I accidentally opened an email that appeared to come from my dentist's office and clicked a link to download a program so I could view a document. Shortly afterward, I noticed my cursor moving on its own, so I'm worried that I gave a scammer remote access to my laptop. I deleted the program and performed a factory reset, but I don't know what the attacker may have accessed before then. I'm also wondering whether they could have recovered files I deleted months earlier.
I contacted my bank and credit card providers, froze the affected accounts, and had new account information issued. I changed passwords for all my accounts, froze my credit reports with the three major credit bureaus, and haven't noticed suspicious logins, unfamiliar locations, account alerts, or problems accessing my email since the incident last week. The laptop is powered off, and I plan to have it professionally wiped and reinstall the operating system from trusted installation media.
How serious could this be, and is there anything else I should do? Should I be concerned about deleted documents or continue taking additional precautions with my accounts?
4 Answers
For your important accounts, enable multifactor authentication, preferably with an authenticator app or security key rather than text messages when possible. Also sign out of all existing sessions, revoke unfamiliar connected apps, review email forwarding rules and recovery details, and make sure your passwords are unique. Continue monitoring credit reports and financial statements for several months.
Deleted files can sometimes be recovered with specialized forensic tools, depending on how the drive was used and whether the data was overwritten. However, that doesn’t mean the scammer recovered them. A basic phishing attack or remote-access session does not automatically prove that every deleted file was searched or copied. If the laptop contained especially sensitive information, professional wiping or replacing the drive is the safest approach.
It’s understandable to feel shaken, but you acted much faster than many people do. Going forward, inspect unexpected messages carefully: check the real sender address, avoid opening unsolicited attachments or installers, and verify unusual requests through a known phone number or website instead of using the message’s link. Reviewing what made the email look convincing can help prevent a repeat.
You’ve already handled most of the important steps: contacting the financial institutions, replacing account details, changing passwords, freezing your credit, and wiping the laptop. Keep checking your bank, card, email, and account-security activity for a while, but there’s no clear sign from what you described that the attacker still has access.

Thanks, I tried to deal with everything as quickly as possible. The uncertainty has been stressing me out, but I’m trying to move on and stay vigilant.