PNG ACCOUNT SAFETY

Support Asking for an OTP, Password or Remote Access?

Before you reply, check what the person is asking you to do. A familiar name, logo or profile picture does not verify a sender. Use this checklist for unexpected account-support messages.

Published by PGKBETS for general education. This is not an independent security assessment, a guarantee of any service's safety, or a replacement for its verified support procedures.

1. Identify the request

These examples are illustrative, not reports of incidents involving a particular operator.

“Send me the code you just received”

An OTP is a one-time password. Read the message that contains it to understand which action it authorises.

Entering a code yourself in a verified process you initiated is different from giving it to another person. If you did not request the action, do not approve it or share the code.

“Tell me your password so I can fix it”

Do not disclose your current password. Open the service independently and use its account-recovery process instead of a reset link supplied by an unverified sender.

“Install this app and let me control your phone”

Remote-control software can expose information or allow actions on your device. An app being genuine does not mean the person asking you to use it is genuine.

Do not install it or approve access for an unexpected caller. Seek technical help through a contact you independently trust.

“Send a screenshot to prove your account”

First verify the recipient and ask what information is actually needed. Never include passwords, OTPs or banking PINs in screenshots.

If a screenshot is necessary, crop or redact unrelated personal details, payment information and notifications.

2. Verify through a separate channel

  1. Stop using the message's links, attachments and contact numbers.
  2. Open an official app or an address you independently verified earlier. Do not rely on the sender's profile or a search advert.
  3. Start a new support conversation there. Describe the request without sharing the secret or code.
  4. Ask whether the request is genuine and what secure procedure applies. If it cannot be verified, do not proceed.

You can ask: “I received a message asking me to share a code or install remote-access software. Can you verify this request and explain the secure procedure? I will not send passwords or codes.”

3. If you already responded

You shared a password or code

Contact the affected service through a verified channel promptly. From a trusted device, change an exposed password and any reused passwords. Review account activity and use available options to end unfamiliar sessions.

An expired code does not prove that nothing happened. Ask the service to check the action it may have authorised.

You allowed remote access

End the remote session; disconnect the device from the internet if necessary to stop access. Avoid sensitive accounts on that device until it has been checked.

Use another trusted device to secure accounts. Seek trusted technical assistance to review remote-access permissions and software, update security tools and scan for malware.

If banking information or money is involved, contact your own bank or payment provider immediately through its official channel. Explain what was shared or authorised. Recovery is not guaranteed.

4. Keep a useful record

Keep evidence privately. Do not post codes, identity documents or full financial details publicly. Report impersonation to the messaging platform and the organisation being impersonated.

Official guidance and reporting

These links are provided as references. They do not imply endorsement of PGKBETS by the organisations listed.