It's done. You hung up, or closed the window, and now you realize what just happened: you let a stranger remotely access your computer, believing they were a real technician from Microsoft, Apple, or your internet provider. Don't panic — but you do need to act now, in order, without wasting time.
This isn't an article about how to spot a scam — you're already past that point. This is a concrete recovery plan for people who already gave access, already paid, or already installed something a fake technician sent them. Each section answers one specific question: what might have been exposed, how to check it, and in what order to take back control.
If access is still active right now
If someone is still connected to your computer while you're reading this, stop reading and disconnect your ethernet cable or turn off Wi-Fi immediately. Then come back — the "Step 1" section below covers exactly what to do next.
How This Guide Is Different
If you're trying to learn how to recognize a scam before it happens — the fake popups, the alarm sounds, the fake "scans" — our guide Tech Support Scam Warning Signs covers exactly that: the 12 red flags, the classic script, and a side-by-side of a real remote session versus a scam session.
This article starts from a different point: the damage is already done. You called the number, or clicked the link, and a "technician" took control of your screen through AnyDesk, TeamViewer, or Windows Quick Assist. There's no "how to spot it" section here — just the concrete actions to take in the minutes, hours, and days that follow, to limit the damage, check what was actually touched, and get your accounts back under your own control.
This isn't about being "gullible"
Tech support scams are run by professional call centers using scripts refined over thousands of calls. They target completely normal human responses — trust in an authority figure, panic in the face of a perceived emergency, the social pressure that makes it hard to just hang up. This didn't happen to you because you're "bad with computers." Focus now on recovery, not on self-blame.
Priority Table: Immediate Actions by Urgency
Depending on exactly what happened, some actions are far more urgent than others. Use this table to figure out where to start:
| What Happened | Urgency | Immediate Action |
|---|---|---|
| Remote access is still active | 🔴 Critical — right now | Disconnect the internet, force-close the software via Task Manager |
| Gave a credit/debit card number | 🔴 Critical — within the hour | Call your bank's fraud line to block the card |
| Paid by gift card or wire transfer | 🔴 Critical — within the hour | Call the retailer and your bank immediately |
| Remote access given but session ended | 🟠 Urgent — today | Change all passwords from a different device |
| Downloaded or installed software | 🟠 Urgent — today | Full malware scan, avoid transactions on that device |
| Saved passwords were visible on screen | 🟠 Urgent — 24-48h | Change email, banking, and any important accounts |
| Only called, never gave access | 🟢 Precaution | Block the number, report to the Anti-Fraud Centre |
Step by Step: The Full Recovery Plan
Work through these in order. Don't skip a step even if it feels like it's already covered.
Disconnect the internet immediately
If you suspect access might still be active, unplug the ethernet cable or turn off Wi-Fi (bottom-right icon on Windows, top-right on Mac). This instantly cuts any remote connection, even before you've closed the software itself.
Force-close the remote access software
Open Task Manager (Ctrl+Shift+Esc on Windows, or Activity Monitor on Mac) and end any AnyDesk, TeamViewer, or Quick Assist process. Then uninstall the software entirely from Settings — a simple restart isn't always enough.
Avoid any transactions on that computer for now
Until you've confirmed the computer is clean, avoid logging into your bank, email, or any sensitive account from that device. Use your phone or another computer for the steps below.
Change your passwords from a clean device
From your phone or another untouched computer, immediately change your primary email password first (it's the most important account — it can reset everything else), then your online banking, then any other important account (Facebook, iCloud, Microsoft).
Turn on two-factor authentication (2FA)
On your email and banking accounts, turn on two-step verification if it isn't already active. Even if the scammer has your password, a second factor (a text code or an authenticator app) blocks an unauthorized login.
Call your financial institution
If you gave a credit or debit card number, or the scammer saw your online banking session, call the fraud number on the back of your card right away. Ask for a preventive block and transaction monitoring.
If you paid by gift card or wire transfer
Call the gift card retailer's customer service line immediately (Google Play, Amazon, Apple) — some can freeze the balance if you report it within hours of purchase. For an e-transfer or wire, contact your bank without delay; recovery odds drop fast with time.
Check for new user accounts
In Windows, go to Settings > Accounts > Other users and confirm you recognize every account listed. Scammers sometimes create a hidden admin account for later access.
Review installed programs
Look through your list of installed applications (Settings > Apps) for anything you don't recognize, particularly other remote access tools you didn't install yourself.
Run a full malware scan
Open Windows Defender ("Windows Security" in the Start menu) and run a full system scan, not just a quick scan. It can take 30 to 60 minutes but it's necessary to catch malware left running in the background.
