What to do if…
your computer suddenly shows a new local administrator account you did not create
Short answer
Treat this as a possible compromise. Disconnect the computer from networks now, avoid using it for sensitive accounts, and secure your email and money accounts from a different trusted device.
Do not do these things
- Don’t use this computer for email, banking, password managers, work systems, or shopping until it has been checked.
- Don’t delete the suspicious administrator account yet unless a trusted IT or security professional tells you to.
- Don’t make lots of changes, such as disabling services, uninstalling software, editing system settings, or running commands from forums.
- Don’t install random “cleanup”, “driver”, or “security” tools.
- Don’t let anyone you did not contact first remote into the device.
- Don’t enter new passwords on the suspect computer.
What to do now
-
Isolate the device.
Turn off Wi-Fi, unplug Ethernet, stop mobile tethering, and disconnect any VPN if you can see it. If it is safe and simple, unplug unknown USB devices. -
Capture only the basics.
Take a photo or screenshot of:- the login screen showing the new account name
- any user list you can see without digging
- any warning, pop-up, or security alert that appeared at the same time
Write down the exact account name and when you first noticed it.
-
If it is work, school, or IT-managed, stop and escalate.
Contact your IT helpdesk or security team and say: “A new local administrator account appeared that I didn’t create. I have taken the device offline.” Don’t try to fix it yourself unless they instruct you to. -
From a different trusted device, secure your key accounts.
Use your phone or another computer that you trust to:- change your primary email password first
- change banking, finance, and password-manager passwords if you used them on this computer
- turn on or re-check multi-factor authentication
- sign out of other sessions where the service gives you that option
If you reused the same password elsewhere, change it there too.
-
Check whether the account is real only if you can do this safely.
If you can sign in with a known-good account you already trust, use the computer’s built-in user management screen to check whether:- the unknown account exists
- it has administrator privileges
- your usual account’s privileges changed
If you are unsure, skip this and get help.
-
Scan using trusted tools only.
On Windows, Microsoft Defender Offline can restart the computer and scan outside normal Windows, then you can run a full scan afterwards. On Mac or Linux, use built-in security tools, a reputable security product you already trust, or in-person professional support. Do not download a tool from a pop-up, advert, or unknown support site. -
Use the safer recovery path if the account looks unauthorised.
If the account was truly unauthorised, keeps returning, your privileges changed, or a scan finds malware, a safer recovery path is usually:- back up only irreplaceable personal files, such as documents and photos
- avoid backing up programs, installers, scripts, or unknown files
- wipe or reset the device and reinstall the operating system from trusted sources
- restore files only after scanning them
If you are not confident, use reputable in-person support rather than an unknown remote-fix offer.
-
If money was lost or you were scammed, report it and tell your bank.
Contact your bank or payment provider promptly using a known phone number, app, card number, or official website. In England, Wales, or Northern Ireland, fraud and cybercrime are generally reported through Report Fraud. In Scotland, fraud is generally reported to Police Scotland by phone, online, or in person. If there is immediate danger or a crime is happening now, call 999.
What can wait
- You do not need to work out who did it right now.
- You do not need to decide immediately whether to wipe or replace the computer.
- You do not need to contact every service at once; start with email, banking, finance, and password-manager accounts.
- You do not need to prove exactly how it happened before asking for help.
Important reassurance
A surprise administrator account is a reasonable reason to pause and take it seriously. Disconnecting the device and protecting your key accounts from another device are strong first steps even before you know the full cause.
Scope note
These are first steps only to reduce harm and buy time. Later decisions about forensic checks, rebuilding the device, workplace incident handling, insurance, reporting, or legal issues may need specialist help.
Important note
This is general information, not professional IT, legal, financial, security, therapeutic, or other professional advice. If the device is owned or managed by your employer, school, or another organisation, follow their security process.
Additional Resources
- National Cyber Security Centre — Mitigating malware and ransomware attacks
- National Cyber Security Centre — Malware
- GOV.UK — Where to Report a Cyber Incident
- GOV.UK — Avoid and report internet scams and phishing
- Stop! Think Fraud — Reporting fraud
- Police.uk
- Police Scotland — Scams and frauds advice from Police Scotland
- Microsoft — Microsoft Defender Offline scan in Windows - Microsoft Defender for Endpoint
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.