Independent information and risk assistance

How to keep account information secure on the page using the name BJ77

The purpose of this page is to prevent account takeover and to determine the first hour's actions if the account is compromised. Regardless of what the page claims about your identity, do not share your password, PIN, or OTP with anyone else; a full review of App permissions is provided in a separate App/APK guideline.

Basic security measures

  • Use a different long password for each site.
  • Use a trusted password manager to check domain match.
  • Secure the password and recovery information of the linked email.
  • Keep your phone and computer updated and use a strong screen lock.
  • If the current account has a 2FA option, enable it on your authenticator or device after verifying your identity.
There is no guarantee that 2FA, session review, or account closure features are available on BJ77—even if options appear in the account, independently verify the domain and data destination.
পাসওয়ার্ড, SIM ও ডিভাইসের বহুস্তর নিরাপত্তা

Never share OTP and PIN

OTP is only for specific actions initiated by you. Do not provide it to support staff, payment agents, acquaintances, or anyone claiming to be from the “security team.” PIN and full password should not be part of any support process.

  1. If you receive an OTP that you did not request, change the associated email password.
  2. Do not click on links in messages; check the account from a clean device.
  3. Keep a screenshot of the request and sender information.
  4. If there is a financial alert, report it through the provider's genuine channel.

Signs of SIM swap

Sudden loss of network, calls/SMS being disabled, unfamiliar SIM replacement notice, or multiple account reset messages together can be signs of SIM swap.

  • Contact the mobile operator's known support channel from another phone
  • Request a temporary freeze or security review of MFS and bank account
  • Change email password and recovery method from a clean device
  • During the incident, keep a list of operator tickets and affected accounts

If there are suspicious Apps on the device

If there is suspicion of account takeover, briefly check for unknown Apps, browser extensions, or profiles. Secure the account from a clean and updated device without using email, MFS, or bank passwords on the suspicious device.

A full review of Accessibility, Device Administrator, notification access, overlay, and SMS permissions is a matter of App/APK guidelines.

First hour if the account is compromised

  1. Disconnect and stop working
    Do not log in or make payments on the suspicious device.
  2. Gather evidence
    Screenshot alerts, time, domain, App, transaction, and communication.
  3. Secure the email first
    Change password and recovery method from a clean device.
  4. Cancel the session
    Sign out of unknown devices where the feature is available.
  5. Inform the financial provider
    Report suspicious transactions without giving PIN/OTP.
  6. Inform a trusted person
    Do not handle the pressure of being a “recovery expert” alone.

List of incident evidence

  • First alert and exact time
  • Affected email, SIM, device, and financial account
  • Unknown session, App package, or phone number
  • Transaction reference and total loss

Questions and answers

Can the same password be used on other sites?

No. A leak will put another account at risk; use a unique password for each site.

What should I do if the SIM suddenly loses network?

SIM swap can happen. Inform the operator and secure your financial account.

Is it safe to get help by screen sharing?

No. This may expose OTP, account, and notification.

What should I do if I receive an unknown login notification?

Secure your email and change your password from a clean device and cancel the session.

What should I do if someone asks for money in the name of account recovery?

Do not make payment; keep evidence and Transaction guidelines See.