What to do if…
your computer suddenly shows a new local administrator account you did not create
Short answer
Assume the computer may be compromised: disconnect it from the internet, do not delete or edit the suspicious account yet, and secure your most important online accounts from a different trusted device.
Do not do these things
- Don’t keep using this computer for email, banking, cloud storage, work logins, or a password manager.
- Don’t delete the suspicious administrator account yet; it may remove useful clues.
- Don’t reconnect the computer just to test whether the account is still there.
- Don’t install unknown “security” tools or run commands copied from random posts or videos.
- Don’t let anyone you did not contact first remote into the computer.
- Don’t pay an extortion demand just because a message says you must decide immediately.
What to do now
-
Disconnect the computer from the network.
Turn off Wi-Fi, unplug Ethernet, and disconnect from any VPN. If an unknown USB drive, security key, or external device is plugged in and it is safe to remove, unplug it. Do not reconnect the computer to see what happens. -
Record the basics before changing anything else.
Take a photo of the login screen or user list showing the new account. Write down:- the exact account name
- when you first noticed it
- whether your usual account still appears
- whether your usual account still has administrator rights
- any recent remote-support session, repair visit, new software, update, or shared-device use
-
If this is a work, school, or managed device, stop and escalate.
Contact the IT, helpdesk, or security team from another device and say: “A new local administrator account appeared that I did not create. I have taken the device offline.” Do not try to remove the account unless they tell you to. -
From a different trusted device, secure the accounts that could unlock everything else.
Use your phone or another computer you trust, not the affected computer. Start with:- your primary email account
- bank, credit card, payment, and investment accounts
- work or school accounts
- cloud storage and password-manager accounts
Change passwords to unique new passwords, turn on or re-check multifactor authentication where available, and sign out of other sessions or devices where the service offers that option.
-
Check whether there is an obvious non-criminal explanation, without taking risks.
Think about whether a repair shop, family member, IT tool, school/work management profile, remote-support program, or operating-system setup could have created the account. If you cannot confirm the source quickly, keep treating it as suspicious. -
Use built-in user management only if you can do it safely.
If you can sign in with a known-good account you trust, you may check whether the unknown account has administrator privileges and whether your normal account was changed. Do not delete the unknown account yet. If you are not confident, skip this and get help. -
Scan using trusted tools for your operating system.
On Windows, run Microsoft Defender Offline if available, then run a full scan after Windows restarts. Microsoft Safety Scanner can be used as an additional Microsoft scan tool. On a Mac, keep the device offline and use Apple’s built-in security protections and software update route; if you are unsure, contact Apple Support or a reputable local technician. On Linux, get help from someone you trust before editing sudo, root, or user files. -
If the account was truly unauthorized, plan for a clean recovery.
If the account keeps returning, scans find malware, files are encrypted, or you cannot explain how the account appeared, the safer recovery path is often to back up only irreplaceable personal files, wipe or reset the computer, reinstall the operating system from trusted sources, and restore files cautiously after scanning them. -
If money, identity theft, extortion, or ransomware is involved, report and contact affected services.
Contact your bank or card issuer promptly if financial accounts may have been used. For cybercrime or ransomware in the U.S., you can file a report with the FBI Internet Crime Complaint Center. If this is an organization, follow the incident-response process and consider CISA ransomware guidance.
What can wait
- You do not need to identify the attacker right now.
- You do not need to prove the exact method right now.
- You do not need to decide immediately whether to wipe the computer; first isolate it, record the basics, and secure key accounts.
- You do not need to contact every service today; start with email, finance, work or school, cloud storage, and your password manager.
Important reassurance
A surprise administrator account is serious because administrator access can change settings, install software, and reach other files. The first protective moves are still simple: get the computer offline, preserve basic information, and secure the accounts that matter most from a different device.
Scope note
These are first steps only. Later decisions about forensics, legal reporting, insurance, workplace response, data breach duties, or reinstalling the operating system may need specialist help.
Important note
This is general information, not professional cybersecurity, legal, financial, law-enforcement, or technical-repair advice. If the device is owned or managed by your employer or school, follow their policies. If you suspect financial fraud or identity theft, contact the relevant bank, card issuer, or account provider promptly.
Additional Resources
- Microsoft — Microsoft Defender Offline scan in Windows - Microsoft Defender for Endpoint
- Microsoft — Microsoft Safety Scanner Download - Microsoft Defender for Endpoint
- Consumer Advice — How To Recover Your Hacked Email or Social Media Account
- Cisa — Multifactor authentication
- Ic3 — Ransomware - Internet Crime Complaint Center (IC3) Lock Close Facebook X (Twitter) YouTube LinkedIn Instagram
- Ic3 — Complaint Form - Internet Crime Complaint Center (IC3) Lock Close Facebook X (Twitter) YouTube LinkedIn Instagram
- Cisa — Ransomware response checklist
- Apple Support — Protecting against malware in macOS
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.