“Install AnyDesk and I’ll help”: when remote support takes over your money
A call from a bank or support desk ends with a request for remote access. Learn when to end the call and what to do after sharing your screen.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 2 September 2026
- READING TIME
- 8 min read
- TOPIC
- Human Security
The call begins with an offer of help. “Someone is trying to withdraw your money”, “there is an old investment account in your name” or “your computer is sending suspicious traffic”. The caller knows the bank’s name, sounds composed and offers a solution. You only need to install AnyDesk, TeamViewer or another remote-control app.
The app itself is not malware. Support teams and administrators use these tools legitimately. The danger begins when a stranger persuades you to hand over the screen, mouse and keyboard, then guides you straight into online banking.
What the caller gains from the connection
CERT Polska describes cases in which criminals impersonate investment or exchange staff, among others, and persuade a victim to install AnyDesk. They then ask the person to sign in to their bank. With remote access active, the criminal can see the display and operate the computer. CERT also identifies the risk of transfers and fast loans taken out using the victim’s identity.
The criminal does not need to know the password in advance. They can ask the owner to type it, hide part of the display, move a window or describe an approval as “cancelling” a fraudulent transaction. What the customer approves in the banking app may actually be a transfer, new beneficiary or another account change.
Caller ID does not prove who is calling. CERT notes that the displayed number can be spoofed. Ending the call and dialling a number taken from the bank’s official site is safer than continuing or returning the call from the recent-calls list.
The sentence that ends the call
Set a clear boundary: I do not install remote-access software at the request of someone who called me unexpectedly. It makes no difference whether the display says bank, police, Microsoft, IT support or an investment exchange.
A real bank employee does not need control of a private computer to “secure the account”. A corporate helpdesk may legitimately use remote assistance, but it should do so through a known portal, after a ticket initiated by the employee, with a visible scope and a clear way to end the session. An unsolicited call changes the situation completely.
Say: “I am ending this call and will contact the organisation through its official number.” An honest adviser will accept that. A criminal will often threaten financial loss, tax consequences or a breach of secrecy around an alleged investigation. That pressure is one more reason to stop.
If the remote session is already active
When something feels wrong:
- Disconnect the computer from the internet by turning off Wi‑Fi or removing the cable.
- Close the remote-control app and shut the device down if you cannot confirm that the session has ended.
- From a different, trusted device, call the bank using its official number.
- Explain that a third party could see or control the screen during login. Ask the bank to secure the account and review transfers, beneficiaries, limits, loans and active sessions.
- Do not return to the alleged adviser and do not accept their offer to “fix” the incident.
Closing one window may be insufficient if the app was configured for unattended access or another program was installed. Once the money is protected, have a trusted professional or corporate IT inspect the device. Do not use it for email, banking or password changes in the meantime.
What to check after the incident
Preserve the number, call time, app name, codes shared and safe screenshots where possible. Write down the order of events before details fade. From another device, change email and banking passwords, end unfamiliar sessions and add a second factor where it was absent.
If money moved or a loan was attempted, report the incident to the police. In Poland, the incident and any links can be submitted through incydent.cert.pl. At work, tell the helpdesk or security team immediately even if the bank balance looks unchanged; the remote party may have seen documents, email and customer data.
A routine for home and work
Save the bank’s official number in a relative’s phone and show them how to disconnect a device from the internet. At work, document which tools the helpdesk uses, what a genuine session request looks like and who initiates it. An employee must be able to refuse without fearing that they are “making IT’s job harder”.
Breachroad’s conclusion is that remote-assistance safety depends primarily on initiation and context. The same app can be a safe tool inside a ticket you opened or a route to theft after an unexpected call.
The facts about the AnyDesk scenario, caller-ID spoofing and contacting the bank quickly come from CERT Polska. The detailed sequence for disconnection, account protection and device review is our response plan. Pair it with our guide to calls from a fake bank employee.
Cybersecurity training and social-engineering simulations help staff practise the moment of refusal and help support teams provide genuine remote assistance safely.

