Back to Blog

A Tech Support Scammer Accessed the Shared Computer: What Housemates Should Do

A room-by-room response for containing a remote-access scam on a computer used by more than one person.

A tech support scam on a shared computer becomes a household incident, not just one person's mistake. Disconnect that computer from Wi-Fi and Ethernet, stop using it for passwords or payments, and tell every regular user what happened. From a different trusted device, secure the most important accounts first. Do not let embarrassment delay the warning.

Contain access before investigating

If the scammer is still connected, turn off Wi-Fi on the computer, unplug its network cable, and power down the router only if you cannot otherwise disconnect it. Do not keep clicking around while the stranger watches. Photograph the screen with another device if a payment request, phone number, remote-access program, or chat is visible.

Write down what the person did while access was active. Did they open a browser, email, a password manager, tax files, banking sites, or a shared drive? Did anyone type a password or one-time code? This short exposure list is more useful than a vague statement that the scammer “saw everything.” Leave the suspect computer offline until it can be checked or reset.

The FTC's tech support scam guidance says to change a password immediately if it was given to a scammer, including anywhere else that reused password is used. Use a phone or computer that the scammer never controlled for those changes.

Secure each person's accounts in the right order

Start with email because it can reset other accounts. Then protect the password manager, financial accounts, mobile carrier account, cloud storage, and shopping accounts with saved cards. Change unique passwords, review recovery email addresses and phone numbers, sign out unknown sessions, and check forwarding rules. A password change alone may not remove an active session or a malicious mail rule.

Each housemate should review only their own private accounts. One coordinator can maintain a checklist without collecting anyone's new passwords. If a shared vault was exposed, rotate the shared credentials and follow the separate former-resident password vault checklist to confirm who still has access.

Call a bank using the number printed on the card or shown in its official app if payment details were visible. Contact the payment provider promptly if money was sent. Never use a callback number supplied by the caller, pop-up, invoice, or chat.

Recover the computer and document the incident

List remote-control software installed during the call. A qualified technician may be able to assess it, but a full operating-system reset from trusted installation media is the clearest household boundary when the machine held several people's data. Back up irreplaceable personal files cautiously, not applications or unknown installers. Scan restored files before opening them.

Preserve receipts, call logs, emails, screenshots, payment records, and the scammer's stated company name. Report the incident at ReportFraud.ftc.gov. If identity information was exposed, use IdentityTheft.gov for a recovery plan. Agree who will handle the computer, who will contact financial providers, and when everyone may trust the device again.

Before returning it to the kitchen table, create separate operating-system accounts with standard user privileges. Avoid a single browser profile for the household. Install updates and only the remote-help tool that a known support provider specifically requires, then remove it afterward.

How HomeCo helps

Create one private HomeCo task group for containment, account checks, financial calls, computer recovery, and reports. Assign tasks without writing passwords, card numbers, recovery codes, or copies of identity documents into the board. Attach only sanitized evidence, or record where encrypted originals are stored.

Add a completion rule to each task: “confirmed from a clean device,” “provider case number saved,” or “fresh operating system installed.” That turns a frightening, fuzzy incident into visible responsibilities without making one housemate the permanent technology department.

FAQ

Should we reset the router too?

Not automatically. Change the router administrator password and review settings if the scammer opened its control page, learned the administrator credential, or changed DNS or remote-management settings. Otherwise, focus first on the compromised computer and accounts.

Can we keep using the computer offline?

Keep it offline for evidence gathering, but do not use it to enter secrets. Even without internet access, activity can alter logs or files. Set a clear owner for assessment or reset.

Does everyone need to change every password?

Prioritize accounts that were open, stored in the browser, typed during access, or protected by exposed email. Reused passwords must also change wherever used. Other housemates should still review sessions and alerts for their own accounts.