Incident Response — Remote-Access Scam (Tech-Support / Imposter Scam)
You picked up a call. Someone said your account had been hacked. They sounded calm and official. They had you type a web address, install AnyDesk, and read out a code so they could “remove the malware.” An hour later you hung up. This morning the money is gone and the remote-access tool is still on the screen.
This page is the playbook. Do the boxed list first. Read the rest after the immediate fire is out.
STOP — next 10 minutes
Section titled “STOP — next 10 minutes”The order matters. Disconnecting the network kills the active session. Calling the bank before changing passwords matters because the bank can freeze the account from their side even if the attacker has your current password. Email comes before bank because whoever controls your email can reset every other account.
Why running a virus scan WILL NOT fix this
Section titled “Why running a virus scan WILL NOT fix this”The instinct after any compromise is to run a virus scan. It will not help here, and waiting on a scan to finish wastes the window when fraud is still reversible.
AnyDesk, TeamViewer, LogMeIn, Quick Assist, ConnectWise/ScreenConnect, RustDesk, Splashtop, Chrome Remote Desktop, GoToAssist — these are legitimate software with real signed installers. Real businesses use them every day for legitimate IT support. No antivirus will flag them, because they are not malware.
The only way to be safe is to manually uninstall them AND revoke any “unattended access” setting they enabled. Unattended access is the dangerous one: it lets the attacker log back in even when you are not sitting at the computer, even after you uninstall the visible app, if they kept the credentials. Treat any unattended-access password or PIN you set during the call as burned.
A scanner cannot tell the difference between a real IT technician who installed AnyDesk for you and a thief who tricked you into installing AnyDesk. You have to remove it by hand.
Remove the remote-access tool — step by step
Section titled “Remove the remote-access tool — step by step”Do this only after the computer has been off the internet for at least 10 minutes and the bank is on notice. The computer can stay offline through this whole section.
Windows
Section titled “Windows”- Settings → Apps → Installed apps.
- Find AnyDesk (or TeamViewer, LogMeIn, etc.) in the list.
- Click the ⋯ menu next to it → Uninstall. Confirm.
- Restart the computer.
- Open Task Manager (Ctrl+Shift+Esc) and look under the Processes tab — verify nothing related to a remote-access tool is still running.
- Settings → Apps → Optional features → look for Quick Assist (Windows built-in). If you do not use it, remove it.
- Open the Applications folder (Finder → Applications, or Shift+Cmd+A).
- Drag AnyDesk (or whatever was installed) to the Trash.
- Empty the Trash.
- Open Activity Monitor (Cmd+Space, type “Activity Monitor”) and verify nothing remote-access-related is still running. Sort by Process Name and skim for anything you do not recognize.
Both platforms
Section titled “Both platforms”- Check the System Tray (Windows, bottom-right) or Menu Bar (Mac, top-right) for tray icons of remote-access tools you do not recognize. Right-click and look at the application name. Some tools hide as innocuous icons.
- If you use Chrome, open
chrome://appsand remove Chrome Remote Desktop if it is there and you did not install it intentionally.
Common remote-access apps to look for and remove
Section titled “Common remote-access apps to look for and remove”- AnyDesk — the one most often used in this scam.
- TeamViewer — also very common.
- LogMeIn / GoToAssist — older, still used.
- Quick Assist — built into Windows. Can be disabled under Settings → Apps → Optional features.
- ConnectWise Control / ScreenConnect — used by IT companies; appears as a small icon.
- RustDesk — open-source, increasingly seen in scams.
- Splashtop — legit remote-work tool, occasionally used.
- Chrome Remote Desktop — browser-based, easy to miss.
If you are not sure what something is, write down the name and search for it on a different device before removing it. But when in doubt, removing a remote-access tool you did not personally install is the safe choice — you can always reinstall later.
Assume what the attacker now has
Section titled “Assume what the attacker now has”Even after the session is closed and the software is gone, treat the following as compromised. Plan on this list. Do not hope.
