Screen-sharing scams are emerging as a deceptive route to UPI fraud, with cybercriminals exploiting trust rather than breaking into payment systems. Fraudsters are posing as bank officials, customer-care executives, delivery agents, or representatives of online platforms. Thus, persuading victims to install remote-access or screen-sharing applications.
The Indian Computer Emergency Response Team (CERT-In) warned that such applications can give fraudsters extensive access to a victim’s device and enable financial fraud.
The fraud starts with an unsolicited phone call or message. The fraudster claims that there is a refund that is waiting, KYC requires an update, there is a failed payment, or verification of a service.
Then, the victim is directed to install remote access software like AnyDesk or other screen-sharing software. This seems harmless as it is introduced for offering technical support. The moment access is granted, the fraudster can see your device activities. With the permissions given, the fraudster can interact with the software and see whatever is on the screen.
The scammer guides the victim through a series of apparently routine steps. The victims are asked to open a UPI application, check a refund request, or complete a verification process.
The victim is then persuaded to approve a payment or enter the UPI PIN. Lastly, the moment you share your PIN, your account is attacked.
Never install a remote-access application at the request of an unsolicited caller. Do not share your UPI PIN, OTP, banking credentials, or screen during a financial transaction.
You also need to contact banks through official applications or verified customer-care channels rather than numbers provided by callers or found through unreliable searches. If any suspicious remote-access app is already installed, disconnect the session, remove the application, secure banking accounts, and immediately inform the bank.
Also Read: Bill Gates Sounds Alarm on AI, Cybersecurity: Impact on Future Jobs