Skip to content
Utah Community Learning

Never let a stranger onto your computer, and what to do if you did

About 22 minutes

Never let a stranger onto your computer, and what to do if you did

Last time we examined the fake Microsoft call. This lesson is the other half of it: what you actually do with your hands, in the moment, when someone is asking you to let them in.

The rule is short. Nobody gets remote access to your computer unless you called them first, using a number you looked up yourself. Not a number they gave you. Not a number on a pop-up. One you found.

That is the entire rule. If you retain nothing else from this lesson, retain that.

Why this works on people who are not foolish at all

Kylie, my neighbor, got a call from "Microsoft" about a virus on her machine. She is sharp. She runs her own budget spreadsheets; she is not someone who falls for things easily. But the caller was calm and specific, described suspicious activity, walked her through a "free scan," and by the time she thought to question it, she had already granted him access to her computer.

I do not fault her for it, and I want to say so plainly at the outset, because this is precisely the sort of thing that happens to normal, careful people on an ordinary day. It is not a matter of intelligence. It is a matter of someone running a script engineered to rush you. That is the point I keep returning to in this class: nearly every scam depends on urgency, and if you feel rushed, that feeling is the tell, not the virus warning.

What letting someone in actually means

When you let a stranger remote into your computer, you are not merely letting them look. Depending on the tool, they can see your files, your saved passwords, and your bank tabs if you have them open, and they can move your mouse and type as though seated there. Some of these tools continue to permit that even after you close the window, if you do not fully uninstall the software they had you download.

So if you are on the phone right now and someone is asking you to install something so they can "take a look," hang up. Do not finish the sentence. Hang up, and call the company back using a number from their real website or the back of a card, not anything they gave you.

If you already did it — here is what to do, step by step

This is the part that matters more, because the rule is easy to state and hard to recall in the moment. If you already let someone in, here is what Kylie and I did that afternoon.

  1. Disconnect from the internet first. Unplug the ethernet cable or turn off your wifi. This severs their access immediately, before anything else.
  2. Uninstall the remote access program they had you download. Check your programs list for anything unfamiliar that was installed that day.
  3. Change your passwords, starting with anything financial, and do it from a different device if possible. Your phone, a neighbor's computer, whatever is available.
  4. Call your bank and report what happened. They handle this constantly. They will be neither shocked nor annoyed.
  5. Run a full scan with whatever antivirus you already have. I will state plainly that antivirus software is mostly a distraction at this point, people buy the subscription, feel safe, and click a bad link anyway, but for this specific task, checking for something they installed, it is worth running.
  6. If it feels serious enough, wipe the machine and reset it. That is what we ended up doing with Kylie's, over an afternoon. Not an enjoyable afternoon, but a far better one than the alternative.

None of these steps require skill with computers. They require moving through them in order and not skipping to the end out of embarrassment. Nobody in my class is permitted to feel foolish about this. It happens to plenty of people more comfortable with technology than I am.

One more habit while we are on it

My father used to click "unsubscribe" on every spam email he received, trying to tidy things up. I had to explain to him three separate times that this only confirms to the scammer that your address is real and someone is reading it. The same principle applies here. A "quick scan" or a "free security check" offered out of nowhere is not cleaning anything up; it is confirming that you are a live target. I ended up printing him a one-page sheet and taping it by his computer, because saying it aloud was not sticking. Sometimes you need it in writing where you will see it again.

Before next time

Write down the real phone number for your bank and your computer's brand, from an actual bill or the box it came in, and place it near the computer. Then, if a call like this comes, you are not hunting for the number while someone talks quickly in your ear.

~kenneth

Never let a stranger onto your computer, and what to do if you did — Online Safety and Scam Prevention · Utah Community Learning