My sister runs a company with employees on payroll, and someone recently accessed her payroll account and attempted to transfer $150,000. The payroll provider detected the transaction and locked the account, and the bank has been contacted to freeze things. So far, the money is still in the account, but the transfer may already be processing. The login reportedly came from her laptop early in the morning, and the attacker may also have accessed her email because they were able to obtain the multi-factor authentication code. We have powered off the laptop and are trying to decide what to do next. Would completely wiping and reinstalling Windows from a USB drive be enough, or are there other steps we should take to protect the business, preserve evidence, and prevent another unauthorized transaction?
4 Answers
A clean Windows installation should remove ordinary remote-access tools and other malware installed on the laptop, but it should not be the first step if there is any chance the device will be investigated. Keep the laptop powered off and disconnected from all networks, and get qualified incident-response or cybersecurity help before wiping it. In the meantime, have the bank and payroll provider stop or recall the transfer and monitor every related account.
Treat every account that may have been exposed as compromised. From a known-clean device, change the email, banking, payroll, cloud, and other important passwords, using unique passwords for each account. Check email forwarding rules, recovery addresses, logged-in sessions, app passwords, and authorized devices. Also verify where MFA codes are being sent and replace or reset any compromised authenticator, phone number, or recovery method.
If professionals confirm that the laptop can be rebuilt, use a trusted installation USB, completely erase the system drive, reinstall Windows, apply all updates, and restore only verified files. Before using it for payroll again, enable MFA with a strong authenticator or security key where possible, limit payroll permissions, require approval for large transfers, and review account alerts and audit logs. A wipe fixes the computer itself, but it will not secure an email, bank, or payroll account that the attacker already accessed.
Because this is a business and a large attempted transfer is involved, contact law enforcement, the bank's fraud department, the payroll provider, and a professional incident-response team. Preserve the laptop and any phone used for MFA in their current state if possible. Do not reconnect them, browse through them, or reinstall Windows until evidence has been collected or investigators say it is safe. Change the router and Wi-Fi administrator credentials from a clean device as a precaution, but avoid destroying logs if someone is helping investigate the network.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures