PanicStation.org
uk Technology & digital loss

What to do if…
you suspect someone has remote access to your computer because the cursor is moving on its own

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy UK guide

Short answer

Disconnect the computer from the internet now, and stop typing passwords or opening sensitive accounts on it. Use a different trusted device to secure your email and financial accounts first.

Do not do these things

  • Don’t keep “testing” by logging into email, banking, shopping, work, or password-manager accounts on that computer.
  • Don’t install random “anti-hack” tools or accept help from anyone who contacted you unexpectedly.
  • Don’t pay anyone to “fix it” if they approached you first.
  • Don’t give anyone a remote-access code, screen-sharing code, password, one-time code, or banking approval.
  • Don’t sign into a password manager on the suspected computer until you have secured it from another device.
  • Don’t factory reset a work, school, or managed device before contacting IT, because you may remove information they need.

What to do now

  1. Get the computer offline.
    Unplug any Ethernet cable. Turn off Wi-Fi using a hardware switch, keyboard shortcut, router switch, or Wi-Fi menu if you can do that without typing sensitive information. If the cursor is actively moving and you cannot safely control the computer, hold the power button to shut it down.

  2. Use a different trusted device for account security.
    Use a phone, tablet, or computer that you do not think is affected. Start with:

    • email accounts, because they control password resets
    • banking and payment accounts
    • your main Apple, Google, Microsoft, or work account
    • your password manager, if you use one
  3. Secure email first.
    Change the email password. Check for unfamiliar forwarding rules, filters, recovery email addresses, recovery phone numbers, and signed-in devices if your email provider shows them. Sign out of other sessions or devices where the account offers that option.

  4. Secure money-related accounts next.
    Check recent transactions from a trusted device or by using the official number on your bank card. If you see a payment you did not authorise, or if you gave someone remote access while banking was open, contact your bank promptly.

  5. If this is a work, school, or managed computer, stop and contact IT.
    Tell them you suspect unauthorised remote control, that the cursor moved without you, and that the device is offline or shut down. Follow their instructions before scanning, deleting apps, or resetting the computer.

  6. Write down what happened.
    Note the date and time, what you saw, any remote-access app names, any pop-up messages, and whether you typed passwords or opened banking. If it is safe, take a photo or short video using your phone rather than using the suspected computer.

  7. Check only obvious remote-access clues while offline, if you can do that safely.
    Look for unfamiliar remote-access apps, browser downloads, recently installed programs, or unfamiliar user accounts. Do not open unknown files, click pop-ups, or reconnect to the internet just to investigate.

  8. Keep the computer offline until there is a safe clean-up plan.
    A trusted IT person, the device maker’s support route, or reputable security support may advise a scan, removal of remote-access software, a reset, or a reinstall. If it is a managed device, let IT decide.

  9. Report through the correct UK route if money, accounts, or personal data may be at risk.
    In England, Wales, or Northern Ireland, use Report Fraud for cyber crime or fraud. In Scotland, report cybercrime to Police Scotland online, by phone, or in person; use 101 for non-emergencies. If there is immediate danger or a crime is happening now, call 999.

What can wait

  • You do not need to decide right now whether to wipe or reinstall the computer.
  • You do not need to identify who may have done it today.
  • You do not need to check every account immediately; secure email and financial accounts first, then work outward.
  • You do not need to buy new software while panicked.
  • You do not need to reply to anyone who is pressuring you to reconnect the computer.

Important reassurance

Cursor movement can be caused by ordinary issues such as a faulty mouse, touchpad sensitivity, lag, accessibility settings, or a connected device. Treating it as a possible compromise for now is still sensible: disconnecting, securing accounts from another device, and slowing down are reversible steps.

Scope note

These are first steps only to reduce harm and buy time. Later decisions, such as scanning, reinstalling, recovering money, or handling a work device, may need specialist technical support, your bank, your IT team, or the correct reporting route.

Important note

This is general information, not legal, medical, financial, therapeutic, technical, or other professional advice. If you believe a crime is in progress, someone is threatening you, or there is immediate risk to safety, contact emergency services.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us