Account recovery guide

Cricket ID hacked? Recover and secure your account

Act quickly, but use only verified channels. This checklist prioritises email security, password changes, session control, evidence and fraud reporting.

Immediate action: secure the associated email first, change the affected password from a trusted device, sign out other sessions and contact the service through its verified website or app.

Signs that an account may be compromised

  • A login or OTP alert appears when you did not try to sign in
  • Your password, phone number or email changes unexpectedly
  • You are locked out although the details were correct
  • Unknown activity, messages or transactions appear
  • A recovery message arrives that you did not request

One alert does not always prove a takeover, but it is enough reason to inspect the account through a verified route. Do not follow the link inside a suspicious message.

How to recover and secure the account

1. Use a trusted device

Stop using a device that may contain unknown remote-access software or malware. Update the operating system and browser before recovery.

2. Secure the associated email

Email often controls password resets. Change its password, enable multi-factor authentication and review recovery details and active sessions.

3. Open the genuine website independently

Type a previously verified address or use the official app. Avoid login links sent by unknown contacts. Review our fake website checklist if the domain is uncertain.

4. Reset the Cricket ID password

Create a long, unique password that is not used anywhere else. Never share the new password or OTP with support.

5. Sign out unknown sessions

Use “log out all devices” or session management if available. Remove unfamiliar devices, apps and connections.

6. Check account details and activity

Review the registered email, phone, recovery options, messages and transactions. Record anything you did not authorise.

7. Contact verified support

Use the contact route published on the genuine website. Explain the timeline and provide non-secret identifiers—never a password, PIN, OTP or recovery code.

Evidence to save

  • Suspicious website URLs and message links
  • Phone numbers, email addresses and social handles
  • Login alerts and account-change notifications
  • Transaction references, amounts and timestamps
  • Screenshots of conversations and unauthorised activity

Keep original messages where possible. Do not delete evidence until the service, bank or authorities confirm it is no longer required.

If money or payment details are involved

  1. Contact your bank or payment provider immediately through its official number or app.
  2. Ask what protective action is available for the account or transaction.
  3. For cyber financial fraud in India, call 1930 promptly.
  4. Submit the incident through the official National Cyber Crime Reporting Portal.
  5. Continue monitoring related financial and email accounts.

How to reduce the risk of another takeover

  • Use a different password for every important account
  • Enable multi-factor authentication where available
  • Keep recovery email and phone details current
  • Never share an OTP, PIN, password or reset link
  • Review sessions and login alerts regularly
  • Remove remote-access apps you do not recognise

See our detailed guide to Cricket ID passwords, OTPs and recovery codes.

Official reporting resources in India

Report cybercrime through the National Cyber Crime Reporting Portal. For broader safe-account practices, consult the CERT-In Digital Safety Compass Handbook.

Continue learning

Read the online Cricket ID guide or visit the Cricket ID FAQ.