Stop contact with the scammer, disconnect active remote access and use trusted contact methods for financial institutions.
A full-screen warning, alarm sound or phone number appears in the browser.
A stranger connected remotely or installed support software.
New apps, browser extensions, ads or redirects appeared.
Email, social, banking or shopping accounts show suspicious access.
Money, gift cards or personal information may have been shared.
Slowdowns, login prompts, security warnings or unexplained changes.
If someone is actively connected, disconnect internet access and stop communicating with the caller.
CDNJ checks for remote tools, malware and unwanted changes.
Cleanup, password changes and account follow-up are prioritized.
Disconnect the computer from the internet, stop communicating with the caller, avoid entering more passwords, and contact the shop. For financial exposure, also contact the relevant bank or card provider through a trusted number.
No. A device can be inspected and cleaned, but it may not be possible to prove exactly what a remote person viewed or copied. The response should focus on reducing further risk.
Use a different, trusted device when possible. Prioritize email, banking and any account that reused the same password.
No. Many fake virus alerts are web pages designed to frighten people into calling. Even so, the device should be checked if software was installed or access was granted.