You let someone remote into your computer and now you're not sure: the recovery checklist
The call sounded official: your internet provider, a big software company, your bank's fraud team, or a refund you were told you were owed. You installed a small program or read out a code, and for a while a stranger had remote access to your screen and keyboard. Now you've hung up with a bad feeling. This is the calm order to shut a remote access scam down and limit the damage. Work on the assumption that they saw and could do more than they showed you on screen, then go down the list. Most of this takes minutes, and doing it in order matters.
Last reviewed: 22 July 2026
First, cut their access
Disconnect the computer from the internet right now. Unplug the network cable, or turn off the Wi-Fi. That ends any live session immediately: while it's offline, no one on the other end can touch it. You don't need to throw the machine out the window; you just need it off the network.
Change the passwords that matter, from a different device
Not on the computer they touched. Use your phone on mobile data, or another computer you trust.
Change your email password first, because it's the account that can reset all the others, then your banking, then anything you signed into during or around the call. Make each new password unique, and turn on (or re-check) two-factor authentication while you're there. If the attacker has already locked you out of your inbox, our hacked email recovery help walks through getting it back.
If money was involved, call your bank now
Some tells that the call was really about money: they "accidentally refunded too much" and asked you to send the difference back, asked you to buy gift cards, had you log in to online banking while they watched, or shuffled money between your own accounts to make a balance look wrong. All of these are scripts.
Ring your bank on the number printed on your card, not a number they gave you, and not one from a text. They can freeze the account and try to stop or reverse a payment if you move quickly. If any banking happened during that call, this is the most time-critical step on the page. A standing hold on banking resets is exactly what our protect your money approach is built for, so the next attempt has a window to be caught.
Deal with the computer itself
Uninstall the remote-access tool they had you install. The common ones are ordinary, legitimate programs, the sort technicians use every day, that were misused here. Removing the app is the obvious first move, but assume more than that was set up.
The honest position: a computer that a stranger had full control of shouldn't be trusted for banking again until it has been properly checked, or wiped and set up fresh. Get it looked at by a technician. Until then, do your sensitive logins on a different device.
Check for the quiet leftovers
While a stranger had control, they may have changed things you can't see. On your email, look for mail forwarding you didn't set up, filter rules that hide security messages, and a recovery email or phone that's been swapped. Review the apps and devices connected to your account and remove anything you don't recognise. Then check recent login activity for sign-ins that aren't yours. Our guide to how an account takeover really unfolds shows exactly where these hidden rules and forwarding settings live, so you know what to look for.
Expect the second call
These scams often come back. A different "helper" rings a few days later offering to recover the money you lost, and it's usually the same crew having another go at someone they've marked as a target. Treat any call, text or pop-up that follows this as suspect. You decide who you contact, using numbers you look up yourself, not numbers that come to you.
Report it (Australia)
Getting yourself safe and reporting the crime are two different jobs, so do both. If money moved, your bank comes first; the reports help you and help the next person.
- Scamwatch: report the scam so it's tracked. Its guidance on impersonation and phishing calls covers exactly this kind of approach. Run by the National Anti-Scam Centre.
- ReportCyber at cyber.gov.au: the national police-referral tool for cybercrime, run by the Australian Signals Directorate's ACSC. Use this especially if money was involved or a business device was hit.
- IDCARE (1800 595 160): Australia and New Zealand's free identity and cyber support service, if you're worried your identity has been misused.
The short version: disconnect the computer from the internet to end their access, then from a different device change your email password first, then banking, then anything else you logged into. If any money or banking was involved, call your bank on the number from your card straight away. Remove the remote-access software but treat the machine as untrusted until it's checked, audit your email for hidden forwarding and rules, ignore the inevitable "we can recover your money" follow-up call, and report it to IDCARE, Scamwatch and ReportCyber.
General guidance only. safe2recover doesn't access your computer or recover funds. Your bank handles money already moved, a technician makes the machine safe to trust again, and IDCARE supports the identity side; this page is the order to work through.