What to Do After a Computer Scam and Remote-Access Attack
Question details
The user needs to know how to secure their computer, online accounts, and personal data after falling victim to a tech support scam involving unauthorized remote access.

- Product
- Computer Security
- Device & OS
- not provided
- Scenario
- A fraudulent caller gained remote access to the user's computer under the guise of providing fake Microsoft 365 or firewall support.
- Observed behavior
- The computer and associated online accounts are now potentially compromised, putting the user's passwords, payment information, and personal data at risk of theft.
Immediately disconnect your compromised computer from the internet by unplugging the Ethernet cable or turning off Wi-Fi to prevent scammers from maintaining access or stealing additional data.
Secure Your Accounts and Financial Information
Take immediate action on a separate, uncompromised device to lock scammers out of your digital life and protect your finances.
Since the scammers had remote access to your primary computer, you must assume that all passwords, auto-fill data, and saved banking details have been compromised. Do not use the infected computer to change your passwords.
Grab a smartphone, tablet, or a different uncompromised computer to perform all security updates.
Immediately change the passwords for your email, banking, social media, and primary Microsoft or Apple accounts.
Turn on two-factor authentication (2FA) or MFA for your sensitive accounts to require an extra security code before logging in.
Call your bank and credit card providers using the phone numbers on the back of your cards. Inform them of the fraud so they can freeze your accounts or issue new cards.

Clean and Restore Your Compromised Computer
Remove the malicious tools the scammers installed and ensure your operating system is safe to use again.
Verify and Install Legitimate Antivirus Software
Ensure your computer is protected by legitimate security software, especially if it was recently purchased without an active antivirus.
Switch to WPS Office for a Secure and Lightweight Alternative
If you fell victim to a fake Microsoft 365 support scam, you might be looking for a simpler, safer alternative. WPS Office offers a free, lightweight, and highly secure environment to handle all your documents without the risk of confusing subscription traps or unsolicited support calls.
- 1. Download WPS Office: Navigate to the official WPS website on your clean computer and download the secure installation file.
- 2. Install the software: Run the setup wizard and follow the standard instructions to easily install the suite.
- 3. Open existing files natively: Launch WPS Office and instantly open your existing Word, Excel, and PowerPoint documents without losing any formatting.

Frequently Asked Questions
How can I tell if a tech support alert or call is a scam?
Legitimate tech companies like Microsoft or Apple will never proactively call you to warn you of a computer problem. Any unsolicited call, alarming pop-up message on your screen with a phone number, or request to pay for support via gift cards or wire transfers is a scam.
Is it safe to use my computer after a scammer had remote access?
It is not safe until the computer has been completely cleaned. You should disconnect it from the internet, remove all remote-access software, and run a thorough offline malware scan. If in doubt, back up your files and perform a factory reset.
What should I do if I logged into my bank account while the scammer had access?
Call your bank immediately using the official number on the back of your debit or credit card. Inform them that your computer was compromised while you were logged in, ask them to monitor for fraudulent transactions, and reset your online banking passwords from a different device.
Can I rely solely on Microsoft Defender for my computer security?
Yes, for most users, the built-in Microsoft Defender provides strong, real-time protection against malware and viruses. However, no antivirus can stop you from voluntarily giving a scammer remote access, which is why recognizing social engineering tactics is just as important as software security.




