, copied, changed, or retained.

Use a clean, trusted device

Secure accounts in the order they can unlock other accounts.

Use unique passwords, sign out unfamiliar sessions, and enable MFA where the provider supports it. Keep every password, MFA code, recovery key, and identity document under the owner's control.

  1. Priority 1

    Primary email

    Change the password, revoke unfamiliar sessions and connected apps, and inspect recovery methods, forwarding rules, filters, delegates, and sent/deleted mail.

  2. Priority 2

    Banking and payments

    Use official apps, the number on the back of the card, or a number independently found on the provider’s site. Review transactions and follow the provider’s fraud instructions.

  3. Priority 3

    Password manager and saved-browser accounts

    Protect the vault account, revoke unknown sessions, rotate exposed or reused passwords, and keep the new recovery information under the owner’s control.

  4. Priority 4

    Phone, cloud, shopping, tax, benefits, and social accounts

    Prioritize accounts that store payment methods, private documents, identity data, or can reset other accounts. Review sign-ins and recovery settings before normal use.

Device response

A scan is evidence, not a guarantee.

An ordinary cleanup cannot determine what a remote person viewed or copied or guarantee that a device is completely clean. Tech Genie can inspect common persistence points and document visible findings.

  1. 1. Scope before changing

    Record what is known, whether the device is personal or business-owned, what accounts were open, and whether files, payments, or identity information may be involved.

  2. 2. Inspect visible persistence

    Review remote-access software, startup entries and services, browser extensions and notifications, local user accounts, security settings, and other obvious changes within an approved scope.

  3. 3. Scan and update carefully

    Run supported security scans and updates after evidence and escalation needs are understood. Record findings, including when nothing obvious is found.

  4. 4. Choose the assurance level

    A focused cleanup may fit a lower-risk incident. A planned reset or clean reinstall can provide higher ordinary assurance, but it is destructive and still cannot reveal everything the remote person viewed or copied.

Know when normal repair stops

Some incidents need a bank, provider, law enforcement, insurer, attorney, or forensic specialist.

Escalate when substantial money is involved, identity theft is suspected, the device belongs to a business, legal evidence may matter, or regulated/client data may have been exposed. Tech Genie can help with device triage and documentation, but does not perform financial recovery, legal advice, law-enforcement investigation, or forensic certification.

Owner-controlled support

What a local visit can do.

Review visible device changes, run approved scans, document findings, explain cleanup versus reinstall options, and leave an action list. You type your own credentials and approve every meaningful or destructive change.

Calm containment, then a written handoff

Get the device reviewed without repeating the scammer's remote-access pattern.

On-site or phone-guided triage is usually safer after suspicious remote access. If remote help is considered later, the customer approves it explicitly and remains in control.

How Tech Genie helps

Solve the problem and make it easier next time.

Tech Genie identifies the cause, handles the agreed work, and explains what changed and what to do next.

Review known remote-access tools, startup behavior, browser changes, local accounts, Windows Security status, and other visible indicators within an approved scope.
Document what was checked, separate urgent account and financial actions from device cleanup, and explain when a reset, reinstall, backup review, or specialist escalation may be appropriate.
Keep credentials and private files under the owner's control while documenting the work completed. A standard cleanup visit is not a forensic investigation and cannot determine everything that was viewed, copied, or retained.

FAQ

Quick answers before booking.

What is the first thing to do after someone remotely accessed my computer?

End the remote session and disconnect the affected computer from Wi‑Fi or Ethernet. If money or an important account may be involved, use a separate trusted phone or device to contact the bank or provider and secure accounts. Do not use the affected computer for those steps.

Can a malware scan prove that the computer is completely safe?

No. A scan and inspection can find many known problems, but they cannot prove what a person viewed or copied or guarantee that every form of persistence is gone. Higher assurance may require a carefully planned reset or clean reinstall after backups and evidence needs are considered.

Should I factory-reset the computer immediately?

Not automatically. A reset can remove useful evidence and create data-loss or recovery problems. Disconnect first, protect money and accounts from a trusted device, preserve the basic timeline, then choose a cleanup or reinstall path with informed approval.

Keep troubleshooting