What to do if…
your computer firewall settings changed and you did not change them
Short answer
Disconnect the device from the internet or network, then record what changed before you alter it. Until you can explain the change, avoid using that device for banking, email, password managers, or work systems.
Do not do these things
- Don’t keep using the device for sensitive accounts “just to finish something”.
- Don’t install “fix” tools from pop-ups, unknown websites, adverts, or unsolicited support messages.
- Don’t turn off antivirus, endpoint protection, or other security tools to make warnings disappear.
- Don’t wipe or reset the device before recording the basics, especially if it is a work, school, or managed device.
- Don’t assume the change is harmless only because the firewall is now on; the concern is the unexpected change.
- Don’t argue with the settings while you are panicking. Contain first, record second, then check.
What to do now
-
Disconnect the device from networks. Turn off Wi-Fi, unplug Ethernet, stop any mobile tethering, and turn off Bluetooth if you use it for nearby connections. This buys time and reduces the chance of more unwanted access.
-
Record what you can see before changing it. Take screenshots or phone photos of:
- the firewall page showing the current state
- any allowed apps, exceptions, inbound rules, or outbound rules you can see
- the date and time on the device
- any warning, admin prompt, or security notification linked to the change
-
Write down the recent context. Note any recent updates, new apps, remote-support sessions, VPN changes, USB devices, router changes, or work/school logins. Keep it brief; you are making a timeline, not solving everything now.
-
If it is a work, school, or managed device, stop and contact IT or security. Many organisations change firewall settings through device management or policy. Tell them: “The firewall settings changed and I did not change them.” Follow their instructions before reconnecting.
-
Check for an obvious legitimate cause without getting stuck.
- Windows: Open Windows Security and check Firewall & network protection. If you know how to use Event Viewer, check the Security log around the time you noticed it. Event ID 4950 can show a local Windows Firewall setting change when the relevant auditing is enabled, but policy-pushed changes may not appear that way.
- macOS: Go to Apple menu, System Settings, Network, Firewall. Open the firewall options and note any app or service you do not recognise.
- Router: If the change is on your router rather than the computer, do not sign in from the suspicious device. Use another trusted device if you need to check the router admin page.
-
Run a scan using security software you already trust. Use your existing antivirus, endpoint protection, or built-in security tool. If it needs updates, reconnect only long enough to update the operating system and security tool, then run a full scan.
-
Protect important accounts from a different device. Use a phone or computer you believe is safe. Prioritise email, banking, password manager, work accounts, and any account used for password resets. Change passwords where needed and turn on two-step verification where available.
-
If several devices or the router seem affected, treat the network as suspect for now. Avoid sensitive sign-ins on that network. If you think active misuse is happening and you can tolerate the disruption, disconnect the router from the internet until you can check it safely.
-
If money, accounts, or personal data have been misused, act on that harm. Contact your bank immediately about unauthorised payments or card use. If you are in England, Wales, or Northern Ireland, report cyber crime or fraud to Report Fraud. If you are in Scotland, contact Police Scotland on 101 for non-emergency reporting. If a crime is happening now or there is immediate danger, call 999.
What can wait
- You do not need to decide now whether to wipe the device, replace it, or rebuild everything.
- You do not need to fully understand firewall rules today.
- Router firmware updates, perfect home-network hardening, and long-term password reorganisation can wait until the device is contained and key accounts are protected.
- You do not need to prove whether it was malware, an update, or device management before asking IT, a trusted repair professional, or your bank for help.
Important reassurance
An unexpected firewall change is worth taking seriously, but it does not prove that everything is lost. Disconnecting, recording the change, checking for a managed-device explanation, scanning, and protecting key accounts are calm first steps that reduce the chance of things getting worse.
Scope note
These are first steps only: contain the risk, avoid irreversible mistakes, and get the right help involved. Repeated changes, signs of remote access, business systems, or a managed device may need IT or security support.
Important note
This is general information, not personalised technical, legal, financial, security, or professional advice. If you cannot quickly confirm the firewall change was legitimate, it is safer to treat it as suspicious until checked.
Additional Resources
- National Cyber Security Centre — How to recover an infected device
- National Cyber Security Centre — Malware
- National Cyber Security Centre — Mitigating malware and ransomware attacks
- Apple Support — Change Firewall settings on Mac
- Microsoft — Firewall and network protection in the Windows Security app
- Microsoft — 4950(S): A Windows Firewall setting has changed.
- Police.uk
- Police Scotland — You’ve accepted all cookies
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.