The “bank security team” calls. The caller knows your name or your bank and says someone has applied for a loan. To stop it, they tell you to install AnyDesk, TeamViewer, or another remote-support app.
The software itself may be legitimate. The danger is giving control to an unexpected caller who then guides you into your bank.
How the call develops
It starts with a problem and a rush: a transfer is “leaving now”, someone is “taking out a loan”, and action must happen before the call ends. The number on the screen may look like the bank’s number — caller ID can be spoofed.
The caller then asks you to install an app and read out its session code. Once they can see the screen, they may:
- ask you to open online banking and watch the login, balance, and personal details,
- cover the screen, move a window, or call a transfer a “technical account”,
- push you to enter a text-message code or approve an operation in the banking app,
- copy files or change settings, depending on the permissions you grant.
An approval in the app is not a test. Read what it approves: the amount, recipient, and type of operation.
What a bank does not need
A bank may ask for limited details to check identity. It does not need a customer, after an unexpected call, to:
- install remote-control software,
- give a password, PIN, full text-message code, or BLIK code,
- move money to a “safe” or “technical” account,
- hide the call from family, police, or branch staff.
Do not settle this inside the same call. Hang up. Dial a number from the card, the bank’s app, or its official website yourself. This is the second-channel rule in practice.
If access was already granted
Disconnect the computer or phone from the internet and end the remote session. Do not use that device to sign in to the bank again. From another trusted device, call the bank, describe the remote access, and ask it to review and block access and transactions as appropriate.
Then change important passwords, beginning with email and banking, review authorised devices, and preserve the call time, number, messages, and session ID. Keep the device offline and have it inspected or reset before using it again for banking, email, or passwords. Uninstalling the app does not reverse transfers or make exposed details secret again. Use the first-minutes checklist for the short order, and the remote-access decision tree before any future session.