JILILUCK Smishing: Handling a Text That Asks for a Code
Smishing is phishing by SMS: a text that pushes you to open a link or read out a code.
Key facts and contents
- JILILUCK Account Hacked
- If your account is hacked, change the login password first, then the fund password, then contact Customer Services from the lobby menu.
- JILILUCK Account Verification Steps
- Account verification asks you to prove who you are: a valid government photo ID, a selfie with ID, and a mobile number confirmed by SMS code.
- JILILUCK and PAGCOR E-Games
- PAGCOR e-games are electronic games such as eBingo and eCasino games.
- JILILUCK and PAGCOR Licensed Sites
- PAGCOR publishes two lists of registered brands and domain names, both headed 17 September 2026.
- JILILUCK and the PAGCOR Self Exclusion Form
- File through PAGCOR's OSEA portal at osea.pagcor.ph, or use the Self-Exclusion Application Form on pagcor.ph with your ID and photos.
- JILILUCK Phishing Scam
- A phishing scam copies a casino login page so you type your username, password and codes into the thief's form.
- JILILUCK Two Step Verification
- Two step verification asks for a second proof after your password, such as a code from an authenticator.
Smishing is phishing delivered by SMS: a short text that tries to make you open a link, enter your details or read out a code. It works because a text feels personal and arrives on the device you trust most. The notes below show how to recognise one, what to do with the code it wants, and how it connects to the rest of the PAGCOR online safety pages.
Red flags in a smishing text
A smishing message has a job to do in very few words, so it leaves the same marks every time. Check the message against this list before you do anything else.
- It pushes a deadline. “Account locked in 24 hours” or “claim now” is there to stop you thinking.
- It carries a short or odd link. A shortened link hides where you are going.
- It uses a brand name loosely. The sender may name a casino, a wallet or a bank you do use, which is guesswork that happens to land.
- It asks for a code, a password or a fund password. No real step asks you to send these back in a text.
- It comes from a number you do not know, or from a sender name that looks right but is not in the conversation thread you already have.
- It offers money for nothing. A prize, a refund or a “bonus ready to withdraw” is bait.
The text scam routes to expect
A text scam has a handful of storylines, and each one ends at the same place: your login or your code. Match yours to the right-hand column.
| What the text says | What it wants |
|---|---|
| Your casino account is locked or suspended | Your password on a copied login page |
| A deposit or withdrawal needs “confirming” | Your wallet or bank details |
| A wallet such as GCash or Maya is “limited” | Your wallet login and the code it sends |
| A prize or a “free” reward is waiting | A fee, or your details, before you can “collect” |
| A support agent offers to fix an issue | The code you just received |
The copied pages those links lead to are the subject of the phishing scam red flags page.
OTP scam: why a code is never for sharing
An OTP scam targets the one-time password that proves it is you. On the JILILUCK lobby, the registration form sends an SMS code only after you press Kunin ang code, and the code goes into the form you are filling in. The same logic applies to any wallet or bank: a code you did not just ask for means someone else is trying to log in as you, and a person asking you to read a code out is the thief.
- Stop. Do not reply and do not tap the link.
- If you did not request the code, someone has your password or is guessing it. Change the password in the real lobby or wallet at once.
- If you already read a code out, treat the account as taken and go to the account hacked first-hour steps.
- Add a second step that does not rely on SMS where the service allows it: the two step verification setup shows the options.
What to do with a text that links to a casino page
Do not use the link. Opening it is the risk, because the page may be a copy of the login screen.
- Type the lobby address into your browser yourself. The lobby opens at jililuck.com, and you can read the page checks on the phishing scam page.
- Log in there and look inside your account or the Customer Services menu for the matter the text mentions.
- If nothing is there, the text was bait. Customer Services in the lobby menu is the only support channel the Terms of Service recognise, and any other channel claiming to be support is fake.
- Delete the message and block the sender.
Texts that claim to be from a wallet
A wallet text is the same trick with a different logo. Open the wallet from its own program or an address you typed, and read the notice there. The e-wallet payment pages explain how Philippine wallets and banks move money, so you know which notices are normal and which are not.
A text says your wallet is limited and links to a login page
Do not tap it. Open the wallet yourself, check the message centre inside it, and contact the wallet through the support entry in its own screens.
You replied to a text with a code
Change the password of the account that code belongs to, then check its recent activity and follow the account hacked steps.
FAQ
What does smishing mean?
It is phishing by SMS. The word joins SMS and phishing: a text message built to make you open a link, enter details or read out a one-time code.
Should I ever read an SMS code to a caller or a chat agent?
No. A code you asked for is for you to type into the page you are on. Anyone who asks you to read it out is trying to use it on their own screen.
May text galing sa casino na may link, safe ba?
Treat it as unproven. Do not tap the link. Type the lobby address yourself, log in there, and look for the matter inside your account or in Customer Services.
Can I report a text scam?
Yes. Keep the message, block the number and report it through the channel of the wallet, bank or network involved; read the steps on their own support pages.