The call usually comes mid-afternoon. A polite man says he is from your internet provider and there is a problem with your connection. He knows your name. He knows roughly where you live. He asks you to open a website so he can run a test, and twenty minutes later he is moving your mouse pointer around your own screen while you watch.
That is a remote access scam, and Australians lost $69.9 million to it in 2025 alone.
The broader picture is worse. Australians reported $2.18 billion in scam losses across 274,577 reports last year, up 7.8 per cent on 2024. Losses have actually come down almost 30 per cent since the 2022 peak, which is genuine progress, but the scams that remain are the sophisticated ones. And they are aimed disproportionately at older Australians: people aged 65 and over account for around 17 per cent of the population but 26.5 per cent of reported scam losses.
If you are reading this because something has just happened, skip to the next section. If you are reading it because you want to be ready, the last two sections matter most.
How to tell if you have actually been hacked
Most people who worry about this have not been hacked. Some people who have been hacked have no idea. Here is what actually indicates a problem.
On your devices:
- Your mouse pointer moves on its own, or windows open and close without you touching anything
- A program you did not install appears, especially anything named like a support or connection tool
- Your browser homepage or search engine changed by itself
- The machine suddenly runs hot and slow with nothing obvious open
- Your antivirus has been switched off and will not switch back on
On your accounts:
- Friends tell you they got a strange message from you
- You receive a password reset email you did not request. This one matters. It usually means someone has your email address and is actively working through your accounts
- Emails you expect are not arriving, which often means a forwarding rule or filter has been added to your inbox by someone else
- A login alert from a city or device you do not recognise
- Small unexplained transactions, often a dollar or two, testing whether the card works
The password reset email you did not ask for is the single most useful early warning, and the one most often ignored.
The first hour, in order
Order matters here. Doing the right things in the wrong sequence can lock you out of your own recovery.
1. Disconnect the device from the internet. Unplug the ethernet cable or turn off Wi-Fi. If someone has remote access, this ends their session immediately. Do not shut the machine down if you can avoid it, because a technician may be able to see what was installed.
2. Move to a different device. Use your phone, a partner's laptop, anything that was not involved. Everything from here happens on the clean device.
3. Change your email password first, not your banking password. This is the step people get wrong. Your email is the master key. Whoever controls it can reset every other account you own by clicking "forgot password". Secure it before anything else, then work outwards to banking, then to everything else.
4. Check your email account's settings, not just the password. Look specifically at forwarding rules, filters and recovery options. A common move is to add a rule that quietly forwards or deletes anything containing the word "bank" or "invoice", then add a recovery phone number the attacker controls. Changing your password does not remove any of that. In Gmail it sits under Settings, then Forwarding and POP/IMAP, and Settings, then Filters and Blocked Addresses. In Outlook, check Rules and Forwarding.
5. Sign out everywhere. Google, Microsoft and Apple all have an option to end every active session on every device. Use it. Otherwise the attacker's existing session may stay alive despite the new password.
6. Call your bank. Use the number on the back of your card, not one from an email, a text or a search result. Tell them plainly that you believe your details are compromised and ask them to place a hold or reissue the card. Australian banks now sit under the Scams Prevention Framework, which places legal obligations on banks, telcos and digital platforms to prevent, detect and respond to scams, so report it properly and in writing.
7. Turn on multi-factor authentication on email and banking if it is not already on. An authenticator app or a passkey is meaningfully stronger than an SMS code, because SMS can be intercepted through a SIM swap.
The scams actually working in Australia right now
Knowing the shape of them is most of the defence.
Investment scams, $837.7 million lost in 2025. By far the biggest category. It typically starts on social media or through a messaging app, moves to a professional looking platform with a dashboard showing your balance growing, and collapses when you try to withdraw. The dashboard is a web page. The money left the moment you sent it. Crypto features heavily because it is fast and hard to reverse.
Phishing, 65,361 reports and the most reported scam of the year. Text messages and emails impersonating Australia Post, myGov, the ATO, toll operators and banks. The modern ones are clean. No spelling errors, correct logos, and a link that goes to a near perfect copy of the real login page.
Payment redirection, $166.8 million. This one hits small businesses hardest. A supplier's email account is compromised, the attacker watches the invoicing for a few weeks, then sends a genuine looking invoice with new bank details. Nothing looks wrong because nothing is fake except the account number. Every business should have a rule that changed bank details are verified by phone, on a number you already had, before payment.
