Online safety guide

How to spot a fake Cricket ID website

A polished design is not proof of trust. Use these 12 checks before entering credentials, sharing personal information or sending money.

Quick answer: stop if the domain is misspelled, the operator cannot be identified, support asks for passwords or OTPs, or you are pressured to pay immediately. Verify the website independently before continuing.

12 checks before trusting a Cricket ID website

Read the complete domain character by character

Look for substituted letters, extra hyphens, unexpected numbers and unfamiliar domain endings. A padlock only means the connection is encrypted; it does not prove the operator is genuine.

Open the site independently

Avoid signing in through a forwarded message or unknown advertisement. Type a previously verified address or use a trusted bookmark. CERT-In advises checking URL integrity before entering credentials.

Identify the actual operator

Look for a consistent business identity, contact route, terms and privacy information. A logo, brand-like name or copied “About” paragraph is not proof.

Check whether claims can be verified

Claims such as “official,” “licensed” or “years of experience” need evidence from an authoritative source. Do not treat a badge image as verification.

Separate an ID from authentication secrets

A username can identify an account. Passwords, PINs, recovery codes and OTPs authenticate access and must remain private. Support should not ask you to read out an OTP.

Pause when urgency replaces explanation

Pressure to deposit immediately, keep the conversation secret or act before an offer expires is a warning sign. A legitimate process should leave time to check.

Treat guaranteed outcomes as suspicious

No account identifier can guarantee winnings, returns, deposits, withdrawals or uninterrupted access. Promises of risk-free results are not reliable evidence.

Review payment instructions carefully

Check whether the recipient identity, payment route and published terms are consistent. Be cautious when payment is repeatedly redirected to unrelated personal accounts.

Test support without sharing secrets

Ask clear questions about the operator, privacy, eligibility, fees and dispute handling. Evasive or contradictory answers deserve a pause.

Search suspicious identifiers

India’s National Cyber Crime Reporting Portal provides facilities to check or report suspect website URLs, phone numbers, email addresses and social handles.

Check your device and browser

Keep software updated and do not install unknown apps, browser extensions or remote-access tools at a stranger’s request.

Keep evidence before blocking contact

Save the URL, messages, phone number, timestamps and transaction references. Evidence can help a bank, platform or law-enforcement report.

Warning signs in WhatsApp, SMS or social messages

  • A shortened link hides the real destination
  • The sender requests an OTP, password, PIN or screen-sharing session
  • The payment account changes without a documented explanation
  • The message contains threats, secrecy or unrealistic guarantees
  • The sender refuses to provide verifiable operator information

CERT-In’s phishing guidance recommends expanding and verifying shortened URLs, using unique passwords and never sharing sensitive details such as passwords or PINs through email or text.

What to do if you already entered details or sent money

  1. Stop further contact and payments.
  2. Change exposed passwords immediately, starting with the associated email account.
  3. Contact your bank or payment provider using its official channel.
  4. Save screenshots, URLs, transaction IDs and the sender’s identifiers.
  5. For cyber financial fraud in India, call 1930 promptly and file a report through the official portal.

Official reporting resources in India

Use the National Cyber Crime Reporting Portal to report cybercrime. Its “Report Suspect” facility accepts suspicious website URLs, WhatsApp or Telegram handles, phone numbers, email addresses and related identifiers. For immediate cyber financial fraud reporting, the official helpline is 1930.

For broader phishing safety practices, see the CERT-In Digital Safety Compass Handbook.

Continue learning

Learn the difference between a Cricket ID, password and OTP, read our online Cricket ID security guide, or use the Cricket ID FAQ.