What to Do If a Tech Support Scammer Gets Remote Access to an Elderly Parent’s Computer

If a remote access scam involving an elderly parent occurs, stop communicating with the scammer immediately. Disconnect the computer from the internet if access may still be active. Then update security software, run a full scan, and remove unauthorized software. Change important passwords from a trusted device and enable two-factor authentication. Review financial accounts if banking information may have been exposed. The FTC recommends these steps after a scammer gains access to a computer.

If money was also sent, contact the payment provider immediately. Save messages, screenshots, payment records, and other evidence. Report the scam through appropriate official channels.

Article Summary:

A remote access scam can give criminals direct access to an older adult’s computer. Scammers may pretend to be Microsoft, another technology company, an internet provider, or technical support staff. They may ask the victim to install remote-support software. They may then view information, request passwords, or install unwanted programs. This guide explains what caregivers should do after an elderly parent computer scam leads to unauthorized remote access. It covers computer security, passwords, financial accounts, evidence, reporting, and future prevention.

Caregiver helping an elderly parent secure a computer after a remote access scam
Table of contents

    What Does It Mean When a Scammer Gets Remote Access?

    When a scammer gets remote access to a computer, they may interact with the device from another location.

    Legitimate remote-support tools can help trusted people solve computer problems. The security risk depends on who receives access and why.

    Tech support scam remote access usually begins when a victim installs software or approves an unexpected connection.

    If you want to understand the broader warning signs and prevention strategies, see our guide to Tech Support Scams Targeting Seniors.

    Microsoft warns that scammers with remote access may steal information or install malware, ransomware, or other unwanted programs.

    The situation should therefore be treated as a security incident.

    The first priority is stopping further access.

    The second priority is protecting accounts and personal information.

    What Should You Do Immediately After a Scammer Gets Remote Access?

    If a scammer got remote access, the first priority is stopping further access.

    The next stage of remote access scam recovery is protecting accounts and personal information.

    Stop Talking to the Scammer

    End the phone call, chat, or remote-support session.

    Do not follow additional instructions from the scammer.

    Do not allow another connection because the scammer claims they need to finish the repair.

    Do not pay an additional fee to “secure” the computer.

    Scammers may continue the conversation after gaining trust.

    Ending communication reduces the opportunity for further manipulation.

    Disconnect the Computer From the Internet

    If remote access may still be active, disconnect the computer from the internet.

    You can disconnect Wi-Fi or unplug the Ethernet cable.

    This can interrupt an active remote session.

    However, disconnecting the internet does not remove remote-access software.

    The computer still needs to be checked and secured.

    Do Not Use the Compromised Computer for Sensitive Accounts

    Avoid using the affected computer for banking or other sensitive accounts until it has been checked.

    Do not enter new passwords if you believe the device may contain unwanted software.

    When possible, use a trusted device for changing important account credentials.

    This creates separation between the potentially compromised computer and the recovery process.

    How Do You Remove a Scammer’s Remote Access?

    Caregiver helping an older parent remove unauthorized remote access software from a computer

    To remove remote access software safely, you must do more than close the scammer’s window.

    The scammer may have instructed the older adult to install remote-support software.

    That software should be identified and evaluated before normal computer use resumes.

    Identify Remote-Access Software

    Think back to what the scammer asked your parent to install.

    Write down the software name if it is known.

    Do not assume unfamiliar software is malicious simply because you do not recognize it.

    Some remote-support tools have legitimate uses.

    The concern is whether the software was installed because of an unsolicited scam.

    Remove Unauthorized Software

    Remove remote access software after a scam when it was installed because of the scammer’s instructions.

    Microsoft specifically advises uninstalling applications that scammers asked victims to install.

    If you are unsure whether a program is safe to remove, ask a trusted technical professional.

    Avoid downloading another “cleanup” program from a website recommended by the scammer.

    Run Security Software

    Updating security software is an important first step to secure a computer after a scam.

    Then run a full security scan.

    Follow the security software’s instructions if it identifies malware or other threats.

    The FTC recommends updating security software, running a scan, and removing anything the scan identifies as a problem.

    Microsoft also recommends running a full Windows Security scan after a tech support scam.

    Consider a Professional Computer Check

    Professional help can be useful when a computer was compromised by a scammer or the scammer had extended access.

    It is especially important if the scammer installed several programs or the computer behaves differently afterward.

    Use the computer manufacturer, a reputable technician, or another trusted support source.

