Scammed or hacked? What to do in the first hour

The order of operations after a remote-access scam, a hacked account, or a malware infection. What to do first, who to call, and how to get the written report your bank will ask for.

Last updated 2026-07-26 · 8 minute read · Applies to: Windows laptop, MacBook, iPhone, Samsung

If you have just given someone remote access to your computer: disconnect it from the internet, call your bank on the number on the back of your card, and change your passwords from a different device. Do those three things now, in that order. Everything else can wait an hour.

Remote-access scams are the most common serious incident we see at the Bendigo shop, and they overwhelmingly target people who did nothing careless. The caller was convincing, sounded official, and was very patient. There is no shame in it. What matters is the next hour.

This is the order we walk people through when they come in, and what to bring if you need a report for your bank or insurer.

1. Disconnect the device from the internet

Turn off Wi-Fi, or unplug the network cable. This ends any active remote session immediately, which stops anything still in progress. Don't shut the computer down if you can avoid it. Leaving it on preserves evidence of what was run, which matters if you need a report later. Just cut it off from the network and leave it alone.

2. Call your bank from a different phone

Use the number on the back of your card or from the bank's official app, never a number the caller gave you, and never a number from a search result you clicked during the incident. Tell them exactly what happened and ask them to freeze affected accounts and flag recent transactions. Australian banks have dedicated scam teams and the first hours are the ones where money can most often be stopped or recalled.

3. Change your passwords from a device that wasn't involved

Use your phone if the incident was on the computer, or a family member's computer if it was your phone. Start with your email, the master key that resets everything else, then banking, then anything sharing that password. Turn on two-factor authentication as you go. Do not change passwords on the affected device: if something is still logging keystrokes, you're just handing over the new ones.

4. Check what was actually installed

Remote-access scams almost always involve installing a legitimate remote tool: AnyDesk, TeamViewer, UltraViewer, and similar. That software is still there afterwards, and often set to start automatically and accept connections. Removing the obvious app is not the same as removing everything that was configured. This is the part worth having checked properly rather than guessing at.

5. Report it officially

Report to Scamwatch (scamwatch.gov.au) and, if money was lost or accounts were accessed, to ReportCyber (cyber.gov.au), the police reporting portal. You'll get a reference number. Insurers and banks frequently ask for it, and it's much easier to get on the day than three weeks later. If your identity documents were shared, contact IDCARE, Australia's free identity support service.

6. Get the device professionally cleaned and documented

Bring the device into the Bendigo shop and tell us it was a scam. That changes what we look for. We check for remote-access tools, scheduled tasks, browser extensions and stored credentials, not just viruses. Where a machine has been thoroughly compromised, a clean reinstall is the only honest answer, and we'll say so rather than charge you for a clean that won't hold. See virus and malware removal.

7. Ask for the written report

This is the step people miss. Banks and insurers frequently want a technician's written account of what was found on the device before they'll process a claim. We produce these regularly, a documented assessment of what was installed, what was accessed, and what was done to remediate it. Ask for it when you drop the device off, because it's far easier to document before the machine is cleaned than after.

Warning: Not Telstra, not the NBN, not Microsoft, not Apple, not your bank, not the ATO, and not the police. No exceptions. The caller ID showing a real company's number proves nothing, because numbers are trivially spoofed. If someone rings and wants onto your computer, hang up. If you're worried it might be genuine, hang up and call the organisation on a number you looked up yourself.

Frequently asked questions

I gave someone remote access to my computer. What do I do first?

Disconnect it from the internet, call your bank on the number from the back of your card, and change your email password from a different device. In that order. Then report it to Scamwatch and get the machine checked properly. Remote-access software is usually left behind and configured to reconnect.

Will a factory reset remove everything a scammer installed?

A proper clean reinstall will remove software on that device, yes. What it does not fix is anything already taken: saved passwords, files copied off, accounts logged into elsewhere. That's why changing passwords from a separate device comes first and matters more than the reinstall.

Can you tell what the scammer actually did on my computer?

Often, to a useful degree. Remote-access tools leave logs, installers leave timestamps, and browsers record what was opened. It's rarely a complete picture, but it's usually enough to document what was installed and when, which is what a bank or insurer is asking for.

Do you provide reports for banks and insurers?

Yes. A written assessment of what was found on the device and what was done about it is a service we provide regularly, and it's often exactly what a claim needs. Tell us you need one when you drop the device off, so we document before cleaning.

My phone got a virus warning in the browser. Am I infected?

Almost certainly not. Full-screen "your phone is infected" pop-ups are advertising, not diagnosis, and they cannot scan your device. Close the tab, clear the browser cache, and install nothing it recommends. Genuine phone malware is rare and doesn't announce itself with a countdown timer.

How much does it cost to have a device checked after a scam?

Assessment is free, so if you're not sure whether anything actually happened, bring it in and we'll look. A documented check and report is priced as standard labour and confirmed before we start, and if the machine needs a full clean reinstall on top, we quote that separately.

Related guides

Visit Geekly Bendigo

37 Williamson Street, Bendigo VIC 3550 · Open Monday–Friday 9am–5pm, Saturday 10am–2pm · Phone 0421 206 766 · hello@geekly.com.au

Every repair is done 100% in-house with a one-year warranty. 700+ five-star Google reviews, 18,622 repairs completed since 2020.

Book a repair · Transparent pricing · Contact us