My elderly father gave personal details to obvious phone scammers before I intervened. The laptop's sign-in screen appeared to say that something was blocked, although I'm not sure exactly what it showed. I disconnected the Wi‑Fi and ended the call before they could ask for money. I don't know whether they actually gained remote access or whether they were simply trying to frighten him into paying.
We've contacted the banks, cancelled the cards, changed the Microsoft password and updated several other passwords. So far, there are no suspicious bank transactions, Microsoft sign-ins or unusual emails. Would a clean Windows reinstall be enough, and is there anything else we should check or do?
5 Answers
Changing passwords from a different, trusted device was the right move. Add two-factor authentication wherever possible, sign out unknown sessions, and contact the banks again if any suspicious activity appears. You probably don’t need to move him to a completely different operating system; that could create more confusion than it solves. Training and restricting administrative access are likely to help more.
It isn’t clear that the computer was hacked at all. Many scams rely on alarming messages, fake warnings and persuading the victim to install remote-support software or make a payment. If your father didn’t approve a remote connection or download anything, they may never have accessed the laptop. Even so, reinstalling Windows is reasonable if you want certainty; also check the browser for unfamiliar extensions and review recent account sign-ins.
If the scammers definitely had remote access, a clean Windows reinstall is a sensible way to remove anything they may have installed. Before restoring files or signing back in, install all updates, enable Windows Security, and make sure the important accounts use unique passwords and two-factor authentication. Keep monitoring bank and email activity for a while as well.
For prevention, give him a standard Windows account instead of an administrator account. He can still browse and use email, but installing software will require an administrator approval. Set up an administrator account that only you control, keep automatic updates and Defender enabled, and consider an ad blocker. Most importantly, agree on a rule that unexpected callers claiming there is a computer problem should be hung up on and verified independently.
A standard account is exactly what I was looking for. I’d like anything installed or changed on the computer to require my approval.
A full reinstall should be enough for an ordinary remote-support scam, provided you erase the system partition and reinstall from official Windows media. Save only personal documents and scan them before copying them back. An offline Defender scan can be an additional check, but antivirus results alone can’t prove that a machine is perfectly clean.

That makes sense. We disconnected the laptop quickly, and there’s no sign that they accessed the accounts, but I’d rather reinstall it to be safe.