Join our Newsletter — 33% off our NHI Course
Home Glossary Identity Beyond IAM Screen Sharing Fraud
Identity Beyond IAM

Screen Sharing Fraud

← Back to Glossary
By NHI Mgmt Group Updated September 8, 2026 Domain: Identity Beyond IAM

Screen sharing fraud is a social engineering technique where a victim is persuaded to install or enable a remote viewing app, letting the attacker watch sensitive activity in real time. In digital banking, this can expose passwords, one-time passwords, and transaction details even when the bank’s application is otherwise secure.

Expanded Definition

Screen sharing fraud is a form of social engineering that abuses remote viewing or screen-control software rather than exploiting the bank app or operating system directly. The key boundary is consent under deception: the victim is tricked into installing, authorising, or actively using a tool that lets the attacker observe on-screen activity in real time.

This matters because the fraud can capture information that would otherwise be protected by strong application security, including login steps, one-time passcodes, payment confirmations, and account recovery prompts. It is not the same as ordinary remote support unless the support relationship is genuine, verified, and limited to a trusted channel. Industry guidance generally treats this as a trust-abuse problem rather than a technical breach of the target app itself.

For a standards-based view of control expectations around access and monitoring, NIST SP 800-53 Rev 5 Security and Privacy Controls provides useful context on access control, auditability, and user awareness, even though it does not define the fraud pattern itself.

Examples and Use Cases

Screen sharing fraud appears wherever a user can be convinced to approve a live view session and then act normally while the attacker watches. In practice, the fraud often unfolds as a staged support or security story that lowers the victim’s suspicion.

  • A fraudster poses as bank support and asks the victim to install a remote access app to “verify” an account problem.
  • An attacker persuades a customer to open a banking session while screen sharing is active, then observes credentials, OTP entry, and transfer approval.
  • A malicious caller uses a fake device infection warning to pressure the victim into granting view access so the attacker can follow recovery steps in real time.
  • An organisation’s service desk is impersonated to redirect the user from normal help channels into an unmanaged remote viewing session.

The practical trade-off is speed versus trust: legitimate remote assistance can be efficient, but the same convenience creates an easy path for deception when identity checks, channel validation, and session boundaries are weak.

Security Implications

The main security issue is that screen sharing converts the victim’s own device into a disclosure channel. Even when passwords are masked or transactions are protected by strong authentication, the attacker can still observe the human process around them, which often reveals enough to complete fraud.

Failure usually happens at the decision point, not the technology layer. The victim may believe they are cooperating with support, a fraud investigator, or a bank representative, while the attacker uses that trust to watch sensitive actions, coach the victim, or wait for a high-value transaction. This can also weaken detection because the activity may look like normal customer behaviour from the bank’s side until the compromise is already complete.

A common practitioner observation is that screen sharing fraud often bypasses controls that focus only on credential secrecy. If organisations do not treat live screen disclosure as a distinct exposure, they can miss the real point of compromise: human-assisted observation of authentication and payment flow.

Domain and Governance Relevance

In digital banking and adjacent identity-heavy services, screen sharing fraud sits at the intersection of customer assurance, authentication design, and fraud governance. The issue is not simply whether the platform is secure, but whether the institution can assume that on-screen activity is private once the user has been socially engineered into sharing it.

That changes governance in a practical way. Controls that depend on one-time passwords, transaction prompts, or step-up verification may still be necessary, but they are not sufficient if the user can be coached live through them. The term therefore belongs in fraud operations, customer education, and identity-risk discussions, especially where support channels or recovery workflows can be impersonated.

For non-human identity programmes, the relevance is indirect rather than primary: the lesson is that machine-side control strength does not fully protect workflows when a person is manipulated into exposing the session. In other words, the trust boundary is the human screen, not only the authenticated account.

Risk and Threat Considerations

Screen sharing fraud creates a direct exposure of credentials, authentication factors, and payment intent through real-time observation. The risk is especially acute in banking, account recovery, and high-trust support scenarios where a victim can be guided through sensitive actions while believing the interaction is legitimate.

Failure mechanism: The attacker leverages social engineering to obtain live screen visibility, then observes secrets, prompts, balances, and transaction steps that are not meant to be disclosed to a third party. The abuse works because many controls protect data at rest or in transit, but do not stop a user from voluntarily displaying it to an impostor.

Impact: The result can be account takeover, fraudulent payments, recovery abuse, or escalation into wider identity compromise. Once the attacker can see the session in real time, they can bypass many user-facing protections by exploiting the victim’s own actions as the disclosure channel.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Identity Management, Authentication and Access ControlScreen sharing fraud exploits trust in authentication and session access.
PR.AT — Awareness and TrainingVictims are manipulated through deceptive support and urgency narratives.
Recommendation — Tighten authentication and session controls to reduce exposure from user-mediated screen disclosure. Train users to verify support channels before installing or enabling any screen-sharing app.
CIS Controls v86 — Access Control ManagementLimits who can access sessions and reduces misuse of remote viewing tools.
Recommendation — Restrict and review remote-access paths so only approved support sessions can occur.
NIST SP 800-635.2 — Authentication Process RequirementsFraud often bypasses authentication by coercing the user during the sign-in flow.
Recommendation — Design authentication flows so they remain resilient when a user is coached in real time.

Practitioner Guidance

What to watch for: The clearest warning sign is any request to install, enable, or continue a remote viewing session that is justified by urgency, account safety, or troubleshooting. Organisations should treat that as a high-risk interaction because the abuse pattern depends on convincing the user that observation is part of the remedy.

Governance implication: Fraud teams, support teams, and identity owners should align on which channels are authorised for assistance and which session behaviours must never be requested. If those rules are inconsistent, attackers can exploit the gap by impersonating the most credible authority available to the victim.

Practitioner takeaway: The strongest defence is not only technical blocking, but making legitimate support paths unmistakable so that a user can recognise when screen visibility is being abused.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org