Use symptom, evidence and one controlled test
Start with what you can observe. “Login broken” is too broad; “OTP arrives, but the screen returns to login after submission” is useful. Write the exact message, time, device, app or web address, and the last action that worked.
Before deleting data, changing credentials or reinstalling, capture the current state. Then perform one low-risk test. If the result changes, record it. If it does not, restore the setting where possible and move to the next step.
Site does not open, redirects or shows a different brand
- Copy the full address before closing the screen.
- Check whether the domain changed after a redirect.
- Try a different trusted network only to separate DNS or connection problems.
- Check device date/time and certificate warnings.
- Do not enter credentials on a substitute domain merely because the design looks familiar.
If the destination changes repeatedly or a message pushes a new “working link,” treat identity as unresolved. A temporary outage does not justify sending a password to an unverified replacement.
OTP missing or verification delayed
Confirm the masked mobile number or email, signal, message blocking and device time. Wait before requesting another code; repeated attempts can trigger rate limits or make it difficult to tell which OTP is current. Never forward an OTP to someone claiming they will complete verification for you.
If the OTP message describes a different action, such as password reset or payment approval, stop. The wording can reveal that someone is attempting another operation.
Login loop after password or OTP
- Capture the error and address.
- Confirm cookies and JavaScript are not blocked for the destination.
- Close duplicate tabs and retry once.
- Check the app or browser for updates.
- Try the same account on one other trusted device without sharing the password.
- Do not keep resetting the password unless the system confirms the credential is wrong.
App will not install or update
Check storage, Android version, file completeness, Play Protect status and whether an older package with a different signature is installed. Do not turn off all security settings. If an update comes from a different source or requests new high-impact permissions, treat it as a fresh installation decision.
App crash, freeze or blank screen
Record the app version, Android version, available storage and the action that triggers the crash. Restart once, close overlays, update Android System WebView where relevant, and test without battery restriction only if needed. Clearing data may remove a session, so confirm you have safe recovery access first.
Payment left the bank but not the wallet
Use the transaction evidence sequence on the payment safety page. The key distinction is whether the bank status is pending, successful or reversed. Do not repeat the transfer while the first state remains unclear.
Withdrawal remains pending or is rejected
Save the request ID, amount, submission time, status history and exact reason. Check whether account ownership, limits or destination details are incomplete. Do not assume a delay proves fraud, but stop immediately if a personal contact demands another payment to release funds.
Account details changed unexpectedly
- Use a clean device and end any remote-access session.
- Change email and account passwords through trusted routes.
- Review linked payment details, recovery information and active sessions.
- Capture unfamiliar activity before it is removed.
- Contact verified support with one case reference.
- Contact the bank and cybercrime channel if money moved without approval.
Support asks for money, an OTP or screen control
End the interaction. A support case can be described using an account ID, error, timestamp and masked evidence. It should not require a UPI PIN, banking password or remote control. CERT-In specifically warns against installing remote-access apps on the instruction of unknown contacts; see its cyber-safety material.
Preserve evidence before a destructive fix
Clearing app data, resetting a phone, deleting messages or reinstalling can remove timestamps, version information and the exact error. Before a destructive step, capture the page address, app version, visible status, device time, recent transaction record and the contact route involved.
Keep the original files unchanged. Work from copies when redacting personal details. If the problem may involve malware, avoid transferring an unknown APK to another phone simply to “test” it. Record its name and hash where possible, then seek a safer analysis route.
What troubleshooting cannot establish
A successful login test cannot prove that a platform is financially reliable. A clean security scan cannot prove that every future app update is safe. A bank debit cannot prove that a platform credited the correct wallet. A support reply cannot prove the identity of the person unless the route itself is verified.
Keeping these boundaries separate prevents one positive sign from being stretched into a broader claim. Use each piece of evidence only for the fact it actually supports.
Escalation ladder
| Problem type | First route | Next route when unresolved |
|---|---|---|
| Account login or identity check | Verified platform support | Document the case and protect linked email or mobile access. |
| UPI or bank transaction state | Bank or payment app | Platform support with UTR and status evidence. |
| Suspected cyber financial fraud | Bank/payment app plus 1930 | National Cyber Crime Reporting Portal and local police as appropriate. |
| Consumer service grievance | Service provider complaint route | National Consumer Helpline or other lawful remedy. |
| Malicious Android behaviour | Disconnect, revoke access, scan and remove | Change credentials from a clean device and preserve evidence. |
Use one decisive evidence item for each symptom
The aim is not to try every possible fix. Choose the smallest observation that separates likely causes, run one low-risk test, and stop when further testing could erase evidence or expose money.
| Symptom | Most useful evidence | One low-risk test | Do not do |
|---|---|---|---|
| Unexpected redirect | Final domain and redirect sequence. | Open the previously saved destination directly on a trusted connection. | Enter credentials into the replacement destination just to see if it works. |
| OTP missing | Masked destination and the action that requested the code. | Wait once, confirm signal/message blocking and request one fresh code. | Send repeated requests or share a received code with support. |
| Login loop | Exact error, device time and whether verification completed. | Correct time, close duplicate sessions and retry once. | Clear all data before confirming recovery access. |
| APK will not install | Android version, storage, source and Play Protect warning. | Confirm compatibility and storage without disabling protection. | Turn off every security control because an installer says so. |
| Deposit missing | UTR, amount, recipient and bank state. | Compare that reference with the wallet history. | Repeat the transfer while the first one is unresolved. |
| Withdrawal delayed | Request ID, submitted time and exact visible state. | Compare the elapsed time with the stated processing window. | Pay an extra fee to a personal contact to release it. |
| Account changed | Recovery detail, unfamiliar activity and last known-good time. | Secure the recovery channel from a clean device. | Continue screen sharing with the person who contacted you. |
Know when troubleshooting should stop
Stop local testing and move to the responsible record holder when the evidence already shows a successful debit, an unknown recovery change, a high-impact permission combination, a payout reference that only the bank can trace, or a suspected fraud interaction. Repeating the same local action cannot reveal a private ledger and may make the record harder to understand.
- Stop after one controlled retry when the result is unchanged.
- Preserve the original error before clearing storage or reinstalling.
- Use one support case rather than several unverified contacts.
- Escalate money fraud promptly instead of waiting for technical troubleshooting to finish.