- Anything you typed during the session, including passwords that were visually obscured. The dots on the screen hide the characters from you. The keystrokes are not obscured to the person watching the remote session.
- Files they opened — tax returns, bank statements, ID documents (driver’s license scans, passport photos), your address book, photos. Anything they double-clicked while they were “looking for malware.”
- Browser saved passwords — Chrome, Edge, Firefox, and Safari all let you export the password store as a CSV from settings. They may have done this in under 30 seconds.
- Email — they may have created mail filters that auto-forward your incoming mail to their address, or that mark password-reset emails as “read” and silently move them to Trash. This is how they keep access after you change passwords. Check Settings → Filters / Rules / Forwarding on every email account.
- Sent emails from your account — check your Sent folder for messages you didn’t send. Scammers sometimes email contacts to spread the same scam or to set up follow-on fraud.
- 2FA codes — if you were logged into accounts during the session, they could have added their own MFA device (their phone number, their authenticator app) to your account. Check the security settings of every important account: bank, email, social media, retirement, brokerage. Remove any “device” or “phone number” you do not recognize.
- Cookies / session tokens — they may have copied the browser session, which lets them stay logged in to accounts even after you change the password. Sign out of all sessions on every account: most services have a “Sign out of all devices” or “Active sessions” option in security settings.
After the immediate fire — long-tail hardening
Section titled “After the immediate fire — long-tail hardening”Days 1–7 after the incident. Do these in roughly this order.
- Change ALL passwords from a clean device — a phone you trust, a relative’s computer, or the compromised computer only after it has been wiped or fully verified clean. Use a password manager so every site has a unique password going forward: Bitwarden (free, recommended), 1Password, or Dashlane.
- Enable MFA on email and bank — see /cybersecurity/prevention/mfa-guide. Prefer an authenticator app (Aegis, 2FAS, Authy) or hardware key over SMS.
- Freeze your credit at all three bureaus — Experian, Equifax, TransUnion. This is free and reversible under federal law. Freezing stops anyone from opening new credit lines in your name. See /cybersecurity/incident-response#freeze-credit.
- Set up account-activity alerts on bank, credit cards, and email. Most banks let you alert on any charge over $1, any login from a new device, or any wire transfer.
- Review the affected computer’s antivirus and Windows Defender / XProtect logs — not because they will have caught the remote-access tool, but to look for anything else that ran during the session.
- Consider a fresh OS reinstall of the affected computer if you handle sensitive data (work documents, tax records, anything you would not want in a stranger’s hands). See /cybersecurity/incident-response/secure-after-compromise. For a casual home computer, a thorough uninstall + password reset + AV scan from a different vendor is often sufficient; for a computer that holds financial or work-sensitive material, reinstall is the only way to be certain.
- Watch your accounts for 60–90 days. Some fraud surfaces later — recurring charges, new accounts opened, tax-return fraud at the next filing season.
Reporting
Section titled “Reporting”Pick the row that matches what happened. Call the first number first.
| Scenario | First call | Secondary | Legal/regulatory |
|---|---|---|---|
| Bank/card drained | Bank fraud line (back of card) | FBI IC3 ic3.gov + local police non-emergency for case number | FTC ReportFraud.ftc.gov; state AG |
| Sent money via Zelle/Cash App/Venmo | Platform’s fraud dept + your bank (ask for Reg E “fraud” not “scam” classification) | FBI IC3 | FTC; state AG |
| Money wired (Western Union/MoneyGram) | The wire service immediately — some have a 30-min reversal window | FBI IC3 | FTC |
| Bought and sent gift cards | The card issuer (Apple/Google/Amazon/Steam) immediately for freeze of unredeemed balance | FBI IC3 | FTC |
| Sent crypto | Receiving exchange (if known) + FBI IC3 Virtual Asset Unit | Chainalysis-affiliated incident-response firms | IRS Form 4684 |
| Target is 60+ | DOJ Elder Justice Hotline 1-833-FRAUD-11 (1-833-372-8311) | AARP Fraud Watch Helpline 1-877-908-3360 | State AG elder-abuse unit |
A note on the Zelle/Cash App/Venmo row: how the bank classifies the loss decides whether you get reimbursed. “Unauthorized” (the attacker controlled the session) usually qualifies for Reg E reimbursement. “Authorized” (you yourself sent the money under false pretenses) often does not, although Zelle’s network rules were updated in 2023 to cover certain imposter scams. Push for the “unauthorized / fraud” classification when the attacker had remote control of your computer at the time of the transfer.
