Keeping Your Casino Account Secure

Almost no compromised gaming account is the result of a platform being hacked. It's a password reused from a site that was breached years ago, or a verification code handed to someone who asked nicely. Both are preventable in about five minutes, and the five minutes are worth more than anything else on this page.

Last reviewed: September 2026

The one rule that matters most: nobody legitimate will ever ask for your password or an SMS verification code. Not support, not a "bonus agent", not anyone on Telegram, WhatsApp or Facebook. Anyone asking is running a scam, without exception and regardless of how convincing they are.

The five-minute checklist

Passwords: why reuse is the whole problem

Large websites get breached regularly, and the stolen credentials end up in databases that circulate freely. Attackers don't target your gaming account specifically — they take millions of email and password pairs from an unrelated breach and try them everywhere, automatically.

If the password protecting your casino balance is the same one you used on a forum in 2019, the strength of that password is irrelevant. It's already on a list.

Two-factor authentication

2FA means a stolen password alone isn't enough — a second factor is needed, usually a code sent to your phone or generated by an app. It's the difference between one lock and two.

If it's available in your account settings, turn it on. The small inconvenience at login is the point: it's equally inconvenient for someone who has your password.

An app-based code is stronger than SMS. SMS codes can be intercepted through SIM-swap attacks, where someone convinces a telco to port your number. Authenticator apps generate codes on your device with nothing transmitted. If both options exist, choose the app.

Scams targeting Australian players

These are the patterns that actually circulate. Recognising one is usually enough to stop it.

The fake support agent

Someone contacts you on Telegram, WhatsApp, Facebook or by SMS, says they're from the platform, and offers to help with a stuck withdrawal or a bonus. At some point they ask for your password, a verification code, or remote access to your device.

Real support doesn't initiate contact through social media, and never asks for credentials. Use only the channels listed on the official support page.

The typosquatted domain

A URL one character different from the real one — a swapped letter, an added hyphen, a different extension. The page looks identical because it's a copy. You log in, and your credentials go straight to whoever built it.

These are commonly distributed through search ads and links in messages. Read the address bar before entering anything, and bookmark the real site rather than searching for it each time.

The cloned app

A modified APK distributed through messaging groups, forums or third-party download sites. It looks like the real app and functions like it, while capturing everything you type.

Only download from the official link on this site. See the app versus browser guide for what to check.

The bonus that needs your login

An offer that's "only available" if you provide your account details, or that requires installing something to claim. Genuine promotions appear inside your account. They never require you to hand over credentials to a third party.

The SIM swap

Someone convinces your telco to transfer your number to their SIM, then uses it to receive your verification codes. Rarer, but serious because it defeats SMS-based 2FA.

Most Australian telcos offer an account PIN or port-out protection. Setting one up takes a phone call and protects far more than your gaming account.

Signs your account may have been accessed

What to do if you think you've been compromised

Order matters here. Work through it in sequence.

  1. Change your password from a different device. If the device you normally use has malware on it, changing the password there just hands over the new one too.
  2. Change your email password as well. Email controls account recovery. If that's compromised, changing anything else achieves nothing.
  3. Turn on 2FA if it wasn't already on.
  4. Contact support immediately. Use the official channels. The account can be secured while it's investigated.
  5. Check your withdrawal and payment details. Someone with access may have changed where payouts go.
  6. Check your bank. If payment details were exposed, your bank needs to know.
  7. Change the password anywhere else you used it. If it was reused, every one of those accounts is exposed too.

Device and network habits

Protecting your withdrawals

Two things make your payouts harder to steal, and both are worth doing early.

Complete identity verification when you open the account. A verified account with a confirmed bank destination is considerably harder for someone else to redirect. It also removes the most common cause of payout delays — see the pending withdrawal guide.

Remember that withdrawals only go to an account in your own name. That rule is an anti-fraud control, and it works in your favour: even with full access to your account, someone can't simply redirect a payout to themselves.

Frequently asked questions

Will support ever ask for my password?

Never. Not your password, not an SMS code, not remote access to your device. Anyone asking for any of those is running a scam regardless of how official they sound or which channel they contacted you on.

How do casino accounts actually get hacked?

Overwhelmingly through reused passwords and phishing, not through platform breaches. Credentials stolen from an unrelated site get tried automatically across thousands of others. A unique password defeats this entirely.

Is SMS two-factor authentication safe?

Much safer than no 2FA, but weaker than an authenticator app, because SMS can be intercepted through SIM-swap attacks. Use the app option if it's available, and ask your telco about port-out protection either way.

Someone messaged me offering to fix my withdrawal

That's a scam. Real support doesn't initiate contact through Telegram, WhatsApp, Facebook or SMS. If a withdrawal is genuinely stuck, contact support yourself through the official page — and check the pending withdrawal guide first, since most cases have a simple explanation.

How do I tell if a site is the real one?

Read the address bar carefully before entering anything. Typosquatted domains change one character or add a hyphen. Bookmark the real site and use the bookmark rather than searching each time — search ads are a common distribution route for fakes.

I think someone accessed my account — what first?

Change your password from a different device, then change your email password, then contact support. Using the possibly-infected device to set the new password defeats the purpose.

Can someone withdraw my balance if they get in?

Withdrawals can only be paid to a bank account in your own name, which is a meaningful barrier. It's not absolute, so contact support immediately if you suspect access — the account can be secured while it's looked at.

Is it safe to save my password in my browser?

On a personal, locked device, browser and phone password managers are reasonable and better than reusing a weak password everywhere. Avoid it on shared computers or any device without a screen lock.

Play within your means. Security and spending are separate things, and both benefit from being decided in advance. Set a deposit limit in your account settings while you're in there turning on 2FA. Strictly 18+.

iJoker88 provides deposit limits, session reminders, cool-off periods and self-exclusion — see the responsible gambling tools guide for how to switch them on.

Need to talk to someone? Gambling Help Online offers free, confidential support to Australians 24/7 on 1800 858 858, or at gamblinghelponline.org.au.