The short answer
Disconnect the device from the internet, then change your email and banking passwords from a different device you trust. Call your bank on a number you look up yourself, remove any remote-access software that was installed, and report the incident at reportfraud.ftc.gov and ic3.gov.
How does a tech support scam start?
Usually with something that looks like your own computer talking to you. A full-screen page appears, often with an alarm sound and a warning that your device is infected, your files are locked, or your bank credentials have been exposed. It tells you not to restart and gives a support number. None of it comes from your operating system; it is a web page designed to look like one.
The other common entry is a phone call or an email about a subscription. Your antivirus renewed for several hundred dollars. Your account was charged for software you never bought. The message includes a number to call to cancel, and calling is the point of the entire message.
Either way, the person who answers is friendly and technical. They ask you to install a support tool so they can "look at the problem." That tool is ordinary remote-access software, and the moment it connects, the other person can see and control everything on the screen.
What actually happens during the session?
The session is theater with a purpose. The caller opens system tools that always show alarming-looking entries — event logs full of routine warnings, lists of background processes, network connections that exist on every computer — and narrates them as evidence of an intrusion. Non-specialists cannot easily tell the difference, which is the whole reason those tools are chosen.
Then the ask arrives: a support plan, a security package, a one-time cleanup fee. Payment is requested in a form that resists reversal, and the caller often stays on the line while you arrange it. In some sessions nothing is charged at all, because the operator is quietly collecting saved passwords, reading email, or planting software that lets them return later.
The most damaging version comes later, as a refund. Weeks or months on, someone calls to say the company is closing and owes you money. They connect again, ask you to log into your bank, and manipulate what is on the screen so it appears that far too much was deposited. Then they ask you to return the difference, usually by wire, gift card, or cryptocurrency. Nothing was ever deposited; the balance display was edited or the money was moved between your own accounts.
What do you do in the first hour after access?
Work in this order. The point is to cut the connection first, then secure accounts from a device the intruder never touched.
- Disconnect the device from the internet — turn off Wi-Fi or unplug the cable. Do not simply close the window.
- Hang up. Do not explain, and do not answer when they call back.
- From a different device you trust, change the password on your primary email account first, then banking, then anything sharing that password.
- Turn on two-factor authentication on email and financial accounts.
- Call your bank on a number from your card or its website, say a stranger had access to your computer, and ask for the accounts to be reviewed and flagged.
- Uninstall the remote-access program that was installed, and check for accounts, scheduled tasks, or startup items you do not recognize.
If you cannot get to another device, use a phone on mobile data rather than the compromised network, and change the email password from there. What matters is that the keystrokes are not going through a machine someone else may still be watching. A password changed on the compromised computer can be captured as you type it.
Email comes first because it is the master key. Anyone holding your inbox can reset passwords everywhere else, so securing a bank account while leaving the email open accomplishes little. While you are in there, check for forwarding rules or filters that were added, since those quietly send copies of everything to someone else.
A one-time code sent by text or app exists to prove it is you. Anyone asking you to read one aloud, type it into a chat, or confirm it "for verification" is using it to take over an account. No genuine support employee needs it.
What if money already left an account?
Speed decides the outcome, and the payment method decides the ceiling. Card payments have a dispute route. Wires are recallable only while the funds sit in the receiving account, which is why the answer on the first hours after a fraudulent wire is a page of its own. Gift cards are occasionally frozen if you call the card brand fast with the receipts. Cryptocurrency sent to a private wallet is generally gone.
| Payment made | First call | What to ask for |
|---|---|---|
| Credit or debit card | Card issuer's fraud line | Dispute the charge and reissue the card |
| Bank wire | Your bank's fraud department | A wire recall request, in writing |
| Gift cards | The card brand's fraud line | Freeze on any unspent balance |
| Payment app | The app and your bank | Fraud claim and account review |
| Cryptocurrency | The exchange, then ic3.gov | Freeze if funds reached a US exchange |
If the "refund" version happened and money was moved between your own accounts to create the illusion of a deposit, tell the bank exactly that. The transfers will appear in the record, and showing that the deposit was internal is often what separates a resolved claim from a denied one.
