Your computers and tablets likely contain several pieces of sensitive information, like your address, historical locations, credit card numbers, photos, videos, email addresses, contacts, and more. If someone wrongfully gains access to these devices, they may be able to access this information or even applications that you’re already logged into so they can steal even more information.
How you respond will depend on how the device was compromised:
- Your device may be accessed physically, when a person steals the device or uses a password they should not have known, or
- Your device may be accessed remotely when it is infected with a virus, malware, or spyware after you click a suspicious link or download a malicious app.
Knowing these two pieces of information will help you understand how to respond.
The following, immediate steps can help lock down your device and potentially kick out anyone who wrongfully gained access. These steps will also lead you through identifying the right organizations and companies that can help you regain control.
These are critical steps that should be taken in the following order:
- Disconnect the device from Wi-Fi or internet connection.
- Turn off Bluetooth.
- Log out of all accounts on the device (social media, email, apps, etc.)
- See who has access to your accounts or which devices are signed in:
- It is recommended you reboot to safe mode to disable all third-party apps that may be running in the background.
-
- Find and delete any newly installed apps or apps that you do not recognize. Be sure to look for any hidden apps. This may help remove any malicious software that may have been downloaded with these apps.
- Cancel any credit cards that are linked to your device.
- Change the password on the device you believe is compromised, as well as the passwords of any accounts that were accessed through that device.
- DO NOT try to back up your compromised device until it has been fixed because rare, nasty malware infections can be duplicated in a device backup.
We’ve outlined some next steps for you to consider. If you put several of these into practice, you’ll be safer day-to-day.
- A compromise may be the result of device theft or from someone abusing a password they shouldn’t know. If this is the case, use a new, unique device password and do not share it with people you do not trust.
- Use a password manager and create and store unique passwords for each individual online account. Repeat passwords are one of the biggest vulnerabilities in many types of online scams.
- If you really want to improve your security, download an MFA “authenticator” app, which is used specifically for multi-factor authentication (MFA) codes. Learn more about them here.
- Speaking of MFA, never share the one-time passcodes that are sent to your phone or email inbox with anyone and remember that no legitimate company will ever ask you for the one-time passcode over the phone or in a customer support chat.
- Log out of your accounts or apps rather than leaving them open when not in use.
- Avoid using free public Wi-Fi without a VPN. This will shield your account information and activity from scammers.
- Download an antivirus scanner for your device to specifically look for viruses and malware that can spy on your digital activity (sometimes called “spyware” or “stalkerware”).
- Update your software to the latest version.
- Get help from a professional who can assess the situation and determine whether your device is infected with malware, who else may have access to your device, and how to safely restore important settings. Help is available at many companies and organizations, such as:
- The company that made your device (for example, visit a Genius Bar for Apple devices).
- Companies that make cybersecurity products you currently use on your devices.
- Nonprofit and community-based tech clinics.
- If you are no longer receiving calls/messages or are receiving calls/messages not meant for you, contact your phone carrier (it is possible there was a SIM card swap).
- Reset your lock screen passcode through the device’s settings screen.
The following resources can help guide you in scam education, response, and reporting:
If your computer or tablet was compromised
General information on device compromise
- Apple: If you think your Apple ID has been compromised (Apple support)
- Credit Lock vs. Credit Freeze (FAQ)
- Sanitization and disposal of electronic devices (Canadian Centre for Cyber Security)
- Personal Information Retention and Disposal: Principles and Best Practices (Office of the Privacy Commissioner of Canada)
- Computer Security Clinic for Survivors of Intimate Partner Violence (IPV) run by Cornell Tech at Cornell University.
- How to Tell If Your Computer Has a Virus and What to Do About It (National Cybersecurity Alliance)
Recognizing and preventing future incidents
- 7 Steps to avoid getting hacked (PC Magazine)
- The 7 red flags of phishing (Get Cyber Safe)
- Don’t take the bait: Recognize and avoid phishing attacks (Canadian Centre for Cyber Security)
- How to Know If You’ve Been Hacked, and What to Do About It (Wired)
- BBB Tip: How to create a strong password
- How to spot the “red flags” of scams (BBB)
- Learn more about impersonation scams (BBB)
- BBB Scam Alert: Tech support scams
- BBB Tip: Malware Scams
- BBB Tip: Phishing scams can come in text messages, prize offers