JILILUCK Account Hacked: What to Do in the First Hour
If your account is hacked, change the login password first, then the fund password, then contact Customer Services from the lobby menu.
Key facts and contents
- JILILUCK Account Verification Steps
- Account verification asks you to prove who you are: a valid government photo ID, a selfie with ID, and a mobile number confirmed by SMS code.
- JILILUCK and PAGCOR E-Games
- PAGCOR e-games are electronic games such as eBingo and eCasino games.
- JILILUCK and PAGCOR Licensed Sites
- PAGCOR publishes two lists of registered brands and domain names, both headed 17 September 2026.
- JILILUCK and the PAGCOR Self Exclusion Form
- File through PAGCOR's OSEA portal at osea.pagcor.ph, or use the Self-Exclusion Application Form on pagcor.ph with your ID and photos.
- JILILUCK Phishing Scam
- A phishing scam copies a casino login page so you type your username, password and codes into the thief's form.
- JILILUCK Smishing
- Smishing is phishing by SMS: a text that pushes you to open a link or read out a code.
- JILILUCK Two Step Verification
- Two step verification asks for a second proof after your password, such as a code from an authenticator.
An account hacked alert feels like a disaster, and the next hour decides how much damage a thief can do. The Terms of Service say bets made with a member’s account and password are treated as valid, so the moves below put a lock between the thief and your balance first and sort out the cause second. The wider PAGCOR online safety pages cover the checks that stop it happening again.
Account hacked: the first hour in order
Work through these in order, from a phone or computer you trust and on a connection you control.
- Open the real lobby by typing the address. It opens at jililuck.com. Do not use a link from a message.
- Change the login password. If you cannot log in, choose Nakalimutan ang password, then use the I-reset window with your Username and your e-mail or Mobile No.
- Change the fund password. The lobby uses a separate fund password that you enter for every withdrawal, so a thief with only the login password is still short of it. Change it anyway.
- Contact Customer Services. Use the menu entry, which is the only support channel the Terms recognise. Say what you saw and when.
- Check your wallet and bank. Look at recent activity in the Maya app or your bank’s own screens, and change the PIN or password there if the same one was in use.
- Check your login on the phone. The mobile number you verified is also what password recovery uses, so make sure it is still yours.
Cause 1: you typed your login on a copied page
The most common cause is a copy of a login page. The thief collected your username and password when you entered them.
You signed in from a link in a text, a chat or an advert
Assume the password is known. Change it in the real lobby, then the fund password. The phishing scam red flags page shows how to tell the copy from the real page.
Cause 2: a password reused or easy to guess
A password that matches another site, your birthday or your username falls to a leak or a guess. This is the weak point most account security advice starts from.
The same password was used on another site or wallet
Give the lobby its own password and give the fund password a different one, because the lobby treats login and withdrawal as two different passwords. Change the other site’s password too.
Cause 3: you gave away a one-time code
A scammer who already has your password only needs the SMS code that follows. They ask for it in a text or a call, and a rushed reader hands it over.
You read a code out to someone who contacted you
Change the password straight away, then add a second step that does not depend on SMS. The two step verification setup lists the choices, and the lobby’s help centre says Google Authenticator can be added.
Cause 4: someone else can use your phone or a shared device
A saved password on a shared handset, or a Tandaan tick box left on, lets anyone who picks the device up log in. The Terms allow one account per shared computer, so keep sessions on your own device.
A friend, a family member or a public computer had access
Log out everywhere you can, clear saved passwords from that browser and change both passwords again after you are off the shared device.
Account security habits that stop a repeat
These are the habits that take the next attack away. Each row names what to do and what it protects.
| Habit | What it protects |
|---|---|
| A password only the lobby uses | Stops a leak elsewhere reaching your balance |
| A separate fund password | A thief needs a second secret to withdraw |
| An authenticator code instead of SMS | A stolen SIM or a read-out code is not enough |
| A verified mobile number | Keeps password recovery in your hands |
| Typed addresses and bookmarks | Skips every copied login page |
A verified account also helps: the account verification steps explain what proving who you are involves, and the e-wallet pages cover what to check on the wallet side.
Still not working?
If you cannot get in and the I-reset route does not reach you, the e-mail or number on the account may have changed. The help centre says personal information is edited through customer service, so ask there first.
- Open Customer Services from the lobby menu, not from a chat that found you.
- Give your Username and describe what happened.
- Keep screenshots of any message you received, and block the sender.
- Pay no “recovery fee” to anyone who contacts you first, and keep every conversation inside Customer Services.
FAQ
What is the first thing to do when an account is hacked?
Change the password from a device you trust, using the lobby's I-reset route if you cannot log in. Then change the fund password and look at recent activity.
Who do I contact if my JILILUCK account is hacked?
Customer Services in the lobby menu. The Terms of Service say it is the only support channel they recognise, and anyone else claiming to be support is fake.
Na-hack ang account ko, paano ko mababawi?
Use Nakalimutan ang password and the I-reset window with your Username and your e-mail or mobile number. If that fails, ask Customer Services in the menu.
Does the account holder answer for bets made by a thief?
The Terms of Service say bets made with a member's account and password are treated as valid. That is why speed matters: change both passwords before anything else.