What should I do if I am phished or my credentials are compromised?
If you believe you have been phished or your credentials have been compromised, it's important to take these immediate actions to protect your online accounts and personal data:
- Change your password: Change the password for your account immediately. Use a strong, unique password, which can be generated with password management tools.
- Enable 2FA: If your account supports two-factor authentication (2FA), enable it. This provides an extra layer of security by requiring a second verification method (e.g., a code sent to your phone) to access your account.
- Check your accounts: Review all your other online accounts (email, social media, banking, etc.) to ensure they haven't been compromised as well. If you use the same password for multiple accounts, change those passwords too.
- Scan for viruses: Run a full system scan on your computer and any devices you used to access your account. Make sure your antivirus and anti-malware software is up to date.
- Monitor accounts: Keep a close eye on your accounts for any suspicious activity. This includes checking for unauthorised transactions, changes to account settings, or new login attempts.
- Notify Deriv: Contact our Customer Support team. Please have the scammer account’s information and evidence/screenshots ready so we can take appropriate action as soon as possible.









