The short answer
If a scammer accessed your computer remotely, immediately disconnect the device from the internet. Change all passwords, including banking and email, using a different, clean device. Run a thorough security scan to remove malicious software. Never reconnect your old crypto wallet or provide private keys to anyone. Contact your bank to secure your accounts, and notify relevant cybercrime reporting authorities.
Remote access scams are particularly dangerous because they allow fraudsters to see exactly what you see and take control of your computer. If you have been targeted in this way, you must prioritize securing your digital environment to prevent further damage.
Your priority is to establish a secure perimeter. This means moving away from the compromised hardware and using secondary, safe methods to audit and secure your sensitive accounts.
01Immediate Containment Steps
Once you realize an unauthorized person has had remote access, turn off the internet connection to that specific device immediately to stop them from continuing to interact with it.
Do not attempt to 'negotiate' with the scammer. They may try to scare you into paying more by threatening to delete files or expose information. Shutting off the connection prevents them from causing further immediate harm to your systems.
Source for this section[1] Australian Cyber Security Centre: getting help
02Cleaning Your Digital Environment
You cannot trust a computer that has been controlled by a scammer. They may have installed keyloggers, screen-capture software, or remote access Trojans that remain active after you reconnect.
If possible, perform a factory reset or seek professional IT advice to wipe the device completely. If you must use the device, scan it thoroughly with reputable antivirus software, but be aware that hidden malware can often bypass standard scans.
Source for this section[1] Australian Cyber Security Centre: getting help
03Securing Sensitive Accounts
Assume that every password stored or typed while the scammer had access is compromised. Use a clean, separate device to change your credentials for your most sensitive accounts.
1. Change passwords for email, banking, and crypto exchanges. 2. Enable multi-factor authentication (MFA) everywhere, preferably using a hardware token or an authentication app rather than SMS. 3. Monitor your bank account statements for any suspicious transactions initiated without your authorization.
Source for this section[1] Australian Cyber Security Centre: getting help
04Wallet and Asset Protection
If the scammer had access to your desktop wallet, assume those funds are at risk. Do not attempt to move assets from a compromised wallet using the same computer. If you have a hardware wallet, ensure it is disconnected.
Do not re-use any seed phrase or private key that was on the compromised device. If a wallet was accessed or the seed phrase was potentially viewed during the screen-sharing session, consider that wallet permanently insecure.
Source for this section[2] Ethereum: wallet custody and recovery
05Hypothetical Security Audit Checklist
Use this checklist to review your current state of security after an incident:
1. Is the compromised device physically disconnected from the network? 2. Have I changed my banking passwords from a new, clean device? 3. Did I check for any unauthorized browser extensions added during the remote session? 4. Have I reviewed my email's forwarding rules (scammers often set up auto-forwarding)? 5. Have I updated my security questions?
Source for this section[1] Australian Cyber Security Centre: getting help
Checklist
- Disconnect your device from the internet.
- Use a separate, clean device to change all important passwords.
- Notify your bank regarding potential unauthorized access.
- Perform a full system reset or secure wipe of the affected device.
- Review your email accounts for unauthorized forwarding or password resets.
- Report the incident through the ReportCyber portal.
- Assume any wallet on the machine is now compromised.
Questions people ask
Can I keep using the same computer after I run a virus scan?
It is safer to perform a factory reset or wipe the drive. Scammers can hide software that standard scans might miss.
What if they threaten to lock my files?
This is a common tactic to keep you in fear. Do not pay. Seek professional IT help to resolve the situation.
How do I secure my crypto if my wallet was on the screen?
Assume the wallet and its private keys are compromised. Stop using it and move any remaining assets to a new, secure wallet setup.
Safety boundaries
- No legitimate helper needs your seed phrase, private key, password, one-time code, remote access to your device or a wallet connection.
- Nobody can promise that funds will be recovered. Treat any guarantee, or any fee demanded to release funds, with suspicion.
- Find official contact details yourself, through the regulator, bank or platform website, not through a message or advert you received.
- This guide is general education. It is not legal, financial or tax advice and does not assess your situation.
If you want to organise your facts, the initial claim outline on our homepage collects only a short summary and contact details. It creates no client relationship and promises no outcome. Do not send documents or credentials.
Official sources
- [1]Australian Cyber Security Centre: getting help
Checked 4 October 2026 - [2]Ethereum: wallet custody and recovery
Checked 4 October 2026
AI-assisted educational content published by Central Crypto Claim using the official sources listed below. No independent expert review is claimed. This is not legal, financial or tax advice.
