Remote Access Scams: What to Do Right Now

Published: August 18, 2026
📖 7 min read

If someone on the phone right now is asking you to install screen-sharing or remote-desktop software, disconnect the call and close the software before reading any further explanation. This is a documented scam pattern the FBI has repeatedly warned about, and the single action that matters most in the first few seconds is stopping the connection, not understanding why it happened. Once you're safe, the rest of this page walks through how the scam works, what to check, and where to report it.

How the scam works, once you're safe

These scams typically make contact by phone, text, email, or a pop-up warning claiming fraud has been detected on your account or that you're owed a refund. The caller, often posing as tech support, your bank's fraud department, or a well-known company, talks you through installing free remote-desktop or screen-sharing software, framed as necessary to "fix" the problem or process the refund. This software itself is ordinary and has legitimate uses; the scam is entirely in how it's being used against you in this moment, not in the software existing at all.

The two things they need you to do

Once remote access is granted, the scam depends on two things happening: first, that you keep the connection open long enough for the scammer to see or control your screen, and second, that you log into a financial account, your bank, a cryptocurrency exchange, or similar, while connected. In some documented cases, scammers have specifically guided victims into opening a cryptocurrency account during the call, moving money through a channel that's significantly harder to reverse than a standard bank transfer. Neither step is something a legitimate support interaction ever requires; real technical support does not need you to log into your bank account while someone else can see or control your screen.

The follow-on risk: a second scam pretending to help you recover the first

A documented and growing pattern as of 2025 involves scammers impersonating the FBI's own Internet Crime Complaint Center (IC3), contacting people who already reported or lost money to a scam, and offering to help "recover" the funds. The FBI has specifically warned about this, noting more than 100 reports of IC3 impersonation between December 2023 and February 2025. This does not mean IC3 itself is compromised; it means scammers are deliberately targeting people who are already victims and already looking for help, which is exactly why any unsolicited contact claiming to be a recovery service, even one claiming a government affiliation, deserves the same scrutiny as the original scam.

What to do in the next hour

If a remote access scam has just happened to you:

  1. Disconnect the software and the call immediately if you haven't already, and restart your device if you're able to.
  2. Contact your bank's fraud line directly, using the number on your card or statement, not one given to you during the call, and tell them what happened.
  3. Change passwords for any account you logged into during the session, from a different, trusted device.
  4. Check for unfamiliar transactions or new accounts, particularly any cryptocurrency account you may have been guided to open.
  5. Do not respond to anyone who contacts you afterward offering to help "recover" the money, especially if they claim a law enforcement affiliation; verify independently through official channels first.

If any bank or card details were also shared during the call, our guide on what to do if you gave a scammer your bank details covers the fuller containment sequence.

Why legitimate support never needs this combination

It is worth being precise about what makes this a scam mechanism rather than a normal support interaction, since remote-access tools genuinely are used by legitimate IT and customer-support teams. The specific combination that signals a scam is being asked to install remote-access software as a result of unsolicited contact (a call, text, or pop-up you didn't initiate) and then being guided to log into a financial account while that connection is active. A bank's real fraud department does not need to see your screen to secure your account, and a real technical-support interaction you initiated yourself, through a channel you verified independently, carries far less risk than one that arrived at you first with urgency attached.

Where to report it

Report the incident to your bank first, then file a report with your country's official fraud-reporting body; our guide on reporting financial fraud in your country names the right channel for the US, UK, Canada, Australia, India, and how to find yours elsewhere. If you're in the US, the FBI's Internet Crime Complaint Center at ic3.gov is the direct channel for this category, alongside our companion resource on where to get real help after fraud. Many of these scams also begin with a fake support number, covered in our fake support number guide, which is worth reading if you're not sure how the contact started.

A note on how to use this

This page describes a documented scam pattern and a general response sequence; specific steps for securing accounts vary by bank and provider, so follow their stated fraud-response process alongside this guide. Please also read our full Disclaimer. FinMateMastery is not a law enforcement agency and cannot recover lost funds; it can only point you to the channels that can help.

Why this scam often pairs with a fabricated sense of officialdom

Remote access scams frequently borrow the visual and verbal trappings of legitimate institutions to make the request feel routine: a caller who references account details you might recognize, a pop-up styled to look like a genuine security warning from your operating system or antivirus software, or a script that mimics the calm, procedural tone of a real support call. None of this borrowed officialdom is a coincidence; it exists specifically to make an unusual request, installing software and then logging into a bank account while someone else watches, feel like a normal part of getting help rather than the two-step process a scam actually requires. Recognizing that the request itself, not the tone or the visual polish surrounding it, is what determines legitimacy is the most reliable defense against this pattern.

Frequently asked questions

What should I do first if someone is asking to remotely access my screen right now?
Disconnect the call and close the remote-access software immediately, before doing anything else. Everything else, checking accounts, reporting, changing passwords, comes after that.

Is remote-desktop software itself dangerous?
No, it has legitimate everyday uses. The danger is entirely in being talked into granting access to someone posing as support during an unsolicited or unverified contact.

Why do scammers ask victims to open a cryptocurrency account during these calls?
Cryptocurrency transfers are significantly harder to reverse than standard bank transfers, which makes them a preferred channel once a scammer has remote access and wants to move money out.

I already reported this scam and now someone is contacting me offering to help recover my money. Is that legitimate?
Treat it with serious suspicion. The FBI has documented scammers specifically impersonating its own Internet Crime Complaint Center to target people who already lost money, offering fake recovery help as a second scam.

Aron Benjamin

Leave a Comment

Scroll to Top