Accounts are rarely broken into. They are usually handed over, by someone who thought they were talking to support.
The four habits
Step 1: Sign in only through eBuy's own pages. Check the address before you type a password.
Step 2: Never share an OTP, a reset link, or a verification code with anyone, whoever they say they are.
Step 3: Verify your email and keep your phone number current, so a reset can actually reach you.
Step 4: Sign out on shared devices, or use the sign-out-everywhere option in your profile.
What an attack looks like
- A call or message asking you to confirm a code "for security"
- A login page that looks right but sits on a slightly wrong address
- A courier or refund link that asks you to sign in again
- Someone claiming to be support who needs your password to "fix" something
Contact support if
- You get a password reset you did not ask for
- You see activity on your account you do not recognise
- You think you gave a code to someone you should not have
eBuy support will never ask for your OTP, your password, or your full bank details, in chat, email, or on a call. Nobody legitimate needs them.