Check a link
Use five layers of verification
- 1Read the final domain after any redirect or shortened URL.
- 2Identify who provides the account or support contact before sharing information.
- 3Compare the file name, version and installation instructions.
- 4Read app permissions, profile details and operating-system warnings.
- 5Stop if anyone requests an OTP, PIN, remote access or a release fee.
Red flags
Warning signs that require immediate action
- An unsolicited message sends a link and pressures you to act immediately.
- The app requests permissions unrelated to its function.
- A support contact asks you to install a remote-access app.
- A withdrawal supposedly requires an extra payment to a personal account.
- A password, OTP or TAC is requested through chat.
Recovery
If you already entered sensitive information
- 1Disconnect the suspicious app, revoke its permissions and uninstall it.
- 2Change the account and related email passwords from a trusted device.
- 3Review transactions and contact your bank or e-wallet if payment data was entered.
- 4Keep screenshots, the domain, file name and time of the incident.
- 5Prepare a clear timeline using the support checklist.
Frequently asked questions
Direct answers and practical next steps
Does HTTPS prove that a site is safe?
No. HTTPS protects the connection but does not prove the identity or intentions of the site owner.
What if I installed a suspicious APK?
Stop using it, revoke permissions, uninstall it, change passwords from a trusted device and contact your bank or e-wallet if payment details were entered.
Can support ask for an OTP or TAC?
Never provide an OTP, TAC, PIN or full password. Those codes authorise sensitive actions and should remain private.