For every report, keep a copy. IC3 gives you a confirmation number; write it down. The bank’s case number, the police report number, and the IC3 number are the three pieces of paper insurance, the IRS, and your state AG may ask for later.
If you live alone or are helping someone who does
Section titled “If you live alone or are helping someone who does”This is exhausting. Doing it under stress alone, in your 50s, 60s, 70s, with adrenaline still up, is harder than the checklist makes it look. You do not have to do it alone.
- AARP Fraud Watch Helpline: 1-877-908-3360. Trained advocates who will stay on the line and walk through every step with you. Free. They are not the police and not a bank, but they know exactly what to do next.
- Adult Protective Services (APS) — search “[your state] APS” — if the victim is unable to act for themselves, has cognitive decline, or is being pressured by someone in the household. APS can also help with follow-on scams.
- National Center on Elder Abuse: ncea.acl.gov — directory of state and local resources.
- A trusted family member. If you are helping a parent or relative through this, the most useful thing you can do in the first hour is be the “different device” they use to call the bank, and stay with them physically or on the phone while the rest of the checklist happens. Do not blame. The shame is the scammer’s weapon for the next scam — leave the door open for them to tell you when something else feels off later.
The scam pattern — recognize it next time
Section titled “The scam pattern — recognize it next time”The same pattern repeats with different brand names. Once you have seen it, it is hard to un-see.
- Unsolicited call claiming to be “Amazon,” “Microsoft,” “Apple,” “the IRS,” “your bank,” “Social Security.” Sometimes triggered by a pop-up on a website telling you to call a number.
- Creates urgency: “your account has been hacked,” “we need to act now,” “do not tell anyone,” “do not hang up or your account will be permanently locked.” The pressure is the tell.
- Asks you to install software to “fix” or “verify” — AnyDesk, TeamViewer, Quick Assist, or any “remote support tool.” A legitimate company will never call you and ask you to install remote-control software.
- Asks you to read out one-time codes, log into your bank “to verify your identity,” or buy gift cards / withdraw cash / wire money to “secure your funds” or “to help us catch the hackers.” No real fraud department ever asks for gift cards. No real fraud department ever tells you to move money out of your own account to a “safe account.”
- Asks you not to talk to anyone — not your spouse, not your bank in person, not your family. Real institutions encourage you to verify with other people.
Real companies do not call you out of the blue and ask to install software. The IRS does not call — they send a letter. Microsoft does not call. Amazon does not call. Apple does not call. Social Security does not call. Your bank does not call asking for your password or one-time code — they do not need it, they can already see your account.
If a call gives you any of these signs: hang up. Look up the company’s real number yourself (from the back of the card, from a paper bill, from the official website you type in directly — not a number the caller gave you, not the first search result, and not a number from a pop-up). Call them back. If something is actually wrong, they will see it on their side.
Pivot to
Section titled “Pivot to”- /cybersecurity/incident-response — the parent index for everything in this catalog: data breach, lost device, account takeover, ransomware.
- /cybersecurity/threats/social-engineering — why this works on smart people, the psychology of urgency, and how to train yourself out of it.
- /cybersecurity/incident-response/secure-after-compromise — the longer “is my computer safe to use again?” walkthrough, including when to reinstall the OS and how to migrate files safely off a compromised machine.