No genuine bank, wallet, or government office will ask for your OTP, PIN, or password. Not to verify you, not to reverse a transfer, not for any reason. The one-time code that arrives on your phone authorises a transaction. If you read it out, you are approving that transaction for whoever asked. If anyone asks for a code, hang up or stop replying. Contact the institution yourself using the number on your card, the official app, or the official short code.
Don't trust a message or call just because it shows a familiar name or number. Caller IDs can be spoofed, accounts can be hacked, and official-looking messages can be forged. Before acting on any request that involves money, codes, or personal details, verify it through a channel you control: call the person on the number you already have, or look up the organisation's official contact yourself. A genuine request survives a five-minute check. Pressure to skip that check is itself a warning sign.
Most takeovers exploit weak defaults. A few minutes of setup removes the easiest paths: Turn on two-step verification in Telegram and WhatsApp so a stolen code alone cannot take your account. Set a voicemail PIN, because default voicemail passwords are used to hijack messaging accounts. Use a strong, unique password for internet and mobile banking, and turn on SMS or app alerts for every transaction so you spot problems within minutes, not weeks.
Before sending money, check that the account or wallet name matches the person or business you intend to pay. Be suspicious of any request to pay a different account 'just this once', to pay urgently, or to keep a payment secret. Offers that sound too good, such as prizes, guaranteed returns, or deep discounts for paying right now, are classic pressure tactics. Real institutions and real businesses do not need your urgency.
Use the report form if you saw a suspicious number, account, link, or handle.
Run a safety check before you send money, share a code, or trust a message.