Skip to main content

Morning Overview

One WhatsApp screen-share can hand a stranger the bank codes as they land on your phone

A scam built entirely around a single WhatsApp feature is draining bank accounts by turning a phone’s own screen into the thief’s window. Instead of guessing passwords or building fake login pages, criminals simply ask a victim to share their screen during a call, then wait for the phone to do the rest, since one-time passcodes and account alerts arrive as notifications the caller can read in real time. Security researchers describe it as effective precisely because it needs no hacking skill at all, only a convincing voice and a few minutes of a victim’s trust.

How a Bank Impersonation Call Leads to a Screen Share

The scheme typically opens with an unexpected WhatsApp video or voice call from someone posing as a bank fraud investigator, a Meta support agent, or occasionally a relative claiming to be in trouble. The caller manufactures urgency almost immediately, warning of a suspicious charge, a locked account, or a security breach that supposedly needs to be fixed before money disappears. That manufactured panic is what gets a target to stop thinking like a skeptic and start following instructions.

Once trust and urgency are established, the caller asks the victim to open WhatsApp’s built-in screen-sharing tool, framed as a routine step to “verify” the account or walk through a fix together, according to ESET’s WeLiveSecurity research team. Because the request comes from inside a familiar, legitimate app rather than an unfamiliar download, it rarely triggers the same suspicion that installing separate remote-access software would.

What a Screen-Share Actually Exposes on a Locked-Down Phone

Once sharing is active, the scammer sees whatever appears on the victim’s display in real time, including banking app balances, contact lists, and, critically, the pop-up notifications that arrive from a bank the moment a one-time passcode is generated. That last detail is what makes the scam far more damaging than ordinary phishing, because the codes designed to be the last line of defense against account takeover become visible to the attacker the instant they land on the screen.

Security researchers note that scammers frequently escalate by asking victims to open a banking app “just to check” a balance, or to attempt a transfer themselves so the criminal can watch the authentication flow and capture the exact code needed to approve a fraudulent payment. From the bank’s perspective, the transaction looks legitimate because the correct device and the correct code were used, which is part of why these losses are so difficult to reverse once the transfer clears.

Why the Passcode, Not the Password, Is the Real Prize

Most people have absorbed the lesson that passwords should never be spoken aloud to a stranger on the phone. Screen-sharing scams sidestep that caution entirely, since the victim never says a code out loud or types it anywhere the attacker controls. The phone simply displays the code, and a shared screen makes that display visible to whoever is watching, which is why researchers describe the technique as more effective against security-conscious people than a traditional phishing text would be.

The same access can extend beyond banking. A scammer who can see a phone’s screen can also read verification codes for email, social media and other messaging accounts, opening the door to a second wave of fraud in which the compromised WhatsApp account itself is used to message the victim’s contacts, asking them for money or spreading the same scam further. That secondary wave can be more damaging than the original theft, since messages arriving from a genuine, trusted contact carry far more credibility than a message from a stranger.

The Warning Signs Before Anything Is Shared

The clearest red flag is the request itself: no legitimate bank, telecom provider or platform support team asks a customer to screen-share a personal device over a messaging app in order to resolve a security problem, a point echoed in Malwarebytes’ own breakdown of the technique. A second warning sign is the pairing of urgency with unfamiliarity, since a real caller from a bank’s fraud department will already have account details on file and will not need a customer to narrate their own screen back to them.

Unsolicited calls, whether video or voice, are themselves worth treating with suspicion when they arrive from unknown numbers claiming to represent an institution. Verifying independently, by hanging up and calling a bank’s published number rather than any number provided during the suspicious call, closes the loop that scammers depend on to keep a victim engaged long enough to act.

Recovering After a Screen Was Already Shared

Anyone who has shared their screen with an unknown caller should assume that any codes or balances visible during that session were seen. The immediate priorities are contacting the bank to freeze the account and reverse any pending transfers, changing passwords on the accounts that were visible on screen, and checking WhatsApp’s own linked-devices settings for any session that was not initiated by the account owner. Enabling two-step verification on WhatsApp itself adds a second layer that a scammer cannot bypass with a screen-share alone.

Because the scam relies on speed and panic, slowing the interaction down is the most reliable defense. Ending the call, verifying the story through an independent channel, and never activating screen-sharing for someone who initiated contact removes the one ingredient the entire scheme depends on to succeed.

This article was produced with AI assistance and edited by Morning Overview staff.


More from Morning Overview