Account safety · International
Gave a scammer remote access? Secure the device before banking again
Disconnect the session, use a clean device for urgent calls and credentials, and check the wider account compromise.
By Stonebridge Resolution · Published 4 October 2026 · Updated 4 October 2026
AI-generated illustration; not a depiction of a real case.
The short answer
Disconnect the affected device from the internet and stop the remote session. Contact financial providers and change exposed credentials from a different, trusted device; closing the visible window may not remove all access.
Stop the live access
If someone is controlling your screen, disconnect the device from Wi-Fi or its network cable. Do not follow instructions to keep the session open so they can reverse an error or complete a refund.
Use another device or a trusted phone to contact your bank immediately if payments or account details were exposed. Explain that remote access was involved and ask about blocking transactions, account access and any compromised cards.
Protect email and financial accounts from a clean device
Secure your main email account because it can be used to reset other passwords. Change exposed or reused passwords, review recovery details, sign out unfamiliar sessions and enable stronger authentication where available.
Check financial accounts for new payees, scheduled transfers and changes to contact details. A password change may not remove every active session or third-party permission, so use the provider's full account-security process.
Have the affected device assessed
Uninstalling the named remote-access app may not address additional software or changes made during the session. Follow official operating-system security guidance and consider trusted professional help if you are unsure.
Do not use an unsolicited technician recommended by the caller. If a reset or reinstall is proposed, understand what data will be lost and preserve necessary documents safely. Device security and evidence preservation both matter.
Record what the attacker could see
Write down the remote tool's name, the session time, the caller's details and which accounts or documents were opened. Save payment records and communications from a safe environment.
If a wallet phrase, password manager or identity document was visible, treat that as a separate exposure requiring its own response. Do not assume the incident is limited to the payment you first noticed.
Expect follow-up impersonation
The next caller may claim to be the bank's fraud team or a recovery technician who knows details of the incident. Knowledge of your loss is not proof of legitimacy.
Call back using independently verified numbers. No refund should require you to log into banking while a stranger watches, reveal a one-time code or move money to a safety account.
Checklist
- Disconnect the affected device.
- Call financial providers from a trusted device.
- Secure email, credentials and sessions.
- Arrange trusted device assessment and document exposures.
Common questions
Is closing the remote-access window enough?
Not necessarily. Additional access or software may remain. Keep the device offline until it is assessed and secured.
Should I change passwords on the same computer?
Use a different trusted device while compromise is suspected, so replacement credentials are not exposed again.