Report the incident to the right authorities
Contact the Canadian Anti-Fraud Centre at 1-888-495-8501 or online at antifraudcentre-centreantifraude.ca. In the US, report to the FTC at reportfraud.ftc.gov. Also file a report with your local police — some banks require a police report number to process a fraud claim.
Have a professional confirm the system is clean
Even after all these steps, it's hard to know for certain whether persistent access or quiet spyware was installed. A technician can review system logs, scheduled tasks, and network connections to confirm the computer is genuinely secure.
Recovery Checklist — print or copy this list
Not sure everything is actually clean?
Our certified bilingual technician connects remotely (a real session, initiated by you), checks system logs, new accounts, and installed software — same-day, from $119.99. No fee if not resolved.
How to Know If Your Data Was Actually Stolen
This is the question almost everyone asks afterward, and the honest answer is: you can't know for certain without a technical inspection. Here are the signals worth checking yourself in the meantime:
- Unexpected "new sign-in" emails. Gmail, Outlook, and most services send an alert when a new device signs in. Check your email folder and your account's login history.
- Unfamiliar bank transactions. Even small amounts (often a test before a bigger withdrawal) should be reported immediately.
- Password changes you didn't make. If you're locked out of an account, that's a strong sign someone else already changed it.
- New devices listed on your accounts. Google, Apple, and Facebook let you see connected devices — check that no unfamiliar device appears there.
- Slowdowns or odd computer behavior. A fan running for no reason, a cursor moving on its own, programs opening without you touching anything.
- Antivirus disabled without you doing it. Scammers sometimes disable Windows Defender during the session to make installing malware easier.
If you notice even one of these signs, treat it as if your data was potentially exposed and act accordingly — change your passwords everywhere, not just on the affected account. For a broader diagnostic of your computer's health, also see our guide Is My Computer Hacked? 15 Warning Signs, useful for checking whether signs persist even weeks after the incident.
3 Real-World Scenarios (Composite Canadian Cases)
These three scenarios are inspired by typical cases our technicians encounter — the names are fictional, but the situations are representative.
Case 1 — Barbara, 74, Ottawa
Barbara received a call from a man claiming to be a "Microsoft technician," saying her computer was sending out security alerts. Frightened, she installed AnyDesk and let the man browse her computer for about 20 minutes while he "cleaned viruses," then asked for $350 payable in iTunes gift cards. She hung up just before reading out the card numbers. After following the plan above — disconnecting the internet, uninstalling AnyDesk, changing passwords with her son's help — an IT Cares technician confirmed no hidden account had been created, but found a keylogger had been installed. Full cleanup completed the same day. Cost: $119.99.
Case 2 — Daniel, small business owner, Winnipeg
A popup locked his desktop screen while he was processing online orders. He called the number shown, granted remote access, and provided his business credit card number for an "annual protection package" costing $499 USD. Realizing the scam the next day, he immediately contacted his bank (the charge was successfully disputed) and IT Cares for a full inspection, since the computer stored customer data. The inspection revealed the spyware had reached the shared office network — a router password reset and a cleanup of three workstations were required.
Case 3 — The Chen family, Calgary
Their 15-year-old believed a "Apple Security" popup on the family iPad was real and followed instructions to install a remote configuration profile. No payment was made, but the profile granted partial access to device settings. The parents removed the configuration profile in Settings, changed the whole family's Apple ID credentials, and reported the call to the Canadian Anti-Fraud Centre. No paid inspection was needed in this case — an example where acting fast, before any transaction occurred, kept the damage to a minimum.
What these three cases have in common
In all three situations, how quickly the family acted after realizing it was a scam made the biggest difference — whether that meant disputing a transaction, catching spyware before it caused more damage, or simply cutting off access before it could be used.
Common Mistakes to Avoid After the Incident
Beyond the steps to follow, here are the most common mistakes our technicians see people make right after a tech support scam — reactions that feel logical in the moment but can complicate recovery or hide a real problem.
- Reinstalling Windows immediately without checking anything first. A full reinstall might feel like the fastest fix, but it also wipes the system logs that would let a technician confirm exactly what the scammer did or didn't do. If you suspect sensitive data was viewed, an inspection before reinstalling can matter, especially if you need to document the incident's scope for insurance or an employer.
- Reusing a slight variation of the same password. Changing "House2024" to "House2025" offers almost no real protection if the original password was compromised. Use a genuinely different password, ideally generated and stored by a password manager.
- Ignoring small unfamiliar charges on your statement. Fraudsters often test a stolen card with a $1–$5 charge before attempting a larger one days later. A small unrecognized charge is never trivial — report it immediately even if it looks insignificant.
