If you clicked a suspicious message or login page, act quickly but do not panic. A phishing link may try to capture your password, mobile number, card details or identity documents. Treat the pokies.net as untrusted until you confirm the address independently. The steps below explain how to contain the risk, protect your devices and check whether your account or payments need urgent attention.
1. Stop the phishing attack immediately
Close the suspicious page without entering further information. Do not download an app, install a browser extension or call a phone number shown in the message. If you entered a password, assume it may have been copied even if the page looked professional. Save the message, sender address and full link as evidence, but do not open the link again.
What information might be at risk?
A phishing page can collect login details, email access, date of birth, phone number, card information and screenshots of identity documents. It may also use a fake bonus, such as a the pokies sign up bonus or the pokies free spins, to create urgency. The offer itself is less important than the information you entered and what an attacker could do with it.
| Information entered | Immediate concern | First protective action | Further check |
|---|---|---|---|
| Password | Account takeover | Change it from a trusted device | Review active sessions |
| Email address | Targeted scams | Secure the email account | Check forwarding rules |
| Card details | Unauthorised payments | Contact your bank | Watch transactions |
| ID documents | Identity misuse | Record what was shared | Seek identity-support advice |
2. Change passwords and secure your email
Your email account should be treated as the control centre because password resets and withdrawal messages may arrive there. Use a trusted device, type the known address yourself and create a new password that has not been used anywhere else. Do not use details such as your name, birthday or favourite the pokies slot.
Protect the account behind the login
Change the casino password first if it was reused elsewhere, then change the password on your email account and any payment service connected to it. Turn on multi-factor authentication where it is available. Review recent sign-ins, remove unknown devices and check that no unfamiliar recovery email, phone number or automatic forwarding rule has been added.
- Change reused passwords from a clean, trusted device.
- Enable multi-factor authentication on email and payment accounts.
- Sign out unknown sessions and remove unfamiliar recovery methods.
- Contact support through a verified channel, not through the phishing message.
- Keep screenshots and timestamps for your bank, provider or police report.
3. Check your device for unwanted software
A phishing page does not always need a successful login to cause trouble. Some links lead to malware, fake updates or files designed to monitor activity. Run the latest security scan on your computer or phone, install operating-system updates and remove anything you downloaded after clicking the link. If the device behaves strangely, avoid using it for banking until it has been checked.
When should you stop using the device?
Stop entering passwords if you notice new browser extensions, repeated pop-ups, unknown apps, unusual battery use or unexpected security warnings. A trusted technician or your device maker can help inspect it. If you used a work device, tell your employer’s IT team. Do not try to prove that the device is safe by logging into more accounts.
| Sign of compromise | Safer response | Account to review | Reason |
|---|---|---|---|
| Unknown browser extension | Remove it after recording its name | Email and banking | It may read web activity |
| Unexpected password reset | Use the provider’s official recovery page | An attacker may control recovery | |
| Unrecognised payment | Call the bank using its official number | Card or bank account | Fast reporting can limit loss |
| New app after the click | Disconnect and scan the device | All accounts used on it | Malware may capture credentials |
4. Check withdrawals, deposits and personal details
Sign in only through a verified route, and inspect your profile, cashier history and messages. Look for changed bank details, new withdrawal requests, unfamiliar deposits or attempts to alter your name and contact information. The Pokies describes AUD payments, card and cryptocurrency deposits, and bank-transfer withdrawals, so review each payment route that you have used.
What should you do if money is involved?
Contact your bank immediately if you entered card details or see an unrecognised transaction. Ask whether the card should be blocked or replaced. Keep in mind that published payment information is not consistent: card deposits have been listed with minimums of A$30 and A$50, while withdrawal figures and processing times vary between pages. Do not rely on a message promising a fast payout to resolve the issue.
5. Understand the legal and safety position
If you are asking, “are the pokies legal in australia?”, separate the player’s actions from the provider’s legal status. The Pokies is an offshore service accepting Australian players, not a casino licensed by an Australian regulator. ACMA issued a formal warning to Digibrite S.R.L. in September 2025 and has blocked 56 domains associated with the brand as at 18 September 2026.
Why this matters after a phishing incident
An offshore operator may offer limited practical protection if an account is frozen, a withdrawal is disputed or personal information is mishandled. The brand has also displayed conflicting licence claims, so do not treat a logo or licence number on a copied page as proof of regulation. The Pokies is browser-only, and there is no need to install an APK or unofficial app to access an account.
6. Report the incident and prevent another click
Report fraudulent transactions to your bank and the phishing message to the relevant platform. In Australia, Scamwatch accepts scam reports, while IDCARE can provide guidance if personal documents were exposed. Use only independently verified support details. Ask the account provider to temporarily close or restrict the account if you cannot confirm its security, and keep a written record of every request.
Review the warning signs that led to the click. Messages that demand immediate verification, promise unusually generous rewards or threaten account closure deserve extra care. Bookmark a verified login page, avoid links in unsolicited messages and check the domain letter by letter. A password manager can also help because it usually will not fill credentials into an unfamiliar address.
Practical takeaway
The safest sequence is simple: stop interacting with the link, secure reused passwords, protect your email, scan the device, contact your bank and review account activity. Treat bonus claims and urgent withdrawal messages with suspicion. Because The Pokies has no Australian licence and its domains have faced ACMA blocking action, consider the wider privacy and payment risks before supplying more information. If gambling is becoming difficult to control, call the National Gambling Helpline on 1800 858 858, which is free and confidential 24/7.