Start with destination identity, not the logo
A login or registration screen can be reproduced quickly. The strongest first check is the complete address shown by the device. Read it from the beginning of the domain to the ending, and watch for added words, swapped letters, unusual subdomains or a redirect that changes the address after the first tap.
A lock icon only indicates that the connection is encrypted. It does not confirm that the operator is trustworthy. Compare the address with a previously saved record, a statement inside an already installed app, or a support route you independently verified. Avoid relying on a forwarded message, a comment, a sponsored post or a personal contact who claims to be support.
A clean login sequence
- Open the address yourself instead of accepting a shortened or redirected link.
- Confirm that the account identifier requested matches what you originally used, such as mobile number or email.
- Enter the password only after the domain and page state remain stable.
- Read the OTP message before entering the code. The message should make sense for the action you initiated.
- After access, review the displayed account ID, wallet history, recovery details and recent activity before making any payment.
If the page returns to the same login screen, do not assume the password is wrong. A blocked cookie, outdated app webview, unstable connection, incorrect device time or temporary service error can cause a loop. Test one change at a time so you know what resolved it.
Registration data: necessary versus excessive
Account creation normally needs a limited set of details. Treat requests for banking passwords, UPI PINs, full card PINs, remote-control access or unrelated device permissions as unacceptable. Identity verification, where legally required, should explain why the information is needed and how it is handled.
| Request | Safer interpretation | Reason to stop |
|---|---|---|
| Mobile number or email | May be used as an account identifier and for verification. | The same screen also asks for bank credentials or a payment PIN. |
| One-time password | Enter only for an action you started and only on the expected screen. | A person asks you to read the code aloud or send a screenshot. |
| Referral or invitation field | Optional or promotional information should be clearly described. | You are told that entering a code guarantees winnings or withdrawal approval. |
| Identity document | May be requested for a stated compliance purpose through a secure process. | It is requested through a personal chat with no privacy notice or case reference. |
| UPI or bank destination | May be needed later for withdrawals after ownership checks. | You are asked to “verify” it by approving a debit or sharing a PIN. |
Passwords, OTPs and recovery codes
Use a password that is not reused on email, banking, social media or other gaming accounts. A unique password limits the damage if one service leaks credentials. A password manager can help generate and store a long value without repeating it.
Recovery codes and backup access are as sensitive as the main password. Store them away from chat screenshots and shared photo backups. Do not keep a password, OTP screenshot and identity document together in one conversation where a compromised account could expose all three.
- Use a different password for each important account.
- Keep the recovery email or mobile number under your control.
- Review active sessions after an unexplained login alert.
- Remove old devices that are no longer used.
- Do not approve a login prompt that you did not initiate.
Identity documents and KYC requests
Some services use identity verification, but the need for verification does not make every document request safe. Check whether the request appears inside the account area you opened independently, whether a privacy notice explains the purpose, and whether the channel provides a case or submission record.
When a copy is appropriate, consider adding a visible watermark that states the purpose and date without covering essential details. Send only the requested side or page, and avoid combining a document, selfie, bank statement and account password in one thread. A personal messaging account with no case reference is a weak destination for high-value identity data.
| Safer characteristic | Higher-risk characteristic |
|---|---|
| Request appears in an independently opened account area. | Request arrives from a new personal number after a public complaint. |
| Purpose, retention and accepted file types are explained. | The contact asks for every document “just in case.” |
| Submission produces a confirmation or case reference. | Files must be sent repeatedly to different contacts. |
| No authentication secret is requested with the document. | OTP, password, PIN or screen control is demanded at the same time. |
Device, network and session context
Account access can fail because the context changed rather than because the account disappeared. A new phone, private DNS, VPN, incorrect device clock, blocked cookies, old Android WebView or an aggressive battery setting can affect login. Record the context before changing it.
Public Wi-Fi adds uncertainty and should not be used for password recovery or payment. A mobile network or trusted home connection is easier to control. If a VPN is required for another purpose, disconnect it only as a test and record whether the destination or behaviour changes; do not use a VPN to bypass rules or service restrictions.
When an account may be compromised
Warning signs include a password reset you did not request, changed recovery details, unfamiliar transaction history, login alerts from a new device, or support messages that mention information you never provided. Act from a clean device if you suspect the current phone is controlled remotely.
- Disconnect any active screen-sharing or remote-access session.
- Change the account password from a trusted route.
- Change the email password if email is used for recovery.
- Review linked bank or UPI details and recent money movement.
- Capture the account ID, suspicious activity and time before it disappears.
- Contact the relevant platform through a route you verify independently.
If money was transferred because of deception, do not wait for the account investigation to finish. Contact the bank or payment app and use the official cyber financial fraud reporting route promptly.
Prepare a concise account-support note
A clear message is easier to investigate than a long conversation containing passwords and unrelated screenshots. Include the account ID, approximate creation date, last successful access, current error, device type, date and time, and the exact action already attempted. State that no OTP or password will be shared.
“Account ID: [masked]. Last successful access: [date/time]. Current issue: login returns to the same screen after verification. Device: [model/Android version]. I have checked date/time and restarted once. Please confirm the case reference and the next non-sensitive verification step.”
Source checks
CERT-In warns against sharing personal or financial details with unknown contacts and against installing remote-access apps on someone else’s instruction. Its public awareness material also highlights the risk of malicious mobile applications. See the official CERT-In safety booklet.
For any suspected cyber financial fraud, use the Government of India cybercrime portal or call 1930. Reporting creates a record; it does not guarantee recovery, so the bank or payment provider should also be contacted immediately.