What to do if…
your computer firewall settings changed and you did not change them
Short answer
If it is safe to do so, isolate the device from the internet and treat the change as a possible compromise until you can explain it. Record what you saw, then use a different trusted device to protect key accounts and get help if needed.
Do not do these things
- Don’t keep logging into email, banking, payroll, tax, or work systems from that device.
- Don’t click “allow” prompts for apps, ports, or services you do not recognize.
- Don’t download “fix” tools from pop-ups, search ads, unknown websites, or unsolicited support messages.
- Don’t give remote access to anyone who contacted you unexpectedly.
- Don’t wipe or reset the device immediately if it belongs to work or school, or if you may need records of what happened.
- Don’t treat “restore defaults” as proof the cause is gone.
What to do now
-
Isolate the device. Turn off Wi-Fi, unplug Ethernet, and disconnect any VPN. If you cannot do that calmly or safely, shut the device down for now.
-
Record the change before altering settings. Use your phone to photograph:
- the firewall on/off status;
- any new allowed apps, exceptions, ports, or inbound rules;
- the network profile, such as public, private, or domain;
- the date and time shown on the device;
- any recent warning or permission prompt.
-
Think of the last ordinary thing that happened. Write down whether this followed an operating system update, new app install, game install, work policy update, email attachment, USB device, remote support session, or router change. Do not spend long on this.
-
If it is a work or school device, stop and contact IT or security. Managed devices can have firewall settings changed by policy. Do not reconnect the device or “fix” rules yourself unless they tell you to.
-
Check the firewall screen without making unnecessary changes.
- Windows: Open Windows Security, then Firewall & network protection. Look for the active network profile and any warning that the firewall is off. If you know how to use Event Viewer, you can note Windows Firewall events near the time you noticed the change; Event ID 4950 may appear when a Windows Firewall setting change is logged.
- Mac: On recent macOS versions, open System Settings, then Network, then Firewall. Review Firewall options and note any app or service you do not recognize.
-
Remove only clearly unwanted exposure if you must reconnect. If you need the device online briefly to update security tools, avoid sensitive logins. Do not leave an unknown app allowed through the firewall, and do not leave an unknown open port enabled unless IT or a trusted technician confirms it is needed.
-
Run trusted security checks. Use the built-in or already-installed security tool, or a security tool from the operating system vendor or your organization. Update it from a trusted source when you can do so safely, then run a full scan.
-
Protect high-value accounts from a different trusted device. Start with email and any accounts that can reset passwords or hold money, work access, tax information, cloud files, or saved payment details. Change passwords and turn on multi-factor authentication where available.
-
If other devices or the router also look wrong, pause sensitive use on that network. Avoid banking, payroll, and account recovery on that home network until you have changed the router admin password, checked for firmware updates, and removed unknown router rules or remote-management settings.
-
Report only if the situation fits. If money was stolen, accounts were taken over, someone is extorting you, or there is clear cyber-enabled fraud, file a complaint with the FBI’s IC3. If personal information was misused, use IdentityTheft.gov and consider a fraud alert or credit freeze.
What can wait
- You do not need to decide right now whether to reinstall the operating system or buy a new computer.
- You do not need deep log analysis before isolating the device and protecting accounts.
- Router hardening, perfect firewall rules, and long-term security improvements can wait until the immediate risk is contained.
- You do not need to prove whether it was malware, a software update, or a policy change before taking safe first steps.
Important reassurance
A firewall change you did not make can feel alarming, but it does not automatically prove that someone is inside the computer. Isolation, documentation, trusted scanning, and account protection are a solid first response while you work out what caused it.
Scope note
These are first steps only to reduce avoidable damage and buy time. If the change repeats, you see signs of remote access, money or accounts are affected, or the device is managed by work or school, you may need help from IT, your security provider, your bank, or a qualified technician.
Important note
This is general information, not personalized technical, legal, financial, forensic, therapeutic, or professional advice.
Additional Resources
- Microsoft — Firewall and network protection in the Windows Security app
- Microsoft — Risks of Allowing Apps Through Windows Firewall
- Apple Support — Change Firewall settings on Mac
- Microsoft — 4950(S): A Windows Firewall setting has changed.
- Ic3 — Welcome to the Internet Crime Complaint Center
- IdentityTheft.gov — Identitytheft
- Consumer Advice — Credit Freezes and Fraud Alerts
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.