Account safety

Two-factor authentication, session hygiene, account controls

The destination stores credentials and runs KYC. Your account safety depends on your own configuration. Use the controls listed below.

Controls

Turn these on inside the app

Two-factor authentication

OTP via phone, or TOTP via authenticator app. Two-factor blocks most account-takeover attempts even if your password leaks.

Strong password

Use a unique password per service. A password manager is the simplest way to enforce uniqueness.

Session review

Review active sessions inside the account settings. Sign out unknown sessions immediately.

Withdrawal lock

Enable a withdrawal lock so withdrawals above a threshold require a re-authentication.

Cool-off

Set a cool-off period during which logins are blocked. Useful after a long losing streak.

Self-exclusion

Self-exclusion blocks the account for a chosen period. Use it if play is no longer fun.

Phishing

How to spot a fake login

The destination's login URL is the only legitimate login URL. Any other URL is phishing, even if it looks identical.

  • Check the URL bar carefully. The destination domain is the only place to enter credentials.
  • Never enter credentials from a link in an SMS, WhatsApp message, or social-media DM.
  • The destination will never ask for your password by phone.
  • If a "support agent" asks for your OTP, treat it as a scam.
Phishing playbook

What to do when a phishing message arrives

Step-by-step instructions for handling a suspicious message that claims to be from the brand.

Step one: do not click any link

The first instinct on receiving a phishing message is to click the link to "verify" or "secure" the account. Resist that instinct. The link is the attack. Opening the link can install malware or steal your credentials.

Step two: report the message

Forward the message to the destination's abuse reporting address. The destination will confirm whether the message is legitimate. Most operators publish the abuse reporting address inside the help section of their app.

Step three: change your password

If you clicked the link or entered your credentials, change your password immediately. Use a unique password per service. Enable two-factor authentication after the password change.

Step four: review recent activity

Sign in to your account and review the recent activity log. Look for withdrawals, login attempts, or balance changes you do not recognise. Report anything suspicious to support.

Step five: file a complaint

If you have lost money to a phishing scam, file a complaint with your local cybercrime authority. In India, the cybercrime helpline is 1930. Other countries have equivalent authorities. The complaint helps build a case against the operators of the phishing site.

Phishing playbook

What to do when a phishing message arrives

Step-by-step instructions for handling a suspicious message that claims to be from the brand.

Step one: do not click any link

The first instinct on receiving a phishing message is to click the link to "verify" or "secure" the account. Resist that instinct. The link is the attack. Opening the link can install malware or steal your credentials.

Step two: report the message

Forward the message to the destination's abuse reporting address. The destination will confirm whether the message is legitimate. Most operators publish the abuse reporting address inside the help section of their app.

Step three: change your password

If you clicked the link or entered your credentials, change your password immediately. Use a unique password per service. Enable two-factor authentication after the password change.

Step four: review recent activity

Sign in to your account and review the recent activity log. Look for withdrawals, login attempts, or balance changes you do not recognise. Report anything suspicious to support.

Step five: file a complaint

If you have lost money to a phishing scam, file a complaint with your local cybercrime authority. In India, the cybercrime helpline is 1930. Other countries have equivalent authorities. The complaint helps build a case against the operators of the phishing site.

Recognising phishing in advance

Phishing messages share common traits. They create urgency ("your account will be closed"), they ask for credentials or OTPs, they link to look-alike domains, and they come from free email addresses rather than the destination's domain. Recognising these traits in advance stops most phishing attempts.

Why SMS phishing works

SMS phishing works because it reaches people on their phone, where they are more likely to react quickly. The combination of urgency, short form factor, and trusted phone makes SMS a high-yield channel for phishers. Treat every unexpected SMS about your account with caution.

Bookmark the destination's login URL

Bookmark the destination's login URL in your browser. Always open the destination through the bookmark, never through a link in an SMS or email. The bookmark removes the phishing channel entirely.

