← all articles

Helping a Parent Recover From a Scam Call

Your parent calls you, voice shaking, and tells you someone just got them on the phone. Maybe it was a fake “Microsoft support” agent, someone posing as a grandchild in trouble, or a caller claiming to be from the bank’s fraud department. Whatever the script, the call is over now and the question is what actually needs to happen next.

Phone scam recovery isn’t one action, it’s a short sequence of checks, done in the right order. Some of it matters in the first hour. Some of it matters over the following weeks. None of it requires panic, and none of it requires your parent to feel stupid, because these scripts are built by people who run them hundreds of times a day and refine what works.

How these calls actually work

Understanding the mechanics helps you figure out what’s actually at risk, instead of guessing.

Caller ID spoofing is trivial. Scam operations route calls through SIP trunking services that let the caller set the displayed number to almost anything, including a bank’s real support line or a neighbor’s number to increase pickup rates. Phone networks have rolled out a call authentication framework called STIR/SHAKEN, which attaches an attestation level to a call based on whether the carrier can verify the caller actually owns the number they’re displaying. It catches some spoofing and gets flagged as “Scam Likely” or similar on many phones, but it isn’t universal and doesn’t cover every carrier or every route, so a spoofed number making it through clean doesn’t mean much.

Tech support and refund scams often push toward installing remote access software like AnyDesk or TeamViewer, framed as letting the “technician” fix a problem. Once installed, the caller can see the screen and, depending on the tool and permissions granted, control the mouse and keyboard. This is the step that matters most for recovery, because it changes the scope from “someone lied to me” to “someone had hands on my device.”

Bank and government impersonation scams rely on urgency and authority. They tell the target that funds are at risk right now, and the fastest path to “safety” is moving money themselves, buying gift cards, or reading out a one-time passcode. No legitimate bank or agency asks for a one-time passcode over the phone. That single fact is one of the most reliable tells, but it’s easy to forget in the moment because the whole call is designed to short-circuit careful thinking.

First, figure out if money or access actually moved

Before anything else, sit down with your parent and ask three plain questions: did they send money, gift card codes, or crypto; did they read out a one-time passcode or PIN; and did they install anything or let someone control the screen. The answers determine everything that follows.

If money moved through a bank transfer or wire, call the bank’s fraud line directly, using the number on the back of the card or the official app, not any number given during the call or texted afterward. Banks vary in what they can reverse, and recovery odds drop fast the longer the money has had to move through intermediary accounts, so speed here genuinely helps.

If it was gift cards, the funds are usually gone once the codes are read out, since the scammer can redeem them almost immediately. It’s still worth calling the retailer’s fraud line, because some have processes for flagging cards before redemption, but don’t set expectations high.

If a one-time passcode was read out, treat every account tied to that phone number or that specific login as potentially compromised, not just the one the scammer claimed to be calling about.

If they installed anything or gave remote access

This is the step people skip because the money part feels more urgent, and it’s the one that actually creates ongoing risk.

Remote access tools, once granted control, can be used to install additional software, browse files, or capture what’s on screen, including saved passwords visible in a browser. Uninstalling the app afterward removes that specific tool but doesn’t undo anything it was used for during the session.

Disconnect the device from the internet, then run a full scan with the device’s built-in security tool (Windows Security on Windows, or a reputable scanner on other platforms). This won’t tell you with certainty what happened during the remote session, only whether something was left behind, so don’t treat a clean scan as proof nothing was taken. If your parent uses a Mac, check System Settings for any new profiles or extensions, since some remote-access scams add background helper apps that aren’t obvious from the desktop.

If there’s any chance a password manager, banking app, or email account was open and visible on screen during the session, treat every credential visible in that window as exposed and change it, starting with email, since email is usually the recovery path for everything else.

Locking down accounts

Start with email, because it’s the account most other resets flow through. Change the password to something not reused anywhere else, and turn on two-factor authentication if it isn’t already on, preferring an authenticator app over SMS where the account offers it, since SMS codes can be intercepted through SIM swapping in some cases, while an app tied to the physical device doesn’t have that exposure.

Move to banking and any account that had a passcode read out loud, then anything reused with the same password as the email account. Reused passwords are the actual mechanism by which one exposed account turns into five, so this step matters more than it sounds.

If your parent uses a password manager, this is a reasonable moment to introduce one, not as a cure for phishing, but because it removes the habit of reusing the same password everywhere, which is what lets a single leak cascade.

Dealing with the phone number itself

The scam call revealed that the number is active and answered, which means it will likely get sold or reused by other operations. There’s no way to make a phone number that’s already circulating in scam lists stop being called entirely, but you can cut the volume down.

Most carriers offer a spam/scam filtering service, sometimes on by default and sometimes needing activation through the carrier’s app or a settings menu. On the phone itself, both iOS and Android let you silence calls from numbers not in your contacts, sending them straight to voicemail instead of ringing through. This is blunt, since it also silences legitimate unknown callers like a doctor’s office, but for a parent who’s already been targeted once, that tradeoff is often worth it.

Registering the number on the national Do Not Call registry does reduce legitimate telemarketing, but has no effect on scam operations, since they aren’t complying with the registry to begin with.

The part that isn’t technical

The instinct after a scam call is to walk through exactly what should have been noticed, and that instinct usually makes things worse. These scripts are built and tested against thousands of people, adjusted based on what gets a response, and run by people doing this as a full-time job. Falling for one is closer to encountering a well-designed system than to making a personal mistake.

What actually helps is agreeing on a plan for next time, before there is a next time. A simple rule works well: any call about money, account security, or a family member in trouble gets a callback to a number you already have on file, never a number given during the call, before any action is taken. That single habit defeats almost every version of this scam regardless of how convincing the caller sounds, because it removes the urgency the whole call was built around.

Reducing the odds of a repeat call

None of this stops scam calls from coming, and no single setting or app claims to. What it does is lower how often they get through and how much damage one succeeds at doing. Combine carrier-level filtering, contacts-only ringing for unfamiliar callers, and a standing rule to hang up and call back on a known number. Layered together, these cut down both the frequency and the stakes of the next attempt, which is a more realistic goal than trying to eliminate the calls entirely.

If you want more explainers like this one on the everyday privacy and security decisions that actually matter, head back to the homepage.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →