Account security guide

Cricket ID password vs OTP: what never to share

Your ID identifies the account. Your password, PIN and OTP prove access. Knowing the difference helps protect the account from takeover.

Quick answer: you may enter an ID on a genuine sign-in page, but never send your password, PIN, recovery code or OTP to another person—even someone claiming to be support.

The difference in simple terms

Cricket ID or username

This identifies which account you want to access. It is not enough by itself to prove that you own the account.

Password or PIN

This is a reusable secret. Anyone who gets it may be able to sign in, so it should be unique and kept private.

OTP or one-time password

This short-lived authentication code can approve a login, recovery or transaction. Never read it out or forward it.

Recovery code or reset link

This can bypass the usual password during recovery. Treat it with the same care as a password.

Information you should never send to support

  • Your current password or PIN
  • An OTP received by SMS, email or an authenticator app
  • A password-reset link or recovery code
  • A full card PIN, UPI PIN or banking password
  • A screen-sharing view while confidential codes are visible

Genuine support may ask for non-secret information to locate an account, but it should not need the secrets that authenticate you. End an unusual conversation and contact the organisation through a separately verified website or app.

Why an OTP is not “just a verification number”

An OTP is often the final proof needed to approve access. Its short expiry does not make it safe to share. A fraudster may already have your ID and password and need only the current OTP to complete an account takeover.

Common warning signs

  • A caller says the account will close unless you share a code immediately
  • A message asks you to copy an OTP into WhatsApp or chat
  • “Support” sends a shortened or misspelled login link
  • You are asked to install a remote-access or screen-sharing app
  • A login alert arrives when you did not try to sign in

Before following a link, use our 12 checks for spotting a fake Cricket ID website.

Safer account habits

  1. Use a long, unique password that is not reused on email or banking accounts.
  2. Enable multi-factor authentication when available.
  3. Keep your email account and phone number secure because they may be used for recovery.
  4. Review login alerts and active sessions regularly.
  5. Use only a previously verified website or official app to sign in.

What to do if you shared a password or OTP

  1. Change the affected password immediately from a trusted device.
  2. Sign out of other sessions if that option is available.
  3. Secure the associated email account and change any reused passwords.
  4. Contact the service and payment provider through official channels.
  5. Save messages, phone numbers, URLs and transaction details as evidence.
  6. For cyber financial fraud in India, call 1930 promptly and report it through the official portal.

Official cyber-safety resources

India’s CERT-In Digital Safety Compass Handbook recommends strong unique passwords, multi-factor authentication and never sharing passwords, PINs or OTPs. Cybercrime can be reported through the National Cyber Crime Reporting Portal.

Continue learning

If access is already compromised, follow our hacked Cricket ID recovery checklist. You can also read the online Cricket ID guide or the Cricket ID FAQ.