I recently opened an email that appeared to come from my dentist's office. It asked me to click a link and install a program to view a document. Shortly afterward, I noticed the cursor moving on its own, so I'm concerned that I may have given a scammer remote access to my laptop. I deleted the program and performed a factory reset, although I'm planning to have the laptop professionally wiped and Windows reinstalled from trusted installation media.
I contacted my bank and credit card companies, froze the affected accounts, and requested replacement account details. I also changed the passwords for all my accounts, froze my credit reports with the three major credit bureaus, and stopped using the laptop. So far, I haven't noticed suspicious logins, unfamiliar locations, account alerts, or any problems accessing my email and other accounts.
How serious might this have been? Could the attacker have accessed files that I deleted months earlier, including potentially sensitive documents? Is there anything else I should do, such as enabling additional security measures, revoking active sessions, or monitoring my identity and accounts?
4 Answers
For your important accounts, enable multifactor authentication—preferably with an authenticator app or security key—then sign out of all existing sessions and revoke any connected apps or saved access tokens. Make sure your email account is secure first, since it can often be used to reset other passwords. Continue checking credit reports and account activity, and report anything unfamiliar promptly.
Treat this as a useful warning rather than something to keep replaying in your head. Review the original message for clues such as an unexpected sender address, unusual wording, mismatched links, or pressure to install software. In the future, verify unexpected document requests through a known phone number or website instead of using the message’s link.
You acted quickly and covered most of the important steps: contacting financial institutions, replacing compromised account details, changing passwords, freezing your credit, and wiping the laptop. Keep monitoring your bank accounts, credit reports, email, and account security logs for a while, but there’s no need to assume the worst if nothing suspicious appears.
Deleted files can sometimes be recovered with specialized tools, but that doesn’t mean the attacker actually searched for or copied them. A phishing incident that gives someone remote access does not automatically mean they examined every deleted file. If the laptop contained anything especially sensitive, a complete wipe and clean operating-system installation is the safest approach.
That makes sense. I’m still worried about what might have happened during the short window of access, but I’ll try to focus on the precautions I can control now.

I definitely learned from it, although I’m disappointed that I didn’t recognize the warning signs sooner. I’ll be much more cautious about unexpected attachments and software requests going forward.