How does an app become a risk?
A fake app can copy the name and appearance of a bank, delivery firm or familiar service. Another scenario uses a genuine remote-support app: the risk is not necessarily the software itself, but granting an unknown person the ability to view or control your device.
Pause when someone guides you through an installation, accessibility settings, screen sharing or a mobile-banking sign-in during a call.
Four checks before installation
- Find the app through the bank or service provider’s official site and use an authorised app store.
- Check the exact publisher name, update history and whether the official site links to that app.
- Compare permissions with purpose. A calculator does not need contacts, text messages or accessibility control.
- Do not rely only on download counts, ratings or a logo. They are signals, not guarantees.
Permissions that deserve extra care
Access to text messages, notifications, microphone, camera, contacts, installing other apps, drawing over apps or accessibility functions should have a clear reason. Reject a request that is not needed for the feature you use.
Do not approve screen sharing or control for someone whose identity you have not verified independently. Never enter a banking PIN, password or code while such a session is active.
If you installed it or granted access
- End the call and disconnect the device from the network if remote access is active.
- If you opened banking, exposed card information or approved a payment, call the bank immediately using its official number.
- From another trusted device, change exposed passwords and end unknown sessions. Start with email if it recovers other accounts.
- For a work device, notify IT or security and do not erase evidence yourself. For a personal device, follow the device recovery steps; uninstalling alone does not prove the device is clean.
- Preserve the app name, link, caller number, time and screenshots you already have. Do not reopen the suspicious link for evidence.
Check your knowledge · 3
of 5
Your turn to choose the next step.
Choose one answer for each question shown. More complex lessons select three questions from a wider question bank when the lesson loads.
Questions and explanations are also available without JavaScript.
Without JavaScript, the full bank of 5 questions is shown.
An app is in an official store and has many ratings. Is it fully verified?
Why does this matter? Store controls and ratings help, but cannot guarantee every app is safe or genuine.
-
Yes, no other check is needed.
Store review reduces risk but does not detect every problem.
-
No; I check the publisher, official link, permissions and purpose.Correct answer
Several independent signals reduce the chance of installing an imitation.
-
Yes, if the icon matches the brand.
Names and icons can be copied.
Unknown 'support' asks to see your screen while you open banking. What do you do?
Why does this matter? Screen viewing or control can expose sensitive information and affect what you approve.
-
End the call and verify the issue directly with the bank.Correct answer
Independent bank contact removes the unknown person from the process.
-
Continue but cover the PIN with my hand.
Screen sharing may expose much more than the PIN.
-
Allow access for only five minutes.
A short session can still be enough for misuse.
You granted remote access and signed in to mobile banking. What is the priority?
Why does this matter? Financial access may have been exposed and needs urgent bank assessment while further control is stopped.
-
Only delete the app icon.
Removing an icon does not prove access is gone or protect the bank account.
-
Wait for the phone to show a warning.
No warning does not mean the device or session is safe.
-
Disconnect and contact the bank immediately using another trusted device or phone.Correct answer
This stops further access and lets the bank assess the account.
A message supposedly from your bank asks you to install an APK outside the app store. What do you do?
Why does this matter? Installing from a message bypasses the normal route to the app and may deliver an imitation.
-
Install it because the file uses the bank's name.
A filename is easy to change and does not verify the publisher.
-
Open the official store or bank website independently of the message.Correct answer
An independent route lets you locate and verify the official app.
-
Forward the file to somebody else to test.
Forwarding may expose another person.
A flashlight app requests SMS and accessibility access. What do you do?
Why does this matter? Those permissions do not fit the basic function and may expose codes or enable interface control.
-
Deny them and remove the app if it cannot justify them.Correct answer
Permissions should have a clear relationship to the app's function.
-
Approve them because the app is free.
Price does not establish safety or a need for access.
-
Approve them only while using mobile banking.
Granting access during banking increases rather than reduces the risk.
No registration. Your answers are not sent; the result is just for you.