Scam Alert:

ACTIVE SCAM ALERT

WhatsApp Screen-Sharing Scam: How It Works and How People Can Stay Safe

Overview

A dangerous form of social engineering scam is using WhatsApp video calls and other screen-sharing technology to trick people into exposing information displayed on their phones or giving criminals remote access to their computers & devices.

The scam usually begins with an unexpected call or message from someone claiming to represent a bank, financial regulator, technology company, WhatsApp, Meta, law enforcement agency, or another trusted organization. In some variations, the caller claims to be a friend or relative experiencing an emergency.

The caller creates an urgent problem that supposedly requires immediate action. The victim may be told that an unauthorized payment has appeared, a bank account has been compromised, a telephone contains malware, an account is about to be suspended, or suspicious activity has been detected.

The criminal then persuades the victim to begin a WhatsApp video call and activate the screen-sharing feature. WhatsApp legitimately allows screen sharing during video calls, but the company warns users that information displayed on the shared screen, including usernames and passwords, becomes visible to the other participant. WhatsApp also displays an additional warning when screen sharing begins with someone who is not saved as a contact.

The criminal does not need to hack the telephone in the traditional sense. The victim is manipulated into revealing the screen voluntarily.

Once screen sharing begins, verification codes, banking information, account notifications, email messages, payment activity, personal information, and other sensitive material can become visible to the scammer.

Some criminals escalate the attack by persuading victims to install legitimate remote-access programs such as AnyDesk or TeamViewer. These programs are designed for legitimate technical support, but once access is granted, a criminal may gain substantially greater control over the victim’s device. The UK Financial Conduct Authority specifically warns that screen-sharing and remote-access scams can expose financial accounts and personal information.

How the Scam Works

The scam generally develops through several recognizable stages.

1. The criminal makes unexpected contact.

The first contact may arrive through WhatsApp, a conventional telephone call, social media, or another messaging service. Caller identification cannot be treated as proof of identity because criminals can spoof telephone numbers and make calls appear to originate from a local number or trusted organization.

2. The criminal impersonates someone with authority.

The caller may claim to represent a bank, regulator, fraud department, technology company, law enforcement agency, or customer support service. The authority of the claimed organization is used to discourage questioning and increase compliance.

3. A crisis is created.

The victim is told that something serious has happened. Common stories include suspicious transactions, malware, account compromise, fraudulent purchases, security breaches, or imminent account suspension.

The purpose of the crisis is psychological. Fear and urgency reduce the amount of time available for independent verification.

4. The criminal moves the interaction to screen sharing.

The victim is instructed to begin a WhatsApp video call and activate screen sharing. The criminal may describe this as a security check, verification procedure, fraud investigation, technical repair, or account-protection measure.

5. Sensitive information becomes visible.

Once screen sharing begins, the criminal can see whatever appears on the shared portion of the screen. This can include one-time passwords, authentication notifications, banking applications, emails, account numbers, payment confirmations, and other information.

6. The criminal may request remote access.

The victim may be instructed to download AnyDesk, TeamViewer, Zoho Assist, or another legitimate remote-support application. The FCA warns that criminals use these tools to obtain access to financial accounts and personal information.

7. Money or accounts are taken.

The criminal may use visible verification codes to authorize transactions, instruct the victim to move money supposedly for security reasons, make purchases, access financial accounts, or compromise other online accounts.

The apparent actions may even look as though the victim personally authorized them, because the victim is being manipulated while the criminal watches the process unfold.

Real Losses Have Already Occurred

This method has produced substantial financial losses.

In September 2026, the UK consumer organization Which? reported the case of a man contacted through WhatsApp by criminals claiming to be Financial Conduct Authority inspectors. The criminals persuaded him to share his screen and kept him engaged for approximately 20 hours over three days. More than £27,000 was stolen through credit cards, Apple Pay, online accounts, and purchases. The criminals also instructed him not to speak with family or friends, isolating him from people who might have recognized the fraud.

The FCA has warned about screen-sharing fraud for years. In an earlier documented case, a 59-year-old woman lost £48,000 after criminals used screen-sharing software to gain access to information associated with her finances. The FCA reported more than £25 million in losses from screen-sharing scam cases it had identified between January 2021 and March 2022.

Security reporting has also described cases in several countries, including India and Hong Kong, with one reported Hong Kong case involving a loss of approximately US$700,000.

The method is not unique to WhatsApp. Any service capable of screen sharing or remote access can potentially be misused in the same way.

