WhatsApp Screen-Sharing Scam Steals Financial Data via Social Engineering
A rapidly growing scam targeting WhatsApp users exploits the platform's screen-sharing feature to steal sensitive financial data and identities. Reported globally in regions including the United Kingdom, India, and Hong Kong, this fraud involves attackers posing as bank representatives or support agents during video calls. By creating a sense of urgency regarding unauthorized charges or account suspensions, scammers manipulate victims into sharing their screens. This action grants criminals real-time visibility of two-factor authentication codes, passwords, and banking details. In severe cases, victims have lost significant sums, with one incident in Hong Kong resulting in a loss of HK$5.5 million. The attackers may also instruct users to install remote access tools like AnyDesk, further compromising device security. Once access is gained, scammers drain bank accounts, hijack social media profiles, and impersonate victims to target their contacts. Security experts emphasize that this threat relies on psychological manipulation rather than technical hacking, urging users to remain vigilant against unsolicited video calls and never share their screens with unknown parties to prevent identity theft and financial loss.
Wire timeline
WhatsApp Screen-Sharing Scam Steals Financial Data via Social Engineering
A rapidly growing scam targeting WhatsApp users exploits the platform's screen-sharing feature to steal sensitive financial data and identities. Reported globally in regions including the United Kingdom, India, and Hong Kong, this fraud involves attackers posing as bank representatives or support agents during video calls. By creating a sense of urgency regarding unauthorized charges or account suspensions, scammers manipulate victims into sharing their screens. This action grants criminals real-time visibility of two-factor authentication codes, passwords, and banking details. In severe cases, victims have lost significant sums, with one incident in Hong Kong resulting in a loss of HK$5.5 million. The attackers may also instruct users to install remote access tools like AnyDesk, further compromising device security. Once access is gained, scammers drain bank accounts, hijack social media profiles, and impersonate victims to target their contacts. Security experts emphasize that this threat relies on psychological manipulation rather than technical hacking, urging users to remain vigilant against unsolicited video calls and never share their screens with unknown parties to prevent identity theft and financial loss.
WeLiveSecurity