DEEP DIVE · SC-REMOTE · Remote access

They ask you to install one small program: once remote access is on, the account stops being yours

The previous entry covers how the approach starts. This one picks up later — you half believed them, you installed it, and the little window has just connected. Here is what that moment actually buys them, and what you can still do about it.

Cover: cream background with a red bar down the right edge, headline "Remote access" and the line "Once it is on, they are on your side"
Chain Scam Index · specimen of remote access software misused by a fake support caller
Stop before you click install. If they contacted you first, and somewhere in that conversation they want you to install software, that is already the whole answer. You do not need to work out whether they sound official, and you do not need to research whether the program itself is safe. The decision sits on two facts: who opened the conversation, and who is asking for an install.

Everything below is for people who already installed it, or whose cursor is hovering over "Accept" right now.

Why it has to be you who installs it

The software is not the villain here. AnyDesk says so on its own abuse-prevention page: "AnyDesk is used legitimately by millions of IT professionals worldwide, to remotely connect to their clients' devices to help with technical issues. However, scammers can try to misuse AnyDesk (or any other remote access software) to connect to your computer and steal data, access codes, and even money."

Read where the weight falls in that sentence: on who is connecting. Which is why searching "is remote access software safe" gets you nowhere useful — the tool is neutral, and the thing that went wrong is that a stranger ended up on the other end of it.

They are not there to fix anything. What they are buying is a seat next to you while you type your own credentials in. Every keystroke is yours. Nothing has to be cracked, guessed, or even asked for outright.

The step that slides past almost everyone is being asked to read out the connection code on screen. It looks like a serial number, so people read it out without thinking. AnyDesk lists "access codes" in the same breath as data and money, and that is why — in that moment the code is the door handle.

My own rule with this category of software is deliberately narrow: only for someone I already know, only when I went looking for the help, and it comes off the machine afterwards rather than living on the computer I sign into exchange accounts from. That is not clever security. It is just drawing the "do I know this person" line somewhere I can't argue myself out of.

What they have you do once connected

The US Federal Trade Commission describes the opening move in one line: "If one of these tech support impersonators gets you on the phone, they ask for remote access to your computer and pretend to scan it for viruses." The fake scan matters. It fills the first few minutes with something that looks like work, and it puts you in the role of the person being helped.

What follows is the part that costs you. AnyDesk's page marks it: "If someone who is remotely connected to your device is asking you to login to your bank account or to show any personal passwords, they are most likely a scammer." Swap "bank account" for an exchange or a wallet and the script is unchanged. In practice it arrives as:

  • "Log in so I can see the account." You type it; they watch the screen.
  • "Read me the code you just received and I'll escalate this." The same page is blunt about that class of secret: "Never share online banking login details or any passwords with anyone."
  • "Let me fix the setting for you." Which setting, exactly, is not something you can follow in real time while someone talks to you.

If what they want is a seed phrase or a private key, you are past this entry — treat that wallet as gone and work through the first 4 things to do after a scam.

"I only shared my screen"

This is the half-step people retreat to: no control was given, just a screen share.

Sharing a screen is genuinely not the same as handing over the mouse. It is also less of a gap than it sounds. The second you click the eye icon to check what you typed, the second a verification code arrives as a banner notification, the second you open a file to read something back — it is all on the shared screen. And for that whole stretch, someone is on the phone telling you where to click next.

AnyDesk's rule has no mode setting attached to it: "Never give anyone you don't know access to your devices."

Three signs that end the conversation

Three lines, each one lifted straight from an official page, and each one enough on its own:

  • They called you, and they name a company you have heard of. AnyDesk: "Usually, these criminals will call and report a computer or internet problem they have detected and offer help. They will probably say they work for a widely-known company such as Microsoft or even your bank." The FTC states the counterpart plainly: "Legitimate tech companies won't contact you by phone, email, or text message to tell you there's a problem with your computer."
  • They want you to download something during the call. AnyDesk does not hedge on this one: "No bank or company will ask you over the phone to download software!" The same page adds a general rule worth keeping: "Never trust a call you weren't expecting!"
  • A pop-up gave them the opening. Per the FTC, "Real security pop-up warnings and messages will never ask you to call a phone number." A number inside the warning box is the warning.

Cutting it off, in order

AnyDesk's in-the-moment advice is two sentences long, which is about right: "Stop any phone call just by hanging up!" and "End any remote session by simply turning off your device!" Laid out as something you can actually follow:

  • One: hang up. No explanation, no goodbye, no "so am I being scammed?" While you are still on the line, they still have a chance to talk you back into the script.
  • Two: kill the device. Power it off, or pull it off the network. Do not go hunting for a disconnect button inside the software — you are not necessarily the one driving that interface right now.
  • Three: move to a different device. Everything that comes next happens on your phone or another computer, not on the machine that was just connected.
  • Four: retire every contact detail they gave you — the link, the number, the "case reference", all of it.

It reads as abrupt because there is no gentle version. Hanging up is the step that stalls people: the caller has usually been polite and sounds like they are on your side, so dropping the line mid-sentence feels rude. That flicker of rudeness is part of the design.

What to change once you are off

AnyDesk's after-the-fact list has four items: report the scam to your account provider (bank, credit card institution, online payment system), change the passwords on every account that may have been exposed, have an IT expert check the device, and report the scam to the authorities.

TeamViewer's knowledge base is broader on the password point — its advice is to change your passwords on all platforms to be on the safe side (page self-dated Last Modified: Oct 1, 2024). The FTC's version is the same instinct in fewer words: "If you gave your username and password to a tech support scammer, change your password right away."

Three practical notes on doing it:

  • Change passwords from a clean device. Doing it on the machine that was just connected can hand over the new one too.
  • Passwords are not the whole job. Two-factor bindings, withdrawal whitelists and API keys all deserve a look — a changed setting is much harder to notice than a leaked password. Where each of those lives is covered in the beginner security setup.
  • Get the device itself checked. This is the step most people skip, because nothing on screen confirms it is done.
  • If you are in the US, the FTC's reporting entrance is ReportFraud.ftc.gov; elsewhere, report to your local authority and to the platform.

What the vendors say about themselves

One version of the call opens with "Hello, I'm from TeamViewer support." That sentence contradicts itself, and the company's own knowledge base is where you can show it: "TeamViewer does not provide remote support services of any kind. Our activities are limited to developing and selling the software tools that providers use to offer remote support services." (page self-dated Last Modified: Oct 1, 2024). They sell tools. There is no support desk of theirs to call you.

The same page advises caution with unsolicited phone calls and says not to grant access to devices — PC or mobile — to anyone you do not know or trust. AnyDesk's two prohibitions say the same thing from the other side: never give access to someone you don't know, never share login details or passwords with anyone. TeamViewer also runs a report-a-scam form, which is a reasonable place to send the details after you are safely disconnected.

Where this sits on the timeline

Laid out as a sequence, it is easier to see which square you are standing on:

This entry only covers the square in the middle: the software is installed, or about to be.

FAQ

A pop-up warned me about a virus and gave a support number. Is that the same thing?

It is the front door of the same scheme. The US Federal Trade Commission puts it plainly: "Real security pop-up warnings and messages will never ask you to call a phone number." A number printed inside the warning is the tell, no matter how much the box looks like your operating system.

They said they work for the remote access company itself. Could that be true?

TeamViewer's own knowledge base states that it does not provide remote support services of any kind, and that its activities are limited to developing and selling the software tools that providers use to offer those services (page self-dated Last Modified: Oct 1, 2024). So "I'm from the remote software's support team" does not line up with what the company says it does.

2026-09-17 · Entry created.