Skip to main content

Hacked or Scammed Device Check in South West London

A calm, methodical check of the device and the accounts behind it — no lectures, no judgement

4.8-star Google rating 25+ years experience Fully insured

Last updated: August 2026

Overview

You are not the first, and you will not be told off

The people who ring us about this are rarely careless. They are usually busy, or caught at a bad moment, or dealing with a caller who sounded exactly like the bank and knew far more than a stranger should. Whatever happened, the useful question now is not how it happened but what is still on the machine and what still has access. We work through that in a set order: get any remote-access software off the device, look for malware and keyloggers, review which accounts could realistically have been reached, and help you change the passwords and turn on two-factor sign-in in a sensible sequence rather than a panic. Then we tell you plainly what we found and what we could not determine.

Remote-access tools such as AnyDesk and TeamViewer found and removed
Malware, keylogger and unwanted-program checks across the whole system
Password changes and two-factor sign-in set up in the right order
A clear review of what was reachable, and an honest note of what we cannot know
Same day where possible Remote or in store No judgement, ever
Features

What the Check Covers

Remote-Access Software Removal

Callers posing as your bank, your broadband provider or a well-known software company almost always talk you into installing a remote-access tool. We find what was put on, remove it fully rather than just closing the window, and clear any standing permission it was granted.

Malware and Keylogger Checks

A full examination of the system rather than a single quick scan — what runs at startup, what is scheduled, what has permissions it should not have, and anything designed to sit quietly and record what you type.

Account and Password Reset

Changing passwords from a device that may still be compromised achieves nothing, so we do it in the right sequence: clean the machine first, then reset email, then everything that can be reset through email, with two-factor sign-in enabled as we go.

Exposure Review

We look at what the device had signed in at the time — email, cloud storage, banking apps, saved browser passwords — and go through it with you, so you know where to concentrate rather than worrying about everything at once.

Hidden Changes Undone

Scammers frequently leave things behind: a forwarding rule quietly copying your email elsewhere, an extra recovery address, a new browser extension, an unfamiliar sign-in still authorised. These outlast a virus scan, so we check them by hand.

Practical Next Steps

A short written summary of what we found, what we changed, and the things only you can do — contacting your bank, and reporting it to Action Fraud. We are not financial or legal advisers, and we will not pretend to be.

Process

How We Work Through It

Simple steps to get your problem solved quickly and professionally.

1

Tell us what happened

A few minutes on the phone, in your own words. There is no wrong answer and no version of this we have not heard before. It tells us how urgent it is and whether remote or in store is quicker.

2

Secure the device

Remote-access tools removed, the system examined properly, and anything left behind taken off. Until this is done, changing passwords on that machine is not worth doing.

3

Secure the accounts

Email first, because everything else resets through it, then the accounts that matter most to you, with two-factor sign-in switched on and any unfamiliar rules or devices removed.

4

Write it down

You get a plain summary of what was found, what was changed, what looked untouched, and what we genuinely could not determine either way.

In Depth

What to Expect

Prefer the quick version? The sections above cover most needs. Expand any topic below for more detail.

Signs that something is genuinely wrong

Not every odd computer moment is a hack — most slowness is just an ageing machine. These are the signs that do warrant a proper look:

Sign-ins you did not make

Alerts about logins from unfamiliar places, or two-factor codes arriving when you were not trying to sign in. The second one in particular means somebody already has your password.

Email behaving oddly

Contacts receiving messages you did not send, replies to conversations you never had, or messages vanishing from the inbox — often a forwarding rule quietly put in place by someone else.

Something was installed during a call

If a caller had you download anything at all, treat the device as compromised until it has been checked, whatever they told you the software was for.

Passwords that stopped working

A password that suddenly fails on an account you have used for years usually means it has been changed rather than forgotten. Start with the email account attached to it.

If you are unsure whether what you noticed counts, ring and describe it. We will tell you honestly if it sounds like nothing.

What tends to get left behind

The call ends, but the access frequently does not. These are the things we check by hand, because a scan on its own will not catch them:

  • Remote-access software still installed, sometimes renamed or hidden from the start menu
  • Standing permission for an unattended connection, so no one needs to ask you next time
  • Email forwarding or filing rules quietly copying your messages elsewhere
  • An extra recovery email address or phone number added to your account
  • New browser extensions, or a changed home page and search provider
  • Devices and apps still authorised on accounts you have since changed the password on
  • Scheduled tasks or startup entries that reinstate something after a restart

Removing the obvious program while leaving a forwarding rule in place is how people end up compromised twice. The unglamorous checks are the ones that matter.

What we can do, and what we cannot

Being clear about the limits is more use to you than a reassuring promise:

  • We can remove remote-access software and check the device thoroughly for anything left behind
  • We can help you reset passwords and turn on two-factor sign-in in a sensible order
  • We can identify what was signed in and reachable on the device at the time
  • We cannot recover money that has been transferred, or cryptocurrency that has been sent
  • We cannot tell you with certainty everything a person viewed while controlling your screen
  • We cannot give financial or legal advice — your bank and Action Fraud are the right places for that
  • We cannot undo a payment or contact your bank on your behalf

What we can promise is a methodical job and a straight account of it, including the parts where the honest answer is that nobody can be sure.

