Login access desk: address verification and account hygiene

Login problems are usually one of three things: a forgotten password, a verified mobile or email that has changed, or a phishing attempt. This page is the desk’s standing help guide for the first two; if you suspect phishing, see Customer Care for verified support routes.

Forgotten password — the safe recovery path

Use the operator’s official “Forgot password” link on the login page. The link should appear on the official domain and should not require you to enter your full password anywhere except the login form itself. If a link asks for your password in an email or SMS, treat it as phishing.

Two-factor authentication — set it up now

Two-factor authentication is the single biggest protection you can add to a money account. Use an authenticator app (TOTP) where available; SMS 2FA is a fallback, not a substitute.

Account safety habits editorial illustration
Two-factor authentication, verified recovery channels and device hygiene.

Recognising a phishing attempt

1

Sender domain

A real operator email comes from the operator’s own domain. Gmail, Yahoo, Outlook are red flags.

2

URL

Hover the link. The real URL should match the operator’s official domain exactly.

3

Urgency

“Verify now or your account will be locked” is a classic phishing tactic.

4

Personal data request

A real operator never asks for your full PAN, full card number or OTP by email or SMS.

5

Spelling & grammar

Phishing emails often have small spelling or grammar errors.

Verifying the operator's address bar before entering credentials
Always confirm the address bar matches the operator's official domain before typing a password.

If your account is locked

Login support triage editorial photograph
Support triage: who to contact first, what to attach, what to expect.

If you cannot recover access through the standard flow, contact the operator’s verified customer-care route (see Customer Care). Have your verified mobile number and a copy of your PAN or Aadhaar ready. Do not share your OTP, password or full card number with anyone — not even the operator’s support agent.

Why is my account locked?

Most account locks come from too many failed login attempts, KYC verification issues, or unusual activity triggers. The operator’s verified support route is the way to resolve it.

Can I reset my password by SMS?

Usually yes, via OTP. The OTP is single-use and short-lived. Never share it with anyone, including a support agent.

How long does account recovery take?

For a verified mobile + email account, password reset is immediate. For KYC-related locks, recovery can take 24–72 hours depending on the operator.

Good password hygiene, in three lines

Login password hygiene editorial photograph
Password hygiene: long, unique, stored in a real password manager.

Use a password manager. Generate a unique password for every fantasy-cricket account — do not reuse. Rotate the password every 90 days; if you do not use a manager, write down a fresh random string and store it offline. A leaked password on a fantasy-cricket account can lead to a drained wallet within hours.

Account safety habits editorial illustration
Password hygiene is the single biggest account-level protection.
Three lines on password hygiene: unique, managed, rotated
Three lines, every account: unique password · managed by a tool · rotated every 90 days.

Multiple devices, multiple risks

Most operators allow multiple devices but limit active sessions. If you log in on a public device, log out fully and clear cookies when you finish. If you log in on a device you no longer use, log out remotely from the operator’s account settings if available. A stale session is a small but real attack surface.

Session management on shared and personal devices

Sessions on shared devices are an underrated risk. A friend, family member or colleague who picks up the device can place a contest entry, deposit money, or even change the password. The desk recommends explicit logout on every shared device; private browsing windows; and a periodic check of active sessions in the operator’s account settings if available.

On personal devices, the risk is lower but not zero. A device left unlocked on a desk, a phone in a lost-and-found, a tablet lent to a child — all are session risks. Two-factor authentication mitigates most of these risks; explicit logout closes the rest.

Account safety habits editorial illustration
Two-factor authentication, verified recovery channels and device hygiene.

Recovering a locked account — what to expect

A locked account usually unlocks after KYC re-verification or after a password reset. The typical timeline is 24–72 hours, depending on the operator’s queue. Have your verified mobile, PAN and a one-line summary of the issue ready when you contact the verified customer-care route. Do not share your OTP, password or full card number with anyone — including a support agent.

Account safety habits editorial illustration
Two-factor authentication, verified recovery channels and device hygiene.

What to do if you lose your 2FA device

Losing the device that holds your authenticator-app 2FA codes is a recoverable but inconvenient situation. Most operators offer backup codes at 2FA setup — store them offline. If you did not save backup codes, the recovery flow is: contact the verified customer-care route with your verified mobile + PAN; the operator will guide you through an identity-verification flow. The process takes 24–72 hours.

Biometric login — good but not perfect

Biometric login (fingerprint or face) is faster than password login and is harder to phish. Most operators now support biometric login; enable it if your device supports it. Biometric login is not a substitute for two-factor authentication; it is a layer on top. If your device’s biometric is compromised (e.g. a deepfake attack on face ID), the attacker still needs the 2FA code.

A login security checklist

A standing security checklist for any fantasy-cricket account.

1

Unique password

Use a password manager; do not reuse passwords.

2

Two-factor authentication

Enable on every account that touches money.

3

Verified mobile + email

Both verified, both up to date.

4

Withdrawal lock

Enable in account settings if available.

5

Periodic review

Review active sessions every 90 days; log out of stale devices.

Phishing vs. real — a quick test

A quick test: if the message asks you to act urgently, treat it as suspicious. Real operators do not ask for urgent action. If the message asks for a full password, full OTP or full card number, treat it as phishing; real operators never ask for these. If the link does not resolve to the operator’s official domain, treat it as phishing. A message that fails any of these three tests is not from the operator.

A login recap

A clean login flow has three habits: unique password, two-factor authentication, and verified mobile + email. A clean recovery flow has two habits: backup codes for the authenticator app and a verified customer-care route for in-app help. The two habits together cover most of the common login scenarios.

Login support triage: identifying the right channel for an account issue
Triaging a login issue — verified customer-care first, never a password over chat.

Questions readers ask

I never got the password reset email — what now?

Check spam. If it is not there, verify the email on the account is the one you are checking. Contact the operator’s verified customer-care if it still does not arrive.

Should I save my password in the browser?

A password manager is safer than browser password storage. Most operators now require periodic re-authentication for security reasons.

What is the safest way to log in on a shared device?

Use a private browsing window, log out fully when done, and clear cookies. Do not save the password on a shared device.

Next step

Open the editorial app entry

Verify the current offer in your own account, then play only what you can afford to lose.