Call us — 0131 202 0491
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · The Caller Who Knew the Account

Not a hardware fault — an intruder still in the building: the remote-access scam decoded, the false "you're secure" scan explained, and the right order of operations when someone else has the keys

This case file departs from the others in this volume, because the fault isn't in a drive — it's a person with access they should never have had, and the advice that matters is urgent and different. His account: "I have lost a lot of data and family photos when I was conned by someone saying they were from my internet provider — they had information about the account that only they should have." The reassurance that isn't: "I have run a full scan and the results say my computer is secure." The alarm that is: "recently I've had the control of my computer taken over by a program called 'Secure Server' which appears to be downloading files," alongside a remote-desktop icon offering "This Desk and Remote Desk." His question: can you help? Yes — but the first help isn't recovery, it's getting the intruder out, and this page gives that its proper priority before anything else. When someone else has remote access to your machine, data recovery is not the emergency; ending the access and securing your accounts is.

SystemHome computer subjected to an active remote-access intrusion following a convincing impersonation call — family photos and other data reported lost or moved
Reported situationCaller impersonating the internet provider, armed with real account details · remote-control software installed and operating ("Secure Server"; remote-desktop icons present) · files apparently being downloaded/moved · a security scan reporting the computer "secure" — false comfort
Fault classActive intrusion and social-engineering compromise — not a storage fault; priority is containment and account security, with data recovery secondary
Equipment usedMachine isolated offline · Atola TaskForce 2 write-blocked E01 imaging with hashes · OSForensics deleted-file recovery plus activity-timeline analysis of the intrusion window · recovery only after containment

The decode: the scam, the meaningless scan, and the right order of operations

What happened, named plainly: this is a remote-access scam, one of the most effective there is. The caller's "information only they should have" is the hook — provider details lend false authenticity, and are often gathered from earlier breaches or public data — and once trust is won, the victim is talked into installing remote-control software (here dressed up as "Secure Server," with the remote-desktop icons the giveaway). From that point the intruder can browse, move, download, or destroy files at will, and can lie in wait. His observation that a program is "downloading files" and that remote-desktop controls are present is the active-intrusion evidence that matters most.

Why the scan's "all secure" is worthless here: this deserves emphasis because it's giving dangerous comfort. Antivirus scans hunt for malware — hostile programs. But remote-access tools are legitimate software, used every day for genuine support; a scanner sees nothing wrong because, technically, nothing on the machine is a virus. The threat isn't a malicious file — it's a real person with real access through a real tool. "Your computer is secure" means only "no known malware found," which is a completely different statement from "no one else can control your machine." He is not secure; he is compromised by a route antivirus doesn't police.

The order of operations — the actual help: when access is active, sequence is everything. First, disconnect — pull the network/Wi-Fi, physically — to sever the intruder's live connection immediately. Second, secure accounts from a different, trusted device — change passwords for email, banking, and the provider, from a phone or another computer, never the compromised one (the intruder may be watching keystrokes on it); contact the bank if any financial details were exposed, and the provider to report the impersonation. Third, professional cleanup — the remote-access software and any companions removed, the machine verified clean or rebuilt. Only after the intruder is locked out does data recovery belong: genuinely deleted files (his family photos, if the intruder or the panic removed them) are then recoverable in the ordinary way — from an isolated image of the drive, worked on safely offline. Recover first while access is live, and you're working in a house the burglar still occupies.

The recovery: contained first, then the files

The urgent guidance came first and plainly: disconnect now, secure accounts from another device, report to bank and provider, get the intrusion professionally cleared. With the machine isolated and the remote access ended, the drive was imaged offline and the genuinely lost material addressed the way this archive addresses any deletion — deleted-file recovery from the image, family photographs and documents retrieved where they'd been removed rather than merely relocated by the intruder. What the recovery couldn't do — and this was said honestly — is undo any exposure of data the intruder had already copied out; that risk is managed through the account-security steps, not the disk.

On the bench

Only after the disconnection, the out-of-band password changes and the professional cleanup did this drive reach an imager — and then as evidence: a write-blocked E01 on the Atola TaskForce 2, hashed as captured. OSForensics did double duty on the image. Its activity-timeline and program-artifact analysis reconstructed the intrusion window — the remote tool's installation and the file operations around it — the record that supported his reports to bank, provider and authorities. And its deleted-file recovery retrieved the family photographs the episode had cost, offline, from a copy the intruder could never touch again. Containment first, forensics second, recovery third: the order is the page.

The outcome

The intrusion contained, accounts secured, the machine cleaned, and the genuinely deleted files recovered from an isolated image — in that order, which is the only order that helps. Free assessment for the recoverable data, one fixed written figure including VAT, no recovery, no fee. And the message this page exists to carry to anyone in the same moment: if someone has remote access to your computer right now, stop reading and disconnect — the recovery can wait; ending the access cannot. The incident was one to report to the authorities and the provider both.

You think you were scammed into giving someone remote access

Act in this order, now: disconnect the machine from the internet immediately to cut any live connection; then, from a different trusted device, change passwords for email, banking and your provider, and call your bank if any financial details were shared. Don't trust a "your computer is secure" scan — antivirus doesn't flag legitimate remote-access tools, so a clean scan says nothing about who can control your machine. Get the intrusion professionally removed before doing anything else. Data recovery for genuinely deleted files comes afterward, from an isolated drive — never while the access is still live.

Someone may have remote control of your computer?
Disconnect first, then call Edinburgh Data Recovery on 0131 202 0491 — containment before recovery, files retrieved offline, one written figure, no recovery, no fee.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.

0131 202 0491