Protect your account

Security Best Practices

Most account compromises come from phishing and weak passwords — not sophisticated hacking. These simple habits close that gap.

Use a strong, unique password

  • Aim for at least 12 characters mixing letters, numbers, and symbols.
  • Never reuse a password from another site — if one account leaks, reused passwords let attackers into everything else.
  • Consider a password manager to generate and store unique passwords securely.

Turn on two-factor authentication

If the platform offers two-factor authentication (2FA), enable it. This means even if someone learns your password, they still can't log in without the second verification step — typically an OTP sent to your phone or email.

Recognize phishing attempts

  • Urgent language: Messages demanding immediate action ("verify now or lose your account") are a classic pressure tactic.
  • Look-alike links: Hover over links before clicking to check the actual destination domain.
  • Requests for OTPs or passwords: No legitimate support team will ever ask you to read out or type in your OTP or password to them directly.
  • Unofficial channels: Be cautious of "support" reaching out first via social media DMs, random calls, or messaging apps.

Keep your devices secure

  • Keep your operating system, browser, and any apps updated.
  • Avoid logging in on shared or public computers when possible.
  • Log out of sessions on devices you no longer use.
  • Use a screen lock (PIN, biometric) on the device where your app is installed.

If you suspect your account is compromised

  1. Change your password immediately through the official site.
  2. Enable two-factor authentication if you haven't already.
  3. Review recent account activity for anything you don't recognize.
  4. Contact official support to report the issue and ask about additional protective steps.