1. Use a trusted device
Stop using a device that may contain unknown remote-access software or malware. Update the operating system and browser before recovery.
Act quickly, but use only verified channels. This checklist prioritises email security, password changes, session control, evidence and fraud reporting.
One alert does not always prove a takeover, but it is enough reason to inspect the account through a verified route. Do not follow the link inside a suspicious message.
Stop using a device that may contain unknown remote-access software or malware. Update the operating system and browser before recovery.
Email often controls password resets. Change its password, enable multi-factor authentication and review recovery details and active sessions.
Type a previously verified address or use the official app. Avoid login links sent by unknown contacts. Review our fake website checklist if the domain is uncertain.
Create a long, unique password that is not used anywhere else. Never share the new password or OTP with support.
Use “log out all devices” or session management if available. Remove unfamiliar devices, apps and connections.
Review the registered email, phone, recovery options, messages and transactions. Record anything you did not authorise.
Use the contact route published on the genuine website. Explain the timeline and provide non-secret identifiers—never a password, PIN, OTP or recovery code.
Keep original messages where possible. Do not delete evidence until the service, bank or authorities confirm it is no longer required.
See our detailed guide to Cricket ID passwords, OTPs and recovery codes.
Report cybercrime through the National Cyber Crime Reporting Portal. For broader safe-account practices, consult the CERT-In Digital Safety Compass Handbook.
Read the online Cricket ID guide or visit the Cricket ID FAQ.