My sister owns a business with employees on payroll. Overnight, someone accessed her payroll account and attempted to transfer $150,000 to themselves. The payroll provider detected the fraud and locked the account, and the bank has been contacted to freeze things. The money still appears to be in the account, but the transfer may already be in progress. The login reportedly came from her laptop around 5 a.m., and the attacker may also have accessed her email because they received the multi-factor authentication code. The laptop is currently powered off. Before reinstalling Windows from a USB drive, we want to know whether a clean installation is enough to remove the attacker and what other steps we should take to protect the business, preserve evidence, and prevent another fraudulent transfer.
4 Answers
Because this involves a large attempted business payment, report it immediately to the bank's fraud department, the payroll provider, and law enforcement. Ask the bank whether the transfer can be recalled or blocked and document every case number, time, and person contacted. Bring in a qualified incident-response or cybersecurity firm rather than wiping the machine right away; destroying the evidence could make it harder to determine how the attacker got in and whether other systems were affected.
A clean Windows installation from a properly prepared USB drive will remove normal remote-access tools and other malware stored on the system, but don't treat that as the whole solution. First, keep the laptop powered off and preserve it in case law enforcement, the bank, or a cybersecurity investigator needs to examine it. From a separate, trusted device, change passwords for the email, payroll, banking, and administrator accounts. Also review account recovery methods, active sessions, forwarding rules, delegated access, and where MFA codes are being sent. Make sure the new passwords aren't reused anywhere else.
After the investigation or evidence collection is complete, a full wipe and clean reinstall is reasonable, but download the installer and create the USB using a separate trusted computer. Fully erase the system drive, reinstall Windows, apply all updates, enable disk encryption and a standard user account, and reinstall software only from official sources. Before reconnecting it to business accounts, make sure endpoint protection, automatic updates, and strong MFA are enabled.
Use a known-clean device or a newly purchased computer for the password resets and financial work. Check the email account carefully for suspicious forwarding rules, newly added recovery addresses, unfamiliar devices, app passwords, and changed MFA settings. Reset the business email and financial-account MFA, preferably using a hardware security key or an authenticator app instead of relying only on email or text. Also change the router and Wi-Fi administrator credentials and update its firmware, especially if the laptop had administrative access.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures