Abuse Prevention
Remote access software is a legitimate tool that criminals sometimes turn against the people they call. This page explains how that fraud works, what to do if you have already granted access, and how to report an account to us.
Is HopToDesk a scam?
HopToDesk is a legitimate, open-source remote desktop application used by IT teams and businesses worldwide. Criminals misuse remote access software of every brand, and HopToDesk is no exception. If someone called you and instructed you to install HopToDesk, treat that call as fraudulent, whatever organisation the caller claims to represent.
Our position on fraudulent use
The HopToDesk Terms of Service prohibit using the software to deceive, defraud, impersonate or steal from any person. We suspend accounts involved in fraud, we retain the reports submitted through this page, and we respond to lawful requests from law enforcement.
How this fraud works
Nearly every case reported to us follows the same sequence. The contact is unsolicited. A reason is given for why remote access is required. Payment or account details are then taken while the caller is connected. The stories below account for the great majority of reports.
Unclaimed funds and forgotten cryptocurrency
This is the most frequently reported story. The caller says money is waiting for you and offers to walk you through claiming it, but needs access to your computer to file the paperwork or set up a receiving account. Once connected, they move money out of your accounts, capture the login codes sent to your phone, install malware, or charge repeated fees to release funds that do not exist.
The usual variants are:
- Unclaimed government property. Records supposedly show several thousand in unclaimed funds held by the state. Genuine unclaimed property schemes exist in most countries, which is exactly why this story is convincing.
- Cryptocurrency in your name. Bitcoin was sent to a wallet in your name years ago, or a claim is outstanding against a collapsed exchange. This targets people who followed the news but never bought any.
- A dormant bank account or pension. An account from a former employer has been flagged as inactive. The caller often knows a real previous employer, taken from a professional network profile or a data breach.
- An inheritance. A relative you were not aware of has died and named you as a beneficiary.
- A class action settlement. You are said to be a member of a settled class in a well publicised lawsuit.
- A tax refund. A refund is outstanding and the tax office has been unable to deliver it.
- Fund recovery. If you have already lost money to fraud, a second caller may offer to recover it for a fee. This is a follow-up fraud aimed at people who have been defrauded once.
Fake technical support
A call or a browser pop-up reports that your computer is infected and directs you to a support number. The technician on that number needs remote access to clean the machine. Microsoft, Apple and Google do not contact customers this way. The pop-up and the number are both fabricated. The outcome is malware, stolen banking credentials, or a charge for a repair that was never needed.
Impersonation of a bank or public authority
A caller presents themselves as your bank, the tax office, the police or another government body, reports suspicious activity, and asks to verify your computer remotely. Banks and public authorities never ask you to install remote access software. End the call and dial the organisation back on the number from its official website or the back of your card.
Refund and delivery notices
An email or text message refers to an online order, a payment refund or an undelivered parcel, and gives a number to call to dispute the charge or arrange redelivery. The person on that number talks you through installing HopToDesk to process the refund, then either takes banking credentials or manipulates you into transferring money.
Long-term contact built online
Someone met through a dating site, a social network or a messaging app eventually offers to help with your computer, or asks you to help with theirs. A genuine relationship does not require remote access to your machine.
Warning signs
Treat a request for remote access as fraudulent if any of the following apply.
- You did not make the first contact. They called, emailed or messaged you.
- They know your name, date of birth, former address or employer. This proves nothing. That information is traded cheaply after data breaches.
- They want access to your computer in order to help you claim something or complete paperwork.
- A fee, tax, deposit, verification charge or processing cost has to be paid first, especially by gift card, wire transfer, cryptocurrency or prepaid card.
- There is a deadline. The funds revert next week, only the first claimants qualify, you must act today.
- The caller becomes impatient or hostile when you hesitate or say you want to verify.
How to verify a claim safely
- End the call first. Nothing legitimate is lost by doing so.
- To check for unclaimed property, go to the official service directly. In the United States that is unclaimed.org, run by the association of state unclaimed property offices, or missingmoney.com. In the United Kingdom it is mylostaccount.org.uk. Most countries have an equivalent. Never use a link or number supplied by the caller.
- For a bank or investment account, call the number printed on your card or on the institution's own website.
- For cryptocurrency, if you did not create a wallet and record the recovery phrase yourself, there is no cryptocurrency held in your name. An address you do not control cannot be claimed.
- For an inheritance, estate lawyers write to you on headed paper from a firm with a verifiable address. They do not cold call and they do not ask for access to your computer.
- For a class action settlement, every genuine case has an official claims site run by a court-appointed administrator. Search the case name together with the words official settlement website.
If you have already given someone access
Once you are disconnected:
- Change your passwords on every account that was open or signed in during the session, starting with email and online banking. Use a different device, such as your phone.
- Contact your bank if card or account details were exposed. Ask for the cards to be frozen and the account flagged for fraud monitoring. Fraud lines are staffed around the clock.
- Run a full antivirus scan. On Windows, Microsoft Defender is sufficient. Open Windows Security, then Virus and threat protection, then Scan options, then Full scan.
- Check your statements for the next 30 days. Accounts are sometimes emptied days or weeks later to avoid immediate detection.
- Report the incident to your local police or national cybercrime unit. Your report helps investigators connect cases. Include the HopToDesk ID that connected to you, the 9 to 10 digit number shown in the HopToDesk window, if you noted it.
- Report the ID to us using the form below. Reports are used to warn other users and to support law enforcement enquiries.
- Remove HopToDesk using the instructions below, unless you use it for your own work.
Safeguards in HopToDesk
- Connections must be accepted. By default, a session cannot begin until the person at the receiving computer accepts the request. There is no silent or background access unless unattended access has been configured deliberately.
- Sessions are end to end encrypted. HopToDesk cannot see the content of a session.
- A permanent password can be required for incoming connections, under Settings and then Security, so knowing your ID alone is not enough to connect.
- Two-factor authentication can be enabled for incoming connections, adding a rotating code on top of the password.
- A session can be ended at any point by clicking the disconnect icon in the toolbar or closing the window.
The strongest safeguard is the simplest one. Do not accept a connection from anyone you do not know and trust, and never give your HopToDesk ID or password to someone who contacted you first.
How to remove HopToDesk
If HopToDesk was installed only because a caller asked you to install it, you can remove it safely. Removing it does not delete any of your files.
Windows
- Press the Windows key, type Add or remove programs, and open it.
- Find HopToDesk in the list.
- Select it, choose Uninstall, and follow the prompts.
macOS
- Open Finder and go to Applications.
- Drag HopToDesk to the Trash.
- Empty the Trash.
Linux
- Debian and Ubuntu:
sudo apt remove hoptodesk - Fedora and RHEL:
sudo dnf remove hoptodesk - Arch:
sudo pacman -R hoptodesk
Android and iOS
On Android, press and hold the HopToDesk icon and tap Uninstall. On iOS, press and hold the icon, tap Remove App, then Delete App.
Report abuse
If a HopToDesk ID was used to defraud you or to attempt it, report the ID below. Reports go to our trust and safety team, and to law enforcement partners where relevant. No account is required and the report can be anonymous.