    Do not use a technician whose contact information came from the scammer.

    Which Passwords Should You Change After Remote Access?

    Knowing how to change passwords after a tech support scam is an important part of recovery.

    The priority should be accounts that could expose other accounts or financial information.

    Start With Email

    Secure the primary email account first.

    Email accounts can contain sensitive messages and password-reset links.

    A compromised email account can also make it easier for someone to access other services.

    Create a new strong password.

    Enable two-factor authentication after a scam whenever the affected account supports it.

    Change Financial Account Passwords

    Secure banking and payment accounts that may have been exposed.

    This can include:

    • Online banking
    • Credit-card accounts
    • Payment services
    • Investment accounts
    • Other financial services


    Contact the financial institution directly if financial information was visible during the remote session.

    Change Other Important Accounts

    Review accounts your parent used while the scammer had access.

    Consider:

    • Microsoft accounts
    • Shopping accounts
    • Cloud storage
    • Social-media accounts
    • Important subscription accounts


    If the same password was reused elsewhere, change those passwords too.

    The FTC recommends changing compromised passwords and turning on two-factor authentication after a scammer gains account information.

    What If the Scammer Saw a Password or Security Code?

    Treat passwords exposed by a scammer as compromised and change them from a trusted device.

    Use a trusted device to secure accounts after remote access and change any exposed passwords.

    If the password was reused on another account, change that account too.

    Security codes should also be treated seriously.

    If your parent provided a one-time verification code, review the related account for unexpected changes.

    Check recovery email addresses, phone numbers, login activity, and other security settings when available.

    Do not assume that a scammer stopped using the information simply because the phone call ended.

    What If the Scammer Accessed Online Banking or Financial Information?

    Older woman reviewing her bank account with a caregiver after a tech support scam

    Contact the bank promptly if a tech support scam may have exposed a bank account.

    Explain that a scammer accessed the bank account or may have viewed financial information through the computer.

    Ask what protective steps are appropriate for the account.

    Review recent transactions carefully.

    Look for unfamiliar:

    • Purchases
    • Transfers
    • Withdrawals
    • New payees
    • Account changes
    • Card activity


    If suspicious activity appears, report it immediately.

    If money was actually sent to the scammer, follow the payment-recovery steps in What to Do When an Elderly Parent Has Already Given a Scammer Money.

    The FTC advises people who were scammed to contact the company used to send the money and ask about available recovery options.

    What If the Scammer Installed Malware?

    Remote access can create additional risks, especially if the scammer installed malware or unwanted software.

    Microsoft warns that tech support scammers may install malware, ransomware, or other unwanted programs after gaining access.

    If the remote-access incident started with a fake Microsoft security warning, our guide on how to help an elderly parent recognize a fake Microsoft security alert explains the warning signs and safer response steps.

    Watch for unusual behavior that could indicate malware after a remote access scam.

    Possible warning signs include:

    • Unexpected software
    • Repeated security warnings
    • Unusual pop-ups
    • Browser changes
    • Unknown accounts
    • Slower-than-usual performance
    • Unexpected files
    • Security software alerts


    These signs do not automatically prove malware exists.

    A security scan or professional computer inspection can provide better evidence.

    Do not continue entering sensitive information if you believe the device remains compromised.

    Should You Reset the Computer After a Remote Access Scam?

    A reset is not automatically required after every remote access scam.

    The appropriate response depends on what happened during the session.

    Microsoft says that if a scammer was given access to the device, resetting it may be appropriate in some situations. Microsoft also recommends uninstalling scam-related applications, running a full security scan, applying security updates, and changing passwords.

    A reset may become more relevant when:

    • The scammer installed suspicious software.
    • Malware is detected.
    • The computer continues showing suspicious behavior.
    • You cannot confidently remove unauthorized software.
    • A trusted professional recommends resetting it.


    Before resetting a computer, preserve important files and understand what the reset will remove.

    When uncertain, seek help from a trusted technician.

    What Evidence Should You Save?

    Save evidence before deleting messages or changing devices.

    Useful information includes:

    • Scammer’s phone number
    • Email address
    • Text messages
    • Screenshots
    • Remote-access software name
    • Website addresses
    • Payment receipts
    • Bank transactions
    • Dates and approximate times
    • Names used by the scammer
    • Company names they impersonated
    • Instructions the scammer gave
    • Files or documents they requested


    Create a simple timeline of what happened.

    Write down when the scammer contacted your parent.