Romance scams, $139.9 million. Long build, no rush, and money is never requested early. The request when it comes is usually framed as a temporary problem: a medical bill, a customs fee, a frozen account.
Remote access, $69.9 million. The nbn, Telstra and Microsoft impersonations. Real point worth remembering: your internet provider will never ring you unprompted and ask for access to your computer. Neither will Microsoft, ever, and neither will the ATO.
Text message scams did drop sharply in 2025, from 77,365 reports to 29,058, which suggests the SMS blocking work by telcos is having an effect. Online scams through websites and social media rose 31.8 per cent over the same period. The traffic simply moved.
What not to do
Do not call the number in the pop-up. The frightening full screen warning saying your computer is infected and to call a support line is the scam. Close the browser. If it will not close, hold the power button.
Do not accept a refund. A common second act is a call offering to refund money you lost, which requires access to your banking to process. This is the same crew coming back for the rest.
Do not let anyone stay connected while you sort it out. If someone is on your machine right now, disconnect first and ask questions later.
Do not be embarrassed into silence. The single biggest factor in how much someone loses is how long they wait before telling their bank. These operations are professional, well funded and rehearsed. Falling for one says nothing about your intelligence.
Who to report to in Australia
- Your bank, immediately, before anything else on this list
- Scamwatch at scamwatch.gov.au, run by the National Anti-Scam Centre
- ReportCyber at cyber.gov.au, for cybercrime including hacking
- IDCARE at idcare.org, the national identity and cyber support service, and the right call if your identity documents are involved
- Australian Cyber Security Hotline on 1300 CYBER1, which is 1300 292 371, for 24 hour advice
- The ATO if your tax file number or myGov account may be exposed
The twenty minutes that prevents most of this
You do not need to become a security expert. You need four things.
A password manager. The real risk is not a weak password, it is the same password across forty sites. One breach anywhere then unlocks everything. A password manager fixes this permanently and takes about fifteen minutes to set up.
Multi-factor authentication on email and banking. Passkeys where offered, an authenticator app otherwise, SMS as a last resort.
Automatic updates on. Most successful attacks use holes that were patched months ago.
A separate email address for banking and government. Not published anywhere, not used for shopping or newsletters. It costs nothing and it removes your most sensitive accounts from every future data breach list.
Common questions
What should I do first if I think I have been hacked?
Disconnect the device from the internet, move to a different device, then change your email password before anything else. Your email is the master key, because whoever controls it can reset every other account you own. After that, check your email settings for forwarding rules and unfamiliar recovery numbers, use the sign out everywhere option, and call your bank on the number printed on your card.
How do I know if my email account has been hacked?
The clearest early warning is a password reset email you did not request, which usually means someone has your address and is working through your accounts. Other signs are friends receiving strange messages from you, expected emails not arriving because a filter or forwarding rule was added, login alerts from places you do not recognise, and small test transactions of a dollar or two on your card.
Will changing my password remove a hacker from my email?
Not on its own. A password change does not delete a forwarding rule, a filter, or a recovery phone number the attacker added, and an existing logged in session can survive. Check your mail rules and recovery options, then use the sign out of all devices option, and turn on multi-factor authentication with a passkey or an authenticator app rather than SMS.
Who do I report a scam to in Australia?
Your bank first, immediately. Then Scamwatch at scamwatch.gov.au, run by the National Anti-Scam Centre, and ReportCyber at cyber.gov.au for hacking and cybercrime. IDCARE at idcare.org is the national identity and cyber support service and is the right call if identity documents are involved. The Australian Cyber Security Hotline is 1300 CYBER1, which is 1300 292 371.
When to get someone in
Some of this is genuinely hard to do alone, particularly if someone had remote access to the machine. Once a stranger has been on your computer you cannot assume anything on it is clean, and hunting down what was installed is not a job for guesswork.
HelloTech technicians come to you and handle the whole job: checking whether anything is still running on the machine, removing it properly, working through your accounts to lock them down, checking for the mail forwarding rules and recovery numbers people miss, and setting up a password manager and multi-factor authentication so it does not happen again. We also do plain English digital security checks for people who simply want to know where they stand before something goes wrong.
If something has happened today, call your bank first, then book a HelloTech technician and we will sort the rest.



