Take these steps immediately:
- Disconnect the laptop from the internet to stop any active remote session.
- Uninstall any apps the scammer asked to install or any remote-access tools that were added.
- Consider resetting the device if the scammer had remote access. This is time-consuming, but it may be the best option if suspicious behavior continues.
- Run a full scan with Windows Security or Microsoft Defender Antivirus to remove malware.
- Install all available Windows security updates.
- Change passwords right away for affected accounts, especially email, Microsoft account, banking, and any account that reused the same password. Use unique passwords.
- Turn on multifactor authentication for accounts that support it.
- Monitor sign-in activity for unusual access.
- Contact the bank or credit card provider immediately if any payment details were shared or any payment was made. Ask them to contest charges and replace affected cards if needed.
- Write down what was shared while it is still fresh: passwords, account details, payment details, and what software was installed.
- Report the scam to Microsoft at https://www.microsoft.com/reportascam.
- If this device is used for work or school, notify the IT department immediately.
- If money was lost or identity theft is suspected, report it to local law enforcement.
Important facts:
- Microsoft does not make unsolicited phone calls to fix a computer.
- Real Microsoft error or warning messages do not include a phone number to call.
- If the scammer only had the name and phone number, there is little else to recover from that alone, but more scam calls may follow.
If fake alerts, pop-ups, or other suspicious behavior continue after uninstalling software and scanning, resetting the PC is the strongest cleanup step.
References: