Screen sharing is remote access with better manners
The request sounds smaller than what it grants — and one familiar-looking prompt turns being watched into being operated.

Short answer
Screen sharing transmits everything on your display in real time — notifications, other windows, anything you type — and most conferencing tools include a small prompt that escalates it to full remote control with one click. Never share with someone who contacted you, never open a banking app while sharing, and share a single window rather than the whole screen.
On this page
Someone asks you to share your screen so they can see the problem. It sounds like showing them a photograph — passive, limited, obviously safe. It is closer to handing them a window into everything on your device, and in many tools it is one click away from handing them the controls.
Screen sharing is transmitting what is on your display to someone else in real time. Used properly it is one of the most useful things in remote work. The reason it belongs in a discussion of fraud is that the request sounds so much smaller than what it grants.
What is actually shared
More than the thing you meant to show, in four ways people consistently underestimate.
- Notifications. Messages, one-time codes, calendar reminders, email previews. A banner appearing mid-share is visible to everyone watching, and codes arrive at exactly the moment somebody is trying to use them.
- Everything on the screen, not just the window. Sharing an entire display shows your other tabs, your desktop files, your open documents and whatever you switch to.
- Anything you type visibly. A password typed into an unmasked field, an address, an account number.
- The recording, if there is one. Many tools record by default in an organisational setting, which means this becomes a file that outlives the call.
The request is "can you show me the error". What is granted is "everything on this display, live, plus anything I notice while you look for it".
Sharing versus control
These are different permissions and they get conflated in conversation.
| Screen sharing | Remote control | |
|---|---|---|
| They see your screen | Yes | Yes |
| They move your pointer | No | Yes |
| They can type | No | Yes |
| Grantable by mistake | Sometimes | Yes, often one click |
| Reversible instantly | Yes | Yes, if you know how |
The row that matters is the fourth. Most conferencing tools have a "request control" prompt that appears while you are already sharing, and it is small, familiar-looking and easy to accept reflexively when someone says "let me just fix that for you". That single click is the difference between being watched and being operated.
Know how to stop both before you start — the keyboard shortcut or the button — because knowing it while something is going wrong is not the same as looking for it then.
When the request is the attack
Fraudulent use of screen sharing follows a consistent shape.
It begins with a support pretext. A call about a refund, a suspicious payment, a device problem, an expiring subscription. The screen share is presented as the way to sort it out.
They ask you to open your banking app while sharing, to "verify" or "check" something. Now they see the balances, the account numbers and the interface — enough to guide you convincingly through the rest.
They talk while you act. The narration keeps you moving. You are performing the transaction; they are watching and instructing, which is why the bank's fraud checks pass.
A refund is "processed" in front of you. Numbers typed in a browser are just numbers. A screen showing a credit does not mean money moved, and the follow-up — "we sent too much, please return the difference" — is the actual theft.
The critical fact: anything a fraudulent agent shows you on a screen is only pixels. A page saying your account was credited, an official-looking form, a countdown — all of it is a picture until your own bank, opened by you, says otherwise.
The rules that hold
Five, and the first covers most of it.
- Never share your screen with someone who contacted you. Not a caller, not a chat that opened by itself, not an email support line. Share with people you approached through a route you already had.
- Never open banking or payment apps while sharing. There is no legitimate support reason for it, and it is the point of the exercise in the fraudulent case.
- Share a single window, never the whole screen. Every tool offers this. It removes notifications, other tabs and your desktop from the picture in one choice.
- Turn on do-not-disturb first, so codes and message previews do not appear.
- Refuse remote control. Watching is enough for anything genuine; if a real support process needs control, it will come from your own IT department on a device they manage.
Rule three is the one worth building as a habit even for entirely ordinary calls, because it costs nothing and it removes the accidental disclosures — the message from a friend, the tab you forgot about — that make up most of the real-world damage.
Legitimate remote access, and how it differs
Being clear about this matters, because the useful version exists and is normal.
Your employer's IT department, on a device they manage, after you raised a ticket. They typically cannot connect without your approval and the session is logged.
A colleague you asked, in a call you started.
A support session you initiated from inside a company's own app, where the connection is part of the product rather than a tool you were asked to install.
The distinguishing property in all three: you initiated it, through a channel you already trusted. That is the same test that resolves almost every impersonation question, and it works here without needing to judge how convincing anybody sounds.
The same logic explains why controlling your own machines remotely — a home computer you set up yourself, reached through your own network — is a different category entirely. You are both parties, and there is nobody to impersonate.
If you have already shared
Order matters, and the first step is time-sensitive.
- End the session and disconnect from the network if they had control — a live session ends when the connection does.
- Remove anything you installed, particularly a remote access tool you were talked through.
- Change passwords for anything visible during the call, from a different device.
- Call your bank on the number from your card if banking was on screen, and say a device may have been compromised — it changes how they treat subsequent activity.
- Check for new payees, rules and forwarding in email and banking, since those are added quietly and survive a password change.
- Expect a follow-up contact offering to recover the loss. It is the same operation.
More on the pretexts in impersonation, the chat variant in phishing, and account protection in digital safety. The NCSC's guidance on remote access covers the organisational side.
The short version
Screen sharing transmits everything on your display, including notifications, other windows and anything you type — and in most tools a small prompt turns watching into control with one click.
Never share with someone who contacted you, never open a banking app while sharing, share a single window rather than the whole screen, and turn on do-not-disturb first. And remember that anything shown to you on a screen during such a call is only pixels: a credit is real when your own bank, opened by you, says so.
Frequently asked questions
- What is the difference between screen sharing and remote control?
- Sharing lets someone see your screen; control lets them move your pointer and type. Most tools have a request-control prompt that appears while you are already sharing, and accepting it reflexively is the difference between being watched and being operated.
- Is it safe to share my screen with support?
- Only if you initiated the contact through a route you already had. Never share with someone who called or messaged you, and never open banking or payment apps while sharing — there is no legitimate support reason for it.
- They showed me a refund on screen — was it real?
- Not necessarily. Anything displayed during such a call is only pixels; numbers typed in a browser are just numbers. A credit is real when your own bank, opened by you, shows it.
- What single habit reduces the risk most?
- Sharing a single window rather than the whole screen, with do-not-disturb on. That removes notifications, one-time codes, other tabs and your desktop from the picture in one choice, and it costs nothing on ordinary calls.
Sources
- Mobile device guidance — UK National Cyber Security Centre
- Tech support scams — US Federal Trade Commission
- Wakivo: Wake on LAN & Shutdown — Tecno Blocks
Scamiro
Practical online safety guides covering scams, phishing, suspicious links, fraudulent websites, impersonation, social media scams, and digital fraud.
About the publication