If money is moving or someone is impersonating you, contact your bank immediately. Do not wait until every device has been checked.
1. Disconnect the affected device
Turn off Wi-Fi or unplug the network cable if you think a computer is being controlled remotely, files are being encrypted or malware is active. Avoid deleting files or resetting the device until you know whether evidence may be needed.
2. Secure your main email account first
Your email can be used to reset passwords for many other services. From a clean phone or computer, change its password to a new, unique one. Sign out other sessions, review recovery details and forwarding rules, then enable multi-factor authentication.
3. Protect financial and important accounts
Contact your bank using the number printed on your card or shown in its official app if payment details may be exposed. Then secure banking, shopping, social media and cloud-storage accounts. Never call a number supplied by an unexpected pop-up, email or text.
4. Preserve useful evidence
Keep suspicious emails, messages, transaction references and screenshots. Note when the problem began and what you observed. This can help your bank, support provider or the police-led reporting service understand what happened.
5. Check and clean affected devices
Update the operating system and security software, remove unfamiliar applications and browser extensions, and run a full malware scan. If you are unsure whether the device is clean, avoid using it for passwords or payments until it has been professionally checked.
6. Report the incident where appropriate
If you have lost money or experienced cyber crime, use the official Report Fraud guidance. Organisations should also assess whether personal data has been exposed and whether a report to the ICO is required.
7. Monitor for further activity
Watch bank statements, account sign-in alerts and password-reset messages. Tell contacts if your email or social account sent fraudulent messages so they do not follow malicious links or make payments.
What not to do
- Do not reuse the compromised password on another account.
- Do not pay an unsolicited caller who claims they can fix the problem.
- Do not install remote-access software at the request of an unexpected caller.
- Do not assume the problem is finished just because a pop-up has disappeared.
Independent UK guidance
For additional advice, consult the UK National Cyber Security Centre’s online security guidance and the police-led Report Fraud service.
+44 (0)1743 668200