Cybersecurity Services Melbourne Case Study: Laptop and Phone Hacked After a Fake Bank Tech Support Call

Client name withheld for privacy.

Summary

IT Engineering Pro helped a sole trader who was referred to us by his own bank after hackers remotely accessed his laptop and phone. The attack began with a fake tech support call from someone pretending to be that same bank. We ran a cybersecurity audit to trace how the attackers got in, removed the malware, reimaged both devices, installed premium endpoint protection and wrote a cyber incident report for his bank.

  • Referred by the client’s own bank to IT Engineering Pro for cyber incident response
  • Cyber incident response for a sole trader with a hacked laptop and hacked phone
  • Fake bank tech support call and AnyDesk identified as how the remote access scam started
  • Cybersecurity audit that traced how the hackers gained remote access to both devices
  • Computer backed up first, so the client’s files were protected before any clean-up
  • Malware and virus removal after a full scan, with all malicious files deleted
  • Laptop and phone reimaged to a clean, trusted state
  • Premium endpoint protection on the laptop and phone to help prevent future breaches
  • Cyber incident report written for the client to give to his bank
  • Aligned with ACSC Essential Eight guidance: multi-factor authentication, patching, restricted admin privileges and backups

1. The client profile

Client Sole trader, running his business from one laptop and one phone
Incident After a fake tech support call from someone posing as his bank, hackers gained remote access to his laptop and phone
How he reached us Referred to IT Engineering Pro by his own bank, then brought his devices to our Oakleigh office
Goal Find out what happened, remove the attackers, protect his data and give his bank a clear account of the incident

2. The problem

3. Our cyber incident response

Step 1: Cybersecurity audit

We started with a security audit of both devices to find out how the hackers had gained remote access. The audit traced the attack back to the fake bank tech support call, and found the attackers had used AnyDesk to control the devices remotely. Understanding the entry point first meant we could close it properly, rather than just cleaning up the damage.

Step 2: Back up the computer

Before removing anything, we made a backup of the computer so the client’s business files were protected throughout the clean-up.

Step 3: Malware scan and removal

We ran a full malware scan and deleted all malicious files found on the device.

Step 4: Reimage the laptop and phone

A malware scan alone cannot always guarantee a device is clean, so we reimaged both the computer and the phone. This wipes each device and reinstalls a clean system, removing anything the attackers may have left behind.

Step 5: Install premium endpoint protection

We installed the premium security solution we provide to our clients, on both the laptop and the phone, giving each device ongoing endpoint protection and mobile security to help prevent future breaches.

Step 6: Cyber incident report for the bank

We wrote a full incident report covering what happened, how the attackers got in, what we found and the steps taken to fix it. The client gave this report to his bank.

4. Cybersecurity results

Area Before After
Laptop and Phone Remotely accessed by hackers Reimaged to a clean state
How the attack happened Unknown Traced to a fake bank tech support call and AnyDesk remote access
Malware On the device Scanned and removed
Business files At risk Backed up before clean-up
Protection Not enough to stop the attack Premium endpoint protection on the laptop and phone
Bank No record of the incident Full cyber incident report provided

5. How this aligns with ACSC and Essential Eight guidance

Our response followed guidance from the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), including controls from the Essential Eight, the ACSC’s core set of strategies to protect against cyber attacks:

  • Multi-factor authentication (MFA): set up on the client’s accounts, so a stolen password alone is not enough to get in.
  • Patch operating systems and applications: the laptop and phone were brought fully up to date with the latest security updates.
  • Restrict administrative privileges: the client now uses a standard account for everyday work, so malware cannot easily make changes to the system.
  • Regular backups: the computer was backed up before the clean-up, protecting the client’s business files.

6. Cybersecurity FAQs

Disconnect the device from the internet, contact your bank straight away if any financial accounts could be affected, and change important passwords from a different, clean device. Do not wipe the device yourself before it is checked, because an investigation can show how the hackers got in. Then contact a cybersecurity provider, and report the incident through ReportCyber at cyber.gov.au.

A scammer calls pretending to be from your bank, often its fraud or tech support team, and says there is a problem with your account or computer. They use this to gain remote access to your devices, then try to reach your banking, accounts and personal information. This type of bank impersonation scam is also known as a remote access scam.

Treat any call asking for remote access to your devices, or asking you to install an app such as AnyDesk, as a scam. Hang up, then call your bank back on the number printed on your card or its official website, never on a number the caller gives you. You can report scam calls to Scamwatch.

AnyDesk is a legitimate remote desktop app, but scammers often misuse it. They call pretending to be from your bank, telco or a tech company and ask you to install AnyDesk or a similar app, which gives them control of your device. If you have installed a remote access app at a caller’s request, disconnect from the internet, uninstall the app, contact your bank and have the device checked.

Common signs include the mouse moving on its own, programs you did not install, security software being turned off, password reset emails you did not request, unknown logins to your accounts and unexpected bank transactions.

Not always. A scan finds and removes known malware, but hackers can leave changes behind that are hard to detect. Reimaging the device, which means wiping it and reinstalling a clean system, is the most reliable way to be sure it is clean.

Yes. We document what happened, how the attacker got in, what was found and what was done to fix it, in a report you can give to your bank, insurer or other parties.

Yes. Sole traders often run their business and banking from one laptop and one phone, so a single compromised device can affect both. Strong endpoint protection, regular backups and multi-factor authentication make a big difference at low cost.

Yes. IT Engineering Pro provides cybersecurity services for sole traders and small businesses across Melbourne, including security audits, malware removal, cyber incident response and endpoint protection, from our office in Oakleigh. We start with a free consultation and a fixed, upfront quote.

Been hacked? Get cybersecurity help in Melbourne

IT Engineering Pro provides cybersecurity services, cyber incident response, malware removal, hacked computer repair and help after tech support scams for sole traders and small businesses in Melbourne. We provide a free consultation and give fixed, upfront quotes. Our team also handles managed IT, remote technical support and on-site support across Melbourne.

Call +61 3 9570 4742 · info@itepro.com.au · Request a free quote

IT Engineering Pro, 172 Warrigal Rd, Oakleigh VIC 3166. Open Monday to Friday, 10am to 5pm.