Account safety
Protecting Your Gaming Account from Password Theft and Phishing
An account with a balance or identity documents deserves careful protection. Start with its login and recovery settings, then examine how you respond to unexpected messages.
Use a unique password and protect recovery access
Use a different strong password for each account. A password manager can generate and store it, avoiding reuse across unrelated services. Protect the email account used for password recovery as well: access to that inbox can affect accounts connected to it.
Enable multifactor authentication wherever it is offered. It adds a verification step beyond the password. Keep recovery codes somewhere safe, separate from an easily accessible note containing the password. These practices follow CISA's account-security guidance.
Treat urgency as a reason to verify
An unexpected message may claim that a balance will expire, a bonus requires immediate action or support needs you to confirm a login. NIST identifies urgency, requests for sensitive information and suspicious links or attachments as phishing warning signs.
Rather than using the message's link, reach the service through an independently established address and check the request there. A familiar name or convincing design does not authenticate the sender. See NIST's phishing guidance for its verification and reporting advice.
Apply the checks to a concrete example
Imagine receiving a message headed “Your withdrawal is blocked”, followed by a shortened link and a demand for a one-time login code. Treat the claim and the communication channel as two separate questions. There might be an account issue, but that does not establish that the message came from support.
Open your established account address independently and inspect the account's own notifications. Contact support through that verified route. Do not reply with a password, login code or recovery code just because the message mentions a real transaction.
This is an illustrative scenario, not a report of an incident at Lucky Bear. The same reasoning applies to email, social messages and imitation support profiles.
Prepare a short recovery record
Keep the service's verified address, your account identifier and the official recovery route available without placing passwords in the same note. Record where you stored recovery codes so that losing a phone does not force you to trust an unsolicited helper.
If you suspect a message, save enough information to report it through the legitimate service's channel. If you entered credentials on a suspicious page, use the verified service to change them and review account access promptly. Account protection reduces avoidable exposure; it does not establish that an operator itself is trustworthy.
Related reading
For adults aged 18 and over. Educational content, not a promise of profit. Read our responsible gambling guidance.
Back to the blog