Friday, September 11, 2026
Cyber Kannadigas — also CyberKannadig · CyberKannadiga · Cyberkannadiga · Cyber Kannadiga · Independent · Free · No login · Karnataka-trusted
Scam Awareness SCAM ALERT

AnyDesk Remote Access Scam: How Fraudsters Take Over Your Phone

A "support agent" asks you to install AnyDesk and read out a 9-digit code. That code hands them your screen and your bank apps. Here is how the scam works and how to shut it down.

Ramesh Iyengar
Elder Safety Specialist
Published September 9, 2026 · Updated September 9, 2026 · 8 min read
Quick Answer

An AnyDesk remote access scam is a fraud where a caller pretending to be from your bank, a wallet, or customer care persuades you to install a remote-access app such as AnyDesk or TeamViewer and share the 9-digit code it shows. That code gives the scammer live control of your phone, letting them see your screen, read OTPs, and operate your banking apps. Never install such an app or share the code because someone called you. The Reserve Bank of India has warned about this exact fraud.

Key Takeaways

  • AnyDesk and TeamViewer are legitimate apps, but scammers abuse them to control your phone remotely.
  • The scam turns on one action: you sharing the 9-digit access code the app displays.
  • Once connected, the fraudster can see your screen, read OTPs and operate your bank and UPI apps.
  • No genuine bank or customer-care agent ever needs remote access to your phone to "help" you.
  • If you installed it, disconnect the internet, uninstall the app, and report on 1930 at once.
In this article

    An AnyDesk remote access scam is a fraud in which a caller convinces you to install a remote-access app, most often AnyDesk or TeamViewer, and then share the short code the app displays. The moment you read out that 9-digit code, the scammer’s computer connects to your phone and can see everything on your screen. From there they can watch you type, read the OTPs that arrive, and operate your banking and UPI apps as if the phone were in their own hands. The Reserve Bank of India has specifically warned customers about fraud using the AnyDesk app, so this is a well-documented threat, not a rare edge case.

    The important thing to understand is that AnyDesk is not malware. It is a normal tool that IT staff use to fix computers remotely. The danger is entirely in how scammers trick ordinary people into installing it and granting access. Once you know the pattern, it is easy to refuse. This guide explains how the scam works, the warning signs, and exactly what to do if you have already installed the app.

    What is the AnyDesk remote access scam?

    It is a social-engineering fraud. The scammer does not hack your phone by force; they persuade you to open the door yourself. Posing as your bank, a wallet company, or customer care, they invent a reason you need “help”, a refund that needs processing, a KYC update, a failed transaction, and tell you the only way to fix it is to install a small app so they can “assist” you. That app is a remote-access tool. When you share the access code, you hand over control.

    This scam often begins with a fake customer-care number that a victim finds through a web search when trying to reach a company. It also overlaps closely with fake KYC scams, because “update your KYC” is a common excuse used to get the app installed.

    How does the AnyDesk scam work step by step?

    The sequence is consistent, which makes it easy to spot once you know it:

    1. The pretext. A caller claims to be from your bank or a company’s support team, or you call a fake support number and reach them. They describe a problem, a stuck refund, a KYC issue, a wrong charge, that they will “help” resolve.
    2. The install request. They ask you to download an app from the Play Store or App Store to “verify” or “process” the fix. The app is AnyDesk, TeamViewer, or a similar remote-access tool.
    3. The code. When you open the app, it shows a 9-digit code. The scammer asks you to read it out “so we can connect and help”.
    4. The connection. Once they enter that code and you approve the connection, they can see and control your screen in real time.
    5. The theft. They guide you to open your banking or UPI app, or do it themselves, and initiate transfers. They read incoming OTPs directly off your screen and watch or capture your PIN.

    At no point do they need to “hack” anything. Every bit of access is something you were talked into granting.

    What are the warning signs of a remote access scam?

    These red flags are your early-warning system. Any one of them should end the call.

    Red flag Why it means fraud
    You are asked to install AnyDesk, TeamViewer or a “support” app No genuine bank or customer-care process needs remote access to your phone.
    You are asked to read out a 9-digit code from the app That code is the key to controlling your phone; sharing it hands over your screen.
    The “agent” wants to “process a refund” via an app Refunds do not require remote access or any app you install on a caller’s instruction.
    You are told to open your banking or UPI app while connected They want to operate your accounts or read your OTPs and PIN live.
    You reached the number through a web search, not an official source Fake customer-care numbers are planted online exactly to start this scam.
    Pressure to keep the app running and stay on the call They need continued access to complete the transfers before you notice.

    Why is remote access so dangerous?

    Because it defeats the safeguards you rely on. Normally, an OTP protects your transaction: even if someone knows your card number, they cannot complete a payment without the code sent to your phone. But if a scammer can see your screen, that OTP appears right in front of them the instant it arrives. Similarly, your UPI PIN protects your account, but on a shared screen they can watch you enter it. Remote access turns your own phone into a window the fraudster is looking through. That is why the single rule, never grant remote access to a caller, is so powerful: it keeps every other protection intact.

    How do I protect myself from the AnyDesk scam?

