Body
Overview
A malicious actor can gain unauthorized control of a computer, but it usually requires a path into the device or an account connected to it. Common paths include malicious software, an unsafe remote-access session, a stolen password, an unpatched security flaw, a harmful browser extension, or physical access to an unlocked device.
Knowing your email address, phone number, IP address, or name is not normally enough by itself to control your computer. Simply receiving a suspicious message also does not mean the device has been taken over. Risk increases when you open a harmful file, install software, run a command, grant remote access, enter credentials on a fake site, approve an unexpected MFA request, or use software with an exploitable vulnerability.
An account compromise and a computer compromise are related but different. Someone may gain access to an email, social-media, or cloud account without controlling the physical device. Conversely, malware on a device may capture information from several accounts. The correct response depends on what happened.
How a Computer Can Be Taken Over
Unauthorized access can occur through:
- Malware. A harmful program may be disguised as an attachment, application, browser update, game, utility, cracked software, or document.
- Remote-access software. A scammer may persuade you to install or open a legitimate remote-support tool and then misuse the session.
- Malicious commands. A fake error, CAPTCHA, or verification page may instruct you to open Run, Command Prompt, PowerShell, or Terminal and paste a command that installs malware.
- Stolen credentials. An attacker may use a stolen password, session token, recovery code, or MFA approval to access remote-management, cloud, or administrative services.
- Unpatched vulnerabilities. Outdated operating systems, browsers, applications, routers, or plugins may contain security flaws that can be exploited.
- Malicious browser extensions or applications. Software with broad permissions may read browsing activity, change pages, capture information, or install additional components.
- Physical access. A person with access to an unlocked computer may copy files, install software, add an account, or change security settings.
- Supply-chain or service compromise. In less common cases, a trusted vendor, update channel, website, or service may be compromised and used to distribute malicious content.
Many attacks still depend on social engineering. The attacker creates urgency, fear, curiosity, or a technical problem so that the user performs an action that gives the attacker access.
What Unauthorized Control Can Allow
The level of access depends on the method used and the permissions obtained. An attacker may be able to:
- View, copy, alter, delete, or encrypt files.
- Observe activity on the screen or capture typed information.
- Install additional software or create new accounts.
- Change security, browser, network, or startup settings.
- Access email, cloud storage, financial services, or other accounts used on the device.
- Use the camera or microphone when the malware or application has the necessary access.
- Send messages, distribute malware, or conduct fraud through accounts available on the computer.
- Use the computer as a path to other devices or services.
Not every unusual computer problem is evidence of an attacker. Slow performance, application crashes, battery drain, pop-ups, and network problems can have many causes. Avoid making major changes or purchasing software based only on a frightening pop-up or an unsolicited caller's claim.
How to Protect Yourself
- Install updates promptly. Keep the operating system, browser, applications, security software, and device firmware current. Turn on automatic updates when practical.
- Use built-in security protections. Keep antivirus or anti-malware protection, the firewall, and browser security features enabled.
- Install software from trusted sources. Use official application stores, the vendor's verified website, or an approved UM software source.
- Do not grant remote access to an unexpected caller or message sender. Initiate support through a phone number, website, or help system you already trust.
- Do not run commands for a CAPTCHA or browser security check. Legitimate human-verification and browser security checks do not require you to open Run, Command Prompt, PowerShell, or Terminal and paste a command.
- Review what an installer requests. Stop when an unfamiliar application asks for administrator access, security exclusions, browser control, screen recording, accessibility access, or other broad permissions without a clear reason.
- Use strong, unique passwords and MFA. Protect email and other accounts that can reset passwords or manage the device.
- Use a screen lock. Lock the computer when you step away and do not allow untrusted people to use an authenticated session.
- Review applications and browser extensions. Remove software you no longer need or do not recognize. Do not disable security controls merely because a website or caller tells you to do so.
- Back up important files. Maintain backups appropriate to the value of the information and confirm that important files can be restored.
- Use a standard account for routine work when practical. Limiting administrative privileges can reduce what some malicious software can change.
- Pause when a request creates urgency. A claim that your computer is infected does not become trustworthy because a pop-up, caller ID, logo, or technical-looking screen appears convincing.
If You Suspect Unauthorized Access
Stop sensitive activity on the affected computer. Do not continue banking, shopping, password changes, or access to confidential information until the device has been assessed.
If someone is actively controlling the computer, files are being encrypted, or unfamiliar actions are occurring, end the remote session if you can do so safely and disconnect the device from the network. Record what happened, including the time, message, website, phone number, software name, commands run, and accounts used.
UM device or account
For a UM-owned or UM-managed computer, or when a UM account or university data may be involved:
- Contact the UM IT Helpdesk or UM Information Security Office promptly from another device.
- Describe exactly what occurred. Include whether you installed software, allowed remote access, ran a command, entered a password, approved MFA, or observed someone controlling the device.
- Do not erase, reset, reimage, or continue troubleshooting the computer unless UM support directs you to do so. Those actions can remove information needed to assess the incident.
- Change an exposed UM password through the normal UM account-management process from a trusted device. Deny further unexpected MFA requests.
- Follow UM instructions for disconnecting, transporting, or returning the device.
Personal device or account
For a personal computer that does not involve UM:
- Disconnect an active remote-access session and remove the device from the network when unauthorized control appears to be continuing.
- Contact the device manufacturer, operating-system provider, internet service provider, or another trusted technical-support service using contact information you locate independently.
- Use reputable, current security software and follow the provider's official malware-removal guidance. Do not download a “cleanup” tool from the same pop-up, message, or caller that reported the problem.
- From a separate trusted device, secure accounts that may have been exposed. Change unique passwords, review MFA and recovery methods, sign out other sessions when available, and check for unauthorized changes.
- Contact the financial institution or payment provider immediately if banking, card, or payment information was visible, entered, or used while another person had access.
Use IdentityTheft.gov when identifying information has been used or is at meaningful risk of misuse. A suspected device infection without identity misuse does not automatically require an identity-theft report.
Additional Questions
For possible unauthorized access involving a UM device, UM account, university information, or a UM system, contact the UM IT Helpdesk and the UM Information Security Office.
For a personal device or account:
- Contact the device manufacturer, operating-system provider, internet service provider, security-software provider, or another trusted technical-support service through an independently verified channel.
- Contact the relevant account provider through its official recovery process if an online account was compromised.
- Contact your bank, credit union, card issuer, or payment provider immediately if financial information or money was involved.
- Report internet-enabled crime to the FBI's Internet Crime Complaint Center and consumer fraud to the Federal Trade Commission when appropriate.
Additional Resources