Using a password manager

A password manager auto-fills credentials only on the real destination's domain. If you land on a phishing site, the password manager will not fill in your credentials. The auto-fill refusal is a strong signal that you are on the wrong site.

Phishing playbook

What to do when a phishing message arrives

Step-by-step instructions for handling a suspicious message that claims to be from the brand.

Step one: do not click any link

The first instinct on receiving a phishing message is to click the link to "verify" or "secure" the account. Resist that instinct. The link is the attack. Opening the link can install malware or steal your credentials.

Step two: report the message

Forward the message to the destination's abuse reporting address. The destination will confirm whether the message is legitimate. Most operators publish the abuse reporting address inside the help section of their app.

Step three: change your password

If you clicked the link or entered your credentials, change your password immediately. Use a unique password per service. Enable two-factor authentication after the password change.

Step four: review recent activity

Sign in to your account and review the recent activity log. Look for withdrawals, login attempts, or balance changes you do not recognise. Report anything suspicious to support.

Step five: file a complaint

If you have lost money to a phishing scam, file a complaint with your local cybercrime authority. In India, the cybercrime helpline is 1930. Other countries have equivalent authorities. The complaint helps build a case against the operators of the phishing site.

Recognising phishing in advance

Phishing messages share common traits. They create urgency ("your account will be closed"), they ask for credentials or OTPs, they link to look-alike domains, and they come from free email addresses rather than the destination's domain. Recognising these traits in advance stops most phishing attempts.

Why SMS phishing works

SMS phishing works because it reaches people on their phone, where they are more likely to react quickly. The combination of urgency, short form factor, and trusted phone makes SMS a high-yield channel for phishers. Treat every unexpected SMS about your account with caution.

Bookmark the destination's login URL

Bookmark the destination's login URL in your browser. Always open the destination through the bookmark, never through a link in an SMS or email. The bookmark removes the phishing channel entirely.

Using a password manager

A password manager auto-fills credentials only on the real destination's domain. If you land on a phishing site, the password manager will not fill in your credentials. The auto-fill refusal is a strong signal that you are on the wrong site.

Phishing playbook

What to do when a phishing message arrives

Step-by-step instructions for handling a suspicious message that claims to be from the brand.

Step one: do not click any link

The first instinct on receiving a phishing message is to click the link to "verify" or "secure" the account. Resist that instinct. The link is the attack. Opening the link can install malware or steal your credentials.

Step two: report the message

Forward the message to the destination's abuse reporting address. The destination will confirm whether the message is legitimate. Most operators publish the abuse reporting address inside the help section of their app.

Step three: change your password

If you clicked the link or entered your credentials, change your password immediately. Use a unique password per service. Enable two-factor authentication after the password change.

Step four: review recent activity

Sign in to your account and review the recent activity log. Look for withdrawals, login attempts, or balance changes you do not recognise. Report anything suspicious to support.

Step five: file a complaint

If you have lost money to a phishing scam, file a complaint with your local cybercrime authority. In India, the cybercrime helpline is 1930. Other countries have equivalent authorities. The complaint helps build a case against the operators of the phishing site.

Recognising phishing in advance

Phishing messages share common traits. They create urgency ("your account will be closed"), they ask for credentials or OTPs, they link to look-alike domains, and they come from free email addresses rather than the destination's domain. Recognising these traits in advance stops most phishing attempts.

Why SMS phishing works

SMS phishing works because it reaches people on their phone, where they are more likely to react quickly. The combination of urgency, short form factor, and trusted phone makes SMS a high-yield channel for phishers. Treat every unexpected SMS about your account with caution.

Bookmark the destination's login URL

Bookmark the destination's login URL in your browser. Always open the destination through the bookmark, never through a link in an SMS or email. The bookmark removes the phishing channel entirely.

Using a password manager

A password manager auto-fills credentials only on the real destination's domain. If you land on a phishing site, the password manager will not fill in your credentials. The auto-fill refusal is a strong signal that you are on the wrong site.

Continue to myyonorummyVerified access · 18+ Play now