- Reconnecting the computer to a shared network before checking it. If the incident happened on a device connected to a shared network (office or family), reconnecting it before a full scan can expose other devices on the same network. Isolate the affected computer first.
- Feeling too embarrassed to report it. Many victims hesitate to contact the Anti-Fraud Centre or police out of embarrassment. These organizations handle thousands of similar cases every year — reporting the incident doesn't just help your own case, it also helps trace larger fraud networks affecting other victims.
- Assuming one password change is enough. If the scammer watched your screen for several minutes, they may have had access to more than one account open in your browser. Review every tab and app that was open during the session, not just the main account you remember.
Budget: What Recovery Inspection Actually Costs (CAD)
Here's a realistic breakdown of costs in Canada for the services most commonly needed after a tech support scam:
| Service | Approx. Cost (CAD) | When It's Needed |
|---|---|---|
| Remote inspection / full scan | $119.99 – $149.99 | Remote access given, even without payment |
| Spyware / malware removal | Included in inspection, or +$50-80 if complex | Something detected during the scan |
| Full system reinstall (with backup) | $150 – $250 | Extended access, lingering doubt about system cleanliness |
| Network / router security (business) | $75 – $150 | Computer connected to a shared office network |
| Credit monitoring (self sign-up) | Often free (Equifax/TransUnion) | Personal information potentially exposed |
| Anti-Fraud Centre / police report | Free | Any case where a payment occurred |
Most financial institutions charge nothing to dispute a fraudulent transaction or block a card — never hesitate to call out of fear of fees.
Government Resources and Who to Contact
- Canadian Anti-Fraud Centre: 1-888-495-8501 or antifraudcentre-centreantifraude.ca — official fraud reporting in Canada.
- FTC (United States): reportfraud.ftc.gov — official fraud reporting for US residents.
- Your local police service: for an official report, often required by banks to process a claim.
- Office of the Privacy Commissioner of Canada: if sensitive personal information was exposed.
- Equifax Canada and TransUnion Canada: to place a free fraud alert on your credit file if your personal information may have been compromised.
- Your financial institution: a 24/7 fraud line, usually printed on the back of your card.
Already Gave Access? We'll Confirm You're Clean.
Our technicians inspect your computer from top to bottom, remove any software the scammer installed, check for new accounts, and secure your logins. Transparent diagnostic, flat rate disclosed before we connect anything.
Frequently Asked Questions
Not necessarily, but you should act as if it's possible. A scammer with remote access can see your files, browser-saved passwords, and any accounts left open on screen. The only way to know for certain what was viewed or installed is a technical inspection — checking system logs, new accounts, and installed software from the session.
Check your installed programs list (Settings > Apps) for anything you don't recognize, especially other remote access tools you didn't install yourself. A technician can also review Windows event logs and scheduled tasks for signs of persistent access, which is difficult to confirm with total certainty on your own.
Not always, but it's recommended if the scammer had extended access, you suspect persistent spyware, or you can't confirm with certainty the system is clean. A full reinstall (after backing up personal files, scanned first) removes any doubt entirely. IT Cares can perform this remotely while preserving your data.
It depends on how you paid. Credit card charges can often be disputed with your bank as fraud. Gift card payments can sometimes be frozen if you call the retailer within hours of purchase, but redeemed balances are usually unrecoverable. Wire transfers and cryptocurrency are the hardest to reverse and rarely recovered. Report the incident to your bank and the Canadian Anti-Fraud Centre (or the FTC in the US) as soon as possible in every case.
Disconnect from the internet immediately — unplug the ethernet cable or turn off Wi-Fi. This cuts their access instantly, faster than trying to close the remote software first. Once disconnected, open Task Manager and force-close AnyDesk, TeamViewer, or Quick Assist, then uninstall it before reconnecting to the internet.
Yes. Payment isn't the only risk — remote access alone lets a scammer view files, capture saved passwords, or install software during the session, even if no money changed hands. Treat any granted remote access as a security incident: change your passwords, run a malware scan, and consider a professional inspection regardless of whether you paid.
Comments (3)
Followed this checklist step by step after my dad fell for the fake Microsoft call. The "check for new user accounts" step actually found a hidden admin account we would have never noticed otherwise. Called IT Cares to be sure and they confirmed it was cleaned properly.
Disconnecting the internet first instead of panicking and trying to close the AnyDesk window was the right call — the scammer lost access instantly. Appreciated that this article didn't just repeat "how to spot a scam" articles, it actually told me what to do after.
Had already changed my passwords but wasn't sure if that was enough. IT Cares technician did a remote scan and found nothing malicious, which gave real peace of mind instead of just guessing. Worth the $119.99 to actually know for sure.
Leave a Comment