Skip to content

Global payments intelligence

Updated Sep 12, 2026 · 21:07 UTC

Now tracking Nacha’s September 18 Rules Put IAT Classification and ACH Posting Under Review
Payments intelligence
Payment Infrastructure

WhatsApp Screen-Sharing Scam Exposes Gaps Across Payment Controls

A victim reportedly lost more than £27,000 after fraudsters posing as FCA inspectors kept him on WhatsApp calls and gained visibility into his payment activity.

A UK consumer lost more than £27,000 after fraudsters posing as Financial Conduct Authority inspectors persuaded him to share his phone screen during WhatsApp calls, according to a September 10 report from consumer group Which?. The account shows how impersonation, screen visibility and prolonged coercion can cut across bank, card, wallet and merchant controls rather than producing one obviously fraudulent transfer.

Which? identified the victim only as William. It said the scammers kept him on calls for 20 hours over three days while telling him that his phone was infected and that a bank employee might be involved. By the time relatives intervened, the fraudsters had used or affected his credit cards, Apple Pay, eBay and Argos accounts and had made six iPhone and iPad purchases, the report said.

The loss and transaction details come from Which?’s account and were not independently confirmed by the named financial providers, merchants or law enforcement. No bank, card issuer, wallet provider or merchant was identified as having breached a rule or failed a specific legal duty.

Screen sharing turns authentication into observable data

Screen sharing is not the same as remote control. On its own, it lets another participant see what appears on the user’s display. That can include banking screens, card details entered during checkout and notification banners containing one-time passcodes. A fraudster can then coach a victim through payments or purchases while observing the authentication data used to approve them.

Remote-access software creates a separate and more severe risk because it may let an attacker operate the device. Which? warned that scammers can escalate from screen sharing to tools such as AnyDesk, TeamViewer or Zoho Assist by claiming they need to repair or secure an account. Payment providers should therefore distinguish between passive screen capture, active remote access and transactions made by a customer acting under instruction; each can produce different device and behavioural signals.

In William’s reported case, the attackers allegedly combined an official-sounding identity, warnings about malware and insider fraud, instructions not to speak to family or friends, and hand-offs between supposed departments. The duration matters. A multi-day episode involving several payment instruments may be harder to stop if each institution sees only its own slice of activity.

Meta added a warning, but the risk spans the payment chain

Meta announced in October 2025 that WhatsApp would warn users who attempt to share their screen with an unknown contact during a video call. The company said the prompt was intended to add context because scammers may pressure targets to expose bank details or verification codes. Which? also pointed to WhatsApp controls including context cards, blurred images from unknown contacts and the ability to silence, block or report unknown callers.

Those interventions add friction at the point where a screen-sharing session begins, but they cannot determine whether a saved contact has been compromised, whether a customer understands the warning or whether a later card purchase is being made under coercion. The fraud path can also move outside WhatsApp into a bank app, mobile wallet, marketplace or merchant checkout.

The FCA’s own consumer guidance directly contradicts the impersonators’ story. The regulator says it does not use WhatsApp or other messaging services, will never ask someone to transfer money to it and will not request banking PINs or passwords. It also warns that criminals can spoof FCA telephone numbers and says consumers should independently contact the regulator if a call appears suspicious.

What payment and commerce teams should examine

This case does not establish that one control would have prevented the loss. It does, however, illustrate several questions for fraud, authentication and customer-support teams:

  • Cross-channel velocity: Can issuers identify an unusual sequence of wallet activity, card-not-present purchases and high-value device orders rather than assess each authorization in isolation?
  • Coercion signals: Do payment challenges ask plainly whether the customer is on a call, sharing a screen or acting on instructions from a supposed bank, regulator or police officer?
  • OTP exposure: Are verification messages written so that both the purpose and the destination of a payment are clear even when a criminal can see the code?
  • Merchant fulfilment: Do merchants apply additional review to rapid orders for easily resold electronics, especially where account, delivery, device or payment behaviour changes together?
  • Case coordination: Can customer-support staff recognize when apparently separate card, wallet and marketplace events form one ongoing social-engineering episode?

Warnings should avoid implying that a genuine authority might occasionally ask for screen access to protect funds. For FCA impersonation, the rule is straightforward: the regulator says it does not use WhatsApp and does not ask consumers to move money for security.

A documented loss, not evidence of a new scam category

Screen-sharing fraud is not new. WhatsApp introduced screen sharing in 2023, and regulators and news organizations have warned about remote-access and screen-sharing scams for years. The timely development is the newly reported £27,000 victim account and the way it reportedly spread across several payment and commerce channels.

Which? said it has received a steady stream of screen-sharing scam reports in 2026, but it did not publish a case count, loss total or trend rate in the article. The report therefore supports concern about the method and the specific reported loss, not a claim that incidents have surged nationally.

For payments businesses, the accountability issue is less about assigning all responsibility to one app than about closing the gaps between messaging, device behaviour, authentication and fulfilment. A customer who appears to be authorizing a payment may still be acting under sustained deception while the criminal observes every prompt.