Contain the damage first
Disconnect the device from the internet, but leave it on rather than shutting it down, since its current state may help show what happened. From a different, clean device, call your bank and card issuers using the numbers on your card or statements, change the passwords for email and financial accounts, and turn on multi-factor authentication. Ask the bank to freeze or flag the accounts and to stop pending transfers. Before removing the remote access software, record its name and the session details, or ask a technician to preserve that information for you.
Who moved the money matters
Remote access scams raise a hard question for banks: did the scammer make the transfer through your device, or did you make it yourself at their direction? Under federal rules for electronic transfers, a transfer the scammer started through your device is generally treated as unauthorized, while one you sent yourself after being deceived usually is not, and wire transfers generally fall under separate rules. Banks often look at device logs and session data to decide. Report quickly, because the timing of your report can affect how much of an unauthorized transfer you are responsible for. Be precise in describing what you did and what they did, and say so when you are unsure.
When a lawyer becomes useful
If the bank denies your claim, you can ask for the documents it relied on and challenge its conclusion, and federal and state regulators accept complaints about how claims were handled. Larger losses, losses from retirement or business accounts, and cases involving older adults can raise additional issues, including different rules for business accounts. An IC3 complaint with the FBI creates a record, so file one and keep the reference number. We look at the timeline, the bank's response, and which protections apply to each account.