I let fake tech support remote into my computer, what should I do now?
Last reviewed: 2026-08-01 · Checked with Hunch’s on-device engine, the same one inside the extension. How Hunch checks →
Part of our guide: What to do if you got scammed →
Disconnect that computer from the internet right away, while they had remote access they could install spyware, open your banking, or copy passwords. Genuine companies like Microsoft or Apple never cold-call about a virus or ask to remote in; the pop-up or caller pushing a lookalike host like microsoft-techsupport-secure.example is the scam. Get offline, remove the remote tool, and change passwords from a different, clean device.
Got a message like this? Paste it here →
Tech-support scams target people who worry a pop-up or call means their computer is truly infected, and they lean hardest on older and less technical users. They work because the "technician" sounds authoritative, manufactures panic about stolen data, and uses remote access to both steal and stage a fake problem they'll charge to fix.
Illustrative example of the pattern, not a real message someone received.
How to verify it yourself
- Unplug the network or turn off Wi-Fi so the attacker loses live access immediately.
- Uninstall any remote-access app they had you add, AnyDesk, TeamViewer, or a tool from that .top site.
- From a separate trusted device, change passwords for banking, email, and anything you logged into during the session.
- Run a full malware scan and check for new admin accounts or startup programs before trusting the machine again.
Common questions
Did they steal my banking details?
Assume they saw whatever was open or typed during the session. Call your bank on its official number, watch for unauthorized transactions, and change your banking password from a clean device.
Do I need to wipe my computer?
To be safe, a clean reinstall is best, but at minimum remove the remote tool, run a reputable malware scan, and check for unfamiliar accounts and startup entries.
I paid them, can I get it back?
If you paid by card, dispute it with your bank immediately; gift cards and wire transfers are harder but still worth reporting fast to the FTC and the payment provider.
What if they left something hidden behind?
That's the real risk. Look for new user accounts, changed passwords, and auto-start programs, and reset any credential you entered while they were connected.
If you already responded
- Disconnect the computer from the internet to cut off live remote access.
- Uninstall the remote-access software and any program the caller had you install.
- From a different, trusted device, change passwords for banking, email, and key accounts, and enable two-factor authentication.
- Call your bank on its official number to watch for or reverse fraudulent charges, then run a full malware scan or reinstall.
- Report it at reportfraud.ftc.gov, and remember no legitimate recovery service cold-calls you or charges a fee to undo the damage.
If you were already hit, expect a follow-up
One more thing to expect: after a scam, your details often land on lists that get reused, so you may be contacted again, sometimes by people posing as investigators, your bank's "fraud team," or "recovery agents" who promise to get your money back for an upfront fee. That follow-up is a second scam. No legitimate service charges a fee to recover funds.
Source: FTC, How to Spot, Avoid, and Report Tech Support Scams