Not sure what you need? We're happy to help.

Pricing

Scam and Hacked Device Check Pricing

Starting from

£75

A remote check starts from £75, which suits most cases where a caller had access to one computer and you can get online. An in-store check starts from £89 and is the better option if the machine is behaving oddly, if several devices are involved, or if you would simply rather hand it over and have it looked at properly. If the work turns out to be larger than a check — a heavy infection or a full account rebuild — we tell you the price before going on.

Quoted before we start · No judgement · Written summary of what we found

FAQ

Frequently Asked Questions

I let someone have remote access to my computer. What should I do right now?
Disconnect the computer from the internet — unplug the network cable or switch the Wi-Fi off — and stop using it for anything else, particularly banking. Then, from a different device such as a phone, contact your bank if money or card details were involved; they have their own procedure and time matters to them. After that, ring us on 020 7610 0500. Do not delete anything or start uninstalling in a hurry, because what is there tells us what happened. This is one of the most common calls we take, and taking those first two steps quickly puts you in a far better position than most people who ring.
Can you tell me exactly what the scammer saw or took?
Honestly, no, and anyone who promises that is overselling. A remote session can leave traces — what was installed, when it connected, what was open at the time — and we use every trace we can find. But there is no reliable log of everything a person looked at while they had control of your screen. What we can do is establish what was signed in and reachable at the time, which is the practical basis for deciding what to secure. We tell you what we found, what we did not find, and where we simply cannot be certain. That last category is real, and pretending otherwise would not help you.
Can you get my money back?
No. We are a computer repair and IT support business, not a recovery service, and we cannot retrieve money that has been transferred or recover cryptocurrency. Nor can we give financial or legal advice. What matters here is that you contact your bank’s fraud line as quickly as possible, because they handle disputed payments and their own timescales apply, and that you report it to Action Fraud, the UK’s national reporting centre for fraud and cybercrime. Please also be wary of anyone who contacts you afterwards offering to recover your funds for a fee — approaching people who have already been scammed is itself a common second scam. Our part is the technical side: making the device safe and closing off the access.
Do I need to throw the computer away or reinstall everything?
Almost never. In the great majority of cases the device can be properly cleaned and safely kept, which is the usual outcome of this check. A full reinstall is the right call in a minority of cases — a deep or persistent infection, or one where we cannot satisfy ourselves the machine is clean — and we will say so plainly rather than defaulting to the drastic option. Where the problem is a straightforward infection rather than a scam call, virus and malware removal is often all that is needed and costs less.
How quickly can you look at it?
Usually the same day within our opening hours, which are Monday to Friday 10am to 6pm and Saturday 10am to 5pm. If you can get online, a remote session can often begin within minutes of your call, which is the fastest route in most cases. If you would rather not use the machine at all, bring it into the shop at 66 Lower Richmond Road in Putney, or we can arrange free collection and return across South West London. Do tell us if money is involved, because that moves the job up the queue.
My parent has been targeted. Can I arrange this for them?
Yes, and family members book this for a relative all the time. It often works best if you are there for the conversation while the person whose device it is stays in charge of their own accounts and passwords — that keeps them confident rather than sidelined. We take the same care over the tone as over the technical work; nobody is made to feel foolish. If they would also like unhurried help with the day-to-day things afterwards, including how to recognise the next attempt, our patient tech help sessions cover exactly that, at home or in the shop.
How do I stop this happening again?
Two things matter far more than the rest. The first is two-factor sign-in on your email, because email is the master key to almost every other account you own. The second is a rule you can apply under pressure: nobody legitimate — not your bank, not Microsoft, not your broadband provider — will ring you unprompted and ask to control your computer or read out a code. If someone does, hanging up is always the correct response, and you can ring the organisation back on a number you found yourself. For a business, where a single compromised account can reach the whole company, our cybersecurity work covers the wider picture: account protection, staff awareness and what to do when something does slip through.
Should I report it, and to whom?
Yes, please do, even if you did not lose money. Contact your bank first if any payment or card detail was involved. Then report it to Action Fraud, which is the national reporting centre for fraud and cybercrime in England, Wales and Northern Ireland — in Scotland, reports go to Police Scotland. Reporting helps even when nothing is recovered, because patterns of similar reports are how these operations are eventually identified. We can tell you which technical details are worth including, such as what was installed and when it connected, but the report should come from you rather than from us.

See all frequently asked questions

Explore more

Related Case Studies

View all
Explore more

Helpful Guides

View all

How Much Does IT Support Cost in the UK?

What IT support really costs in the UK in 2026 — market rates per user, hourly and ad-hoc pricing, what drives the price, and our own published figures.

Coverage

Service Areas

We provide Hacked or Scammed Device Check in South West London across South West London

Serving Wandsworth, Wimbledon, Putney, Clapham, Balham, Tooting, and surrounding areas.

View all service areas

Worried About a Device? Ring Us

Call 020 7610 0500 and tell us what happened. No judgement, no jargon — just a methodical check of the device and the accounts behind it, and a straight account of what we find.

Same day service available
Fast Response
Expert Technicians