What to do if you get hacked: a home user guide

I got a call today from a distressed sounding guy, who said someone had taken over his computer, email, and Wi-Fi.

And this isn’t one of those salesy made up stories people use to sell their services, it has really happened. In this case a very kingly sounding gentleman has seemingly been taken in by someone he trusted.

If you’ve been taken advantage of, I’m sorry – it’s scary not knowing what to do if you get hacked. But it’s time to take the power back, and I can help you do that.

Immediate safety rules 

Never accept passwords by email or SMS. This rule is a constant, because emails are not secure, but it is especially important if you think someone could be watching you.

Do not allow remote access (TeamViewer, AnyDesk, Zoom remote, or “install this helper”). That’s how fraudsters keep control. If someone you don’t know asked to remote control your machine – No-No-No!

Do not pay anyone for “recovery” unless this is via a verified company and a proper invoice – scammers ask for payment and vanish. 

I will recommend someone to you if you ask, but will never pressure you for a decision, a payment,  anything.

What you should  to do right now (from a trusted device – NOT the compromised machine)

If you suspect your computer has been compromised, this is what to do if you get hacked. Complete the steps from a different device (library, neighbour’s, friend’s, a parent / sibling or child’s computer/phone):

Disconnect compromised device from internet and power it down.

From another device, log into your primary email(s) and:

  1. Change the password to a new, strong one.
  2. Review account recovery options (alternate email, phone) and make sure they’re correct.
  3. Revoke any active sessions / devices (Google: Security → Your devices → Sign out; Microsoft: sign out everywhere).

Enable 2-factor authentication (2FA) on email and banking accounts (use SMS or an authenticator app if possible).

Notify your bank and ask them to monitor/flag the account for fraud. If money may have already moved, escalate to the bank’s fraud team.

Report to Action Fraud (0300 123 2040 in the UK) and get a crime reference number if possible. That helps banks/registrars treat it seriously.

Get local hands-on help: find a trusted local IT specialist or an incident response firm – this situation needs a rebuild of the compromised machine and a full credential hygiene sweep.

If you are worried about who to trust, I can help you. Ping me an email or (preferably) a WhatsApp message – I usually see them faster.

Evidence to collect (important if you want to pursue recovery)

Be calm but decisive, reserve and send (via a different email or printed) the following to police/registrar/bank:

Copies/screenshots of any ransom/communication from the attacker.

Voicemail audio if you have it (save file).

Dates and times of suspicious activity.

Any emails showing account changes.

The person who called today sounded tired, confused, and concerned – and with so much of our lives online it is easy to see why. Make sure you data is backed up, use multi factor authentication wherever you can, strong passwords. And all the usual stuff – AV, firewalls, patch your computers – these things will be enough almost all the time, unless you lower your guard and let people in.

It is natural to want to trust people, especially people who say they will help you. When I say it I mean I’ll offer you advice without asking for anything from you – you’re OK with me 👽