    Record when remote access was granted.

    Note what information your parent remembers sharing.

    This information can help financial institutions and reporting agencies understand the incident.

    Where Should You Report a Tech Support Scam?

    Knowing how to report a tech support scam can help authorities identify repeated fraud patterns.

    However, reports can help agencies identify patterns and investigate fraud.

    Report the Scam to the FTC

    In the United States, you can report a remote access scam through the Federal Trade Commission’s fraud-reporting system.

    Use the official FTC ReportFraud.gov service.

    The FTC says reports help it build cases, spot trends, and educate the public.

    Include as many factual details as possible.

    Report Internet Fraud to the FBI’s IC3

    The FBI’s Internet Crime Complaint Center accepts reports involving internet-based fraud.

    IC3 specifically provides an avenue for older adults and families to report fraud.

    Include relevant:

    • Contact information
    • Websites
    • Payment details
    • Transaction numbers
    • Screenshots
    • Messages
    • Names used by the scammer


    The FBI also maintains information about tech and customer-support fraud involving older adults.

    Report Microsoft Impersonation

    If the scammer claimed to represent Microsoft, Microsoft provides an official reporting process for technical-support scams.

    Do not use a reporting link supplied by the scammer.

    Open Microsoft’s official support website independently.

    Microsoft currently provides a dedicated page for avoiding and reporting Microsoft technical-support scams.

    What If the Scammer Calls Back?

    Do not assume the second contact is legitimate.

    A scammer may call again using a different name or company.

    They may claim they need to:

    • Finish the repair
    • Refund money
    • Secure the computer
    • Recover stolen funds
    • Verify the account
    • Remove malware
    • Confirm a payment


    End the communication.

    Do not provide new information.

    Do not give the caller remote access again.

    Do not pay another fee.

    If you need help, contact the claimed organization independently.

    How Should You Help an Elderly Parent After a Remote Access Scam?

    The first conversation should focus on safety rather than blame.

    Your parent may already feel embarrassed or frightened.

    Blaming them can make it harder to learn what actually happened.

    Instead, explain that tech support scams are designed to create fear and urgency.

    Ask your parent to show you the messages, phone numbers, websites, and software involved.

    Ask Questions Without Blaming

    Use simple factual questions.

    Ask:

    • Who contacted you?
    • What did they say?
    • What did they ask you to install?
    • Did they control the computer?
    • What information did you provide?
    • Did you enter a password?
    • Did you provide a security code?
    • Did you open online banking?
    • Did you make a payment?
    • Did they contact you again?


    Do not interrupt to criticize the answers.

    Your goal is to understand the complete sequence.

    Create a Simple Family Rule

    Create the rule before another scam occurs.

    For example:

    “If someone unexpectedly says there is a computer problem, stop and call me first.”

    The rule should apply to:

    • Pop-ups
    • Phone calls
    • Emails
    • Text messages
    • Unexpected support requests


    A simple rule is easier to remember during a stressful situation.

    What If Your Parent Already Paid the Scammer?

    If your elderly parent paid a scammer, treat the payment as a separate financial-recovery issue.

    Stop additional payments first.

    Then contact the company used to send the money.

    Depending on the payment method, ask about reversal, recall, dispute, freeze, or refund options.

    Save receipts and transaction information.

    If your parent paid after the scammer gained remote access, also secure the computer and affected accounts.

    For detailed payment-specific recovery steps, see What to Do When an Elderly Parent Has Already Given a Scammer Money.

    Do not pay anyone who promises guaranteed recovery.

    Previous scam victims can become targets for additional recovery scams.

    What Should You Tell Your Parent About Future Remote Access Requests?

    Remote access itself is not always fraudulent.

    Trusted family members and legitimate support services can use remote-support tools.

    The important difference is who initiated the interaction and who is being trusted with access.

    Microsoft advises allowing remote assistance only when the user has initiated the interaction with Microsoft Support directly.

    A useful family rule is:

    Never allow remote access because an unexpected person says it is necessary.

    If technical help is needed, contact the company independently.

    What Not to Do After a Remote Access Scam

    void these mistakes:

    • Do not continue talking with the scammer.
    • Do not allow another remote session.
    • Do not pay additional money.
    • Do not enter new passwords on a potentially compromised computer.
    • Do not ignore suspicious account activity.
    • Do not delete evidence immediately.
    • Do not download another program from the scammer.
    • Do not trust a recovery agent automatically.
    • Do not blame your parent.
    • Do not promise that lost money will definitely return.
    • Do not assume the incident ended when the phone call ended.