Warning Signs

Several behaviors should immediately raise concern:

  • An unexpected caller claims that a bank account, device, or online account is in danger.
  • The caller creates urgency and demands immediate action.
  • The caller asks to move the conversation to WhatsApp or another video service.
  • The caller asks the person to share a telephone, tablet, or computer screen.
  • The caller asks the person to install AnyDesk, TeamViewer, or another remote-access application.
  • The caller asks for verification codes, PINs, passwords, banking information, or security credentials.
  • The caller tells the person not to speak with family members, friends, bank employees, or other professionals.
  • The caller claims money must be transferred to a safe account.
  • The caller becomes angry or threatening when questioned.
  • The caller refuses to allow independent verification through an official telephone number.

The FCA specifically identifies unexpected requests to share a screen or provide remote access as major warning signs of fraud.

Step-by-Step Prevention Strategy

Step 1: Treat unexpected security calls as suspicious

An unexpected caller claiming that an account or device is compromised should never be treated as verified simply because the caller knows personal information or displays a familiar telephone number.

Caller identification can be falsified.

Step 2: Never share a screen with an unexpected caller

Screen sharing should not be activated for someone who unexpectedly claims to represent a bank, regulator, technology company, government agency, or support service.

WhatsApp itself warns users to share screens only with people they trust.

Step 3: Never reveal verification codes

One-time passwords and verification codes exist to confirm account access or transactions. They should never be read aloud, forwarded, photographed, or displayed intentionally to an unsolicited caller.

Screen sharing can expose these codes even when they are never spoken.

Step 4: Do not install remote-access software at a stranger’s request

Programs such as AnyDesk and TeamViewer are legitimate tools, but criminals use them to obtain access to victims’ devices.

A person who did not independently initiate legitimate technical support should not install remote-control software because an unexpected caller requested it.

Step 5: End the call and verify independently

Anyone claiming to represent a bank, card provider, regulator, or other organization should be verified through an independent channel.

The call should be ended. The organization should then be contacted using the telephone number printed on a bank card, official statement, or independently located official website.

No telephone number supplied by the suspicious caller should be used for verification.

The FCA specifically advises consumers contacted unexpectedly by financial businesses to verify firms independently rather than relying on information provided by the caller.

Step 6: Do not allow secrecy

Instructions not to speak with family, friends, bank employees, or police are strong indicators of manipulation.

Legitimate fraud investigators do not need to isolate a customer from trusted people in order to protect an account.

Secrecy protects the scammer, not the victim.

Step 7: Activate additional account security

Two-step verification should be enabled on WhatsApp and other important accounts. Passkeys should be used where available.

These protections create additional barriers if criminals obtain passwords or attempt account takeover.

Step 8: Pay attention to WhatsApp warnings

WhatsApp displays a warning when someone attempts to share a screen with a person who is not saved as a contact. That warning should be taken seriously.

An unfamiliar contact asking for screen access represents sufficient reason to stop the interaction.

If Screen Sharing Has Already Started

Immediate action matters.

  1. Screen sharing should be stopped immediately.
  2. The WhatsApp call should be ended.
  3. Any remote-access application installed at the caller’s request should be disconnected and removed.
  4. The affected device should no longer be used for sensitive account recovery until the extent of access is understood.
  5. Important passwords should be changed from another trusted device, beginning with email, banking, financial, and primary identity accounts.
  6. The victim’s bank and card providers should be contacted directly through verified telephone numbers.
  7. Recent transactions, new payees, digital-wallet activity, card purchases, and account changes should be reviewed.
  8. WhatsApp and other affected accounts should be secured with two-step verification or passkeys where available.
  9. The incident should be reported to appropriate financial institutions, platforms, and law enforcement or national fraud reporting services.
  10. Evidence should be preserved, including telephone numbers, WhatsApp profiles, screenshots, messages, transaction information, remote-access application names, and the approximate timeline of events.

If substantial unauthorized financial activity is occurring, the bank or payment provider should be contacted immediately rather than waiting to determine exactly how the scam worked.

Important Distinction: Screen Sharing Is Not Remote Control

Screen sharing and remote access are related but different.

WhatsApp screen sharing allows another participant to see what appears on the shared screen. WhatsApp states that the information displayed during the session is visible to the person receiving the screen share.

Remote-access software can go considerably further. Depending on the application and permissions granted, the person on the other end may be able to interact with the device, open applications, navigate accounts, or manipulate information.

Criminals may begin with screen sharing and later persuade the victim to provide remote access.

Both requests should be treated as major warning signs when they originate from an unexpected caller.

SCAM ALERT KEY MESSAGE

A bank, regulator, technology company, or government agency contacting someone unexpectedly does not need to watch that person’s telephone screen to protect an account.

An unsolicited request to share a screen should be treated as a scam warning.

The safest response is simple:

  • End the call.
  • Stop the screen share.
  • Do not install remote-access software.
  • Contact the organization independently.
  • Protect the accounts before continuing any conversation.

Leave A Comment

Your comments help the SCARS Institute better understand all scam victim/survivor experiences and improve our services and processes. Thank you

Thank you for your comment. You may receive an email to follow up. We never share your data with marketers.