Disconnect the device and assume full compromise

    If they were on your screen, treat the device as fully untrusted until cleaned.

    JDCS
    By Jordan Dickson · Reviewed by CSG Security Engineers

    Updated June 2026 · 1 min read

    Remote-access scams give the attacker complete control of the device. Until it's clean, you can't trust anything on it — keep it offline until the remediation step.

    What they likely did

      • Opened your banking app or email and screenshotted
      • Installed a hidden remote-access tool that survives reboots
      • Disabled antivirus or security warnings
      • Saved files (passwords, ID copies, browser data) for later use

    Was this guide helpful?

    Know someone who needs this? Send them the guide.

    JD

    Written by

    Jordan Dickson

    Founder, CyberSecurityGuides

    Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.

    Reviewed by CSG Security Engineers

    More from Communications Security