    Frequently Asked Questions

    What should I do if a scammer got remote access to my elderly parent's computer?

    Stop communicating with the scammer.

    Disconnect active remote access, secure important accounts, update security software, run a scan, and change exposed passwords.

    The FTC specifically recommends security updates, scanning, password changes, and two-factor authentication after computer access is given to a scammer.

    Potentially, yes.

    A scammer with computer access may see information displayed on the screen or interact with files and applications.

    The exact exposure depends on what happened during the remote session.

    Treat passwords used or exposed during the session as compromised.

    If the scammer may still have active remote access, disconnecting the computer can interrupt that connection.

    However, disconnecting the internet does not remove remote-access software.

    The device should still be checked and secured.

    Identify the software the scammer asked your parent to install.

    Remove unauthorized applications when appropriate.

    Then update security software and run a full scan.

    If you are unsure what to remove, use trusted technical assistance.

    Yes, especially when the scammer may have seen or interacted with accounts.

    Start with email and other important accounts.

    Change reused passwords elsewhere and enable two-factor authentication where available.

    Start with email, followed by financial and other high-value accounts.

    Email is particularly important because it can be used for password resets.

    Then review banking, payment, shopping, cloud-storage, and other important accounts.

    Contact the bank or financial institution promptly.

    Explain that a scammer had remote access to the computer.

    Review transactions and ask whether additional protective steps are appropriate.

    Yes.

    Microsoft warns that tech support scammers may install malware, ransomware, or other unwanted programs after gaining remote access.

    Run updated security software and seek trusted technical assistance when necessary.

    In the United States, report the incident to the FTC through ReportFraud.gov.

    Internet-related fraud can also be reported to the FBI’s IC3.

    If the scammer impersonated Microsoft, Microsoft also provides an official reporting process.

    In the United States, report the incident to the FTC through ReportFraud.gov.

    Internet-related fraud can also be reported to the FBI’s IC3.

    If the scammer impersonated Microsoft, Microsoft also provides an official reporting process.

    Final Thoughts

    Knowing what to do after a remote access scam helps families respond calmly and protect the affected computer and accounts.

    Start by stopping communication and interrupting active access.

    Then secure the computer, change exposed passwords, protect financial accounts, and preserve evidence.

    Report the incident through appropriate official channels.

    Most importantly, avoid blaming your parent.

    A calm family response makes it easier to uncover what happened and reduce the risk of another scam.

    The goal is not to make an older adult afraid of technology.

    The goal is to give them a simple plan:

    STOP → DISCONNECT → SECURE → CHECK → REPORT

    Sources

    Our Editorial Process
    Nisha Sharma and ElderGuard Home team reviews common household risks and compares easy safety solutions based on real-world use and current home safety trends. Each step is evaluated for clarity, affordability, and ease of use in real homes. We regularly review and refresh our content to keep recommendations relevant and useful. Learn more about our detailed research methods.

    Share Me

    Facebook
    Telegram
    X
    WhatsApp
    Threads

    Free Home Safety Guide - Newsletter

    Get simple advice for senior home safety. Protect your home and your peace of mind.

    We don’t spam! Read our privacy policy for more info. 1-2 email per month. Unsubscribe anytime.

    Disclosure: As an Amazon Associate, I earn from qualifying purchases. This means if you click on a link and buy a product, I may receive a small commission at no extra cost to you.

    Picture of About The Author
    About The Author

    Nisha Sharma holds a Bachelor of Science in Social Work and is a Certified Senior Home Safety Specialist. She has completed over 150 in-home safety assessments and has worked with caregivers and aging families for more than 9 years.

    Her work focuses on fall prevention, smart monitoring technology, and practical aging-in-place strategies. She leads the ElderGuard team in creating clear, research-based home safety guides for seniors.

    Follow Nisha on LinkedIn for more home safety updates.

    Related Guides

    Categories

    Free Home Safety Guide - Newsletter

    Get simple advice for senior home safety. Protect your home and your peace of mind.

    We don’t spam! Read our privacy policy for more info. 1-2 email per month. Unsubscribe anytime.

    Affiliate Disclosure: To support our deep research and high-quality guides, ElderGuardHome may earn a small commission from qualifying purchases made through links on this page—at no additional cost to you. We only recommend products we have thoroughly vetted for senior safety and home accessibility.