How do you clean up the device afterward?
Assume the machine is untrustworthy until you have done something decisive about it. Uninstalling one program is the minimum, not the finish. Remote sessions frequently leave a second tool, a new user account, or a saved credential behind, and any of those restores access without a fresh phone call.
The thorough option is a reset from trusted installation media, then restoring documents from a backup made before the session. Short of that, uninstall the remote tool, scan with reputable security software, review browser extensions, remove unfamiliar accounts and startup entries, and clear saved passwords from the browser after changing them elsewhere. Then check your router's settings, because some sessions change its configuration.
Whatever route you take, do the work before you go back to using the machine for banking or email. The temptation is to run one scan, see nothing, and carry on. Scans miss legitimate remote-access software precisely because it is legitimate software, so the manual review of installed programs and accounts is the part that cannot be skipped.
Finally, warn the people in your contact list. Access to your inbox means access to your relationships, and the follow-up approach often arrives at friends and family as a message from you. That is also how many employment and payment schemes spread, a pattern covered in the answer on fraudulent job and task offers.
Where does this get reported?
Report to the FTC at reportfraud.ftc.gov and, where money was lost or your device was taken over, to the FBI at ic3.gov. Include the phone number you called, the name of the remote-access tool, the company name used, the amounts, and the payment method. Those details are the ones that connect your case to others.
Tell your bank in writing even if it already has your call on record, and keep the written response. If the bank denies the claim and you believe it mishandled something, a complaint to the Consumer Financial Protection Bureau puts the dispute in front of a regulator that requires an answer. The broader map of who handles what is in the answer on which agency takes which report.
Expect a follow-up call. Victim lists get resold, and the next voice claims to be from a refund department, a law enforcement recovery unit, or a company that can trace your payment for a fee. Every one of those is the second fraud described in the answer on offers to recover lost funds. Nobody legitimate calls out of the blue about money you already lost.
What to remember
- A pop-up that shows a phone number and blocks your screen is an advertisement, not a system message from your operating system.
- Once someone had remote control, assume every password typed on that device is known and change them from a different machine.
- The refund stage is where the real money moves, usually through a fake overpayment and a request that you send the difference back.
- Never let a caller open your online banking while connected, and never confirm a one-time code to anyone.
- Report the incident even if you paid nothing, because the phone numbers and software used repeat across thousands of cases.
Other questions people ask
Do I need to wipe the computer completely?
Not always, but it is the only way to be certain. A full reset from trusted installation media removes anything left behind. If a reset is impractical, at minimum uninstall the remote-access tool, run a scan with reputable security software, remove unfamiliar accounts and startup items, and change every password from a different device.
They say I owe them money for the work they did. Do I?
No. A session obtained by deception and used to cause the problem it claims to fix does not create a valid debt. Ignore invoices, block the numbers, and do not negotiate. If someone begins threatening you, keep the messages and report the harassment along with the underlying fraud.
Can I be liable if my computer was used to attack someone else?
Being the victim of an intrusion is not itself a crime, and ordinary users are not held responsible for what an intruder did through their machine. The practical risks are different: stored credentials, saved payment methods, and your contact list being used to approach the people who trust you. Warn your contacts and secure the accounts.
Where this comes from
- FTC Consumer Advice — ScamsHow tech support and refund approaches present.
- FTC — Report FraudFederal consumer complaint portal.
- FBI Internet Crime Complaint Center (IC3)Complaint route for computer intrusion and related losses.
- Cybersecurity and Infrastructure Security Agency (CISA)Federal guidance on securing accounts and devices.
- Consumer Financial Protection Bureau — Submit a ComplaintFor disputes over how a bank handled the transfers.
- USA.gov — Scams and FraudReporting routes in one place.
Clear Justice is a publication, not a law firm. Reading this creates no attorney–client relationship, and nothing here is advice about your situation. Rules change and many of them differ by state — check the official source above or speak to a licensed attorney before you act.