My elderly father gave personal details to obvious phone scammers before I realized what was happening and took over the call. The laptop's sign-in screen appeared to say that it was blocked, although I'm not certain of the exact wording. I disconnected the Wi-Fi and ended the call before they could request payment. We've contacted the banks, cancelled the cards, and changed many passwords, including the Microsoft account password. So far, there are no obvious unauthorized bank transactions, Microsoft sign-ins, or suspicious emails. I'm planning to perform a clean Windows installation, but I'd like to know whether that is sufficient and what else we should check. Would setting up a standard, non-administrator account help prevent something similar in the future?
3 Answers
The biggest long-term protection here is changing the routine, not just adding another antivirus program. Tell him to end unexpected calls and never allow remote access or read out verification codes. Use an ad blocker and keep Windows Defender enabled, but don’t rely on security software to identify every scam. A standard account, automatic updates, password manager, and two-factor authentication will help, while keeping him on Windows avoids the confusion of switching to an unfamiliar operating system.
It isn’t clear that the laptop was hacked at all. These scams often rely on persuading someone to install a tool, read out a code, or send money rather than exploiting the computer directly. If there was definitely remote access, reinstall Windows and update it fully afterward. If not, the reinstall is still a reasonable precaution. Once it’s set up again, make your father a standard user instead of an administrator so installing software requires your approval.
If the scammers had remote access or persuaded him to install remote-control software, a clean Windows reinstall is the sensible way to remove it. Before reinstalling, use a separate trusted device to change important passwords and enable two-factor authentication wherever possible. Also check bank statements, email account security activity, and the Microsoft account’s recent sign-ins. A clean install won’t undo stolen information, so continue watching the accounts for a while.
That makes sense. We’ve already contacted the banks and changed the main passwords, and I’ll check the account activity and add two-factor authentication where it’s available.

We don’t know exactly what he clicked or entered, but there’s no sign that money was taken or that the Microsoft account was accessed. I’ll set up a standard account for him after reinstalling Windows.