    A few firm habits will keep you completely safe:

    • Never install a remote-access app because a caller told you to, whatever the reason.
    • Never share the 9-digit code AnyDesk, TeamViewer or any similar app displays.
    • Never open your banking or UPI app while on a call with someone guiding your screen.
    • Find support numbers on official sources only, the bank’s official app, its website, or the back of your card, never from a random search result or a message.
    • Hang up on anyone who insists. Genuine help never requires remote control of your phone.
    • Keep OTPs, PINs and passwords private, no exceptions.

    These habits also protect you from related UPI fraud, since remote access is often just the delivery method for a UPI or banking theft.

    How does the scam usually reach you?

    Remote-access fraud almost always starts with a believable reason to be on the phone with “support”. Knowing the common entry points helps you stay alert:

    • A fake customer-care number. You search online for a bank, wallet or delivery company’s helpline and call a number that turns out to belong to scammers, who then walk you into installing the app.
    • A refund or cashback offer. A caller says you are owed a refund and that they need to “process” it through an app on your phone.
    • A KYC or account-update pretext. The same story used in fake KYC messages, resolve your “pending verification” by installing an app, doubles as a way in for remote access.
    • A “failed transaction” fix. They claim a payment got stuck and that they must connect to your phone to reverse it.

    In every case, the request to install an app and share a code is the moment to stop. That step is never part of genuine support.

    Which apps do scammers ask you to install?

    AnyDesk is the name most associated with this fraud in India because of the RBI’s warning, but it is not the only tool abused. Scammers may name any remote-access or screen-sharing app. The lesson is not to memorise a blocklist of names, it is to refuse the category entirely.

    What the caller says What is really happening
    “Install this app so I can guide you” They want live control of your screen
    “Just read me the 9-digit code” That code connects their device to yours
    “Open your banking app so I can check” They plan to operate your accounts or read your OTP
    “Keep the app open, do not disconnect” They need continued access to finish the transfers

    If any caller asks you to install an app you did not choose and share a code from it, treat it as fraud regardless of the app’s name.

    What should I do if I already installed AnyDesk on a caller’s instruction?

    If you have installed the app or shared the code, act immediately, minutes matter:

    1. Disconnect the internet. Turn off Wi-Fi and mobile data to cut the remote connection instantly.
    2. Uninstall the app. Remove AnyDesk, TeamViewer or whatever was installed.
    3. Secure your accounts from a safe device. Change your net-banking password and UPI PIN.
    4. Call your bank’s official helpline to freeze transactions and block your card or account if needed.
    5. Call 1930, the National Cyber Crime Helpline, and report the fraud.
    6. File on cybercrime.gov.in with the app name, the caller’s number, and any transaction details.

    For the full reporting process and what happens after you file, see our guide on how to report cyber fraud through 1930 in Karnataka. Reporting quickly gives your bank the best chance to freeze any transfers, though recovery is never guaranteed.

    Helping older relatives stay safe

    Remote-access scams are particularly effective against people who are less familiar with how banking apps and OTPs work, which often means elderly parents. Explain the one rule clearly: nobody legitimate ever needs to install an app on your phone or see your screen to help you. If a caller asks for that, hang up and call a trusted family member. Our guide on protecting elderly parents from online scams offers more ways to have that conversation without causing alarm.

    The bottom line

    The AnyDesk remote access scam is not about a dangerous app; it is about a convincing caller talking you into handing over control of your own phone. The whole fraud collapses if you refuse two things: installing the app and sharing the code. No real bank or support team will ever ask for either. Keep that rule, share it with your family, and if you have already granted access, disconnect, uninstall, secure your accounts, and report it on 1930 without delay.

    Targeted by a scam — or already lost money?

    Act immediately: (1) call your bank and freeze the account · (2) call the national Cyber Crime Helpline 1930 · (3) file a complaint at cybercrime.gov.in · (4) visit your nearest police station. See our scam-awareness guide for step-by-step help.

    Ramesh Iyengar
    Elder Safety Specialist

    Ramesh Iyengar

    Ramesh Iyengar is the Elder Safety Specialist at Cyber Kannadigas. A retired educator from Mysuru who later trained as an adult-learning facilitator, he has run community smartphone-literacy sessions for senior citizens for several years. Ramesh writes specifically for older readers and the… Read full profile →

    Frequently Asked Questions

    No. AnyDesk and TeamViewer are legitimate remote-access tools used by IT professionals. The scam is not the app; it is fraudsters tricking you into installing it and handing them the access code so they can control your phone.
    The code is the address that lets another device connect to yours. When you read it out to a scammer, you are giving their computer permission to see and control your phone screen, including your banking apps.
    It would not. No genuine bank or customer-care team needs remote access to your phone to process a refund, fix KYC, or resolve a complaint. Any such request is a clear sign of fraud.
    If they control your screen, they can read OTPs as they arrive and enter your UPI PIN as you type, or watch you type it. That is why you must never grant remote access; disconnect immediately if you already did.
    Turn off Wi-Fi and mobile data at once, uninstall the app, and from a safe device change your net-banking password and UPI PIN. Call your bank to freeze transactions, then call 1930 and report on cybercrime.gov.in.
    Usually through a fake refund, KYC update, or "resolve your complaint" story, often after you called a fake customer-care number found online. The pretext varies; the goal is always to get you to install the app and share the code.

    Stay scam-safe: alerts in your inbox

    Get new scam alerts, UPI-safety tips, and digital-literacy guides weekly. Free.

    Related Articles

    More from Ramesh Iyengar