Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · An Honest Redirection

Nothing Has Been Lost, and That Is Why This Is Not Our Job

Her enquiry describes something happening rather than something broken. Applying for something online when "a small window opened at the base of the screen and someone started typing, asking if I needed assistance. This has not happened before, so I knew" something was wrong. She is writing from a different computer. That instinct was exactly right — and what she needs in the next few hours is not a recovery service.

MediaPersonal computer subjected to unauthorised remote access — no data loss reported; owner using a separate machine to make contact
Reported situationOwner completing an online application · unsolicited window appearing on screen · unknown party typing and offering assistance · owner recognising the situation as unauthorised · owner now using a different machine · advice sought
Fault classSecurity incident rather than data loss — remediation and credential protection indicated; recovery services applicable only if content was subsequently destroyed
Equipment usedPosition identified as a security incident rather than a recovery before any work · machine isolated from the network · credential changes directed to a separate device · remote access software identified for removal · recovery scope limited to content actually destroyed

The decode: what matters now, in order

First — disconnect the machine from the network. Unplug the cable or switch off the wireless. Remote access requires a connection, and removing it ends any session immediately. Leaving the machine on but disconnected preserves it for examination; turning it off is also acceptable.

Second — change passwords from a different device, and start with email. Changing them on the compromised machine achieves nothing, because anything typed there may be captured. Email comes first because it is the reset route for everything else — whoever controls it controls the rest.

Third — contact the bank if any financial detail was on screen or entered. That call is more urgent than anything technical, and banks deal with this constantly.

Why she is already ahead: she recognised it, stopped, and moved to a different machine. That is the correct sequence and most people do not manage it, particularly when the intrusion is framed as help.

How this generally happens: remote access requires software to have been installed or permission granted — frequently during a telephone call, or through a link, or as part of what appears to be support. It is worth establishing what was installed and when, because removing it is part of making the machine safe.

Now the honest part, which is why this page exists. Nothing has been lost. Her files are where they were, and a recovery service has nothing to recover — this is a security matter, and the useful routes are her bank, her email provider, the relevant reporting body, and somebody who can examine and clean the machine.

When it does become a recovery matter: if files were encrypted, deleted, or the machine was wiped. Then there is something to work on, and the same principles apply as anywhere else — stop using it, and do not let anybody reinstall over it.

What not to do meanwhile: do not reconnect it to check anything, and do not let the machine be reset or reinstalled until it has been established whether anything was destroyed.

On the bench

The position was identified as a security incident rather than a recovery before any work — content residing where it was, with the difficulty being unauthorised access rather than loss. The machine was isolated from the network, remote access requiring a live connection. Credential changes were directed to a separate device, changes made on a compromised machine being capturable, with email prioritised as the reset route for other accounts. Recovery scope was limited to content actually destroyed.

The outcome

The position identified honestly before any work, the machine isolated, and credential changes directed elsewhere. Free assessment, and no charge where the answer lies with your bank and your account providers. The decode: nothing has been lost, which is why this is not a recovery. Disconnect the machine from the network, change your passwords from a different device starting with email, and telephone your bank if any financial detail was on screen. You were right to stop and move machines.

Somebody accessing your computer remotely

Disconnect it from the network now — unplug the cable or turn off the wireless, which ends any session immediately. Then change your passwords from a different device, starting with email, because anything typed on the affected machine may be captured and email is the reset route for everything else. Telephone your bank if any financial detail was on screen or entered; that call is more urgent than anything technical. Leave the machine off or disconnected rather than reinstalling it, until you know whether anything was destroyed. Remote access needs software installed or permission granted, so establishing what was added matters for cleaning it.

Concerned somebody has been in your machine?
Disconnect it and change passwords elsewhere — then call Oxford Data Recovery on 01865 593000; free assessment, and a straight answer where the routes run through your bank and your providers rather than through us.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.