The essentials
- Assume everything on the device was visible: saved passwords, banking sessions, files, email.
- Disconnect the machine now and do your banking from a different device until this one is professionally cleaned.
- Call your bank on the number on your card — especially if any payment, "refund", or screen-share of your account happened.
- The "accidental over-refund" they beg you to return is the core of the scam — it is your own money moved between your accounts.
- Your number is now on a victim list; expect polished follow-up calls, including from the "refund department".
These operations are industrial call centers with scripts, quotas, and props — the "virus scan" that finds infections, the technician who sounds genuinely helpful for an hour. Falling for a rehearsed production is not gullibility.
What matters now is narrow: cut their access, protect the money, and clean the machine — in that order.
Do this now
- Disconnect the computer. Turn off Wi-Fi or pull the cable. Remote-access tools reconnect the moment the machine is online, and some are configured to accept them silently.
- Call the bank from another device. Use the number on your card. Report what happened, dispute any transfers, and ask them to watch the account — screen-shared banking sessions get replayed.
- Change the passwords that matter. From a clean device: banking, email, and anything with saved passwords in the browser on that machine. Email first — it resets everything else.
- Remove their software — then check deeper. Uninstall AnyDesk, TeamViewer, or whatever they used, but assume they may have added more. A professional scan for persistence is worth it before you trust the machine again.
- Review what moved. Statements, payment apps, gift-card purchases, crypto — the losses are sometimes staged to appear days later.
- Report it. Bank, police or national fraud service, and the platform whose name they abused. Reports feed the takedowns that slow these call centers.
What not to do
- Do not use the machine for banking or email until it is cleaned.
- Do not return the "over-refund" — that transfer is the theft; call the bank instead.
- Do not answer their follow-up calls, and never let anyone back on the machine.
- Do not be ashamed into silence — these scripts are engineered by teams who do nothing else all day.
- Do not trust the next caller who "knows about the scam" and offers to reverse it.
Preserve the evidence
Whatever else happens, these are the artifacts the investigation — and any insurance claim, dispute, or prosecution — will be built from:
- The phone numbers, names, and company they claimed.
- The remote software they had you install, and roughly when.
- Bank statements marking every movement during and after the call.
- Screenshots or photos of anything still on the screen.
- Receipts or codes if gift cards or crypto were involved.
Keep a clear head
The scam works by manufacturing an emergency and then solving it for you — authority plus urgency, for an hour or more, with a friendly voice. Feeling foolish afterward is near-universal and entirely misplaced: you were run through a professional production.
If this happened to a parent or older relative, keep the conversation warm. Shame is what stops people telling family before the second, larger loss.
Questions victims ask
They showed me viruses on my screen. Were they real?
No. The "scan" is a prop — a script that prints alarming text, or an ordinary system log narrated dishonestly. Its job is to justify the remote access and the fee.
They refunded too much by mistake and need the difference back. What now?
That is the heart of the scam. They moved your own money between your accounts to fake an over-refund, and the "difference" you send back is the theft. Call your bank; send nothing.
Is my computer still infected?
Treat it that way until checked. Removing the remote-access app is the visible part; persistence — scheduled tasks, extra tools, changed settings — is what a proper scan rules out.