An OTP belongs in the sign-in screen
Use a one-time code only in the process you started in the service’s genuine app or website. Someone who obtains the code may be able to complete that action as you.
Do not read an OTP aloud on a call, forward it through chat or include it in a support screenshot. If a code arrives unexpectedly, do not share it and review your account through the usual sign-in route.
Use a unique password
Choose a password you do not reuse on other services. If the provider offers additional account protection, review the available options in its settings. Lock your phone and keep its operating system up to date.
On a shared device, avoid leaving an account signed in. Do not save sensitive information in public notes, shared photo albums or messages that others can access.
Recognise a suspicious support request
- A person asks for an OTP, password, payment PIN or recovery code.
- You are told to install a remote-access app so someone can operate your phone.
- You are asked to transfer money to a personal account to unlock an old withdrawal.
- The message pressures you to act immediately or move away from the provider’s established support channel.
Pause and contact the provider through the channel you already know, rather than the contact details supplied in that message.
If access may have been exposed
Use the genuine account recovery route from a device you trust. Review active sessions and the provider’s security settings where available. Contact your bank promptly through its established channels if payment credentials may be affected.
Keep relevant messages and transaction records privately. Do not continue engaging with someone who is asking for codes or additional payments.